IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 147 matching records.
AUTO-POLL // 2026-10-02 23:40 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P7 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-10-01 14:37 UTC
Security Journalism

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 14:50 UTC

Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's

MalwareSecurity ResearchThreat Actors
P0
2026-10-01 08:04 UTC
Other

AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds

Security Affairs · Pierluigi Paganini · indexed 2026-10-01 08:10 UTC

DIVD was breached through two Zammad zero-days that let an AI agent reach root in seconds, steal data and pivot to other services before being stopped. The Dutch Institute for Vulnerability Disclosure, a nonprofit organization of volunteer security researchers whose whole job is finding and responsibly disclosing vulnerabilities in other people’s software, just disclosed that […]

AI SecuritySecurity ResearchVulnerabilities
P25
2026-10-01 05:54 UTC
Security Journalism

Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 07:20 UTC

Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working

AppleSecurity ResearchVulnerabilitiesCVE-2026-86950
P5
2026-09-30 16:46 UTC
Security Journalism

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 17:55 UTC

Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol

MicrosoftSecurity ResearchThreat ActorsVulnerabilitiesCVE-2026-73570
P20
2026-09-30 05:30 UTC
Security Journalism

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 07:00 UTC

Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler

Security ResearchVulnerabilitiesCVE-2026-88772
P25
2026-09-29 13:45 UTC
Security Journalism

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 15:25 UTC

Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical

Security Research
P0
2026-09-28 11:46 UTC
Security Journalism

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 12:40 UTC

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through

AI SecurityMalwareSecurity Research
P0
2026-09-25 13:18 UTC
Security Journalism

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 16:10 UTC

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material

AppleMalwareSecurity Research
P0
2026-09-24 06:32 UTC
Security Journalism

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 08:35 UTC

Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses. "The campaign compromised 7 accounts –

Cloud SecurityMicrosoftSecurity Research
P0
2026-09-23 18:06 UTC
Security Journalism

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 20:00 UTC

Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terraform providers and Go modules is below - gocommunity-io/dockerd (222 downloads) kreuzwenker/

MalwareMicrosoftSecurity ResearchThreat Actors
P0
2026-09-23 08:43 UTC
Vendor Research

CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM

Rapid7 · Rapid7 · indexed 2026-09-23 09:30 UTC

OverviewOn September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted traffic.BIG-IP APM provides identity-aware access control for applications and other corporate resources …

Security ResearchVulnerabilitiesCVE-2026-94127
P50
2026-09-22 17:58 UTC
Security Journalism

Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 19:25 UTC

Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data. The package, named "tw-pkgprobe-7731," was first uploaded to the npm registry in mid-August 2026 by an npm account named "twdepprobe7731."

Security Research
P0
2026-09-22 16:14 UTC
Security Journalism

Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 17:55 UTC

A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used in

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-22 14:04 UTC
Other

Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-22 14:10 UTC

The researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender Update DoS Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher named the exploit BigDiskBuster, it triggers a Denial of Service Vulnerability in Windows Defender Update. The security researcher […]

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-22 11:17 UTC
Security Journalism

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 12:10 UTC

A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been

MicrosoftSecurity ResearchVulnerabilitiesCVE-2026-65660
P20
2026-09-22 06:33 UTC
Security Journalism

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 06:55 UTC

Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta. The flaw is in

MalwareSecurity Research
P0
2026-09-21 14:15 UTC
Security Journalism

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-21 14:45 UTC

Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor "automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary

MalwareSecurity Research
P0
2026-09-21 10:33 UTC
Community

TerminalFix: PNG Steganography, (Mon, Sep 21st)

SANS Internet Storm Center · indexed 2026-09-21 10:30 UTC

Microsoft Security Research published an interesting blog post "TerminalFix campaign deploys a reverse tunnel through multistage intrusion" about a malware campaign. The aspect that I want to take a closer look at, is the fact that the threat actors used PNG files with steganography. I reached out to the researchers and they kindly shared the IOCs for the PNG files with me.

MalwareMicrosoftSecurity ResearchThreat ActorsThreat Intelligence
P0
2026-09-21 08:27 UTC
Other

The Target Is No Longer the Model. It’s the Agent.

Security Affairs · Pierluigi Paganini · indexed 2026-09-21 09:25 UTC

AI agents are becoming the new attack surface, exposed to poisoned skills, prompt injection, jailbreaks and attacks through connected tools. I read the AI security research published in a single month, February 2026, and when you put it all together, it’s not a list of curiosities. It’s a field guide to a new attack surface. […]

AI SecurityAppleSecurity Research
P0
2026-09-19 18:36 UTC
Security Journalism

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-19 11:30 UTC

Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system. This was security research,

Cloud SecuritySecurity Research
P0
2026-09-18 18:02 UTC
Security Journalism

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 20:25 UTC

A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is now public, and any machine still running an older kernel should be updated. The flaws

Cloud SecurityLinuxSecurity Research
P0
2026-09-18 10:40 UTC
Security Journalism

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 11:00 UTC

Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and

MalwareSecurity Research
P0
2026-09-18 06:17 UTC
Security Journalism

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 06:30 UTC

Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. "Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses

AI SecurityMalwareMobile SecurityPhishingSecurity ResearchThreat Actors
P0
2026-09-17 10:05 UTC
Security Journalism

China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. "SparroWocky is a modular, C++ backdoor," ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News

APT / Nation-StateMalwareSecurity ResearchThreat Actors
P0
2026-09-16 14:36 UTC
Security Journalism

One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 16:25 UTC

Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension. Once the extension was installed, it could access each product's built-in AI with a single click. On Comet, Edge,

MicrosoftSecurity Research
P0
2026-09-15 18:54 UTC
Security Journalism

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 19:10 UTC

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

MalwareSecurity ResearchThreat Actors
P0
2026-09-15 15:23 UTC
Security Journalism

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 15:50 UTC

Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America.

LinuxMalwareMicrosoftSecurity Research
P0
1 2 3