IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 571 matching records.
AUTO-POLL // 2026-10-04 12:05 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P8 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P8
P8
COOL // 6 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2025-12-22 11:40 UTC
Other

Explore Payment Gateways Through an Attacker’s Lens | Inside the Payment Gateway Integrations Security Handbook

Red Hunt Labs · Lohit · indexed 2026-09-07 17:30 UTC

Payment gateways are built to move money reliably. Attackers view them as systems built on trust, timing, and assumptions. A gateway that works consistently is not a sign of safety. It is a stable environment to study, probe, and eventually abuse. This blog examines payment gateways from an attacker’s perspective, grounded in real exploitation patterns and reinforced with direct insights from industry experts. These patterns are documented extensively in the RedHunt Labs Payment Gateway Integra…

AppleCloud SecurityCybercrimeDFIR
P0
2025-12-09 17:00 UTC
Vendor Research

Further Hardening Android GPUs

Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC

Posted by Liz Prucka, Hamzeh Zawawy, Rishika Hooda, Android Security and Privacy Team Last year, Google's Android Red Team partnered with Arm to conduct an in-depth security analysis of the Mali GPU, a component used in billions of Android devices worldwide. This collaboration was a significant step in proactively identifying and fixing vulnerabilities in the GPU software and firmware stack. While finding and fixing individual bugs is crucial, and progress continues on eliminating them entirely…

Cloud SecurityDFIRLinuxMobile SecurityThreat Intelligence
P0
2025-09-17 00:00 UTC
Other

Entra ID actor token validation bug allowing cross-tenant global admin

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A critical vulnerability discovered in Microsoft's Entra ID (formerly Azure AD) allowed for cross-tenant access and potential global admin privilege escalation. The flaw was found in the legacy Azure AD Graph API, which improperly validated the originating tenant for undocumented "Actor tokens." An attacker could use a token from their own tenant to authenticate as any user, including Global Admins, in any other tenant. This vulnerability bypassed security policies like Conditional Access. The …

Cloud SecurityMicrosoftVulnerabilities
P10
2025-08-14 00:00 UTC
Other

AWS ECS Agent Information Disclosure Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in the Amazon ECS agent could allow an introspection server to be accessed off-host. This information disclosure issue, if exploited, could allow another instance in the same security group to access the server's data. The vulnerability does not affect instances where off-host access is set to 'false'. The issue has been patched in version 1.97.1 of the ECS agent.

Cloud SecurityVulnerabilities
P0
2025-05-19 00:00 UTC
Other

AWS Security Tool Introduces Privilege Escalation Risk

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS's Account Assessment for AWS Organizations tool, designed to audit cross-account access, inadvertently introduced privilege escalation risks due to flawed deployment instructions. Customers were encouraged to deploy the tool in lower-sensitivity accounts, creating risky trust paths from insecure environments into highly sensitive ones. This could allow attackers to pivot from compromised development accounts into production and management accounts.

Cloud SecurityVulnerabilities
P10
2025-05-10 00:00 UTC
Other

FreeRTOS and coreSNTP Security Advisories

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Security advisories were issued for FreeRTOS and coreSNTP releases containing unintended scripts that could potentially transmit AWS credentials if executed on Linux/macOS. Affected releases have been removed and users are advised to rotate credentials and delete downloaded copies.

AppleCloud SecurityLinux
P0
2025-05-06 00:00 UTC
Other

Azure AZNFS-mount Utility Root Privilege Escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A critical vulnerability in AZNFS-mount utility, preinstalled on Azure HPC/AI images, allowed unprivileged users to escalate privileges to root on Linux machines. The flaw existed in versions up to 2.0.10 and involved a SUID binary. Azure classified it as low severity but fixed it in version 2.0.11.

Cloud SecurityLinuxVulnerabilities
P10
2025-04-29 00:00 UTC
Other

AWS Default Roles Can Lead to Service Takeover

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Research uncovered security flaws in default AWS service roles, granting overly broad permissions like full S3 access. This allows privilege escalation, cross-service access, and potential account compromise across services like SageMaker, Glue, and EMR. Attackers could exploit these roles to manipulate critical assets and move laterally within AWS environments. AWS has since updated default policies and documentation to mitigate risks.

