IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 131 matching records.
AUTO-POLL // 2026-10-02 22:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P6
P6
COOL // 45 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-09-30 14:16 UTC
Vendor Research

Higher education is under siege, and fragmented security is making it harder to respond

Rapid7 · Rapid7 · indexed 2026-09-30 15:05 UTC

Higher education faces a difficult security equation. Universities hold large volumes of sensitive student, financial, health, and research data while supporting open networks, distributed users, legacy infrastructure, and increasingly complex cloud environments. Attackers have taken notice, and the pressure on security teams continues to grow.In Q2 2025, universities faced an average of 4,388 cyberattacks per organization per week, up 24% from the same period in 2024. Nine in ten universities …

Data BreachesDFIRMalwareMicrosoftRansomwareThreat IntelligenceVulnerabilities
P40
2026-09-30 14:00 UTC
Vendor Research

Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570

Microsoft Security Blog · Microsoft Security Research, Mahesh Mandava and Rajesh Kumar Natarajan · indexed 2026-09-30 15:00 UTC

Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation guidance. The post Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 appeared first on Microsoft Security Blog.

MicrosoftThreat IntelligenceVulnerabilitiesCVE-2026-73570
P5
2026-09-30 14:00 UTC
Vendor Research

Vulnerability Discovery and Exploitation Trends in the AI Era

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-30 14:45 UTC

Written by: Robin Grunewald, Supriya Mazumdar, Kelli Vanderlee Introduction Google Threat Intelligence Group (GTIG) examines vulnerability disclosure and exploitation statistics to evaluate the impact of artificial intelligence (AI) on the vulnerability threat landscape. We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered. Key findings: Vulnerability discl…

AI SecurityCloud SecurityLinuxMicrosoftNetwork SecurityThreat ActorsThreat IntelligenceVulnerabilities
P60
2026-09-30 08:24 UTC
Security Journalism

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 09:55 UTC

Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional

Threat ActorsThreat Intelligence
P0
2026-09-30 07:25 UTC
Other

WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign

Security Affairs · Pierluigi Paganini · indexed 2026-09-30 07:50 UTC

Mandiant and GTIG detail active exploitation of a Citrix NetScaler zero-day, deploying custom web shells WHIPSHOT and SLAPSHOT for root access. Mandiant and Google Threat Intelligence Group caught active exploitation of a zero-day in Citrix NetScaler ADC and Gateway appliances in late September 2026. The bug, tracked as CVE-2026-88772 (CVSS score of 9.5), has been […]

Threat IntelligenceVulnerabilitiesCVE-2026-88772
P30
2026-09-29 14:00 UTC
Vendor Research

Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-29 14:00 UTC

Introduction In late September 2026, Mandiant Consulting and Google Threat Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gateway appliances. We have observed evidence that organizations in North America and Europe in the government, financial services, technology, education, and legal and professional services sectors were likely impacted by this exploitation campaign, which has bee…

LinuxMalwareMicrosoftNetwork SecurityPhishingThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-88771CVE-2026-88772
P30
2026-09-29 13:00 UTC
Vendor Research

Introducing Threat Signals: agentic skills for open-source threat intelligence, free for every Cloudflare account

Cloudflare Security · Emilia Yoffie · indexed 2026-09-29 13:20 UTC

We are expanding access to Cloudforce One's Threat Events Platform to every Cloudflare account and introducing Threat Signals. Threat Signals automatically parses open-source threat reporting, extracts structured indicators, and connects threat context directly to your WAF rules.

Threat Intelligence
P0
2026-09-28 15:00 UTC
Vendor Research

NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-09-28 16:30 UTC

Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations. The post NeedyMantis: Unpacking a post-compromise malware family used in targeted operations appeared first on Microsoft Security Blog.

MalwareMicrosoftThreat Intelligence
P0
2026-09-28 13:55 UTC
Other

28th September – Threat Intelligence Report

Check Point Research · urias@checkpoint.com · indexed 2026-09-28 14:15 UTC

For the latest discoveries in cyber research for the week of 28th September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The FBI has confirmed unauthorized activity affecting FBIjobs.gov after the ShinyHunters group defaced the website. The group claimed to have stolen employee and applicant information and shared samples of purported FBI personnel […] The post 28th September – Threat Intelligence Report appeared first on Check Point Research.

