IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,388 matching records.
AUTO-POLL // 2026-10-06 03:20 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 6
NO DATA
--
NO INTEL
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
RESET
2021-12-30 00:00 UTC
Other

Bypassing Identity-Aware Proxy in Google Cloud

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Google Cloud Platform's Identity-Aware Proxy (IAP) allowed attackers to bypass authentication and access IAP-secured web applications. The exploit involved creating a malicious IAP-secured app using the target's OAuth client ID, configuring query parameter-based routing to capture redirect tokens, and using these tokens to hijack authorized sessions.

Cloud SecurityVulnerabilities
P0
2021-12-28 00:00 UTC
Other

Dataflow RCE via unauthenticated JMX service

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Dataflow worker nodes ran an unauthenticated Java Management Extensions (JMX) service that under certain circumstances would be exposed to the Internet, thus allowing unauthenticated remote code execution (RCE) as root in an unprivileged container. The impact of the vulnerability depended on which service account qA assigned to Dataflow worker nodes (by default, that would be the Google Compute Engine default service account, which has the project-wide Editor role assigned).

Vulnerabilities
P15
2021-12-28 00:00 UTC
Other

Google Cloud Shell command injection

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability was discovered in Cloud Shell that enabled command injection and remote shell access. The "Open in Cloud Shell" functionality allowed a user to provide values for both the "git_repo" and "go_get_repo" parameters, which would clone the target repo in the user's environment. While "git_repo" was validated against a list of trusted repos, "go_get_repo" was not. Therefore, an attacker could have supplied a trusted repository as "git_repo" and an arbitrary command in the "go_get_repo…

Cloud SecurityPhishingVulnerabilities
P0
2021-12-07 00:00 UTC
Other

LPE vulnerability in Eltima (3rd-party cloud desktop driver)

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Several cloud desktop solutions rely on a 3rd-party library called Eltima SDK to provide USB over Ethernet capabilities, to allow users to connect and share local devices such as webcams. SentinelLabs discovered vulnerabilities in Eltima drivers, including proprietary versions used by several cloud services (among them AWS Workspaces), that would allow unprivileged users to escalate privileges to kernel mode.

Cloud SecurityLinuxVulnerabilities
P0
2021-12-02 00:00 UTC
Other

AWS SageMaker Jupyter Notebook instance CSRF

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS SageMaker Notebook server lacked a check of the Origin header that led to a CSRF vulnerability. An attacker could have read sensitive data and execute arbitrary actions in customer environments. The exact same issue existed in GCP previously.

Cloud SecurityVulnerabilities
P0
2021-09-22 00:00 UTC
Other

Predictible seed in Anthos Identity Service LDAP module

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability was discovered in the Anthos Identity Service (AIS) LDAP module of Anthos clusters on VMware versions 1.8 and 1.8.1 where a seed key used in generating keys is predictable. With this vulnerability, an authenticated user could add arbitrary claims and escalate privileges indefinitely.

Vulnerabilities
P0
2021-09-21 00:00 UTC
Other

AWS Workspace client RCE

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

If a user with AWS WorkSpaces 3.0.10-3.1.8 installed visits a page in their web browser with attacker controlled content, the attacker can get zero click RCE under common circumstances.

Cloud SecurityVulnerabilities
P15
2021-08-26 00:00 UTC
Other

ChaosDB

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure's Cosmos DB database service was vulnerable to remote account takeover. Any Azure user could gain full admin access to other customers' Cosmos DB instances without authorization. The vulnerability had a trivial exploit that doesn't require any previous access to the target environment.

Cloud SecurityVulnerabilities
P0
2021-06-13 00:00 UTC
Other

Privilege escalation on Dialogflow cloud platform

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A privilege escalation vulnerability was discovered in Google's Dialogflow cloud platform. When downgrading a user's role from Developer to Reviewer, the permissions were not properly updated, allowing the user to retain Developer-level access. This issue persisted in the Google Cloud Console, where role changes resulted in additive permissions instead of replacements.