Cloud SecurityVulnerabilities
P10
2025-04-22 00:00 UTC
Other

Google Cloud ConfusedComposer Privilege Escalation Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Tenable discovered a privilege escalation vulnerability in Google Cloud Platform's Cloud Composer service, dubbed ConfusedComposer. It allowed users with composer.environments.update permission to escalate privileges to the default Cloud Build service account by injecting malicious PyPI packages. This could grant broad permissions across the victim's GCP project.

Cloud SecurityVulnerabilities
P10
2025-04-15 00:00 UTC
Other

Burning Data with Malicious Firewall Rules in Azure SQL

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Varonis Threat Labs discovered a vulnerability in Azure SQL Server allowing privileged users to create malicious firewall rules that can delete Azure resources when triggered by admin actions. The exploit involves manipulating rule names via TSQL to inject destructive commands, potentially leading to large-scale data loss in affected Azure accounts.

Cloud SecurityNetwork SecurityVulnerabilities
P0
2025-04-09 00:00 UTC
Other

Path Traversal in AWS SSM Agent Plugin ID Validation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A path traversal vulnerability in AWS SSM Agent's ValidatePluginId function allows attackers to create directories and execute scripts in unintended locations on the filesystem. This could lead to privilege escalation or other malicious activities, as files may be written to or executed from sensitive areas of the system with root privileges.

Cloud SecurityVulnerabilities
P10
2025-03-21 00:00 UTC
Other

AWS CDK CLI Issue with Custom Credential Plugins

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS identified a security issue in the AWS CDK CLI versions 2.172.0-2.178.1 where temporary credentials from custom credential plugins could be printed to console output. This potentially exposes sensitive information to users with access to the console. The issue affects plugins that include an expiration property when returning temporary credentials.

Cloud Security
P0
2025-03-10 00:00 UTC
Other

Azure API Connections Expose Backend Secrets

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure API Connections were found to allow any reader on a subscription to access backend resources through a proxy endpoint, potentially exposing secrets from Key Vaults, databases, and third-party services. This vulnerability affects various Azure services and external APIs, enabling privilege escalation and unauthorized access to sensitive information.

Cloud SecurityVulnerabilities
P10
2025-03-04 00:00 UTC
Other

Issue with AWS Temporary Elevated Access Management

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in AWS Temporary Elevated Access Management (TEAM) allows users to modify valid requests and spoof approvals due to improper input validation. This affects versions prior to 1.2.2 of TEAM for AWS IAM Identity Center. AWS has released a fix in version 1.2.2 and recommends customers upgrade to the latest release.

Cloud SecurityVulnerabilities
P0
2025-02-26 00:00 UTC
Other

Silent Reaper (Azure LogicApp Secrets Control Plane Exfiltration)

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure iPaaS services, such as Logic Apps, separate the Control Plane (management) from the Data Plane (execution), but a flaw in this model enabled undetectable data harvesting. An attacker with Azure Reader access to workflow run history can silently extract sensitive data from executions, including secrets and API responses. This is possible because execution details are exposed via the Control Plane, bypassing Data Plane access controls. The root cause of this issue is the unintended exposur…

Cloud Security
P0
2025-02-26 00:00 UTC
Other

Vault Recon (Azure KeyVault Secrets Metadata Control Plane Exfiltration)

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Key Vault enforces a separation between the Control Plane (management) and Data Plane (secrets access). However, a flaw in this isolation allows unauthorized users to enumerate secrets and keys within a vault. By having Reader access or lesser privileges on a Key Vault, an attacker could leverage Azure Resource Explorer to access metadata about stored secrets. This is due to unintended exposure through the Control Plane, which should not provide insight into Data Plane resources. The root…

Cloud Security
P0
2025-02-26 00:00 UTC
Other

AWS EKS Logged ServiceAccount Tokens in Plaintext

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS EKS was logging ServiceAccount tokens in plaintext, including those used for AssumeRoleWithWebIdentity and connecting to the Kubernetes API server. This issue affected clusters between March 2020 and May 2021, potentially exposing sensitive credentials in CloudWatch logs.

