IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 571 matching records.
AUTO-POLL // 2026-10-04 13:50 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P8 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P8
P8
COOL // 6 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2022-11-21 00:00 UTC
Other

AWS AppSync confused deputy via ServiceRoleArn

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The AWS AppSync service could be coerced to assume arbitrary roles in other customers' accounts which trusted the AppSync service. This was due to insufficient validation of a serviceRoleArn parameter (caused by a case-sensitivity parsing issue). With this vulnerability, if an adversary knew the ARN of the role associated with AppSync in the target account, they could use it invoke arbitrary AWS API calls.

Cloud SecurityVulnerabilities
P0
2022-11-07 00:00 UTC
Other

Azure Devops account takeover via dangling subdomain takeover

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Binary Security discovered and registered two dangling cloudapp.azure.com subdomains corresponding to subdomains at visualstudio.com. Had these been discovered and registered by an attacker, this would have been equivalent to a 1-click vulnerability for Azure DevOps: the attacker could have crafted a URL referring to the sign-in API for Azure DevOps Services (app.vssps.visualstudio.com) using one of the two subdomains in the "reply_to" field (since subdomains of visualstudio.com would be allowe…

Cloud SecurityVulnerabilities
P0
2022-10-25 00:00 UTC
Other

Azure CLI code injection vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure CLI contained a code injection vulnerability that could be exploited in a scenario where the host runs a command where parameter values have been provided by an external untrusted source - these could be specially crafted in such a way as to exploit the vulnerability, leading to remote code execution on the host. The vulnerability is only applicable when the Azure CLI command is run on a Windows machine and with any version of PowerShell and when the parameter value contains the `&` or `|…

Cloud SecurityMicrosoftVulnerabilities
P15
2022-10-19 00:00 UTC
Other

BlueBleed

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

In September 22', SOCRadar discovered an insecure public Azure blob storage owned by Microsoft (olyympusv2.blob.core.windows[.]net). This blob storage was used for storing emails and other documents from interactions with their customers (such as contracts and purchase orders). In total, the blob storage contained 2.4TB of data with information concerning thousands of Microsoft customers across dozens of countries, dated between 2017 and August 22'. Following disclosure, Microsoft reconfigured …

Cloud SecurityMicrosoft
P0
2022-10-11 00:00 UTC
Other

FabriXss

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Service Fabric Explorer (SFX) is a tool for inspecting and managing Azure Service Fabric clusters. An attacker with existing access to a "Deployer" type user with CreateComposeDeployment permissions in a given cluster could create a malicious application with a specially-crafted name. This would lead to client-side template injection (CSTI) and storing a malicious XSS payload in a dashboard shared between users of the same cluster. If a victim user with administrative permissions logged into th…

Cloud Security
P0
2022-10-11 00:00 UTC
Other

Azure Arc-enabled Kubernetes privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Arc allows customers to connect on-premises Kubernetes clusters to Azure. This is facilitated by middleware (the Azure Arc-enabled Kubernetes agent) which includes a "cluster connect" feature in the form of a reverse proxy. A vulnerability in this feature could allow an unauthenticated user to elevate their privileges and potentially gain remote administrative control over any Azure Arc-enabled cluster, as long as they know its randomly generated external DNS endpoint. Azure Stack Edge de…

Cloud SecurityVulnerabilities
P10
2022-09-20 00:00 UTC
Other

Azure Cloud Shell access token theft

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An issue in Azure Cloud Shell could have allowed an attacker to take over an Azure App Service domain and leverage it to inject and execute commands in other tenants' terminals if they navigated to the domain while logged into their account. Using this method, an attacker could query the Azure IMDS on other tenants' behalf and thereby obtain their access tokens.

Cloud Security
P0
2022-09-01 00:00 UTC
Other

Synapse Spark LPE

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Synapse Analytics is an analytics service for processing data using various runtimes, among them Apache Spark. Synapse provided users the capability to mount Azure File Shares to their Apache Spark Pools via a script called filesharemount.sh that would execute with elevated privileges. This script would mount the File Share to the /synfs directory. There was a race condition in the script where, if successfully exploited, a user could execute the chown command to change the ownership of a…

Cloud SecurityMicrosoftVulnerabilities
P0
2022-08-19 00:00 UTC
Other

SNS SigningCertUrl improper validation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Amazon SNS' signature validation in the official SDK relied on a weak regex for default AWS certificate locations, that would incorrectly match an S3 bucket named `sns`. This bucket happened to be publicly readable and writeable, allowing an attacker to forge messages to any user of the official SDK SNS validator.

Cloud Security
P0
2022-08-11 00:00 UTC
Other

Cloud SQL escape to host

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

In GCP's case, they introduced a modification to the Cloud SQL's PostgreSQL engine allowing the role assigned to the tenant (cloudsqlsuperuser) to arbitrarily change the ownership of a table to any user or role in the database. Thus, an attacker could (1) create a new table, (2) create an index function with a malicious payload, and (3) change the table owner to GCP’s superuser role (cloudsqladmin). Next, by initiating an ANALYZE command, the malicious function is executed with GCP’s superuser …

Cloud SecurityVulnerabilities
P10
2022-08-10 00:00 UTC
Other

Google Cloud Shell command injection

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability was discovered in Cloud Shell that enabled command injection and remote shell access. By manipulating the "project" parameter, an attacker could have cause an unencoded Python script execution flaw. Exploiting this flaw, they could inject a command to display the contents of the "/etc/passwd" file, successfully execute arbitrary commands and obtain remote shell access. However, the impact of this is unclear, as an attacker would seemingly only be able to gain such a remote shell…

Cloud SecurityVulnerabilities
P0
2022-07-20 00:00 UTC
Other

S3 Replication only logs first destination bucket

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

If a malicious actor with prior access to an AWS environment has permission to modify the S3 Replication Service role access policy, they could abuse cross-account replication to exfiltrate stolen data to an external bucket under their control. Moreover, when configured to replicate to multiple buckets at once, and if logging is only scoped to specific buckets (as opposed to being set to log "all current and future buckets"), then the S3 Replication Service only logs a putObject event to CloudT…

Cloud SecurityData Breaches
P0
2022-07-16 00:00 UTC
Other

Persistence Vulnerability in GCP Cloud Workstations

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A critical security flaw in Google Cloud Platform's Cloud Workstations allows unauthorized access and privilege escalation. The vulnerability stems from persistent session management, enabling users to access and exploit credentials of higher-privileged users. This can lead to impersonation, creation of new service accounts with elevated permissions, and bypassing of access controls.

Cloud SecurityVulnerabilities
P10
2022-07-14 00:00 UTC
Other

Dependency confusion in AWS CodeArtifact

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS CodeArtifact was susceptible to dependency confusion / substitution (i.e, publication of a malicious package to a public repository with the same name as an organization’s internal package). AWS fixed this issue by adding package origin controls, allowing users to limit how versions of a given package can be added to a CodeArtifact repository.

Cloud Security
P0
2022-07-12 00:00 UTC
Other

Microsoft Azure Site Recovery DLL hijacking

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The Microsoft Azure Site Recovery suite contained a DLL hijacking flaw that allowed for privilege escalation from any low privileged user to SYSTEM on hosts where this service was installed. Incorrect permissions on the cxprocessserver service's executable directory allowed new files to be created in it by any user. Since the service ran automatically and with SYSTEM privileges and attempted to load DLLs from the directory, this allowed for a DLL hijacking / planting attack.

Cloud SecurityMicrosoftVulnerabilities
P10
2022-07-11 00:00 UTC
Other

AWS IAM Authenticator for Kubernetes AccessKeyID Validation Bypass

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Amazon Elastic Kubernetes Service (EKS) uses IAM to provide authentication to the cluster through the AWS IAM Authenticator for Kubernetes (aws-iam-authenticator). aws-iam-authenticator can be installed on any Kubernetes cluster, and it is installed by default in any EKS cluster both on AWS cloud and on-premises (Amazon EKS Anywhere). A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges. The bug …

Cloud Security
P0
2022-06-28 00:00 UTC
Other

FabricScape (CVE-2022-30137) - Azure Service Fabric privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Service Fabric allows Linux containers to escalate their privileges in order to gain root privileges on the node, and then compromise all of the nodes in the cluster. An attacker would need to have read/write access to the cluster, and the vulnerability could be exploited on containers that are configured to have runtime access, but this is granted by default to every container. Though the bug exists in both the Windows and Linux versions, it is only exploitable on Linux.

Cloud SecurityLinuxMicrosoftVulnerabilitiesCVE-2022-30137
P15
2022-05-31 00:00 UTC
Other

MWAA logs leak tokens and hostnames

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Two API calls used by Amazon Managed Workflows for Apache Airflow (MWAA) to convert AWS IAM credentials into tokens that can be used to login to Airflow (CreateCliToken and CreateWebLoginToken) were logging the tokens to Cloudtrail. The event included the hostname for the airflow server, so everything required to login to Airflow was in the event. However, the issue was largely mitigated by the fact that the tokens are only valid for 60 seconds and CloudTrail delivers logs on average about ever…

Cloud Security
P0
2022-05-17 00:00 UTC
Other

ELB Cache mechanism HTTP header smuggling

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

While testing rate-limiter protection, The researcher noticed that when forcing HTTP/1 requests and injecting a space after `X-Forwarded-For` he was able to override this specific header, letting him impersonate any IP. Any internal header could have beem overridden, also the one that should not be exposed/forwarded by the client, such as `CloudFront-Viewer-Country-Region` or any other `CloudFront` enhanced header. This special security issue was affecting all AWS users with that a specific set…

Cloud Security
P0
2022-05-09 00:00 UTC
Other

Synlapse

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Synapse Analytics and Azure Data Factory were vulnerable to cross-tenant access and code execution. This was made possible via a combination of (1) a shell injection RCE vulnerability in the integration runtime, (2) credentials for multiple customers stored on a shared host and (3) an insecure management server API.

Cloud SecurityVulnerabilities
P15
2022-05-01 00:00 UTC
Other

AWS package backfill attack

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Two malicious versions were created of packages previously used by AWS. The packages were officially authored and maintained by AWS before they were removed by their legitimate author, and once the packages were removed, their names became available and the two packages were then populated with malicious code. If AWS-deployed software had any dependencies on these packages, this would have led to a dependency confusion attack.

Cloud Security
P0
2022-04-28 00:00 UTC
Other

ExtraReplica

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A chain of critical vulnerabilities was discovered in Azure Database for PostgreSQL Flexible Server, allowing unauthorized read access to other customers’ PostgreSQL databases, thus bypassing tenant isolation. If exploited, a malicious actor could have replicated and gained read access to Azure PostgreSQL Flexible Server customer databases.

Cloud Security
P0
2022-04-20 00:00 UTC
Other

AWS SSM agent local privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The Amazon SSM Agent (used for managing EC2 instances via Amazon Systems Manager) created a world-writable sudoers file, which would have allowed local attackers to inject Sudo rules and escalate privileges to root. This could occur in certain situations involving a race condition.

Cloud SecurityVulnerabilities
P10
2022-04-11 00:00 UTC
Other

AWS RDS local file read

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability was discovered in the Aurora PostgreSQL log_fdw extension for Amazon Relational Database Service (RDS), allowing an attacker to read files on the EC2 host and obtain credentials for an internal AWS service.

Cloud SecurityVulnerabilities
P0
2022-04-05 00:00 UTC
Other

Azure AD information disclosure via undocumented APIs

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Undocumented Azure AD APIs could allow access to internal information of any organization that uses Azure AD. Collected details included licensing information, mailbox information, and directory synchronization status.

Cloud Security
P0
2022-03-10 00:00 UTC
Other

AWS RDS does not enforce SSL/TLS encryption

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The AWS RDS service does not enable secure transport layer security by default, allowing clients to connect insecurely. Additionally, for the more commonly used MySQL and MariaDB RDS engine types, this setting cannot be enabled at all.

Cloud Security
P0
15 16 17 18 19