IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 147 matching records.
AUTO-POLL // 2026-10-02 23:40 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P7 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-09-15 11:12 UTC
Security Journalism

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 12:25 UTC

Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that's designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per F5 Labs. The

Cloud SecurityMicrosoftSecurity Research
P0
2026-09-15 07:48 UTC
Other

Telegram Desktop Flaw Could Turn Old Chat Exports Into Data Theft Traps

Security Affairs · Pierluigi Paganini · indexed 2026-09-15 09:00 UTC

A Telegram Desktop flaw let bots inject JavaScript into exported chats, enabling data theft and page manipulation. Old HTML exports remain unsafe. A vulnerability in Telegram Desktop could have turned an ordinary chat export into a serious data leak. Security researchers Denis and Aleksander Rostilov of ExPatch found a stored cross-site scripting flaw in the […]

Data BreachesSecurity ResearchVulnerabilities
P0
2026-09-14 17:58 UTC
Security Journalism

Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 19:45 UTC

A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12. In Telegram, the message looked ordinary, with a link button, and the script ran only when someone opened the export file in a web browser. It could then copy every message in that file to

Security Research
P0
2026-09-09 07:53 UTC
Other

Chaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-09 08:30 UTC

The researcher Chaotic Eclipse released ShieldCrash, a PoC exploit for a Microsoft Defender Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher named the exploit ShieldCrash, it triggers an arbitrary file read as SYSTEM. The researcher claims that Microsoft has not fully […]

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-09 06:47 UTC
Security Journalism

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 09:30 UTC

The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic

MicrosoftSecurity ResearchVulnerabilitiesCVE-2026-69414
P30
2026-09-08 14:19 UTC
Security Journalism

ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 15:20 UTC

Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel

Security Research
P0
2026-09-08 11:01 UTC
Vendor Research

CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

Rapid7 · Stephen Fewer · indexed 2026-09-08 12:25 UTC

OverviewWhile conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server.CVE IDDescriptionCWECVSSv4CVE-2026-86206Semicolon/Forwarded access-control bypassCWE-791…

MicrosoftSecurity ResearchVulnerabilitiesCVE-2026-18577CVE-2026-86206CVE-2026-86207
P15
2026-09-08 08:43 UTC
Security Journalism

BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 10:00 UTC

Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect

DFIRMalwareSecurity Research
P0
2026-09-07 18:12 UTC
Security Journalism

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 18:40 UTC

Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences

MalwareSecurity Research
P0
2026-09-07 13:42 UTC
Other

Chaotic Eclipse Released GreenSection, A PoC For NVIDIA Memory Corruption Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-09 08:30 UTC

Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher named the exploit GreenSection, it triggers a Memory Corruption flaw. The researcher disclosed a potential security vulnerability in NVIDIA’s Windows user-mode components. […]

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-07 13:42 UTC
Other

Chaotic Eclipse Released A PoC For NVIDIA GreenSection Memory Corruption Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-07 14:40 UTC

Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia GreenSection Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher named the exploit GreenSection, it triggers a Memory Corruption flaw. The researcher disclosed a potential security vulnerability in NVIDIA’s Windows user-mode […]

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-07 11:36 UTC
Security Journalism

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 13:00 UTC

Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake

PhishingSecurity Research
P0
2026-09-07 07:53 UTC
Security Journalism

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 08:35 UTC

Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a

MalwarePhishingSecurity Research
P0
2026-09-04 15:57 UTC
Security Journalism

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 16:10 UTC

Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The

MicrosoftPhishingSecurity Research
P0
2026-09-04 06:47 UTC
Security Journalism

GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 08:40 UTC

OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under its Preparedness Framework. "Astra is state-of-the-art on computer use, browsing, software engineering,

AI SecuritySecurity Research
P0
2026-09-03 15:26 UTC
Security Journalism

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC

Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial

CybercrimeMalwareMicrosoftSecurity Research
P0
2026-09-03 09:52 UTC
Other

Chaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlank

Security Affairs · Pierluigi Paganini · indexed 2026-09-03 10:40 UTC

Chaotic Eclipse released FalconFlank, a PoC exploit for a Crowdstrike Falcon ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Crowdstrike Falcon cybersecurity platform. The researcher named the exploit FalconFlank, it triggers a privilege escalation flaw. According to the researcher, FalconFlank abuses […]

Security ResearchVulnerabilities
P35
2026-09-03 06:26 UTC
Security Journalism

Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 06:45 UTC

The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a proof-of-concept (PoC) for a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0-day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in

Security ResearchVulnerabilities
P35
2026-09-02 12:22 UTC
Security Journalism

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 13:45 UTC

Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices. ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union

MalwareMobile SecuritySecurity Research
P0
2026-09-01 14:33 UTC
Other

Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague

Security Affairs · Pierluigi Paganini · indexed 2026-09-01 14:40 UTC

Chaotic Eclipse released PrettyPrague, a PoC exploit for a GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting GenDigital Avast Antivirus. The researcher named the exploit PrettyPrague, it triggers a privilege escalation flaw. The researcher claims to have found […]

Security ResearchVulnerabilities
P35
2026-09-01 14:07 UTC
Security Journalism

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 14:45 UTC

Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. "The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect

AppleCybercrimeSecurity Research
P0
2026-09-01 09:34 UTC
Other

Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher

Security Affairs · Pierluigi Paganini · indexed 2026-09-01 10:20 UTC

Chaotic Eclipse released HardBreacher, a PoC exploit for a Kaspersky Endpoint Security privilege escalation flaw, adding another zero-day to his list. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Kaspersky Endpoint Security. The researcher named the exploit HardBreacher, it triggers a privilege escalation flaw. Nightmare Eclipse […]

Security ResearchVulnerabilities
P35
2026-09-01 08:26 UTC
Security Journalism

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 08:55 UTC

Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in a series of posts on X, is to deliberately trip a large language model's (LLM) safety mechanisms and prevent its

AI SecurityMalwareSecurity ResearchThreat Actors
P0
2026-08-31 17:07 UTC
Vendor Research

GCP Apigee PE to Service Agent with API Proxy

Tenable Research Advisories · Joshua Martinelle · indexed 2026-08-31 19:05 UTC

GCP Apigee PE to Service Agent with API Proxy Tenable Research has identified and responsibly disclosed a privilege escalation vulnerability in Google Cloud Apigee. This vulnerability allowed an attacker with restricted Apigee permissions to exfiltrate the OAuth access token of the privileged Apigee Core Service Agent.The vulnerability stems from Apigee API Proxies' ability to execute custom JavaScript policy scripts that can access the underlying Instance Metadata Service (IMDS).An attacker wi…

Cloud SecuritySecurity ResearchVulnerabilities
P10
2026-08-29 11:55 UTC
Other

Hack One Robot, Reach the Next: Unitree G1 Security Flaws

Security Affairs · Pierluigi Paganini · indexed 2026-08-29 12:50 UTC

A researcher chained two Unitree G1 flaws to gain root access remotely and showed how a compromised robot could attack others nearby. Security researcher Olivier Laflamme spent about three months digging into the Unitree G1 humanoid robot and eventually found a way to fully compromise it without plugging in a single cable. In his technical […]

Cloud SecuritySecurity Research
P0
1 2 3 4