IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,388 matching records.
AUTO-POLL // 2026-10-06 00:55 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 6
NO DATA
--
NO INTEL
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
RESET
2025-05-06 05:00 UTC
Security Journalism

Do Tigers Really Change Their Stripes?

Huntress · indexed 2026-09-07 17:30 UTC

Across the larger cybersecurity community, an often-used adage is that “threat actors always change their tactics.” However, when we really start to look at and track incident data, we begin to see that while some changes may be necessitated based on infrastructures and other challenges the threat actor may encounter, there are times when tactics remain consistent across incidents. Recent investigations into exploitation activity for CVE-2025-31151 and CVE-2025-30406 show similar TTPs across di…

DFIRThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2025-30406CVE-2025-31151
P5
2025-05-06 00:00 UTC
Other

Azure AZNFS-mount Utility Root Privilege Escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A critical vulnerability in AZNFS-mount utility, preinstalled on Azure HPC/AI images, allowed unprivileged users to escalate privileges to root on Linux machines. The flaw existed in versions up to 2.0.10 and involved a SUID binary. Azure classified it as low severity but fixed it in version 2.0.11.

Cloud SecurityLinuxVulnerabilities
P10
2025-04-29 00:00 UTC
Other

AWS Default Roles Can Lead to Service Takeover

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Research uncovered security flaws in default AWS service roles, granting overly broad permissions like full S3 access. This allows privilege escalation, cross-service access, and potential account compromise across services like SageMaker, Glue, and EMR. Attackers could exploit these roles to manipulate critical assets and move laterally within AWS environments. AWS has since updated default policies and documentation to mitigate risks.

Cloud SecurityVulnerabilities
P10
2025-04-28 00:00 UTC
Government

Vulnérabilité dans SAP NetWeaver (28 avril 2025)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Le 24 avril 2025, SAP a publié un bulletin de sécurité relatif à la vulnérabilité CVE-2025-31324 qui permet l'exécution de code arbitraire à distance pour un utilisateur non authentifié. Cette vulnérabilité est provoquée par un contournement de la politique de sécurité qui permet de télécharger...

VulnerabilitiesCVE-2025-31324
P5
2025-04-22 00:00 UTC
Other

Google Cloud ConfusedComposer Privilege Escalation Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Tenable discovered a privilege escalation vulnerability in Google Cloud Platform's Cloud Composer service, dubbed ConfusedComposer. It allowed users with composer.environments.update permission to escalate privileges to the default Cloud Build service account by injecting malicious PyPI packages. This could grant broad permissions across the victim's GCP project.

Cloud SecurityVulnerabilities
P10
2025-04-15 00:00 UTC
Other

Burning Data with Malicious Firewall Rules in Azure SQL

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Varonis Threat Labs discovered a vulnerability in Azure SQL Server allowing privileged users to create malicious firewall rules that can delete Azure resources when triggered by admin actions. The exploit involves manipulating rule names via TSQL to inject destructive commands, potentially leading to large-scale data loss in affected Azure accounts.

Cloud SecurityNetwork SecurityVulnerabilities
P0
2025-04-09 00:00 UTC
Other

Path Traversal in AWS SSM Agent Plugin ID Validation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A path traversal vulnerability in AWS SSM Agent's ValidatePluginId function allows attackers to create directories and execute scripts in unintended locations on the filesystem. This could lead to privilege escalation or other malicious activities, as files may be written to or executed from sensitive areas of the system with root privileges.

Cloud SecurityVulnerabilities
P10
2025-04-01 00:00 UTC
Other

ImageRunner: Privilege Escalation Vulnerability in GCP Cloud Run

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An attacker with `run.services.update` and `iam.serviceAccounts.actAs` permissions but without explicit registry access could deploy new revisions of Cloud Run services that pulled private container images stored in the same GCP project. This was possible because Cloud Run uses a service agent with the necessary registry read permissions to retrieve these images, regardless of the caller’s access level. By updating a service revision and injecting malicious commands into the container's argumen…

Vulnerabilities
P10
2025-03-26 00:00 UTC
Other

CodeQLEAKED - CodeQL Supply Chain Attack via Exposed Secret

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A publicly exposed GitHub token in CodeQL workflow artifacts could allow attackers to execute malicious code in repositories using CodeQL, potentially leading to source code exfiltration, secrets compromise, and supply chain attacks. The vulnerability stemmed from a debug artifact containing environment variables, which could be downloaded and exploited within a 1-2 second window.

Vulnerabilities
P0
2025-03-25 00:00 UTC
Other

Entra ID Bug Creates Immutable Users

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A bug in Entra ID restricted management administrative units allowed creating immutable users that couldn't be modified or disabled, even by Global Administrators. This could enable an attacker to protect a compromised account from containment. The issue was caused by a timing vulnerability when removing users from restricted AUs and required specific steps to remediate affected accounts.

MicrosoftVulnerabilities
P0
2025-03-10 00:00 UTC
Other

Azure API Connections Expose Backend Secrets

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure API Connections were found to allow any reader on a subscription to access backend resources through a proxy endpoint, potentially exposing secrets from Key Vaults, databases, and third-party services. This vulnerability affects various Azure services and external APIs, enabling privilege escalation and unauthorized access to sensitive information.

Cloud SecurityVulnerabilities
P10
2025-03-04 00:00 UTC
Other

Issue with AWS Temporary Elevated Access Management

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in AWS Temporary Elevated Access Management (TEAM) allows users to modify valid requests and spoof approvals due to improper input validation. This affects versions prior to 1.2.2 of TEAM for AWS IAM Identity Center. AWS has released a fix in version 1.2.2 and recommends customers upgrade to the latest release.

