Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

general

20 articles

Security Affairs general Sep 26

Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem

Exploit.in data shows how a 2005 cybercrime forum helped shape today’s ransomware ecosystem, with users and practices surviving for decades.

Security Affairs → Details

BleepingComputer general GitHub Sep 26

GitHub Actions re-enabled with Mini Shai-Hulud payload still active

Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than...

BleepingComputer → Details

HackRead general Oracle Sep 26

ShinyHunters Bypass WAF Rules to Resume Oracle PeopleSoft Attacks

ShinyHunters exploit CVE-2026-35273 in Oracle PeopleSoft using URL encoding to bypass WAF rules, deploy web shells and spread the SIDEEYE backdoor.

T1190 1 IOC

HackRead → Details

BleepingComputer general Sep 26

OpenAI's AI agents accidentally uploaded user-provided images to third-party sites

OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks. [.

BleepingComputer → Details

SecurityWeek general Microsoft Sep 26

New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions. The post New x47.

SecurityWeek → Details

The Hacker News general Google Oracle Sep 26

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors global...

T1190 1 IOC

The Hacker News → Details

The Hacker News general Sep 26

Zero Trust for AI Agents Starts With Fixing Zero Visibility

The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift.

The Hacker News → Details

SecurityWeek general Sep 26

OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure

OpenAI’s CEO said there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.” The post OpenAI Sa...

SecurityWeek → Details

The Hacker News general WordPress Sep 26

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated atta...

The Hacker News → Details

The Hacker News general Microsoft Amazon Sep 26

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

The U.S.

1 IOC

The Hacker News → Details

GBHackers general Linux Sep 26

Red Heron Exploits Critical Gitea Flaw to Steal Repositories and Deploy Linux Rootkit

A threat actor tracked as Red Heron has exploited the critical Gitea remote code execution vulnerability CVE-2026-60004 to steal source-code repositories, es...

T1190 1 IOC

GBHackers → Details

GBHackers general Microsoft Docker Sep 26

Windows 11 Update Causes Black Screen and Desktop Loading Issues After Sign-In

Microsoft has confirmed a Windows 11 issue that can leave users with a black screen after sign-in or prevent the desktop from loading automatically. The prob...

GBHackers → Details

The Hacker News general Intel Sep 26

Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received th...

The Hacker News → Details

GBHackers general Intel Sep 26

Kiteworks Warns Users to Take Systems Offline Amid Suspected Zero-Day Threat

Kiteworks has urged customers worldwide to temporarily shut down their servers after receiving credible law-enforcement intelligence that a threat actor may ...

GBHackers → Details

Security Affairs general WordPress Sep 26

U.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog

U.S.

1 IOC

Security Affairs → Details

GBHackers general Microsoft Sep 26

Uncensored Local AI Model Bypasses EDR to Dump Windows LSASS Credentials

A new demonstration shows how a locally hosted, uncensored AI model can help generate a Windows LSASS credential-dumping utility that reportedly evaded endpo...

GBHackers → Details

GBHackers general Microsoft Sep 26

Storm-3168 Hackers Abuse Compromised Service Principals to Destroy Azure Cloud Resources

Microsoft has uncovered a destructive Azure campaign linked to Storm-3168, also known as JADEPUFFER, in which attackers abused compromised service principals...

GBHackers → Details

GBHackers general Sep 26

OpenAI Says Misaligned AI Agents Hacked Hugging Face and Bypassed Security Controls

OpenAI has disclosed that autonomous AI agents compromised portions of Hugging Face’s infrastructure during internal cybersecurity evaluations after pursuing...

GBHackers → Details

SC Media general Sep 25

Bitget loses $351.6 million in suspected North Korean crypto hack

The breach was discovered on Thursday evening when security systems detected unauthorized transfers.

SC Media → Details

SC Media general Sep 25

Researchers identify AliExpress-themed phishing campaign using disposable domains

EfficientIP Research Labs identified potential .cyou domains on June 9 that were later registered and began resolving to IP addresses on July 2.

T1566

SC Media → Details

«Previous page 1 ... 58 59 60 61 62 ... 332 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA