IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 571 matching records.
AUTO-POLL // 2026-10-04 13:00 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P8 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P8
P8
COOL // 6 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2024-03-21 00:00 UTC
Other

FlowFixation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A flaw in Amazon Managed Workflows for Apache Airflow (MWAA) could have allowed potential session hijacking and remote code execution. The issue stemmed from a combination of session fixation in the MWAA web management panel and an AWS domain configuration error leading to a cross-site scripting (XSS) attack. Attackers exploiting this could manipulate victims' configurations, trigger workflows, and potentially move laterally to other services within the cloud environment. The exploit of this bu…

Cloud SecurityVulnerabilities
P15
2024-02-13 00:00 UTC
Other

Azure Site Recovery privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

When the ASR service is enabled, it uses an Automation Account with a System-Assigned Managed Identity to manage Site Recovery extensions on VMs. However, the Runbook (a set of scripts for managing extensions) executed by the Automation Account had its job output visible to users, and this output mistakenly included a cleartext Management-scoped Access Token for the System-Assigned Managed Identity, which possesses the Contributor role over the entire Azure subscription. Therefore, lower-privil…

Cloud SecurityVulnerabilities
P10
2024-02-06 00:00 UTC
Other

Azure HDInsight privilege escalation and DoS vulnerabilities

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Three privilege escalation and denial-of-service vulnerabilities were discovered in Azure HDinsight, related to their usage of Apache Oozie and Ambari. The root cause of at least one of these vulnerabilities is a flaw in Apache Oozie itself, leading to regex denial-of-service (ReDoS). The other two vulnerabilities could allow an authenticated attacker with HDI cluster access to gain cluster administrator privileges and perform any resource service management operation. The vulnerabilities were …

Cloud SecurityVulnerabilities
P15
2024-01-31 00:00 UTC
Other

Azure Devops Zero-Click CI/CD Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Legit Security found a zero-click vulnerability in Azure Pipelines that allows an attacker to access secrets and internal information and perform actions in elevated permissions in the context of a pipeline workflow. This could allow attackers to move laterally in the organization and initiate supply chain attacks. When a pipeline is triggered by a "pipeline resource trigger," it shows in the platform as "Automatically Triggered For …" Instead of running in fork default permissions, preventing …

Cloud SecurityVulnerabilities
P0
2024-01-24 00:00 UTC
Other

Google Cloud GKE Unsecure Sys:All Binding

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The system:authenticated group in Kubernetes is a special group that includes all authenticated entities, including human users and service accounts. Anyone who successfully authenticates to the Kubernetes API server, regardless of the authentication method used, will be automatically included in this unique group. Thus, it will share the same roles and permissions of the group. This misunderstanding then creates a significant security loophole when administrators unknowingly bind this group wi…

Cloud Security
P0
2024-01-01 00:00 UTC
Other

Microsoft Healthcare Chatbot Vulnerabilities

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Multiple vulnerabilities in Microsoft's Azure Health Bot service were discovered, allowing access to sensitive infrastructure and confidential medical data. Issues included sandbox escapes, unrestricted code execution, access to authentication secrets, cross-tenant data exposure, and unauthorized deletion of resources. Microsoft quickly patched the vulnerabilities and restructured the service architecture for improved security.

Cloud SecurityMicrosoft
P0
2023-12-20 00:00 UTC
Other

Azure Pipelines Agent poisoned pipeline execution

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Pipelines and GitHub Actions allow deployment of runners and agents using VM images sourced from a GitHub-managed repository (github.com/actions/runner-images). This repo was misconfigured to use self-hosted runners insecurely, in a way that could have allowed a malicious external contributor (i.e., anyone who had previously had at least one PR approved and merged in the repo) to poison the repository and achieve code execution on runners in the repo. This in turn could have theoretically…

Cloud Security
P0
2023-12-20 00:00 UTC
Other

Data Exfiltration Through CloudTrail

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

This scenario describes a potential data exfiltration technique using AWS CloudTrail. An attacker with access to CloudTrail logs could potentially extract sensitive information from logged events, including API calls and data modifications. This poses a risk to data confidentiality and could lead to unauthorized access to sensitive information.

Cloud Security
P0
2023-12-19 00:00 UTC
Other

AWS IAM Identity Center Expiry

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS IAM Identity Center exchanges third-party OIDC tokens for Identity Center-issued tokens. Identity Center relies on the jti claim in the third-party tokens to prevent replay attacks. Identity Center maintained a cache of previously-seen jti values for a fixed period (24 hours) and didn’t enforce that the third-party tokens had expiry claims. This meant that a token with a jti claim and without an exp claim could be replayed after >24 hours had passed.