Cloud Security
P0
2025-02-19 00:00 UTC
Other

Abusing AWS Serverless Image Handler Configuration Weakness

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS solution 'Dynamic Image Transformation for Amazon CloudFront', prior to version 6.2.6, contains a configuration weakness. The Lambda role doesn't constrain bucket access, and the environment variable can be set to a wildcard, allowing access to any bucket. This could potentially lead to unintended access to sensitive images across multiple buckets in the AWS account.

Cloud Security
P0
2025-02-06 00:00 UTC
Security Journalism

Device Code Phishing: OAuth 2.0 Attacks in Google & Azure

Huntress · indexed 2026-09-07 17:30 UTC

All OAuth 2.0 implementations are equal. Some are just more equal than others. This blog covers device code phishing and compares OAuth implementations between Google and Azure. Does OAuth implementation impact the efficacy of hacker tradecraft? Find out here!

Cloud SecurityPhishing
P0
2025-01-23 00:00 UTC
Other

AWS Sign-in IAM User Login Flow Username Enumeration

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in AWS IAM Sign-in login flow could allow attackers to enumerate IAM usernames by measuring server response times. This issue affected AWS Sign-in IAM User login flow prior to January 16, 2025. AWS has since introduced a delay in response times across all authentication failure scenarios to mitigate the vulnerability.

AppleCloud SecurityVulnerabilities
P0
2025-01-17 00:00 UTC
Other

Finding SSRFs in Azure DevOps

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Three SSRF vulnerabilities were discovered in Azure DevOps, allowing access to internal metadata endpoints and potential CRLF injection. The issues affected the endpointproxy and Service Hooks functionality. DNS rebinding could bypass initial fixes. Microsoft awarded $15,000 in bug bounties for the findings.

Cloud SecurityMicrosoft
P0
2025-01-16 00:00 UTC
Other

CloudWatch Dashboard Sharing Exposes EC2 Tags

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in AWS CloudWatch dashboard sharing allowed viewers to access EC2 instance tags and potentially invoke Lambda functions in the source account. The issue stemmed from a logic bug in the AWS Console combined with a "fail open" condition in Amazon Cognito. AWS has since patched the vulnerability.

Cloud SecurityVulnerabilities
P0
2025-01-15 00:00 UTC
Other

Issue with Amazon WorkSpaces and AppStream 2.0 Clients

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS identified two vulnerabilities in specific versions of native clients for Amazon WorkSpaces, Amazon AppStream 2.0, and Amazon DCV. These issues could allow man-in-the-middle attacks, potentially giving attackers access to remote sessions. Affected versions include WorkSpaces clients 5.20.0 or earlier, AppStream 2.0 Windows client 1.1.1326 or earlier, and various DCV clients. AWS recommends upgrading to patched versions to address these security concerns.

Cloud SecurityMicrosoft
P0
2025-01-08 00:00 UTC
Other

Hijacking Azure Machine Learning Notebooks

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Machine Learning notebooks can be hijacked by attackers with Storage Account access to inject malicious code. A now-fixed vulnerability allowed Reader role escalation to code execution. The article details the attack methods, including modifying notebooks, obtaining managed identity tokens, and exfiltrating data. It also introduces a tool for dumping AML workspace credentials.

Cloud SecurityVulnerabilities
P0
2024-12-29 00:00 UTC
Other

AWS Neuron SDK Dependency Confusion Vulnerability Recurs

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS Neuron SDK has reintroduced a dependency confusion vulnerability three times in four years. The issue stems from using the --extra-index-url parameter in pip install commands, which allows potential installation of malicious packages from PyPI instead of AWS's private repository. Despite previous reports, AWS has not fully addressed the problem, leaving new packages vulnerable to exploitation.

Cloud SecurityVulnerabilities
P0
2024-12-16 00:00 UTC
Other

Dirty DAG - Azure Apache Airflow Integration Vulnerabilities

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Unit 42 researchers identified vulnerabilities in the Azure Data Factory's integration with Apache Airflow. These vulnerabilities include misconfigured Kubernetes Role-Based Access Control (RBAC), improper secret handling in Azure’s internal Geneva service, and weak authentication mechanisms. Exploiting these flaws, attackers could gain shadow admin control over Azure infrastructure by crafting malicious DAG files or compromising service principals, leading to unauthorized access, data exfiltra…

Cloud SecurityMalware
P0
11 12 13 14 15