Law EnforcementThreat Intelligence
P0
2026-09-28 10:05 UTC
Vendor Research

Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772

Rapid7 · Rapid7 · indexed 2026-09-28 10:25 UTC

OverviewOn September 27, 2026, Citrix disclosed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including two critical remote code execution (RCE) vulnerabilities: CVE-2026-88771 and CVE-2026-88772. Both of these RCE vulnerabilities carry a critical CVSSv4 score of 9.5, and both have been confirmed as being actively exploited in the wild as zero-days prior to the vendor disclosure. CVE-2026-88771 affects vulnerable NetScaler deployments in their default configuration, w…

Network SecurityThreat IntelligenceVulnerabilitiesCVE-2026-88771CVE-2026-88772CVE-2026-887729CVE-2026-887739
P95
2026-09-27 05:35 UTC
Vendor Research

Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities

Tenable Blog · Satnam Narang · indexed 2026-09-27 10:00 UTC

CVE-2026-88771 and CVE-2026-88772, two zero-day vulnerabilities in Citrix NetScaler, have been confirmed as exploited in the wild. Citrix released patches on September 27, 2026.Change logUpdate September 27: Citrix published security bulletin CTX697096, confirming CVE-2026-88771 and CVE-2026-88772 as the two zero-day RCE vulnerabilities and releasing patches. Post updated with CVE IDs, CVSS scores, patch versions, and IoC guidance.Click here to review the change log historyUpdate September 27: …

APT / Nation-StateCloud SecurityNetwork SecurityRansomwareThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2023-6549CVE-2025-6543CVE-2026-19489CVE-2026-19490CVE-2026-88771CVE-2026-88772
P95
2026-09-26 07:48 UTC
Security Journalism

Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-26 10:05 UTC

Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. "Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, Chief

Threat ActorsThreat Intelligence
P0
2026-09-25 14:00 UTC
Vendor Research

ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-26 06:55 UTC

Introduction As an update to the June 2026 post, ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit, Mandiant and Google Threat Intelligence Group (GTIG) have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), along with expanded global targeting across multiple sectors. In June, the threat actor exploited this vulnerability as a zero-day predominantly against academic institutions. This new wave of activity stems from UNC6240 modifying its explo…

LinuxMicrosoftNetwork SecurityThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-35273
P50
2026-09-24 06:24 UTC
Other

No One Gets Phished: The New Group-IB Browser Agent Applies Predictive Intelligence At The Click

Group-IB · indexed 2026-09-24 09:10 UTC

One employee reaches a phishing page. The tab closes, the domain is blocked for every browser in the company, and the targeted password is already being reset. The new Group-IB Browser Agent brings the corporate browser under XDR coverage, checking every page against predictive Threat Intelligence in real time.

PhishingThreat Intelligence
P0
2026-09-21 23:13 UTC
Other

21st September – Threat Intelligence Report

Check Point Research · urias@checkpoint.com · indexed 2026-09-21 23:20 UTC

For the latest discoveries in cyber research for the week of 21st September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Japan’s Digital Agency, which operates the Government Solution Service used by multiple ministries, has confirmed a data breach after attackers exploited a vulnerability in a VPN appliance. Approximately 246,000 records were exposed, […] The post 21st September – Threat Intelligence Report appeared first on Check Point Research.

Data BreachesNetwork SecurityThreat IntelligenceVulnerabilities
P0
2026-09-21 10:33 UTC
Community

TerminalFix: PNG Steganography, (Mon, Sep 21st)

SANS Internet Storm Center · indexed 2026-09-21 10:30 UTC

Microsoft Security Research published an interesting blog post "TerminalFix campaign deploys a reverse tunnel through multistage intrusion" about a malware campaign. The aspect that I want to take a closer look at, is the fact that the threat actors used PNG files with steganography. I reached out to the researchers and they kindly shared the IOCs for the PNG files with me.