Cloud SecurityVulnerabilities
P0
2025-01-24 00:00 UTC
Other

Entra ID Allows Users to Update Principal Names

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A configuration change in Entra ID allowed unprivileged users to update their own User Principal Names (UPNs) through interfaces like the Entra admin center and PowerShell. This could lead to impersonation risks. Microsoft quickly fixed the issue after it was reported. The vulnerability affected synchronized hybrid environments as well.

MicrosoftVulnerabilities
P0
2025-01-23 00:00 UTC
Other

AWS Sign-in IAM User Login Flow Username Enumeration

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in AWS IAM Sign-in login flow could allow attackers to enumerate IAM usernames by measuring server response times. This issue affected AWS Sign-in IAM User login flow prior to January 16, 2025. AWS has since introduced a delay in response times across all authentication failure scenarios to mitigate the vulnerability.

AppleCloud SecurityVulnerabilities
P0
2025-01-16 00:00 UTC
Other

CloudWatch Dashboard Sharing Exposes EC2 Tags

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in AWS CloudWatch dashboard sharing allowed viewers to access EC2 instance tags and potentially invoke Lambda functions in the source account. The issue stemmed from a logic bug in the AWS Console combined with a "fail open" condition in Amazon Cognito. AWS has since patched the vulnerability.

Cloud SecurityVulnerabilities
P0
2025-01-14 00:00 UTC
Government

[MàJ] Vulnérabilité dans les produits Fortinet (14 janvier 2025)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

\[Mise à jour du 28 janvier 2025\] Une preuve de concept permettant l'exploitation de cette vulnérabilité est disponible publiquement. Le 14 janvier 2025, Fortinet a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-55591 affectant FortiOS et FortiProxy. Elle permet à un...

AppleNetwork SecurityVulnerabilitiesCVE-2024-55591
P5
2025-01-09 00:00 UTC
Government

[MàJ] Vulnérabilité dans les produits Ivanti (09 janvier 2025)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Une vulnérabilité jour-zéro de type débordement de pile a été découverte dans Ivanti Connect Secure (ICS), Policy Secure (IPS), Neurons for Zero Trust Access (ZTA) gateways. Cette vulnérabilité, d'identifiant CVE-2025-0282, permet à un attaquant non authentifié de provoquer une exécution de code...

VulnerabilitiesCVE-2025-0282
P5
2025-01-08 00:00 UTC
Other

Hijacking Azure Machine Learning Notebooks

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Machine Learning notebooks can be hijacked by attackers with Storage Account access to inject malicious code. A now-fixed vulnerability allowed Reader role escalation to code execution. The article details the attack methods, including modifying notebooks, obtaining managed identity tokens, and exfiltrating data. It also introduces a tool for dumping AML workspace credentials.

Cloud SecurityVulnerabilities
P0
2024-12-29 00:00 UTC
Other

AWS Neuron SDK Dependency Confusion Vulnerability Recurs

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS Neuron SDK has reintroduced a dependency confusion vulnerability three times in four years. The issue stems from using the --extra-index-url parameter in pip install commands, which allows potential installation of malicious packages from PyPI instead of AWS's private repository. Despite previous reports, AWS has not fully addressed the problem, leaving new packages vulnerable to exploitation.

Cloud SecurityVulnerabilities
P0
2024-12-11 00:00 UTC
Other

Code Execution in Azure API Management Developer Portal

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Azure API Management Developer Portal allows arbitrary code execution and secret exfiltration. The issue stems from a workflow that loads untrusted data from opened issues, potentially allowing attackers to inject malicious commands. This could lead to code execution in the runner, granting access to sensitive tokens and permissions.

Cloud SecurityVulnerabilities
P0
2024-11-12 00:00 UTC
Other

ModeLeak: LLM Model Exfiltration Vulnerability in Vertex AI

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in GCP's Vertex AI service allows privilege escalation and unauthorized access to sensitive LLM models. Attackers can exfiltrate these models by exploiting misconfigurations in access controls and service bindings. By exploiting custom job permissions, researchers were able to escalate their privileges and gain unauthorized access to all data services in the project. In addition, deploying a poisoned model in Vertex AI led to the exfiltration of all other fine-tuned models, posi…

AI SecurityVulnerabilities
P10
2024-11-01 00:00 UTC
Other

Confused Deputy Vulnerability in Amazon DataZone

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Amazon DataZone allowed potential attackers to assume roles in AWS accounts by exploiting a confused deputy problem. This could have granted unauthorized access to sensitive data managed by DataZone or other AWS services accessible by the IAM role trusting DataZone. The issue has been resolved, with no customers reportedly impacted.

Cloud SecurityVulnerabilities
P0
2024-11-01 00:00 UTC
Other

Repo swatting attack deletes/blocks GitHub and GitLab accounts

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A technique called "repo swatting" allows attackers to delete GitHub and block GitLab accounts by exploiting file upload features and abuse reporting mechanisms. Attackers upload malicious files to a target's repository, then report the account for hosting malicious content, potentially resulting in account deletion. The vulnerability was partially mitigated by October 2024 via changes in upload URL paths and requirement for each uploader to be authenticated (in GitHub).

Vulnerabilities
P0
2024-10-24 00:00 UTC
Other

AWS CDK Bucket Squatting Risk

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The AWS Cloud Development Kit (CDK) is a way of deploying infrastructure-as-code. The vulnerability involves AWS CDK’s use of a predictable S3 bucket name format (cdk-{Qualifier}-assets-{Account-ID}-{Region}), where the default “random” qualifier (hnb659fds) is common and easily guessed. If an AWS customer deletes this bucket and reuses CDK, an attacker who claims the bucket can inject malicious CloudFormation templates, potentially gaining admin access. Attackers supposedly only need the AWS a…

Cloud SecurityVulnerabilities
P0
39 40 41 42 43