IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,388 matching records.
AUTO-POLL // 2026-10-06 01:55 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 6
NO DATA
--
NO INTEL
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
RESET
2024-02-13 00:00 UTC
Other

Azure Site Recovery privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

When the ASR service is enabled, it uses an Automation Account with a System-Assigned Managed Identity to manage Site Recovery extensions on VMs. However, the Runbook (a set of scripts for managing extensions) executed by the Automation Account had its job output visible to users, and this output mistakenly included a cleartext Management-scoped Access Token for the System-Assigned Managed Identity, which possesses the Contributor role over the entire Azure subscription. Therefore, lower-privil…

Cloud SecurityVulnerabilities
P10
2024-02-09 00:00 UTC
Government

[MàJ] Vulnérabilité dans Fortinet FortiOS (09 février 2024)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

\[Mise à jour du 19 mars 2024\] Le CERT-FR a connaissance de codes d'exploitation publics et de nouvelles tentatives d'exploitation. Le 8 février 2024, Fortinet a publié l'avis de sécurité concernant la vulnérabilité critique CVE-2024-21762 affectant le VPN SSL de FortiOS. Cette vulnérabilité...

AppleNetwork SecurityVulnerabilitiesCVE-2024-21762
P5
2024-02-06 00:00 UTC
Other

Azure HDInsight privilege escalation and DoS vulnerabilities

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Three privilege escalation and denial-of-service vulnerabilities were discovered in Azure HDinsight, related to their usage of Apache Oozie and Ambari. The root cause of at least one of these vulnerabilities is a flaw in Apache Oozie itself, leading to regex denial-of-service (ReDoS). The other two vulnerabilities could allow an authenticated attacker with HDI cluster access to gain cluster administrator privileges and perform any resource service management operation. The vulnerabilities were …

Cloud SecurityVulnerabilities
P15
2024-01-31 00:00 UTC
Other

Azure Devops Zero-Click CI/CD Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Legit Security found a zero-click vulnerability in Azure Pipelines that allows an attacker to access secrets and internal information and perform actions in elevated permissions in the context of a pipeline workflow. This could allow attackers to move laterally in the organization and initiate supply chain attacks. When a pipeline is triggered by a "pipeline resource trigger," it shows in the platform as "Automatically Triggered For …" Instead of running in fork default permissions, preventing …

Cloud SecurityVulnerabilities
P0
2024-01-12 00:00 UTC
Government

[MàJ] Multiples Vulnérabilités dans GitLab (12 janvier 2024)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

\[Mise à jour du 29 janvier 2024\] Le 25 janvier 2024, l'éditeur a publié un avis de sécurité concernant plusieurs vulnérabilités affectant GitLab CE et EE. La vulnérabilité CVE-2024-0402 est considérée critique avec un score CVSSv3 de 9,9. Elle permet à un attaquant authentifié d'écrire des...

VulnerabilitiesCVE-2024-0402
P5
2023-12-27 00:00 UTC
Other

Amazon Cognito Rate Limit Bypass Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A rate limit bypass vulnerability was discovered in Amazon Cognito, allowing attackers to potentially brute-force login credentials, password reset PINs, and MFA codes by sending requests in parallel. The vulnerability affected the main login flow, password reset function, and MFA process, potentially exposing user accounts to unauthorized access.

Vulnerabilities
P0
2023-12-20 00:00 UTC
Other

Poisoning GitHub's Runner Images Supply Chain Attack

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A critical vulnerability in GitHub's actions/runner-images repository allowed arbitrary code execution on self-hosted runners, potentially enabling modification of GitHub's runner base images. The flaw stemmed from misconfigured self-hosted runners on a public repository with default workflow approval settings. The researcher gained persistence, accessed secrets, and could have inserted malicious code into GitHub's runner images used by customers.

Vulnerabilities
P10
2023-12-15 00:00 UTC
Other

Google OAuth Vulnerability Allows Indefinite Access

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Google OAuth allows employees to retain indefinite access to applications like Slack and Zoom after being removed from their company's Google organization. The issue stems from the ability to create Google accounts using corporate email aliases, which can't be off-boarded by the organization. This bypasses typical account removal processes and poses a significant security risk.

Vulnerabilities
P0
2023-12-13 00:00 UTC
Government

Vulnérabilité dans Apache Struts 2 (13 décembre 2023)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Le 4 décembre 2023, Apache a publié un avis de sécurité concernant la vulnérabilité critique CVE-2023-50164 concernant le cadriciel Struts 2. Cette vulnérabilité permet à un attaquant non authentifié de téléverser une porte dérobée sur un serveur vulnérable, et ainsi exécuter du code arbitraire à...

VulnerabilitiesCVE-2023-50164
P5
2023-11-16 00:00 UTC
Other

Extracting Managed Identity Credentials from Azure Functions

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Azure Function Apps allowed extraction of Managed Identity credentials from the encrypted startup context of Linux containers. This gave attackers with container access the ability to persist as the Managed Identity, breaking the intended security model. Microsoft has since patched the issue by encrypting the sensitive payload.

