IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,418 matching records.
AUTO-POLL // 2026-10-02 21:55 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P6
P6
COOL // 45 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-10-01 16:55 UTC
Security Journalism

Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 17:15 UTC

Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site. Investigators identified him as KillSec's suspected

Law EnforcementRansomware
P15
2026-10-01 16:45 UTC
Security Journalism

ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 17:15 UTC

This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years. That is the lesson running through the list. Attackers do not always need a brilliant new trick. They can

Vulnerabilities
P40
2026-10-01 14:37 UTC
Security Journalism

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 14:50 UTC

Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's

MalwareSecurity ResearchThreat Actors
P0
2026-10-01 14:30 UTC
Security Journalism

Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass

Security Week · Kevin Townsend · indexed 2026-10-01 14:40 UTC

Rob Juncker is chief product and technology officer at Mimecast. Is he a hacker? “Unequivocally yes,” he says. The post Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass appeared first on SecurityWeek.

P0
2026-10-01 14:30 UTC
Security Journalism

Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says

Security Week · Kevin Townsend · indexed 2026-10-01 14:40 UTC

PwC’s survey found that only 22% of leaders would use fully autonomous AI for cyber defense, while just 21% are implementing quantum-resistant security measures. The post Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says appeared first on SecurityWeek.

P0
2026-10-01 14:17 UTC
Security Journalism

Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader

Security Week · Eduard Kovacs · indexed 2026-10-01 14:20 UTC

Police took control of KillSec’s leak site and secured at least 110 terabytes of data stolen from victims. The post Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader appeared first on SecurityWeek.

Ransomware
P15
2026-10-01 14:01 UTC
Security Journalism

The Day-One Hole in Zero Trust Architecture

BleepingComputer · Sponsored by Specops Software · indexed 2026-10-01 14:15 UTC

Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. Specops explains why identity verification should begin before credentials, MFA methods, and access are issued. [...]

P0
2026-10-01 14:00 UTC
Vendor Research

Preparing governments for an era of interconnected cyber risk

Microsoft Security Blog · Matthew Thomas · indexed 2026-10-01 14:40 UTC

According to this year’s Microsoft Digital Defense Report, government agencies and services were the sector most impacted by cyber threats in 2026, accounting for 27% of observed activity, up from 17% in 2025. The post Preparing governments for an era of interconnected cyber risk appeared first on Microsoft Security Blog.

Microsoft
P0
2026-10-01 14:00 UTC
Vendor Research

Insights from the 2026 Microsoft Digital Defense Report

Microsoft Security Blog · Terrell Cox · indexed 2026-10-01 14:40 UTC

Read highlights from the 2026 Microsoft Digital Defense Report, which reflects a security environment that continues to grow more interconnected. The post Insights from the 2026 Microsoft Digital Defense Report appeared first on Microsoft Security Blog.

Microsoft
P0
2026-10-01 13:51 UTC
Security Journalism

Kiteworks patches max severity code injection vulnerability

BleepingComputer · Sergiu Gatlan · indexed 2026-10-01 14:00 UTC

Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution. [...]

Vulnerabilities
P5
2026-10-01 13:33 UTC
Other

Inside Gemini 4 Argon, the model Google is testing on its own infrastructure first

Security Affairs · Pierluigi Paganini · indexed 2026-10-02 07:20 UTC

Google unveils Gemini 4 Argon, a frontier AI model built for coding, enterprise work, and autonomous cybersecurity defense, rolling out to trusted testers. Google announced Gemini 4 Argon, and it’s not going straight to the public. It’s rolling out first to a set of trusted cyber defenders through what Google calls the Fairwind Program, which […]

Microsoft
P0
2026-10-01 13:33 UTC
Other

Inside Gemini 4 Argon, the model Google is testing on its own infrastructure first

Security Affairs · Pierluigi Paganini · indexed 2026-10-01 14:40 UTC

Google unveils Gemini 4 Argon, a frontier AI model built for coding, enterprise work, and autonomous cybersecurity defense, rolling out to trusted testers. Google announced Gemini 4 Argon, and it’s not going straight to the public. It’s rolling out first to a set of trusted cyber defenders through what Google calls the Fairwind Program, which […]

Microsoft
P0
2026-10-01 13:15 UTC
Security Journalism

AI Has Changed Attack Speed, Not Security Fundamentals

Security Week · Joshua Goldfarb · indexed 2026-10-01 13:40 UTC

As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. The post AI Has Changed Attack Speed, Not Security Fundamentals appeared first on SecurityWeek.

