IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,388 matching records.
AUTO-POLL // 2026-10-06 01:55 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 6
NO DATA
--
NO INTEL
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
RESET
2024-10-23 00:00 UTC
Government

[MàJ] Multiples vulnérabilités dans Fortinet FortiManager (23 octobre 2024)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

**[Mise à jour du 14 janvier 2025]** **Publication des correctifs** Le 14 janvier 2025, Fortinet a publié un avis de sécurité relatif à la vulnérabilité CVE-2024-50566 qui correspond à la vulnérabilité de type jour-zéro pour laquelle une preuve de concept a été publiée en novembre 2024. Des...

Network SecurityVulnerabilitiesCVE-2024-50566
P5
2024-10-22 00:00 UTC
Government

Exploitations de vulnérabilités dans Ivanti Cloud Services Appliance (CSA) (22 octobre 2024)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Ivanti a publié plusieurs avis de sécurité sur des vulnérabilités affectant CSA qui sont activement exploitées : * le 10 septembre 2024, Ivanti a publié un avis de sécurité concernant la vulnérabilité CVE-2024-8190 qui permet à un attaquant, authentifié en tant qu'administrateur, d'exécuter du...

VulnerabilitiesCVE-2024-8190
P5
2024-10-15 00:00 UTC
Other

CloudShell Vulnerability Grants Unintended AWS Access

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in AWS CloudShell allowed users to gain unintended command-line access to the underlying AWS infrastructure. During a training session, a delegate unexpectedly received the identity context of an EC2 instance role within an ECS cluster, instead of the intended AWS account. This issue potentially bypassed existing controls aimed at preventing lateral movement and access to higher-privileged management roles.

Cloud SecurityVulnerabilities
P0
2024-10-09 00:00 UTC
Other

Subdomain Takeover Vulnerability in GitLab Pages

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in GitLab Pages allowed attackers to take over dangling custom domains pointing to 'instanceX.gitlab.io'. The issue occured when adding an unverified custom domain to GitLab Pages, which serves content for 7 days before disabling. This could lead to cookie stealing, phishing campaigns, and bypassing of Content-Security Policies and CORS.

PhishingVulnerabilities
P0
2024-09-26 00:00 UTC
Other

Google Cloud Data Fusion GitHub Actions Vulnerabilities

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Multiple "pwn request" vulnerabilities were discovered in Google Cloud Data Fusion, which is based on open-source CDAP code. These vulnerabilities affect GitHub Actions and allow for remote code execution (RCE) and compromise of build artifacts. The issues potentially impact both the Google Cloud platform and GitHub's CI/CD infrastructure.

Cloud SecurityVulnerabilities
P15
2024-09-16 00:00 UTC
Other

CloudImposer

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Google Cloud Composer is a managed service for Apache Airflow. Tenable discovered that the Cloud Composer package was vulnerable to dependency confusion, which could have allowed attackers to inject malicious code when the package was compiled from source. This could have led to remote code execution on machines running Cloud Composer, which include various other GCP services as well as internal servers at Google. The dependency confusion stemmed from Google's risky recommendation in their docu…

Cloud SecurityVulnerabilities
P15
2024-09-16 00:00 UTC
Other

Document AI data exfiltration

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The Document AI service unintentionally allows users to read any Cloud Storage object in the same project, in a way that isn't properly documented. The Document AI service agent is auto-assigned with excessive permissions, allowing it to access all objects from Cloud Storage buckets in the same project. Malicious actors can exploit this to exfiltrate data from Cloud Storage by indirectly leveraging the service agent's permissions. This vulnerability is an instance of transitive access abuse, a …

Vulnerabilities
P0
2024-09-13 00:00 UTC
Other

Escalating from Reader to Contributor in Azure API Management

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Azure API Management allowed users with Reader access to escalate privileges to Contributor level by accessing admin user keys via the ARM API. This permitted full management capabilities through the Direct Management API, including reading secrets and modifying configurations.

