IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 571 matching records.
AUTO-POLL // 2026-10-04 12:50 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P8 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P8
P8
COOL // 6 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2024-12-12 00:00 UTC
Other

Bedrock API Logging Issue

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Sysdig's Threat Research Team discovered an issue with Amazon Bedrock API logging in CloudTrail. Failed API calls were logged as successful without error codes, hindering detection efforts and potentially generating false positives. The issue affected Bedrock Runtime APIs, specifically InvokeModel and Converse. AWS resolved the problem.

Cloud Security
P0
2024-12-11 00:00 UTC
Other

Code Execution in Azure API Management Developer Portal

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Azure API Management Developer Portal allows arbitrary code execution and secret exfiltration. The issue stems from a workflow that loads untrusted data from opened issues, potentially allowing attackers to inject malicious commands. This could lead to code execution in the runner, granting access to sensitive tokens and permissions.

Cloud SecurityVulnerabilities
P0
2024-11-09 00:00 UTC
Other

Sketchy Cheat Sheet

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Multiple vulnerabilities were discovered in Google's Cloud Architecture Diagramming Tool, including XSS, unauthorized access to user data, and misconfigured storage buckets. The issues allowed accessing sensitive customer information and potentially executing arbitrary code. Google ultimately decommissioned the service due to the severity of the flaws.

Cloud Security
P0
2024-11-08 00:00 UTC
Other

Issue with data.all Framework Multiple CVEs

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Multiple security vulnerabilities were identified in data.all, an open source development framework for building data marketplaces on AWS. The issues affect versions 1.0.0 through 2.6.0 and include problems with authentication token invalidation, unauthorized operations on DataSets and Environments, incorrect object-level authorizations, potential access to sensitive data via logs, and unauthorized mutating update operations on notification records.

Cloud Security
P0
2024-11-01 00:00 UTC
Other

Confused Deputy Vulnerability in Amazon DataZone

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Amazon DataZone allowed potential attackers to assume roles in AWS accounts by exploiting a confused deputy problem. This could have granted unauthorized access to sensitive data managed by DataZone or other AWS services accessible by the IAM role trusting DataZone. The issue has been resolved, with no customers reportedly impacted.

Cloud SecurityVulnerabilities
P0
2024-10-24 00:00 UTC
Other

AWS CDK Bucket Squatting Risk

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The AWS Cloud Development Kit (CDK) is a way of deploying infrastructure-as-code. The vulnerability involves AWS CDK’s use of a predictable S3 bucket name format (cdk-{Qualifier}-assets-{Account-ID}-{Region}), where the default “random” qualifier (hnb659fds) is common and easily guessed. If an AWS customer deletes this bucket and reuses CDK, an attacker who claims the bucket can inject malicious CloudFormation templates, potentially gaining admin access. Attackers supposedly only need the AWS a…

Cloud SecurityVulnerabilities
P0
2024-10-15 00:00 UTC
Other

CloudShell Vulnerability Grants Unintended AWS Access

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in AWS CloudShell allowed users to gain unintended command-line access to the underlying AWS infrastructure. During a training session, a delegate unexpectedly received the identity context of an EC2 instance role within an ECS cluster, instead of the intended AWS account. This issue potentially bypassed existing controls aimed at preventing lateral movement and access to higher-privileged management roles.

Cloud SecurityVulnerabilities
P0
2024-09-26 00:00 UTC
Other

Google Cloud Data Fusion GitHub Actions Vulnerabilities

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Multiple "pwn request" vulnerabilities were discovered in Google Cloud Data Fusion, which is based on open-source CDAP code. These vulnerabilities affect GitHub Actions and allow for remote code execution (RCE) and compromise of build artifacts. The issues potentially impact both the Google Cloud platform and GitHub's CI/CD infrastructure.

Cloud SecurityVulnerabilities
P15
2024-09-16 00:00 UTC
Other

CloudImposer

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Google Cloud Composer is a managed service for Apache Airflow. Tenable discovered that the Cloud Composer package was vulnerable to dependency confusion, which could have allowed attackers to inject malicious code when the package was compiled from source. This could have led to remote code execution on machines running Cloud Composer, which include various other GCP services as well as internal servers at Google. The dependency confusion stemmed from Google's risky recommendation in their docu…

Cloud SecurityVulnerabilities
P15
2024-09-13 00:00 UTC
Other

Escalating from Reader to Contributor in Azure API Management

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Azure API Management allowed users with Reader access to escalate privileges to Contributor level by accessing admin user keys via the ARM API. This permitted full management capabilities through the Direct Management API, including reading secrets and modifying configurations.