MalwareMicrosoftSecurity ResearchThreat ActorsThreat Intelligence
P0
2026-09-17 07:20 UTC
Other

HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack

Group-IB · indexed 2026-09-17 08:35 UTC

Group-IB Threat Intelligence analyzes HEAVYGRAM, a Telegram-based Windows backdoor attributed with moderate confidence to the Iran-linked threat actor Handala Hack. Active since Fall 2023, it has been used to surveil Iranian dissidents, journalists and government opponents, enabling remote command execution, data exfiltration, and persistence over Telegram command-and-control.

MalwareMicrosoftThreat ActorsThreat Intelligence
P0
2026-09-16 11:15 UTC
Security Journalism

Threat Intelligence Alone Won't Close the Exploitation Gap

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 11:45 UTC

A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most security programs are built to react.

Threat IntelligenceVulnerabilities
P0
2026-09-14 18:01 UTC
Security Journalism

3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 19:45 UTC

An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of

MalwareMicrosoftThreat Intelligence
P0
2026-09-14 12:22 UTC
Other

14th September – Threat Intelligence Report

Check Point Research · urias@checkpoint.com · indexed 2026-09-14 12:30 UTC

For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data included names and government identification numbers, while a criminal marketplace advertised a […] The post 14th September – Threat Intelligence Report appeared first on Check Point Research.

Data BreachesThreat Intelligence
P0
2026-09-11 13:33 UTC
Vendor Research

The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

Rapid7 · Gal Givon · indexed 2026-09-11 15:05 UTC

IntroductionThe surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web channels, and various smaller niche marketplaces. Security teams today face evolving challenges, requiring them to continuously refine monitoring channels, adjust operational strategies, and foster cross-functional internal …

CybercrimeMalwarePhishingThreat ActorsThreat Intelligence
P0
2026-09-10 05:35 UTC
Other

Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days

Security Affairs · Pierluigi Paganini · indexed 2026-09-10 06:35 UTC

Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state actors adopted within roughly two weeks of the first observed use. Google’s Threat Intelligence Group, Microsoft’s MSTIC, and Volexity all contributed to […]

APT / Nation-StateMicrosoftThreat IntelligenceVulnerabilities
P25
2026-09-08 14:00 UTC
Vendor Research

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-08 13:45 UTC

Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, b…

AI SecurityAPT / Nation-StateCloud SecurityData BreachesDFIRMalwareMicrosoftPhishingRansomwareThreat ActorsThreat IntelligenceVulnerabilities
P35
2026-09-08 13:48 UTC
Security Journalism

Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 15:20 UTC

Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI

AI SecurityPhishingThreat ActorsThreat Intelligence
P0
2026-09-08 10:00 UTC
Vendor Research

StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day

Tenable Cyber Exposure Alerts · Satnam Narang · indexed 2026-09-08 14:20 UTC

A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available.Key takeawaysCVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication.Active exploitation of CVE-2026-75650 began on September 4, 2026, t…

DFIRLinuxMalwareThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-75650
P95
2026-09-07 14:54 UTC
Other

7th September – Threat Intelligence Report

Check Point Research · urias@checkpoint.com · indexed 2026-09-07 17:30 UTC

For the latest discoveries in cyber research for the week of 7th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Thomson Reuters, a global information and technology company, has disclosed a breach of its C-Track court case-management platform affecting courts across 11 US states and Canada. An unauthorized party obtained C-Track files […] The post 7th September – Threat Intelligence Report appeared first on Check Point Research.

Threat Intelligence
P0
2026-09-04 11:00 UTC
Other

Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign

Security Affairs · Pierluigi Paganini · indexed 2026-09-04 11:10 UTC

Hunt.io uncovered a Chinese-speaking campaign using AI agents to automate cyberattacks against Asian government, education and industrial targets. Threat intelligence firm Hunt.io just documented a second, separate China-linked campaign wiring commercial AI models directly into live cyberespionage operations, this time hitting Taiwan’s Kuomintang Party archives, Indonesia’s Ministry of Foreign Affairs, government and education systems in […]

AI SecurityAPT / Nation-StateThreat Intelligence
P0
1 2 3