IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,565 matching records.
AUTO-POLL // 2026-10-07 09:10 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P4 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7

RANSOMWARE
P4
P4
COOL // 12 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2025-01-14 00:00 UTC
Government

[MàJ] Vulnérabilité dans les produits Fortinet (14 janvier 2025)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

\[Mise à jour du 28 janvier 2025\] Une preuve de concept permettant l'exploitation de cette vulnérabilité est disponible publiquement. Le 14 janvier 2025, Fortinet a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-55591 affectant FortiOS et FortiProxy. Elle permet à un...

AppleNetwork SecurityVulnerabilitiesCVE-2024-55591
P5
2025-01-13 06:52 UTC
Other

Beyond AI: Group-IB’s Local Expertise in Fraud Protection

Group-IB · indexed 2026-09-07 17:30 UTC

Minimize false positives, proactively prevent threats, and gain customized fraud protection with Group-IB. Our AI-powered solutions are fine-tuned by local experts and real-time threat intelligence in key regions, ensuring optimal security performance and minimal disruption to your business.

CybercrimeThreat Intelligence
P0
2025-01-09 00:00 UTC
Government

[MàJ] Vulnérabilité dans les produits Ivanti (09 janvier 2025)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Une vulnérabilité jour-zéro de type débordement de pile a été découverte dans Ivanti Connect Secure (ICS), Policy Secure (IPS), Neurons for Zero Trust Access (ZTA) gateways. Cette vulnérabilité, d'identifiant CVE-2025-0282, permet à un attaquant non authentifié de provoquer une exécution de code...

VulnerabilitiesCVE-2025-0282
P5
2025-01-08 06:27 UTC
Other

Social Engineering in Action: How Fraudsters Exploit Trust with Fake Refund Schemes in the Middle East

Group-IB · indexed 2026-09-07 17:30 UTC

Fraudsters have devised a sophisticated scheme targeting banking customers in the Middle East, impersonating government officials and using remote access software to steal credit card information and OTP codes. This scam specifically targets individuals who have lodged complaints online via a government portal, taking advantage of their trust and willingness to cooperate in hopes of refunds, leading to significant financial losses through fraudulent transactions.

Cybercrime
P0
2025-01-08 00:00 UTC
Other

Hijacking Azure Machine Learning Notebooks

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Machine Learning notebooks can be hijacked by attackers with Storage Account access to inject malicious code. A now-fixed vulnerability allowed Reader role escalation to code execution. The article details the attack methods, including modifying notebooks, obtaining managed identity tokens, and exfiltrating data. It also introduces a tool for dumping AML workspace credentials.

Cloud SecurityVulnerabilities
P0
2024-12-29 00:00 UTC
Other

AWS Neuron SDK Dependency Confusion Vulnerability Recurs

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS Neuron SDK has reintroduced a dependency confusion vulnerability three times in four years. The issue stems from using the --extra-index-url parameter in pip install commands, which allows potential installation of malicious packages from PyPI instead of AWS's private repository. Despite previous reports, AWS has not fully addressed the problem, leaving new packages vulnerable to exploitation.

Cloud SecurityVulnerabilities
P0
2024-12-19 12:00 UTC
Government

NIST’s International Cybersecurity and Privacy Engagement Update – New Translations

NIST Cybersecurity Insights · Amy Mahn · indexed 2026-08-15 20:45 UTC

As the year comes to a close, NIST continues to engage with our international partners to strengthen cybersecurity, including sharing over ten new international translations in over six languages as resources for our stakeholders around the world. These efforts were complemented by discussions on opportunities for future enhanced international collaboration and resource sharing. Here are some updates from the past few months: Our international engagement continues through our support to the Dep…

P0
2024-12-16 00:00 UTC
Other

Dirty DAG - Azure Apache Airflow Integration Vulnerabilities

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Unit 42 researchers identified vulnerabilities in the Azure Data Factory's integration with Apache Airflow. These vulnerabilities include misconfigured Kubernetes Role-Based Access Control (RBAC), improper secret handling in Azure’s internal Geneva service, and weak authentication mechanisms. Exploiting these flaws, attackers could gain shadow admin control over Azure infrastructure by crafting malicious DAG files or compromising service principals, leading to unauthorized access, data exfiltra…

Cloud SecurityMalware
P0
2024-12-16 00:00 UTC
Security Journalism

Does Santa Like NordVPN? | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress Managed ITDR uncovers risks behind popular VPNs and proxies like NordVPN, Mullvad, and more—helping you steer clear of hackers this holiday season.

Network Security
P0
2024-12-12 00:00 UTC
Other

Bedrock API Logging Issue

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Sysdig's Threat Research Team discovered an issue with Amazon Bedrock API logging in CloudTrail. Failed API calls were logged as successful without error codes, hindering detection efforts and potentially generating false positives. The issue affected Bedrock Runtime APIs, specifically InvokeModel and Converse. AWS resolved the problem.

Cloud Security
P0
2024-12-11 07:11 UTC
Other

Trust Hijacked: The Subtle Art of Phishing Through Familiar Facades

Group-IB · indexed 2026-09-07 17:30 UTC

Explore the advanced tactics employed in recent email phishing campaigns targeting employees from over 30 companies across 12 industries and 15 jurisdictions. This blog unveils sophisticated techniques used to outsmart Secure Email Gateways (SEGs) and exploit trusted platforms, creating highly convincing schemes to deceive victims and steal their credentials.

Phishing
P0
2024-12-11 00:00 UTC
Other

Code Execution in Azure API Management Developer Portal

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Azure API Management Developer Portal allows arbitrary code execution and secret exfiltration. The issue stems from a workflow that loads untrusted data from opened issues, potentially allowing attackers to inject malicious commands. This could lead to code execution in the runner, granting access to sensitive tokens and permissions.

Cloud SecurityVulnerabilities
P0
2024-12-05 12:00 UTC
Government

Data Pipeline Challenges of Privacy-Preserving Federated Learning

NIST Cybersecurity Insights · Dr. Xiaowei Huang, Dr. Yi Dong, Sikha Pentyala · indexed 2026-08-15 20:45 UTC

This post is part of a series on privacy-preserving federated learning. The series is a collaboration between NIST and the UK government’s Responsible Technology Adoption Unit (RTA), previously known as the Centre for Data Ethics and Innovation. Learn more and read all the posts published to date at NIST’s Privacy Engineering Collaboration Space or RTA’s blog . Introduction In this post, we talk with Dr. Xiaowei Huang and Dr. Yi Dong (University of Liverpool) and Sikha Pentyala (University of W…

P0
2024-12-04 07:05 UTC
Other

Deepfake Fraud: How AI is Deceiving Biometric Security in Financial Institutions

Group-IB · indexed 2026-09-07 17:30 UTC

Group-IB’s Fraud Protection team examines how fraudsters use deepfake technology to bypass biometric security in financial institutions, including facial recognition and liveness detection. This blog highlights the use of emulators, app cloning, and virtual cameras to exploit vulnerabilities, and highlights the financial and societal impacts of deepfake fraud.

Cybercrime
P0
2024-11-28 05:52 UTC
Other

Shady Bets: How to Protect Yourself from Gambling Fraud Online

Group-IB · indexed 2026-09-07 17:30 UTC

Scammers are using fake betting game advertisements on social media to target users, with over 500 deceptive advertisements and 1,377 malicious websites identified by Group-IB CERT. These scams promise quick money but are designed to steal personal data and funds, and this blog aims to educate users on how to recognize and protect themselves from such threats.

Cybercrime
P0
121 122 123 124 125