IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,564 matching records.
AUTO-POLL // 2026-10-07 08:35 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P4 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7

RANSOMWARE
P4
P4
COOL // 11 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2025-05-07 05:00 UTC
Security Journalism

Rapid Response: Samsung MagicINFO 9 Server Flaw

Huntress · indexed 2026-09-07 17:30 UTC

Huntress has verified Samsung’s MagicINFO 9 Server (version 21.1050.0) is vulnerable to a publicly available proof-of-concept (PoC). Understand why MagicINFO 9 Server shouldn’t be internet-facing until a patch is applied.

P0
2025-05-06 05:00 UTC
Security Journalism

Do Tigers Really Change Their Stripes?

Huntress · indexed 2026-09-07 17:30 UTC

Across the larger cybersecurity community, an often-used adage is that “threat actors always change their tactics.” However, when we really start to look at and track incident data, we begin to see that while some changes may be necessitated based on infrastructures and other challenges the threat actor may encounter, there are times when tactics remain consistent across incidents. Recent investigations into exploitation activity for CVE-2025-31151 and CVE-2025-30406 show similar TTPs across di…

DFIRThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2025-30406CVE-2025-31151
P5
2025-05-06 00:00 UTC
Other

Azure AZNFS-mount Utility Root Privilege Escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A critical vulnerability in AZNFS-mount utility, preinstalled on Azure HPC/AI images, allowed unprivileged users to escalate privileges to root on Linux machines. The flaw existed in versions up to 2.0.10 and involved a SUID binary. Azure classified it as low severity but fixed it in version 2.0.11.

Cloud SecurityLinuxVulnerabilities
P10
2025-05-05 12:00 UTC
Government

Small Businesses Create Big Impact: NIST Celebrates 2025 National Small Business Week

NIST Cybersecurity Insights · Daniel Eliot · indexed 2026-08-15 20:45 UTC

This week we’re celebrating National Small Business Week—which recognizes and celebrates the small and medium-sized business (SMB) community’s significant contributions to the nation. SMBs are a substantial and critical part of the U.S. and global economic and cybersecurity infrastructure. According to the U.S. Small Business Administration’s Office of Advocacy, [1] there are 34.8 million SMBs in the United States (making up 99% of all U.S. businesses). Of those, 81.7% are non-employer firms wi…

P0
2025-05-02 17:38 UTC
Other

ASP.NET Cryptography for Pentesters

Black Lantern Security · Paul Mueller · indexed 2026-09-07 17:30 UTC

This article was originally posted to blog.liquidsec.net on June 1, 2021.

P0
2025-05-01 05:00 UTC
Security Journalism

Applying Criminal Justice Principles to Detection Engineering

Huntress · indexed 2026-09-07 17:30 UTC

Explore how criminal justice principles can improve detection engineering by distinguishing true threats from false positives. And learn how concepts like burden of proof and intent enhance cybersecurity defense strategies.

P0
2025-04-30 06:00 UTC
Other

Ransomware debris: an analysis of the RansomHub operation

Group-IB · indexed 2026-09-07 17:30 UTC

This blog on RansomHub provides an overview into how this Ransomware-as-a-Service (RaaS) group operates, including its extortion tactics, affiliate recruitment strategies, and the features of its affiliate panel.

Ransomware
P15
2025-04-29 05:00 UTC
Security Journalism

Minutes Matter | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress Managed SIEM makes threat detection and response faster and more accessible. Learn about new features, real-world success stories, and how it enhances cybersecurity and compliance.

P0
2025-04-29 00:00 UTC
Other

AWS Default Roles Can Lead to Service Takeover

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Research uncovered security flaws in default AWS service roles, granting overly broad permissions like full S3 access. This allows privilege escalation, cross-service access, and potential account compromise across services like SageMaker, Glue, and EMR. Attackers could exploit these roles to manipulate critical assets and move laterally within AWS environments. AWS has since updated default policies and documentation to mitigate risks.

Cloud SecurityVulnerabilities
P10
2025-04-28 05:00 UTC
Security Journalism

Identity Threats Got a Whole Lot Nastier, But So Did We

Huntress · indexed 2026-09-07 17:30 UTC

Huntress Managed ITDR with Rogue Apps proactively protects against identity threats, including malicious OAuth apps. Learn about the surge in identity-based attacks and how to defend your business effectively.

P0
2025-04-28 00:00 UTC
Government

Vulnérabilité dans SAP NetWeaver (28 avril 2025)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Le 24 avril 2025, SAP a publié un bulletin de sécurité relatif à la vulnérabilité CVE-2025-31324 qui permet l'exécution de code arbitraire à distance pour un utilisateur non authentifié. Cette vulnérabilité est provoquée par un contournement de la politique de sécurité qui permet de télécharger...

VulnerabilitiesCVE-2025-31324
P5
2025-04-24 05:00 UTC
Security Journalism

How to Stop Malware Attacks with a Security-First Culture

Huntress · indexed 2026-09-07 17:30 UTC

Protect your business from malware attacks by fostering a security-first culture. Learn how to defend against cyber threats, establish strategies, and train employees to spot malware before it strikes.

