IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,565 matching records.
AUTO-POLL // 2026-10-07 09:10 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P4 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7

RANSOMWARE
P4
P4
COOL // 12 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2025-03-04 00:00 UTC
Security Journalism

Cybersecurity Threats in Healthcare [2025 Report] | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

These are the top cybersecurity threats in healthcare, according to Huntress’s 2025 survey of IT pros. Read the full report and learn how to avoid them.

P0
2025-03-03 15:55 UTC
Security Journalism

Hunt for RedCurl | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress discovered RedCurl activity across several organizations in Canada going back to 2023. Learn more about how this APT operates and how they aim to remain undetected while exfiltrating sensitive data.

APT / Nation-State
P0
2025-03-03 15:25 UTC
Other

Tool Release: Webcap

Black Lantern Security · TheTechromancer · indexed 2026-09-07 17:30 UTC

An ultra-lightweight web screenshot tool with advanced features.

P0
2025-02-27 00:00 UTC
Security Journalism

How Effective Is Your SAT Program? | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Discover how modernized security awareness training can transform your workforce into a cybersecurity-first culture. Learn Huntress' key strategies.

P0
2025-02-26 12:00 UTC
Government

Celebrating 1 Year of CSF 2.0

NIST Cybersecurity Insights · Stephen Quinn · indexed 2026-08-15 20:45 UTC

It has been one year since the release of the NIST Cybersecurity Framework (CSF) 2.0 ! To make improving your security posture even easier, in this blog we are: Sharing new CSF 2.0 resources; Taking a retrospective look at some resources and applications you may have missed; and Highlighting ways you can stay involved in our work, helping us help you implement better cybersecurity. NIST’s subject matter experts have worked over the last year to continue expanding the CSF 2.0 implementation reso…

P0
2025-02-26 00:00 UTC
Other

AWS EKS Logged ServiceAccount Tokens in Plaintext

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS EKS was logging ServiceAccount tokens in plaintext, including those used for AssumeRoleWithWebIdentity and connecting to the Kubernetes API server. This issue affected clusters between March 2020 and May 2021, potentially exposing sensitive credentials in CloudWatch logs.

Cloud Security
P0
2025-02-26 00:00 UTC
Other

Silent Reaper (Azure LogicApp Secrets Control Plane Exfiltration)

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure iPaaS services, such as Logic Apps, separate the Control Plane (management) from the Data Plane (execution), but a flaw in this model enabled undetectable data harvesting. An attacker with Azure Reader access to workflow run history can silently extract sensitive data from executions, including secrets and API responses. This is possible because execution details are exposed via the Control Plane, bypassing Data Plane access controls. The root cause of this issue is the unintended exposur…

Cloud Security
P0
2025-02-26 00:00 UTC
Other

Vault Recon (Azure KeyVault Secrets Metadata Control Plane Exfiltration)

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Key Vault enforces a separation between the Control Plane (management) and Data Plane (secrets access). However, a flaw in this isolation allows unauthorized users to enumerate secrets and keys within a vault. By having Reader access or lesser privileges on a Key Vault, an attacker could leverage Azure Resource Explorer to access metadata about stored secrets. This is due to unintended exposure through the Control Plane, which should not provide insight into Data Plane resources. The root…

Cloud Security
P0
2025-02-19 00:00 UTC
Other

Abusing AWS Serverless Image Handler Configuration Weakness

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS solution 'Dynamic Image Transformation for Amazon CloudFront', prior to version 6.2.6, contains a configuration weakness. The Lambda role doesn't constrain bucket access, and the environment variable can be set to a wildcard, allowing access to any bucket. This could potentially lead to unintended access to sensitive images across multiple buckets in the AWS account.

Cloud Security
P0
2025-02-11 00:00 UTC
Security Journalism

2025 Cybersecurity Threat Report | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress’ 2025 Cyber Threat Report is here! Explore the year's biggest threats—RATs, phishing, ransomware—and how evolving tactics demand smarter defense.

PhishingRansomware
P15
2025-02-10 00:00 UTC
Security Journalism

6 Months of Researching OAuth Application Attacks | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

There’s never just one termite. Huntress has spent the last 6 months researching and cracking down on malicious OAuth applications. Read about what we’ve found in this blog!

P0
2025-02-06 00:00 UTC
Security Journalism

Device Code Phishing: OAuth 2.0 Attacks in Google & Azure

Huntress · indexed 2026-09-07 17:30 UTC

All OAuth 2.0 implementations are equal. Some are just more equal than others. This blog covers device code phishing and compares OAuth implementations between Google and Azure. Does OAuth implementation impact the efficacy of hacker tradecraft? Find out here!