Cloud SecurityVulnerabilities
P0
2024-09-12 00:00 UTC
Other

Security Flaw in AWS Transit Gateway Peering Attachments

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A security flaw in AWS Transit Gateway Peering attachments allowed unauthorized acceptance of peering requests between regions. The exploit bypassed the approval step, granting potential unauthorized access to networks. AWS patched the issue on August 7, 2024, after being notified on July 25, 2024.

Cloud Security
P0
2024-08-19 00:00 UTC
Other

WireServing Up Credentials in Azure Kubernetes Services

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Azure Kubernetes Services allowed attackers to escalate privileges and access cluster credentials. Affected clusters used Azure CNI for network configuration and Azure for network policy. Attackers could exploit this issue to steal data and cause financial and reputational damage. The vulnerability has been fixed by Microsoft after disclosure by Mandiant.

Cloud SecurityMicrosoftVulnerabilities
P0
2024-08-15 00:00 UTC
Other

AWS Direct Connect route injection issue

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A BGP-based feature of the AWS Direct Connect service allowed a third party to inject an incorrect route for an external IP, effectively hijacking AWS-sourced traffic. This resulted in connectivity issues between AWS EC2 instances and external systems. The issue was caused by a typo in a Direct Connect customer's configuration, which advertised an incorrect prefix to AWS.

Cloud Security
P0
2024-08-07 00:00 UTC
Other

Bucket Monopoly Attack on AWS Services

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Researchers discovered critical vulnerabilities in 6 AWS services that could allow attackers to breach accounts through malicious S3 buckets. By claiming predictable bucket names, attackers could inject code, steal data, or gain admin access. AWS has since fixed the issues, but the attack vector may still apply to other services and open source projects.

Cloud SecuritySecurity Research
P0
2024-07-24 00:00 UTC
Other

GCP Cloud Functions Privilege Escalation Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A privilege escalation vulnerability dubbed "ConfusedFunction" was discovered in Google Cloud Platform's Cloud Functions service. It allows attackers to escalate privileges from Cloud Function permissions to the default Cloud Build service account during function deployment. The vulnerability affects both first and second-generation Cloud Functions.

Cloud SecurityVulnerabilities
P10
2024-07-16 00:00 UTC
Other

AWS Client VPN buffer overflow

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The AWS Client VPN service was found to be affected by two vulnerabilities which could potentially allow malicious actors with access to a user’s device to execute arbitrary commands with elevated privileges, including escalating to root access. Both vulnerabilities stem from buffer overflow issues, a common programming error that can be exploited to overwrite memory and gain unauthorized control over a system. The impact of these vulnerabilities is severe, as successful exploitation could lead…

Cloud SecurityMalwareNetwork Security
P0
2024-07-15 00:00 UTC
Other

Unauthorized Access to AWS Account Findings in Microsoft Defender for Cloud

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Microsoft Defender for Cloud at one point provided customers with a flawed configuration template through their public GitHub repository. This template creates resources in the customer's AWS account so that Microsoft Defender for Cloud can scan it. In the rare cases in which this template was deployed, under certain, limited circumstances, Defender for Cloud's security findings for these AWS accounts could be disclosed to unauthorized third parties.

Cloud SecurityMicrosoft
P0
2024-06-17 00:00 UTC
Other

Azure Machine Learning SSRF

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Certain API endpoints on ml.azure.com and ai.azure.com used for adding/viewing data connections could be leveraged for server side request forgeries (SSRF). While they do have protections to restrict making requests to internal hosts, it was possible to circumvent those protections using a 301 or 302 redirect response which points to a sensitive host.

Cloud Security
P0
2024-06-11 00:00 UTC
Other

Issue with AWS Deployment Framework

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

CVE-2024-37293 affects the AWS Deployment Framework's bootstrap process, potentially allowing privilege escalation if an actor has permissions to change CodeBuild projects or Lambda functions. The issue is fixed in version 4.0 and above. AWS recommends immediate upgrade and temporary mitigation by adding a permissions boundary to roles created by ADF in the management account.

Cloud SecurityVulnerabilitiesCVE-2024-37293
P15
2024-06-11 00:00 UTC
Other

Issue with Amazon EC2 VM Import Export Service

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS addressed an issue with the Amazon EC2 VM Import Export Service where importing Windows VMs with custom Sysprep answer files resulted in an unprotected backup copy being created, potentially exposing sensitive data. The issue affected imports made before April 12, 2024, and could impact instances launched from affected AMIs.