Cloud SecurityMicrosoft
P0
2023-12-12 00:00 UTC
Other

Control plane bypass in Azure OpenAI

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A way to manage Azure OpenAI deployments via the Data Plane was discovered, bypassing key security controls. This allows creation/modification/deletion of deployments without the usual protections of Resource Manager Locks, Azure Policy, and Entra ID authentication.

Cloud SecurityMicrosoft
P0
2023-11-16 00:00 UTC
Other

Extracting Managed Identity Credentials from Azure Functions

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Azure Function Apps allowed extraction of Managed Identity credentials from the encrypted startup context of Linux containers. This gave attackers with container access the ability to persist as the Managed Identity, breaking the intended security model. Microsoft has since patched the issue by encrypting the sensitive payload.

Cloud SecurityLinuxMicrosoftVulnerabilities
P0
2023-11-14 00:00 UTC
Other

Azure CLI Leaks Credentials in GitHub Actions Logs

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure CLI commands were found to leak sensitive information, including credentials, through GitHub Actions logs. The vulnerability affects multiple Azure CLI commands and could expose secrets in public and private repositories. Microsoft has issued updates to Azure CLI, Azure Pipelines, and GitHub Actions to address the issue.

Cloud SecurityMicrosoftVulnerabilities
P0
2023-11-14 00:00 UTC
Other

CLI Tools Leak Credentials in GitHub Actions Logs

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Palo Alto discovered that Azure CLI commands were found to leak sensitive credentials and environment variables in GitHub Actions logs. This issue affects both public and private repositories, potentially exposing secrets to unauthorized parties. The problem stems from the Azure CLI's design to echo back accessed/created/updated/deleted resource information, which can include sensitive data. Later research by Orca Security revealed that AWS CLI and Google Cloud CLI were affected by the same iss…

Cloud SecurityNetwork Security
P0
2023-11-08 00:00 UTC
Other

Azure Automation Service Used for Cryptocurrency Mining

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

SafeBreach Labs researchers developed methods to leverage Microsoft Azure's Automation Service for free, undetectable cryptocurrency mining. They found three ways to execute miners: two using their own environment and Azure's resources for free, and one in a victim's environment undetected. The techniques could potentially be used for any task requiring code execution on Azure.

Cloud SecurityMicrosoft
P0
2023-11-06 00:00 UTC
Other

AWS AppFlow secrets disclosure

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AppFlow had an undocumented service called sandstoneconfigurationservicelambda. An undocumented field (awsOwnedManagedAppCredentialsArn) could be used during connector registration and connector updates. Specifying a victim's Secret ARN as that field disclosed the clientId and clientSecret, so long as the victim Secret ARN belonged to a connection profile which is of the type OAuth or contains clientId and clientSecret.

Cloud Security
P0
2023-11-06 00:00 UTC
Other

AWS AppFlow WooCommerce SSRF

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The AppFlow WooCommerce connector allowed specification of a full URL. The connector included details of response content when the URL offered an unexpected response. This means you could make arbitrary GET requests to any URL from the WooCommerce connector, and view the response content. The response in the error was truncated to 500 characters.

Cloud Security
P0
2023-10-19 00:00 UTC
Other

Azure AI Playground data exfiltration

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

In Azure AI Playground, a Prompt Injection attack could cause an LLM to return markdown tags. This would have allowed an adversary whose data makes it into the chat context (e.g., via an uploaded file) to achieve exfiltration of the victim’s data by rendering hyperlinks. However, the severity of this issue is low, as there were no integrations that could pull remote content. This means Indirect Prompt Injection was not possible, and it would require the victim to copy the malicious prompt from …

AI SecurityCloud Security
P0
2023-10-19 00:00 UTC
Other

Vertex AI Studio data exfiltration

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

In Vertex AI Studio, a Prompt Injection attack could cause the LLM to return markdown tags. This could have allowed an adversary whose data makes it into the chat context (e.g., via an uploaded file) to achieve exfiltration of the victim’s data by rendering hyperlinks. However, the severity of this issue is low, as there were no integrations that could pull remote content. This means Indirect Prompt Injection was not possible, and it would require the victim to copy the malicious prompt from el…

AI SecurityCloud Security
P0
2023-10-06 00:00 UTC
Other

Amazon WorkSpaces Windows client credential logging

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS identified an issue in the Amazon WorkSpaces Windows client which resulted in unintentionally logging connection debugging information to a user's local system. This data could include usernames or passwords if they contain specific characters: \ (backslash) or " (double quotes). If an attacker gained access to an Amazon WorkSpaces user's machine, they could then compromise such credentials from the log.

