IntelFreed Cybersecurity Intelligence Weather Report

HIGH PRIORITY

Aggregated cybersecurity reporting, advisories and research. 330 matching records.
AUTO-POLL // 2026-10-03 00:20 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 3
NO DATA
--
NO INTEL
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
RESET
2026-09-29 14:00 UTC
Vendor Research

Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-29 14:00 UTC

Introduction In late September 2026, Mandiant Consulting and Google Threat Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gateway appliances. We have observed evidence that organizations in North America and Europe in the government, financial services, technology, education, and legal and professional services sectors were likely impacted by this exploitation campaign, which has bee…

LinuxMalwareMicrosoftNetwork SecurityPhishingThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-88771CVE-2026-88772
P30
2026-09-23 08:29 UTC
Security Journalism

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 08:45 UTC

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break

MalwareMicrosoftThreat ActorsVulnerabilitiesCVE-2026-85046CVE-2026-85880CVE-2026-87491
P30
2026-09-22 19:31 UTC
Other

Check Point Fixes a New Actively Exploited Critical Security Flaw

Security Affairs · Pierluigi Paganini · indexed 2026-09-22 20:50 UTC

Check Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers. Check Point has released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in its Security Management Server. Attackers can abuse the flaw without logging in to upload malicious scripts and execute them on vulnerable […]

VulnerabilitiesCVE-2026-93616
P30
2026-09-22 18:29 UTC
Security Journalism

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 19:25 UTC

Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point

Network SecurityVulnerabilitiesCVE-2026-93616
P30
2026-09-22 16:52 UTC
Government

2026-013: Critical Vulnerability in F5 BIG-IP APM

CERT-EU Security Advisories · indexed 2026-09-22 17:10 UTC

On 22 September 2026, F5 published an advisory addressing a critical vulnerability affecting its BIG-IP APM product. The vendor confirmed active exploitation in the wild. CERT-EU recommends taking appropriate actions as soon as possible.

Vulnerabilities
P30
2026-09-22 12:29 UTC
Security Journalism

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 13:40 UTC

Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are

VulnerabilitiesCVE-2026-93952
P30
2026-09-20 16:12 UTC
Other

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-20 17:10 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Below are detailed descriptions of the flaws: At the time of this writing, there are currently no details on how the […]

Cloud SecurityLinux
P30
2026-09-17 21:13 UTC
Vendor Research

Cisco IOS XR Software Security Hardening Release: September 2026

Cisco Security Advisories · indexed 2026-09-02 16:10 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by …

AppleVulnerabilitiesCVE-2026-20274CVE-2026-20275CVE-2026-20276CVE-2026-20277CVE-2026-20278CVE-2026-20279CVE-2026-20280
P30
2026-09-17 06:39 UTC
Security Journalism

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker

VulnerabilitiesCVE-2026-76460
P30
2026-09-16 16:07 UTC
Vendor Research

Cisco Advance Notification for Publication of September 16, 2026, Security Advisories

Cisco Security Advisories · indexed 2026-09-09 16:30 UTC

On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery. Cisco Identity…

DFIRVulnerabilitiesCVE-2026-20352CVE-2026-76460
P30
2026-09-16 16:00 UTC
Vendor Research

Cisco Nexus Dashboard Software Security Hardening Release: September 2026

Cisco Security Advisories · indexed 2026-09-16 16:05 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by …

VulnerabilitiesCVE-2026-20322CVE-2026-20325CVE-2026-20326CVE-2026-20360CVE-2026-20361CVE-2026-76409
P30
2026-09-16 13:43 UTC
Other

Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks

Security Affairs · Pierluigi Paganini · indexed 2026-09-16 14:15 UTC

Google has patched a high-severity zero-day in the Pixel cellular modem after finding evidence that the vulnerability was exploited in limited, targeted attacks. Google has released its September 2026 Pixel security update, addressing a large set of vulnerabilities, including a high-severity flaw, tracked as CVE-2026-58704 (CVSS score of 8.0), in the cellular modem that has […]

VulnerabilitiesCVE-2026-58704
P30
2026-09-14 16:00 UTC
Vendor Research

Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026

Cisco Security Advisories · indexed 2026-09-14 16:20 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing. One of them is known to be actively exploited. For more information, see Cisco Secure Email Gateway SQL …

VulnerabilitiesCVE-2026-20353CVE-2026-76440CVE-2026-76441CVE-2026-76442CVE-2026-76443
P30
2026-09-11 10:14 UTC
Other

Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware

Security Affairs · Pierluigi Paganini · indexed 2026-09-11 10:55 UTC

Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (FMC) flaws. The main target is CVE-2026-20079, a critical authentication bypass that lets unauthenticated attackers remotely bypass security controls, run […]

Cloud SecurityNetwork SecurityRansomwareVulnerabilitiesCVE-2026-20079
P30
2026-09-11 06:19 UTC
Security Journalism

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 07:40 UTC

Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass

APT / Nation-StateCloud SecurityNetwork SecurityRansomwareVulnerabilitiesCVE-2026-20079
P30
2026-09-09 06:47 UTC
Security Journalism

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 09:30 UTC

The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic

MicrosoftSecurity ResearchVulnerabilitiesCVE-2026-69414
P30
2026-09-08 19:20 UTC
Community

September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)

SANS Internet Storm Center · indexed 2026-09-08 19:35 UTC

This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.

MicrosoftVulnerabilities
P30
2026-09-05 07:31 UTC
Security Journalism

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 07:45 UTC

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Cloud SecurityPhishingThreat ActorsVulnerabilitiesCVE-2026-81578CVE-2026-82078
P30
2026-09-03 19:47 UTC
Other

Cisco Fixed Critical RCE in Nexus 9000 Series Switches

Security Affairs · Pierluigi Paganini · indexed 2026-09-03 20:25 UTC

Cisco patched a critical Nexus 9000 vulnerability, CVE-2026-20212, allowing unauthenticated remote root code execution. Cisco has released patches for a critical flaw, tracked as tracked as CVE-2026-20212 (CVSS score of 9.8) in 10 Silicon One-based Nexus 9000 switches. The vulnerability could let an unauthenticated remote attacker execute code with root privileges. Cisco’s Technical Assistance Center […]

Network SecurityVulnerabilitiesCVE-2026-20212
P30
2026-09-02 10:53 UTC
Security Journalism

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 11:15 UTC

SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are listed below - CVE-2026-83548 (CVSS score: 10.0) - A pre-authentication SSRF vulnerability in the Appliance

Cloud SecurityNetwork SecurityVulnerabilitiesCVE-2026-83548
P30
2026-08-29 16:25 UTC
Security Journalism

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-29 17:20 UTC

Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below - CVE-2026-76581 (CVSS score: 9.8) - An authentication bypass flaw in

Cloud SecurityVulnerabilitiesCVE-2026-76581
P30
2026-08-28 10:58 UTC
Security Journalism

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 11:40 UTC

VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKINGSTONE and DARKLANTERN by the company's zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233.

Network SecurityVulnerabilitiesCVE-2026-74232CVE-2026-74233
P30
5 6 7 8 9