Cloud SecurityLinuxMicrosoftVulnerabilities
P0
2023-11-14 00:00 UTC
Other

Azure CLI Leaks Credentials in GitHub Actions Logs

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure CLI commands were found to leak sensitive information, including credentials, through GitHub Actions logs. The vulnerability affects multiple Azure CLI commands and could expose secrets in public and private repositories. Microsoft has issued updates to Azure CLI, Azure Pipelines, and GitHub Actions to address the issue.

Cloud SecurityMicrosoftVulnerabilities
P0
2023-11-03 00:00 UTC
Other

Hacking Google Bard via Prompt Injection

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Google Bard allowed for prompt injection and data exfiltration through its Extensions feature. By injecting malicious instructions into shared Google Docs, an attacker could force Bard to render images with exfiltrated chat history data in the URL. The exploit bypassed Content Security Policy using Google Apps Script.

AI SecurityVulnerabilities
P0
2023-11-02 00:00 UTC
Other

ApatchMe

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Amazon Managed Workflows for Apache Airflow (MWAA) and the Task instance details page in the Google Composer UI were not patched against CVE-2023-29247 (Stored XSS). This meant that post-authentication, a threat actor could have exploited this to store their JavaScript payload in the victim's managed Apache Airflow instance and run JavaScript on behalf of the victim (who could be an admin or another user with higher permissions than the threat actor, thereby leading to privilege escalation). Wi…

Threat ActorsVulnerabilitiesCVE-2023-29247
P15
2023-08-24 00:00 UTC
Other

Power Platform Privilege Escalation in Azure AD

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Secureworks researchers discovered an Azure AD application with an abandoned reply URL related to Microsoft Power Platform. An attacker could leverage this URL to redirect authorization codes, exchange them for access tokens, and call Power Platform API via a middle-tier service to obtain elevated privileges. Microsoft quickly addressed the issue by removing the identified abandoned reply URL from the Azure AD application.

Cloud SecurityMicrosoftSecurity ResearchVulnerabilities
P10
2023-08-04 00:00 UTC
Other

Power Platform Custom Code information disclosure

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Power Platform could lead to unauthorized access to Custom Code functions used for custom connectors, thereby allowing cross-tenant information disclosure of secrets or other sensitive information if these were embedded in a Custom Code function. The issue occurred as a result of insufficient access control to Azure Function hosts, which are launched as part of the creation and operation of custom connectors in Microsoft’s Power Platform. An attacker who determined the hostna…

Cloud SecurityMicrosoftVulnerabilities
P0
2023-07-18 00:00 UTC
Other

Bad.Build

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An information disclosure vulnerability in the Google Cloud Build service could have allowed an attacker to view sensitive logs if they had gained prior access to a GCP environment and had permission to create a new Cloud Build instance (cloudbuild.builds.create) or permission to directly impersonate the Cloud Build default service account (which is highly privileged by design and therefore considered to be a known privilege escalation vector in GCP). An attacker could then potentially use this…

Cloud SecurityVulnerabilities
P10
2023-06-27 00:00 UTC
Other

Azure Front Door client-side desync

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A client-side desync vulnerability was discovered in Front Door, one of Azure's CDN solutions, caused by mishandling of the 'Content-Length' header in HTTP requests. Exploiting this vulnerability would most likely require user interaction through social engineering (such as clicking on a malicious link), but could allow an attacker to steal session cookies or forge responses to victim requests.

Cloud SecurityVulnerabilities
P0
2023-06-21 00:00 UTC
Other

Critical Authentication Bypass in Google Cloud API Gateway

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A critical authentication bypass vulnerability was discovered in Google Cloud API Gateway, affecting its JWT authentication method. The flaw, stemming from a business logic bug in the ESPv2 service proxy, allowed attackers to bypass authentication controls by manipulating HTTP methods. This vulnerability impacted various authentication methods including Firebase, Auth0, Okta, and Google ID tokens.

Cloud SecurityVulnerabilities
P10
2023-06-13 00:00 UTC
Other

Bucket Traversal in Google Cloud Storage Transfer Manager

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A bucket traversal vulnerability was discovered in the google.cloud.storage.transfer_manager.upload_chunks_concurrently() function of Google Cloud Storage. This issue could potentially allow unauthorized access to files in different buckets or directories within the same project.

Cloud SecurityVulnerabilities
P0
2023-06-12 00:00 UTC
Other

Azure App Services takeover via legacy API

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Binary Security found two vulnerabilities in the legacy Azure Resource Manager (ARM) REST API. The first vulnerability allowed an attacker with Reader access to an Azure Function, acting from a Windows host, to get an admin token that could be exchanged for a master key granting access to all operations in Kudu (the Functions deployment service). This would allow them to tamper with the function by deploying malicious code to it. The other vulnerability allowed an attacker with Reader access to…

Cloud SecurityMicrosoftVulnerabilities
P0
41 42 43 44 45