IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 147 matching records.
AUTO-POLL // 2026-10-02 23:40 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P7 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-08-28 15:27 UTC
Security Journalism

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 15:45 UTC

Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active

MicrosoftSecurity Research
P0
2026-08-28 12:07 UTC
Security Journalism

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 13:15 UTC

Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the first involving a network-adjacent path through chat_go and bashrunner and the

Cloud SecuritySecurity ResearchVulnerabilitiesCVE-2026-76639CVE-2026-76640
P20
2026-08-28 08:20 UTC
Security Journalism

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 08:40 UTC

Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocumented backdoor dubbed HOOKEDGE, a lightweight Windows batch script that's distributed via

APT / Nation-StateMalwareMicrosoftSecurity Research
P0
2026-08-27 13:39 UTC
Security Journalism

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 15:05 UTC

Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindgard. The latest version of

AI SecurityMicrosoftSecurity ResearchVulnerabilities
P0
2026-08-26 15:35 UTC
Security Journalism

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 17:50 UTC

Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka

APT / Nation-StateMalwareSecurity Research
P0
2026-08-26 13:44 UTC
Security Journalism

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 14:20 UTC

Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process. In a report shared with The Hacker News ahead of publication, Island characterized the $320/month service as a subscription-based phishing platform that

MicrosoftPhishingSecurity Research
P0
2026-08-26 05:47 UTC
Security Journalism

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 07:10 UTC

Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures across

ApplePhishingSecurity Research
P0
2026-08-25 11:52 UTC
Security Journalism

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 12:45 UTC

Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the

MalwarePhishingSecurity ResearchThreat Actors
P0
2026-08-25 11:33 UTC
Security Journalism

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 12:45 UTC

Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the development

MalwareSecurity ResearchThreat Actors
P0
2026-08-24 17:41 UTC
Security Journalism

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 23:15 UTC

Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs,

MalwareSecurity Research
P0
2026-08-24 12:35 UTC
Security Journalism

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 14:05 UTC

Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha)

MalwareMicrosoftPhishingRansomwareSecurity Research
P15
2026-08-24 11:51 UTC
Security Journalism

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 12:10 UTC

Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seqrite Labs. The activity is assessed to be the work of a China-nexus threat actor with moderate

APT / Nation-StateMalwareSecurity ResearchThreat Actors
P0
2026-08-24 08:08 UTC
Security Journalism

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 08:45 UTC

Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open

CybercrimeLinuxMalwareMicrosoftSecurity Research
P0
2026-08-24 07:17 UTC
Other

iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset

Security Affairs · Pierluigi Paganini · indexed 2026-08-24 07:35 UTC

iAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets. Abnormal Security researchers have published an analysis of iAuthFlow v2, a phishing toolkit sold on a Russian-language cybercrime forum for $10,000 base price. The author also offers for sale additional capability modules separately. The headline feature is […]

CybercrimePhishingSecurity Research
P0
2026-08-21 18:53 UTC
Security Journalism

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-21 20:30 UTC

Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. "When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process," TrendAI, Trend Micro's

AI SecurityLinuxMalwareSecurity Research
P0
2026-08-21 15:41 UTC
Security Journalism

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-21 16:40 UTC

Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet. "The malware spread through the built-in updaters of

CybercrimeMalwareMobile SecuritySecurity Research
P0
2026-08-20 21:35 UTC
Vendor Research

Unanchored ACCOUNT_ID webhook filters for CodeBuild

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-002-AWS Scope: AWS Content Type: Informational Publication Date: 2026/01/15 07:03 AM PST Description: A security research team identified a configuration issue affecting the following AWS-managed open source GitHub repositories that could have resulted in the introduction of inappropriate code: - aws-sdk-js-v3 - aws-lc - amazon-corretto-crypto-provider - awslabs/open-data-registry Specifically, researchers identified the above repositories' configured regular expressions for A…

Cloud SecuritySecurity Research
P0
2026-08-20 13:48 UTC
Security Journalism

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 14:30 UTC

Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment. The vulnerability ("GHSA-864f-rcv7-6rh4"), which has yet to be assigned a CVE identifier, impacts all versions of the library before and including 7.0.0.

Security ResearchVulnerabilities
P15
2026-08-20 11:39 UTC
Security Journalism

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 13:15 UTC

Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a low-bandwidth request stream by up to 350x against the origin server. The attacks, collectively named "CDN Tsunami," were evaluated against Alibaba, Baidu,

Security Research
P0
2026-08-20 11:05 UTC
Security Journalism

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 11:15 UTC

Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrument command bus. The chain, tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 on the CVSS v3.1 scoring system, impacts AIT-GUI

Cloud SecuritySecurity ResearchVulnerabilities
P0
2026-08-20 10:38 UTC
Security Journalism

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 11:15 UTC

Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its targeting footprint globally. Zimperium zLabs, in a Wednesday report, said the Android malware also features a PIN harvesting workflow targeting more than 140 banking and cryptocurrency applications.

CybercrimeMalwareMobile SecuritySecurity Research
P0
2026-08-20 06:04 UTC
Security Journalism

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 06:15 UTC

Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. "The flaw lives in the Forms module's File

Security ResearchVulnerabilitiesCVE-2026-32475
P30
2026-08-19 19:02 UTC
Security Journalism

Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 19:55 UTC

Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstrated in 2021. The end-to-end experiment used an attacker Worker and a victim Worker controlled by the researchers,

Security Research
P0
2026-08-19 11:34 UTC
Security Journalism

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 13:35 UTC

Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed working directory containing 2,616 files

Cloud SecuritySecurity Research
P0
2026-08-19 11:25 UTC
Security Journalism

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 11:35 UTC

Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity. "The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software

CybercrimeMalwareSecurity Research
P0
2026-08-18 17:05 UTC
Other

Project noRecognition: Teaching AI to Fool Surveillance Cameras

Security Affairs · Pierluigi Paganini · indexed 2026-08-18 18:10 UTC

Researchers tested 31 million patterns to disrupt surveillance AI, with promising results but significant gaps between simulation and real-world use. The Kansas City-based cybersecurity researcher Bill Swearingen spent the past year doing something that sounds almost too simple to work: printing patterns, watching cameras fail to detect them, and repeating. TechCrunch reports that after roughly […]

Security Research
P0
1 2 3 4 5