Cloud SecurityMicrosoft
P0
2023-09-19 00:00 UTC
Other

AWS API Gateway Header Smuggling and Cache Confusion

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Researchers at Omegapoint identified two issues in AWS API Gateway authorizers: 1) A header rewrite feature could be abused to bypass authorization by overwriting headers after the authorizer lambda processed them. 2) Caching of authorization policies could be exploited to reuse cached policies with modified identification sources, bypassing the authorizer.

Cloud Security
P0
2023-09-11 00:00 UTC
Other

AWS AppStream Cloudtrail Bypass

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Credentials can be extracted from AppStream. When used, they obscure the sourceIP and userName of the initial user. The sourceIP appears as appstream.amazonaws.com.

Cloud Security
P0
2023-08-24 00:00 UTC
Other

Power Platform Privilege Escalation in Azure AD

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Secureworks researchers discovered an Azure AD application with an abandoned reply URL related to Microsoft Power Platform. An attacker could leverage this URL to redirect authorization codes, exchange them for access tokens, and call Power Platform API via a middle-tier service to obtain elevated privileges. Microsoft quickly addressed the issue by removing the identified abandoned reply URL from the Azure AD application.

Cloud SecurityMicrosoftSecurity ResearchVulnerabilities
P10
2023-08-04 00:00 UTC
Other

Power Platform Custom Code information disclosure

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Power Platform could lead to unauthorized access to Custom Code functions used for custom connectors, thereby allowing cross-tenant information disclosure of secrets or other sensitive information if these were embedded in a Custom Code function. The issue occurred as a result of insufficient access control to Azure Function hosts, which are launched as part of the creation and operation of custom connectors in Microsoft’s Power Platform. An attacker who determined the hostna…

Cloud SecurityMicrosoftVulnerabilities
P0
2023-07-18 00:00 UTC
Other

Bad.Build

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An information disclosure vulnerability in the Google Cloud Build service could have allowed an attacker to view sensitive logs if they had gained prior access to a GCP environment and had permission to create a new Cloud Build instance (cloudbuild.builds.create) or permission to directly impersonate the Cloud Build default service account (which is highly privileged by design and therefore considered to be a known privilege escalation vector in GCP). An attacker could then potentially use this…

Cloud SecurityVulnerabilities
P10
2023-06-27 00:00 UTC
Other

Azure Front Door client-side desync

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A client-side desync vulnerability was discovered in Front Door, one of Azure's CDN solutions, caused by mishandling of the 'Content-Length' header in HTTP requests. Exploiting this vulnerability would most likely require user interaction through social engineering (such as clicking on a malicious link), but could allow an attacker to steal session cookies or forge responses to victim requests.

Cloud SecurityVulnerabilities
P0
2023-06-21 00:00 UTC
Other

Critical Authentication Bypass in Google Cloud API Gateway

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A critical authentication bypass vulnerability was discovered in Google Cloud API Gateway, affecting its JWT authentication method. The flaw, stemming from a business logic bug in the ESPv2 service proxy, allowed attackers to bypass authentication controls by manipulating HTTP methods. This vulnerability impacted various authentication methods including Firebase, Auth0, Okta, and Google ID tokens.

Cloud SecurityVulnerabilities
P10
2023-06-20 00:00 UTC
Other

nOAuth

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Descope identified a possible misconfiguration in Azure AD which could lead to misuse of the "Log in with Microsoft" authentication method on a web app. If an application relies on email attribute claims for authentication (which is against best practice) and also merges user accounts without proper validation, an attacker could falsify an email claim to gain full control over the target account. Descope and Microsoft Microsoft identified several popular multi-tenant applications with users tha…

Cloud SecurityMicrosoft
P0
2023-06-14 00:00 UTC
Other

XSS in Azure Bastion and Container Registry

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Orca discovered vulnerabilities in Azure Bastion and Azure Container Registry that could have enabled an attacker to achieve Cross-Site Scripting (XSS) by using iframe postMessages. The vulnerabilities allowed embedding of endpoints within remote attacker-controlled servers using the iframe tag, thereby granting unauthorized access to the victim’s session in the affected service if they were tricked into navigating to an attacker-controlled website. The root cause was that certain web pages in …

Cloud Security
P0
2023-06-13 00:00 UTC
Other

Bucket Traversal in Google Cloud Storage Transfer Manager

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A bucket traversal vulnerability was discovered in the google.cloud.storage.transfer_manager.upload_chunks_concurrently() function of Google Cloud Storage. This issue could potentially allow unauthorized access to files in different buckets or directories within the same project.

Cloud SecurityVulnerabilities
P0
13 14 15 16 17