Cloud SecurityVulnerabilities
P0
2024-09-10 00:00 UTC
Government

Vulnérabilité dans SonicWall (10 septembre 2024)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Le 22 août 2024, Sonicwall a publié un correctif concernant la vulnérabilité critique CVE-2024-40766 affectant les pare-feux Sonicwall génération 5, 6 et 7. Cette vulnérabilité, de type contrôle d'accès défaillant, permet à un attaquant de provoquer un déni de service à distance, une atteinte à...

VulnerabilitiesCVE-2024-40766
P5
2024-08-19 00:00 UTC
Other

WireServing Up Credentials in Azure Kubernetes Services

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Azure Kubernetes Services allowed attackers to escalate privileges and access cluster credentials. Affected clusters used Azure CNI for network configuration and Azure for network policy. Attackers could exploit this issue to steal data and cause financial and reputational damage. The vulnerability has been fixed by Microsoft after disclosure by Mandiant.

Cloud SecurityMicrosoftVulnerabilities
P0
2024-08-07 00:00 UTC
Other

Privilege Elevation Vulnerability in Entra ID

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Semperis researchers discovered vulnerabilities in Microsoft applications that allowed privilege elevation in Entra ID beyond expected authorization controls. The most severe finding enabled adding users to privileged roles, including Global Administrator, without proper permissions. The issues affected Device Registration Service, Viva Engage, and Microsoft Rights Management Service. Microsoft has since resolved the vulnerabilities.

MicrosoftSecurity ResearchVulnerabilities
P0
2024-08-03 20:24 UTC
Security Journalism

SlashAndGrab ConnectWise ScreenConnect Vulnerability

Huntress · indexed 2026-09-07 17:30 UTC

Huntress gives you a non-technical breakdown of the SlashAndGab ConnectWise ScreenConnect Vulnerability; dig into the insights on how we discovered it and supported the community along the way.

Vulnerabilities
P0
2024-07-24 00:00 UTC
Other

GCP Cloud Functions Privilege Escalation Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A privilege escalation vulnerability dubbed "ConfusedFunction" was discovered in Google Cloud Platform's Cloud Functions service. It allows attackers to escalate privileges from Cloud Function permissions to the default Cloud Build service account during function deployment. The vulnerability affects both first and second-generation Cloud Functions.

Cloud SecurityVulnerabilities
P10
2024-07-01 00:00 UTC
Government

Vulnérabilité dans OpenSSH (01 juillet 2024)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Le 1 juillet 2024, OpenSSH a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-6387. Cette vulnérabilité permet à un attaquant non authentifié d'exécuter du code arbitraire à distance avec les privilèges *root*. L'éditeur précise que les versions 8.5p1 à 9.7p1 sont...

VulnerabilitiesCVE-2024-6387
P5
2024-06-14 00:00 UTC
Other

GitHub Copilot Chat Vulnerable to Data Exfiltration

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

GitHub Copilot Chat VS Code Extension was vulnerable to data exfiltration via prompt injection when analyzing untrusted source code. The vulnerability allowed attackers to access previous conversation turns and append information from the chat history to an image URL, which was then automatically retrieved by Copilot, sending the data to the attacker.

AI SecurityVulnerabilities
P0
2024-06-11 00:00 UTC
Other

Issue with AWS Deployment Framework

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

CVE-2024-37293 affects the AWS Deployment Framework's bootstrap process, potentially allowing privilege escalation if an actor has permissions to change CodeBuild projects or Lambda functions. The issue is fixed in version 4.0 and above. AWS recommends immediate upgrade and temporary mitigation by adding a permissions boundary to roles created by ADF in the management account.

Cloud SecurityVulnerabilitiesCVE-2024-37293
P15
2024-06-03 00:00 UTC
Other

Abusing Service Tags to Bypass Azure Firewall Rules

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Tenable Research discovered a vulnerability in Azure allowing attackers to bypass firewall rules based on Service Tags by forging requests from trusted services. It affects over 10 Azure services and enables access to internal/private Azure resources. Microsoft updated documentation to clarify Service Tags' security limitations.