Malware
P0
2025-04-24 05:00 UTC
Security Journalism

Credential Theft: Expanding Your Reach, Pt. II

Huntress · indexed 2026-09-07 17:30 UTC

As with many tactics within the MITRE ATT&CK framework, credential theft consists of a number of different techniques. Showing what many of them look like on an endpoint helps other security professionals understand what to look for and how to detect and respond to similar activity.

Phishing
P0
2025-04-23 07:05 UTC
Other

Toll of Deception: Where Evasion Drives Phishing Forward

Group-IB · indexed 2026-09-07 17:30 UTC

Discover the latest phishing campaign targeting a major toll road service provider, where cybercriminals use sophisticated evasion techniques to bypass security detections. This in-depth blog reveals how threat actors exploit legitimate platforms and deploy cloaking methods to disguise malicious links, allowing them to evade detection by security solutions. Discover how these sophisticated tactics create highly convincing phishing pages designed to steal victims’ card information, and how to sa…

PhishingThreat Actors
P0
2025-04-22 05:00 UTC
Security Journalism

Say Hello to Mac Malware

Huntress · indexed 2026-09-07 17:30 UTC

In this month’s Tradecraft Tuesday, we talked about how threat actors are finetuning their macOS malware in order to maintain persistent access and avoid detection by Apple’s security features.

AppleMalwareThreat Actors
P0
2025-04-22 00:00 UTC
Other

Google Cloud ConfusedComposer Privilege Escalation Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Tenable discovered a privilege escalation vulnerability in Google Cloud Platform's Cloud Composer service, dubbed ConfusedComposer. It allowed users with composer.environments.update permission to escalate privileges to the default Cloud Build service account by injecting malicious PyPI packages. This could grant broad permissions across the victim's GCP project.

Cloud SecurityVulnerabilities
P10
2025-04-18 13:20 UTC
Other

How to Eat an Entire Elephant

Black Lantern Security · Micheal Reski · indexed 2026-09-07 17:30 UTC

Scanning the Internet with BBOT

P0
2025-04-17 05:00 UTC
Security Journalism

Tales of Too Many RMMs

Huntress · indexed 2026-09-07 17:30 UTC

In a highly interconnected world, remote monitoring and management (RMM) tools are critical to reducing cost and increasing efficiencies. However, these tools pose challenges and even significant risk if not properly managed.

P0
2025-04-16 05:00 UTC
Security Journalism

Why App Allowlisting & Zero Trust Alone Won't Save You | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

App Allowlisting is a good preventative software tool, but it's not enough. Learn why a layered security approach with detection and response is crucial to protect against today's cyber threats.

P0
2025-04-15 00:00 UTC
Other

Burning Data with Malicious Firewall Rules in Azure SQL

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Varonis Threat Labs discovered a vulnerability in Azure SQL Server allowing privileged users to create malicious firewall rules that can delete Azure resources when triggered by admin actions. The exploit involves manipulating rule names via TSQL to inject destructive commands, potentially leading to large-scale data loss in affected Azure accounts.

Cloud SecurityNetwork SecurityVulnerabilities
P0
2025-04-11 08:50 UTC
Other

CISOs Top Order Of Business: Cyber Risk Reduction & Management

Group-IB · indexed 2026-09-07 17:30 UTC

For modern CISOs, cyber risk management and reduction are nonstop challenges. But this blog offers exactly what you need to build a strategy that empowers you to manage and mitigate threats—cutting through the noise of an otherwise demanding role.

P0
2025-04-11 00:00 UTC
Government

Activités de post-exploitation dans Fortinet FortiGate (11 avril 2025)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Fortinet a publié le 10 avril 2025 un billet de blogue [1] indiquant l'utilisation d'une technique de post-exploitation qui permet une atteinte à la confidentialité des données de l'ensemble du système des équipements Fortigate affectés. Cette technique repose sur l'utilisation d'un lien...

Network Security
P0
2025-04-10 05:00 UTC
Security Journalism

Ransomware Initial Access Brokers Exposed

Huntress · indexed 2026-09-07 17:30 UTC

Discover how a seemingly simple brute force attack led to the uncovering of a suspected ransomware-as-a-service operation. This ecosystem appears to be leveraged by initial access brokers, driving an illicit and complex network of cybercrime.

CybercrimeRansomware
P15
2025-04-09 05:00 UTC
Security Journalism

How EDR and ITDR Elevate Your Security

Huntress · indexed 2026-09-07 17:30 UTC

Threat actors are now exploiting both endpoints and identities in the latest cyberattacks. Learn about the rise of identity-based threats and why a combined EDR and ITDR approach is crucial for your cybersecurity.

Threat Actors
P0
2025-04-09 00:00 UTC
Other

Path Traversal in AWS SSM Agent Plugin ID Validation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A path traversal vulnerability in AWS SSM Agent's ValidatePluginId function allows attackers to create directories and execute scripts in unintended locations on the filesystem. This could lead to privilege escalation or other malicious activities, as files may be written to or executed from sensitive areas of the system with root privileges.

Cloud SecurityVulnerabilities
P10
118 119 120 121 122