Vulnerabilities
P0
2026-10-01 13:04 UTC
Vendor Research

One year later: Sovereign AI and the fight for choice

Cloudflare Security · Carly Ramsey · indexed 2026-10-01 13:20 UTC

AI sovereignty is not a zero-sum game, but many governments now believe it is. Cloudflare's answer: more local open-source models, model-agnostic security tools, and a commitment to giving nations genuine choice.

P0
2026-10-01 13:00 UTC
Vendor Research

How AI Is Changing the Roles Required in the Security Operations Center

Rapid7 · Rapid7 · indexed 2026-10-01 13:20 UTC

As AI takes on more of the enrichment, correlation, and initial assessment inside the SOC, roles, skills, and KPIs still require deliberate redesign. Security leaders need to decide where automation is dependable, where human judgment should remain decisive, and how teams should be measured when alert handling is no longer the center of the operating modelThe Gartner® report, The Roles Required for the AI-Enabled Security Operations Center (SOC), examines the roles and capabilities Gartner expe…

DFIRMicrosoft
P0
2026-10-01 12:08 UTC
Other

Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950

Security Affairs · Pierluigi Paganini · indexed 2026-10-01 12:40 UTC

Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks. A public PoC for the flaw is now available. Apple patched a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that attackers may have exploited to target specific individuals. The flaw is an out-of-bounds write that can lead to arbitrary code execution when […]

AppleVulnerabilitiesCVE-2026-86950
P30
2026-10-01 12:05 UTC
Other

Milk Dragon: Huge Discounts on Social Media? Think Twice Before You Buy

Group-IB · indexed 2026-10-01 14:20 UTC

Milk Dragon, also known as NaiLong is an Adversary-in-the-Middle (AiTM) phishing kit active since October 2025. Unlike conventional phishing tactics that rely on fear and urgency, Milk Dragon lures victims with big discounts on consumer goods distributed via Facebook and TikTok marketplace advertisements.

Phishing
P0
2026-10-01 12:05 UTC
Other

Milk Dragon: Huge Discounts on Social Media? Think Twice Before You Buy

Group-IB · indexed 2026-10-01 12:40 UTC

Milk Dragon, also known as NaiLong is an Adversary-in-the-Middle (AiTM) phishing kit active since October 2025. Unlike conventional phishing tactics that rely on fear and urgency, Milk Dragon lures victims with big discounts on consumer goods distributed via Facebook and TikTok marketplace advertisements.

Phishing
P0
2026-10-01 12:00 UTC
Government

Securing Water and Wastewater Operational Technology Environments

NIST Cybersecurity Insights · CheeYee Tang , Robert Stea, John Wiltberger · indexed 2026-10-01 13:15 UTC

Recent cyberattacks on the U.S. water and wastewater systems (WWS) sector are highlighting the escalating threat to our nation’s critical infrastructure and the practical challenges of securing it. These incidents underscore an important challenge: the connectivity that utilities depend upon must be designed and operated with security as a core priority rather than a secondary consideration. They also provide a critical insight — that effective cybersecurity protections require a broad-based un…

ICS / OT
P0
2026-10-01 11:45 UTC
Security Journalism

How Financial Services Companies Can Modernize Their Software Supply Chain

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 12:25 UTC

Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live. Somebody prices out the regression testing. Somebody else raises the change-freeze calendar. The finding gets an exception, a compensating control, and a date

P0
2026-10-01 11:40 UTC
Security Journalism

Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation

Security Week · Mike Lennon · indexed 2026-10-01 12:00 UTC

The Series B brings the AI-powered offensive security startup’s total funding to roughly $445 million only seven months after its public launch. The post Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation appeared first on SecurityWeek.

P0
2026-10-01 11:14 UTC
Security Journalism

Microsoft enables Windows settings backup by default for orgs

BleepingComputer · Sergiu Gatlan · indexed 2026-10-01 11:30 UTC

Microsoft announced that Windows settings backup and restore is now enabled by default on all Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems upgraded to Windows 11 26H2. [...]

Microsoft
P0
2026-10-01 10:51 UTC
Security Journalism

Treasury Blacklists Most-Wanted ATM Malware Developer and His Network

Security Week · Eduard Kovacs · indexed 2026-10-01 11:00 UTC

The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme. The post Treasury Blacklists Most-Wanted ATM Malware Developer and His Network appeared first on SecurityWeek.

Malware
P0
1 2 3 4 5