Cloud SecurityVulnerabilities
P10
2021-06-01 00:00 UTC
Other

OMIGOD

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure forces the install of an agent on Linux VMs, which contained a vulnerability that would grant root RCE if an attacker could send a web request to them. Initially, Microsoft did not update the agent automatically, and so customers had to patch manually, but a few days later they began patching some services remotely.

Cloud SecurityLinuxMicrosoftVulnerabilities
P15
2021-04-30 00:00 UTC
Other

Password Reset Code Brute-Force Vulnerability in AWS Cognito

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in AWS Cognito's password reset function allowed attackers to brute-force the six-digit reset code, potentially leading to account takeovers. Using concurrent HTTP requests, an attacker could make up to 1587 guesses instead of the documented limit of 20. The issue affected accounts without multi-factor authentication and was fixed by AWS on April 20, 2021.

Cloud SecurityVulnerabilities
P0
2021-03-17 00:00 UTC
Other

Privilege escalation in GCP OS Login

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

GCP provides an OS Login service for managing SSH access to compute instances using IAM roles. An attacker could abuse this feature via LXD, Docker (if available on the target system) and DHCP poisoning of the metadata server to escalate their privileges on a Google Compute Engine VM.

Vulnerabilities
P10
2021-03-09 00:00 UTC
Other

Azure Linux VM extension credential leak

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in the Azure Linux VM extension mechanism allowed an unprivileged user to leak any Azure VM extension’s private data. An attacker could have abused this to gain credentials for the VM itself as well as credentials for extensions associated with the VM. Paired with the design of the VMAccess extension (an official Azure extension for managing VM credentials), this could have been used to achieve privilege escalation, as an unprivileged attacker would have been able to elevate the…

Cloud SecurityLinuxVulnerabilities
P10
2020-11-22 00:00 UTC
Other

IAM privilege escalation in multiple GCP services

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Composer, Dataflow, Dataproc, Dataprep and Data Fusion all used the Compute Engine default service account by default and relied on product-level IAM permissions without requiring the iam.serviceAccount.actAs permission, meaning that users of these services could elevate their privileges. Following disclosure, GCP changed these services to require this permission.

Vulnerabilities
P10
2020-10-17 00:00 UTC
Other

AI Hub Jupyter Notebook instance CSRF

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AI Hub Jupyter Notebook server lacked a check of the Origin header that led to a CSRF vulnerability. An attacker could have read sensitive data and execute arbitrary actions in customer environments.

Vulnerabilities
P0
2020-10-01 00:00 UTC
Other

Google Cloud Shell XSS to RCE Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Google Cloud Shell allowed escalation from XSS to full instance takeover as root. The attack exploited an XSS in the markdown preview functionality to read sensitive files, obtain the instance's private key and hostname, and gain SSH access as root. The issue affected the Eclipse Theia-based editor used in Cloud Shell.

Cloud SecurityVulnerabilities
P15
2020-06-15 00:00 UTC
Other

GKE and EKS CAP_NET_RAW metadata service MITM root privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An attacker with access to a hostNetwork=true container with CAP_NET_RAW capability can listen to all the traffic going through the host and inject arbitrary traffic, allowing to tamper with most unencrypted traffic (HTTP, DNS, DHCP, ...), and disrupt encrypted traffic. In GKE the host queries the metadata service at http://169[.]254.169.254 to get information, including the authorized SSH keys. By manipulating the metadata service responses and injecting our own SSH key, it is possible to gain…

Vulnerabilities
P10
2020-03-08 00:00 UTC
Other

Google wide domain check bypass

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Google's common JavaScript library allowed bypassing domain validation checks across multiple Google products. By using a backslash character in URLs, an attacker could make the regex parser and browser disagree on the authority (domain) portion of a URL, allowing injection of arbitrary domains that pass whitelisting checks.

Vulnerabilities
P0
2020-01-30 00:00 UTC
Other

Azure App Service RCE

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A Vulnerability in App Service could allow an unprivileged function run by the user to execute code in the context of NT AUTHORITY\system, thereby escaping the sandbox. This vulnerability allowed cross-account access when using the Free/Shared tier.

Cloud SecurityVulnerabilities
P15
44 45 46 47