IntelFreed Cybersecurity Intelligence Weather Report

HIGH PRIORITY

Aggregated cybersecurity reporting, advisories and research. 330 matching records.
AUTO-POLL // 2026-10-02 23:35 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P7 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-08-20 13:24 UTC
Security Journalism

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 14:30 UTC

A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection that can lead to remote code execution. "A remote code execution vulnerability exists in Zimbra

VulnerabilitiesCVE-2026-73570
P40
2026-08-13 18:45 UTC
Security Journalism

GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code execution (RCE). The security defect remains unpatched. It was first disclosed on August 12, 2026, at 10:46 UTC, by a researcher named @

Vulnerabilities
P40
2026-06-24 11:00 UTC
Vendor Research

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC

Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access. The vulnerability stems from the device’s file upload feature lacking the ability to prop…

MicrosoftNetwork SecurityThreat ActorsVulnerabilitiesCVE-2026-20127CVE-2026-20182CVE-2026-20245
P40
2025-08-13 22:00 UTC
Security Journalism

Active Exploitation of SonicWall VPNs

Huntress · indexed 2026-09-07 17:30 UTC

A likely zero-day vulnerability in SonicWall VPNs is being actively exploited to bypass MFA and deploy ransomware. Huntress advises disabling the VPN service immediately or severely restricting access via IP allow-listing. We're seeing threat actors pivot directly to domain controllers within hours of the initial breach.

Network SecurityRansomwareThreat ActorsVulnerabilities
P40
2026-10-02 05:50 UTC
Other

U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-10-02 06:00 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Fortinet FortiMail flaw, tracked as CVE-2026-104286 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a path traversal vulnerability that can be triggered through […]

Network SecurityVulnerabilitiesCVE-2026-104286
P35
2026-10-01 08:35 UTC
Other

U.S. CISA adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-10-01 09:10 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Catalyst SD-WAN Manager flaw, tracked as CVE-2026-76504 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability resides in Cisco Catalyst SD-WAN Manager’s […]

VulnerabilitiesCVE-2026-76504
P35
2026-09-30 08:04 UTC
Other

U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-30 09:10 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Apple Multiple Products flaw, tracked as CVE-2026-86950 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Apple has released security updates for iOS, iPadOS […]

AppleVulnerabilitiesCVE-2026-86950
P35
2026-09-28 07:21 UTC
Security Journalism

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 10:25 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerabilities are listed below - CVE-2026-88771 (CVSS score: 9.5) - An improper input validation vulnerability that could allow an unauthenticated attacker to

Cloud SecurityVulnerabilitiesCVE-2026-88771
P35
2026-09-27 17:40 UTC
Government

2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway

CERT-EU Security Advisories · indexed 2026-09-27 18:00 UTC

On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Execution (RCE) vulnerabilities. Citrix has confirmed active exploitation of these 2 critical vulnerabilities in the wild. CERT-EU recommends updating affected software and running a compromise assessment on those exposed on the internet.

Vulnerabilities
P35
2026-09-26 07:42 UTC
Other

U.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-26 08:55 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds WordPress flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a WordPress Core flaw, tracked as CVE-2026-87902 (CVSS score of 9.2), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-87902 allows an unauthenticated attacker to make the get_page_template() function include a readable local […]

VulnerabilitiesCVE-2026-87902
P35
2026-09-25 21:03 UTC
Other

U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-25 22:00 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-65660 is a code-injection vulnerability in Microsoft SharePoint Server that allows an authenticated, low-privileged attacker to execute arbitrary […]

Cloud SecurityMicrosoftNetwork SecurityVulnerabilitiesCVE-2026-65660
P35
2026-09-23 20:37 UTC
Other

U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-23 21:00 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-85102 resides in the VPN negotiation process and lets an unauthenticated attacker bypass security checks […]

Cloud SecurityNetwork SecurityVulnerabilitiesCVE-2026-85102
P35
2026-09-22 09:13 UTC
Other

U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-22 09:40 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Zyxel GS1900 Series Switches flaw, tracked as CVE-2026-7273 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a stack-based buffer overflow that could allow attackers […]

Network SecurityVulnerabilitiesCVE-2026-7273
P35
2026-09-22 05:31 UTC
Security Journalism

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 06:55 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating

Cloud SecurityNetwork SecurityVulnerabilitiesCVE-2026-7273
P35
2026-09-16 11:15 UTC
Security Journalism

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 11:45 UTC

Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," according to a description of the bug in the NIST National Vulnerability Database

VulnerabilitiesCVE-2026-58704
P35
2026-09-16 11:08 UTC
Security Journalism

Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 11:45 UTC

Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file permissions. It affects the following versions - Acronis Backup plugin for cPanel & WHM (Linux

LinuxVulnerabilitiesCVE-2026-87886
P35
2026-09-15 06:11 UTC
Security Journalism

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 06:25 UTC

Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker

VulnerabilitiesCVE-2026-76461
P35
2026-09-14 14:08 UTC
Other

U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-14 14:25 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Two of the above vulnerabilities affect JFrog Artifactory. CVE-2026-42016 can allow attackers to bypass authorization checks and […]

Cloud SecurityVulnerabilitiesCVE-2026-42016
P35
2026-09-10 10:36 UTC
Security Journalism

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-10 11:30 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below - CVE-2026-20079 (CVSS score: 10.0) - An authentication

Cloud SecurityNetwork SecurityVulnerabilitiesCVE-2026-20079
P35
2026-09-10 08:06 UTC
Other

U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-10 08:55 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-75650 (CVSS score of 10.0) is an Adobe Commerce and Magento improper neutralization of special elements in a […]

Cloud SecurityMicrosoftVulnerabilitiesCVE-2026-75650
P35
2026-09-08 14:00 UTC
Vendor Research

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-08 13:45 UTC

Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, b…

AI SecurityAPT / Nation-StateCloud SecurityData BreachesDFIRMalwareMicrosoftPhishingRansomwareThreat ActorsThreat IntelligenceVulnerabilities
P35
3 4 5 6 7