Cloud SecurityPhishing
P0
2025-01-30 00:00 UTC
Security Journalism

Why Every Business Needs Endpoint Protection | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Your endpoints are prime targets for cyberattacks. Learn why protecting them is vital and how endpoint security can shield your business from becoming an easy mark.

P0
2025-01-28 06:43 UTC
Other

Cat’s out of the bag: Lynx Ransomware-as-a-Service

Group-IB · indexed 2026-09-07 17:30 UTC

In this blog, we observed how the Lynx Ransomware-as-a-Service (RaaS) group operates, detailing the workflow of their affiliates within the panel, their cross-platform ransomware arsenal, customizable encryption modes, and advanced technical capabilities.

Ransomware
P15
2025-01-27 12:00 UTC
Government

Privacy-Preserving Federated Learning – Future Collaboration and Continued Research

NIST Cybersecurity Insights · Gary Howarth, Sue Anie · indexed 2026-08-15 20:45 UTC

This post is the final blog in a series on privacy-preserving federated learning . The series is a collaboration between NIST and the UK government’s Responsible Technology Adoption Unit (RTA), previously known as the Centre for Data Ethics and Innovation. Learn more and read all the posts published to date at NIST’s Privacy Engineering Collaboration Space or RTA’s blog . Reflections and Wider Considerations This is the final post in the series that began with reflections and learnings from the…

P0
2025-01-24 00:00 UTC
Other

Entra ID Allows Users to Update Principal Names

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A configuration change in Entra ID allowed unprivileged users to update their own User Principal Names (UPNs) through interfaces like the Entra admin center and PowerShell. This could lead to impersonation risks. Microsoft quickly fixed the issue after it was reported. The vulnerability affected synchronized hybrid environments as well.

MicrosoftVulnerabilities
P0
2025-01-23 00:00 UTC
Other

AWS Sign-in IAM User Login Flow Username Enumeration

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in AWS IAM Sign-in login flow could allow attackers to enumerate IAM usernames by measuring server response times. This issue affected AWS Sign-in IAM User login flow prior to January 16, 2025. AWS has since introduced a delay in response times across all authentication failure scenarios to mitigate the vulnerability.

AppleCloud SecurityVulnerabilities
P0
2025-01-23 00:00 UTC
Security Journalism

PerfMon! What Is It Good For? | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Explore how Performance Monitor (PerfMon) counters can be used as alternative methods for detecting Kerberos roasting attacks, moving beyond the traditional reliance on Windows Events 4768/4769.

Microsoft
P0
2025-01-22 07:14 UTC
Other

Odds & Ends: Unraveling the Surebet Playbook

Group-IB · indexed 2026-09-07 17:30 UTC

Discover the world of surebets, a strategy that guarantees profits by leveraging differing odds from multiple bookmakers. Explore how this approach impacts the betting market, challenging traditional profit models and increasing operational costs for bookmakers.

P0
2025-01-17 00:00 UTC
Other

Finding SSRFs in Azure DevOps

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Three SSRF vulnerabilities were discovered in Azure DevOps, allowing access to internal metadata endpoints and potential CRLF injection. The issues affected the endpointproxy and Service Hooks functionality. DNS rebinding could bypass initial fixes. Microsoft awarded $15,000 in bug bounties for the findings.

Cloud SecurityMicrosoft
P0
2025-01-16 07:24 UTC
Other

The Realty of Deception: Real Estate Frauds Uncovered in the Middle East

Group-IB · indexed 2026-09-07 17:30 UTC

Real estate scams are on the rise as fraudsters exploit online platforms to deceive victims into paying for fake properties. This blog dives into how these scams operate in the Middle East, explains the tools and techniques used to detect and disrupt money-mule networks, and provides practical tips for staying safe.

Cybercrime
P0
2025-01-16 00:00 UTC
Other

CloudWatch Dashboard Sharing Exposes EC2 Tags

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in AWS CloudWatch dashboard sharing allowed viewers to access EC2 instance tags and potentially invoke Lambda functions in the source account. The issue stemmed from a logic bug in the AWS Console combined with a "fail open" condition in Amazon Cognito. AWS has since patched the vulnerability.

Cloud SecurityVulnerabilities
P0
2025-01-15 00:00 UTC
Other

Issue with Amazon WorkSpaces and AppStream 2.0 Clients

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS identified two vulnerabilities in specific versions of native clients for Amazon WorkSpaces, Amazon AppStream 2.0, and Amazon DCV. These issues could allow man-in-the-middle attacks, potentially giving attackers access to remote sessions. Affected versions include WorkSpaces clients 5.20.0 or earlier, AppStream 2.0 Windows client 1.1.1326 or earlier, and various DCV clients. AWS recommends upgrading to patched versions to address these security concerns.

Cloud SecurityMicrosoft
P0
120 121 122 123 124