Cloud SecurityMicrosoft
P0
2024-06-03 00:00 UTC
Other

Abusing Service Tags to Bypass Azure Firewall Rules

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Tenable Research discovered a vulnerability in Azure allowing attackers to bypass firewall rules based on Service Tags by forging requests from trusted services. It affects over 10 Azure services and enables access to internal/private Azure resources. Microsoft updated documentation to clarify Service Tags' security limitations.

Cloud SecurityMicrosoftNetwork SecurityVulnerabilities
P0
2024-05-28 00:00 UTC
Other

Non-Production AWS Endpoints as Attack Surface

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Researchers identified non-production AWS API endpoints that could be abused for defense evasion, including silent permission enumeration, accessing account data without logging, and partially bypassing CloudTrail. AWS has remediated specific issues but thousands of such endpoints may exist.

Cloud Security
P0
2024-05-16 00:00 UTC
Other

Internal Azure Container Registry writable via exposed secret

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A Microsoft employee accidentally published credentials via a git commit to a public repository. These credentials granted privileged access to an internal Azure Container Registry (ACR) used by Azure, which reportedly held container images utilized by multiple Azure projects, including Azure IoT Edge, Akri, and Apollo. The privileged access could have allowed an attacker to download private images as well as upload new images and (most importantly) overwrite existing ones. In theory, an attack…

Cloud SecurityMicrosoft
P0
2024-05-07 00:00 UTC
Other

Lethal Injection

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Multiple vulnerabilities were uncovered in Azure Health Bot service, Microsoft's health chatbot platform. These could have potentially exposed sensitive user data and granted attackers extensive control, allowing unrestricted code execution as root on the bot backend, unrestricted access to authentication secrets & integration auth providers, unrestricted memory read in the bot backend, exposing sensitive secrets, allowing cross-tenant data access and unrestricted deletion of other tenants' pub…

Cloud SecurityMicrosoft
P0
2024-04-26 00:00 UTC
Other

Azure tenant takeover via Microsoft application

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Microsoft Dynamics 365 Supply Chain Visibility allowed arbitrary takeover of Azure tenants via a malicious reply URL. Clicking a link could grant an attacker directory read access or full tenant control if clicked by a Global Admin, without requiring user consent.

Cloud SecurityMicrosoftVulnerabilities
P0
2024-04-15 00:00 UTC
Other

AWS Amplify IAM role publicly assumable exposure

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The AWS Amplify service was found to be misconfiguring IAM roles associated with Amplify projects. This misconfiguration caused these roles to be assumable by any other AWS account. Both the Amplify Studio and the Amplify CLI exhibited this behavior. Any Amplify project created using the Amplify CLI built between July 3, 2018 and August 8, 2019 had IAM roles that were assumable by anyone in the world. The same was true if the authentication component was removed from an Amplify project using th…

Cloud SecurityVulnerabilities
P0
2024-04-11 00:00 UTC
Other

AWS Glue database password leakage

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A principal with the permissions glue:GetConnection and ec2:DescribeSubnets can retrieve the database password of a connection, since the password is loaded into the AWS console website when a connection's edit page is requested. The severity of this issue is low since it requires sufficient prior access.

Cloud Security
P0
2024-04-09 00:00 UTC
Other

AWS IAM Trust Policy Condition Evaluation Bug

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Tag variable names affected whether trust policy conditions were evaluated correctly. If the request tag referenced a principal tag called MemberRole in the JWT token, and the IAM role referenced a resource tag with the same variable name, the condition was always evaluated as true, regardless of whether the tag's values actually matched. Only role trust policies that used a variable substitution for both the request tag and the resource tag in the policy statement resulted in the policy evalua…

Cloud Security
P0
2024-03-27 00:00 UTC
Other

Flaw in Bedrock's Foundation Model Access Control

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A flaw in AWS Bedrock's foundation model access control allowed unauthorized subscriptions to certain models, bypassing IAM policies using the aws-marketplace:ProductId condition key. This could lead to compliance issues and financial risks. AWS has since fixed the issue and notified affected customers.

Cloud Security
P0
2024-03-24 00:00 UTC
Other

IAM Policy Flaw Allowed Unauthorized Access to Bedrock Models

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

TrustOnCloud identified a flaw in how AWS Bedrock enforces IAM access controls using the aws-marketplace:ProductId condition key, which is meant to restrict subscriptions to specific foundation models. Their testing revealed that some Bedrock models, including those from Cohere and Stability AI, were not consistently blocked or allowed as intended by IAM policies, posing potential compliance and cost risks. AWS acknowledged and fixed the issue, notifying affected customers and updating testing …

Cloud Security
P0
12 13 14 15 16