IntelFreed Cybersecurity Intelligence Weather Report

HIGH PRIORITY

Aggregated cybersecurity reporting, advisories and research. 330 matching records.
AUTO-POLL // 2026-10-03 01:55 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 3
NO DATA
--
NO INTEL
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
RESET
2026-08-15 17:14 UTC
Other

SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild

Security Affairs · Pierluigi Paganini · indexed 2026-08-16 18:35 UTC

Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch. A critical SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231 (CVSS score of 10.0), is under active exploitation just days after SAP released a patch. The flaw stems from insufficient authorization checks and input validation. […]

VulnerabilitiesCVE-2026-58231
P25
2026-08-15 07:24 UTC
Security Journalism

Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC-NL) has warned. The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a critical authentication issue impacting the Screen Sharing component that could allow an attacker already on the network to

AppleVulnerabilitiesCVE-2026-65400
P25
2026-08-15 07:18 UTC
Other

GeoServer Zero-Day Is Already Being Probed. That’s the Problem

Security Affairs · Pierluigi Paganini · indexed 2026-08-16 18:35 UTC

GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed GeoServer zero-day is already attracting active exploitation attempts, and there is no patch available yet. Organisations running the open-source geospatial platform should check their exposure. A security researcher with the handler q1uf3ng discloded the vulnerability […]

Security ResearchVulnerabilities
P25
2026-08-12 17:39 UTC
Security Journalism

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and

APT / Nation-StateMalwareMicrosoftThreat ActorsVulnerabilities
P25
2026-08-12 06:15 UTC
Security Journalism

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is a case of insufficient error checking when processing HTTP requests that could allow an unauthenticated, remote attacker to trigger

Network SecurityVulnerabilitiesCVE-2026-20349
P25
2026-08-11 21:28 UTC
Independent Research

Microsoft Plugs Nearly 400 Security Holes

Krebs on Security · BrianKrebs · indexed 2026-08-15 14:33 UTC

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

Microsoft
P25
2026-08-11 17:30 UTC
Other

Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

Check Point Research · matthewsu · indexed 2026-09-07 17:30 UTC

Key Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviation industries. We observed the threat actor distributing modified PDF viewers designed to execute malicious payloads embedded within specially […] The post Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack appeared first on Chec…

Threat ActorsVulnerabilities
P25
2026-08-11 13:11 UTC
Security Journalism

OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. "Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding zero-day vulnerabilities and developing exploit chains) and to reduce refusals for certain higher-risk

DFIRVulnerabilities
P25
2026-08-10 15:00 UTC
Security Journalism

⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place. That’s only part of it. Here’s

MalwareNetwork SecurityVulnerabilities
P25
2026-08-07 10:09 UTC
Security Journalism

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate desync vectors. PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where

AI SecurityVulnerabilities
P25
2026-08-05 12:45 UTC
Vendor Research

Tenable Hexa AI: Automating exposure remediation with agentic routines

Tenable Blog · Ziga Cerkovnik · indexed 2026-08-15 18:55 UTC

Discover how Tenable Hexa AI closes the gap between exposure management and endpoint patching using intent-driven routines, smart guardrails, and human approval.Key takeawaysThe problem: A slow handoff between security workflows creates a days-long remediation gap. The solution: Tenable Hexa AI bridges this gap using intent-driven Routines that automate scoping, deployment, and verification across integrated platforms like Jamf. Safety and control: Autonomy is governed by the harness built into…

AppleVulnerabilities
P25
2026-08-04 13:00 UTC
Vendor Research

The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software

Palo Alto Networks Unit 42 · Xu Zou · indexed 2026-08-15 18:55 UTC

Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain. The post The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software appeared first on Unit 42.

Vulnerabilities
P25
2026-07-08 12:31 UTC
Independent Research

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Krebs on Security · BrianKrebs · indexed 2026-08-15 14:33 UTC

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.

CybercrimeVulnerabilities
P25
2026-02-26 18:38 UTC
Government

2026-002: Multiple Vulnerabilities in Cisco Products

CERT-EU Security Advisories · indexed 2026-08-15 18:50 UTC

On 25 February 2026, Cisco released security advisories addressing multiple high and critical severity vulnerabilities in Cisco Catalyst SD-WAN controllers and Cisco SD-WAN Manager. If exploited, these vulnerabilities could allow attackers to gain administrative access to compromised systems. It is recommended to capture forensic evidence, hunt for indicators of compromise, and apply updates as soon as possible. One of the vulnerabilities, CVE-2026-20127, is exploited in the wild since 2023.

VulnerabilitiesCVE-2026-20127
P25
2025-11-13 16:59 UTC
Vendor Research

Rust in Android: move fast and fix things

Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC

Posted by Jeff Vander Stoep, Android Last year, we wrote about why a memory safety strategy that focuses on vulnerability prevention in new code quickly yields durable and compounding gains. This year we look at how this approach isn’t just fixing things, but helping us move faster. The 2025 data continues to validate the approach, with memory safety vulnerabilities falling below 20% of total vulnerabilities for the first time. Updated data for 2025. This data covers first-party and third-party…

LinuxMobile SecurityVulnerabilities
P25
2025-09-15 05:44 UTC
Other

Agneyastra to the Rescue: Protecting your Firebase Projects before the Tea spills out!

Red Hunt Labs · Bhavarth Karmarkar · indexed 2026-09-07 17:30 UTC

In July 2025, the Tea app 🔗, a mental health and social community platform, experienced a devastating breach that spilled 72,000 images (including 13,000 driver’s license and verification selfies) and over 1.1 million private direct messages onto the internet. The leaks first surfaced on 4chan and quickly spread across forums, torrents, and underground channels. This was not “just another API key leak.” Instead, it was a story about Firebase misconfigurations, poor data retention practices, an…

APT / Nation-StateSecurity ResearchVulnerabilities
P25
2023-04-19 00:00 UTC
Other

BrokenSesame

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

ApsaraDB and AnalyticDB contained several vulnerabilities in their PostgreSQL offerings which ultimately allowed unauthorized access to other tenants' databases and the ability to perform a supply-chain attack on both services, which in turn would have allowed remote code execution (RCE) as well. Both services implemented multi-tenancy through a shared K8s cluster, but contained several bugs related to tenant isolation which an attacker could chain together to achieve the above impact. In Apsar…

Vulnerabilities
P25
2023-03-23 00:00 UTC
Other

Azure Function Apps privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Undocumented APIs used by the Azure Function Apps Portal could have allowed an attacker with existing access to a Reader role on a Function App to escalate their privileges and gain write permissions through arbitrary file reads on Function App containers. For Windows containers, this would only grant an attacker the ability to extract ASP.NET encryption keys (the impact of which remains unclear), but for Linux containers it would have allowed an attacker to read environmental variables contain…

Cloud SecurityLinuxMicrosoftVulnerabilities
P25
2022-10-31 00:00 UTC
Security Journalism

ConnectWise/R1Soft RCE & Supply Chain Risks | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress has validated an initial report for an authentication bypass and sensitive file leak present in the Java framework “ZK”, used within the ConnectWise R1Soft software Server Backup Manager SE.

Vulnerabilities
P25
2022-08-17 00:00 UTC
Other

Remote Code Execution via GitHub Import

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A critical vulnerability in GitLab's GitHub import feature allows remote code execution. The issue stems from improper handling of Sawyer::Resource objects, enabling injection of Redis commands. This can be escalated to execute arbitrary bash commands on the SaaS managed service as well as self-hosted GitLab servers, potentially leading to full system compromise.

Vulnerabilities
P25
9 10 11