Cloud SecurityMicrosoftNetwork SecurityVulnerabilities
P0
2024-04-29 00:00 UTC
Other

GraphNinja

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Microsoft Graph allowed attackers to conduct password-spray attacks without detection. The issue involved switching the 'common' authentication endpoint with that of an unrelated tenant, thereby avoiding the appearance of logon attempts in the victim's logs. This technique could allow attackers to validate user credentials through verbose error messages, but actual successful logons using these credentials would still be recorded in the victims' logs (regardless of endpoint).

MicrosoftNetwork SecurityVulnerabilities
P0
2024-04-26 00:00 UTC
Other

Azure tenant takeover via Microsoft application

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Microsoft Dynamics 365 Supply Chain Visibility allowed arbitrary takeover of Azure tenants via a malicious reply URL. Clicking a link could grant an attacker directory read access or full tenant control if clicked by a Global Admin, without requiring user consent.

Cloud SecurityMicrosoftVulnerabilities
P0
2024-04-25 00:00 UTC
Government

Multiples vulnérabilités dans les produits Cisco (25 avril 2024)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Le 24 avril 2024, Cisco a publié trois avis de sécurité concernant des vulnérabilités affectant les équipements de sécurité ASA et FTD. Deux d'entre eux concernent les vulnérabilités CVE-2024-20353 et CVE-2024-20359 qui sont activement exploitées dans le cadre d'attaques ciblées. La vulnérabilité...

VulnerabilitiesCVE-2024-20353CVE-2024-20359
P5
2024-04-15 00:00 UTC
Other

AWS Amplify IAM role publicly assumable exposure

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The AWS Amplify service was found to be misconfiguring IAM roles associated with Amplify projects. This misconfiguration caused these roles to be assumable by any other AWS account. Both the Amplify Studio and the Amplify CLI exhibited this behavior. Any Amplify project created using the Amplify CLI built between July 3, 2018 and August 8, 2019 had IAM roles that were assumable by anyone in the world. The same was true if the authentication component was removed from an Amplify project using th…

Cloud SecurityVulnerabilities
P0
2024-04-03 00:00 UTC
Other

Bazel supply chain vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Cycode discovered a CI/CD misconfiguration in the Bazel repo, which if exploited could have allowed an attacker to enact a supply chain attack against all Bazel users, which includes Google themselves and therefore likely GCP as well.

Vulnerabilities
P0
2024-04-03 00:00 UTC
Other

Critical GitLab Account Takeover Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

GitLab addressed a critical vulnerability, CVE-2023-7028, affecting managed SaaS gitlab.com instance as well as self-hosted versions 16.1 to 16.7.1. The flaw could allow account takeovers via unverified email password resets. Third party could intercept the password reset request, add their own email to the request and forward it. GitLab would then send the reset link to the added 3rd-party email. This is in effect an account takeover with only precondition of knowing victim email associated wi…

VulnerabilitiesCVE-2023-7028
P15
2024-03-21 00:00 UTC
Other

FlowFixation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A flaw in Amazon Managed Workflows for Apache Airflow (MWAA) could have allowed potential session hijacking and remote code execution. The issue stemmed from a combination of session fixation in the MWAA web management panel and an AWS domain configuration error leading to a cross-site scripting (XSS) attack. Attackers exploiting this could manipulate victims' configurations, trigger workflows, and potentially move laterally to other services within the cloud environment. The exploit of this bu…

Cloud SecurityVulnerabilities
P15
2024-03-07 00:00 UTC
Other

Synapse Analytics privilege escalation via intelligent caching

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Tenable Research discovered a privilege escalation flaw that allows a user to escalate privileges to that of the root user within the context of a Spark VM. This escalation was achieved because of a permissions issue with scripts utilized by the intelligent caching service (AKA "Vegas") present in the environment.

Vulnerabilities
P10
2024-02-23 00:00 UTC
Security Journalism

SlashAndGrab | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Adversaries have been VERY busy in the wake of the ScreenConnect vulnerabilities (CVE-2024-1709 & CVE-2024-1708). Here’s all the post-exploitation details, tradecraft, and tactics we’ve observed so far!

VulnerabilitiesCVE-2024-1708CVE-2024-1709
P5
40 41 42 43 44