IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,567 matching records.
AUTO-POLL // 2026-10-07 10:00 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P3 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7

RANSOMWARE
P3
P3
COOL // 14 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2024-11-21 12:00 UTC
Government

Kicking-Off with a December 4th Workshop, NIST is Revisiting and Revising Foundational Cybersecurity Activities for IoT Device Manufacturers, NIST IR 8259!

NIST Cybersecurity Insights · Katerina Megas, Michael Fagan · indexed 2026-08-15 20:45 UTC

In May 2020, NIST published Foundational Cybersecurity Activities for IoT Device Manufacturers (NIST IR 8259), which describes recommended cybersecurity activities that manufacturers should consider performing before their IoT devices are sold to customers. These foundational cybersecurity activities can help manufacturers lessen the cybersecurity-related efforts needed by customers, which in turn can reduce the prevalence and severity of IoT device compromises and the attacks performed using c…

P0
2024-11-21 09:33 UTC
Other

Tracing the Path of VietCredCare and DuckTail: Vietnamese dark market of infostealers’ data

Group-IB · indexed 2026-09-07 17:30 UTC

Following the arrest in May 2024 of more than 20 individuals behind Facebook infostealers campaigns in Vietnam, we have compared the tactics of operators behind VietCredCare and DuckTail stealers. These 2 malware families have been active before the arrest in Vietnam and are believed to be controlled by Vietnamese threat actors. Based on the research, we decided that the groups operate in a different way and the arrest probably affected the VietCredCare operators.

MalwareThreat Actors
P0
2024-11-18 14:37 UTC
Security Journalism

Silencing the EDR Silencers | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Discover how adversaries are using tools like EDRSilencer to tamper with EDR communications and learn how you can fight back.

P0
2024-11-18 12:00 UTC
Government

Unlocking Cybersecurity Talent: The Power of Apprenticeships

NIST Cybersecurity Insights · Marian Merritt · indexed 2026-08-15 20:45 UTC

Cybersecurity is a fast-growing field, with a constant need for skilled professionals. But unlike other professions — like medicine or aviation — there’s no clear-cut pathway to qualifying for cybersecurity positions. For employers and job seekers alike, this can make the journey to building a team (or entering a successful cybersecurity career) feel uncertain. Enter the registered apprenticeship program — a proven method for developing skilled talent in cybersecurity that benefits both the emp…

P0
2024-11-18 00:00 UTC
Security Journalism

To MFA or Not To MFA | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

MFA could be the thing that stops your payroll money from disappearing in a wire transaction. So why do we treat it as an optional inconvenience?

P0
2024-11-15 00:00 UTC
Government

[MàJ] Multiples vulnérabilités sur l'interface d'administration des équipements Palo Alto Networks (15 novembre 2024)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Le 8 novembre 2024, Palo Alto Networks a publié un avis de sécurité relatif à une vulnérabilité critique dans certains pare-feux Palo Alto Networks. Elle permet à un attaquant non authentifié d'exécuter du code arbitraire à distance sur l'interface d'administration des équipements. L'éditeur...

Network Security
P0
2024-11-13 12:00 UTC
Government

Digital Identities: Getting to Know the Verifiable Digital Credential Ecosystem

NIST Cybersecurity Insights · Bill Fisher, Ryan Galluzzo · indexed 2026-08-15 20:45 UTC

If you are interested in the world of digital identities, you have probably heard some of the buzzwords that have been floating around for a few years now… “verifiable credential,” “digital wallet,” “mobile driver’s license” or “mDL.” These terms, among others, all reference a growing ecosystem around what we are calling “verifiable digital credentials.” But what exactly is a verifiable digital credential? Take any physical credential you use in everyday life – your driver’s license, your medic…

P0
2024-11-13 00:00 UTC
Security Journalism

WTF is ITDR? | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

ITDR is the latest must-know acronym. But what is it? And why does it matter? Let Huntress break down the essentials of identity threat detection and response, and learn why it’s critical for your defenses.

P0
2024-11-13 00:00 UTC
Security Journalism

A Parent's Guide to Securing Children's Tech Gifts | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Safeguard holiday tech gifts for kids this season—secure their devices, protect privacy, and build lifelong safety habits. Feat. resources from our exclusive Fireside Chat.

P0
2024-11-12 00:00 UTC
Other

ModeLeak: LLM Model Exfiltration Vulnerability in Vertex AI

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in GCP's Vertex AI service allows privilege escalation and unauthorized access to sensitive LLM models. Attackers can exfiltrate these models by exploiting misconfigurations in access controls and service bindings. By exploiting custom job permissions, researchers were able to escalate their privileges and gain unauthorized access to all data services in the project. In addition, deploying a poisoned model in Vertex AI led to the exfiltration of all other fine-tuned models, posi…

AI SecurityVulnerabilities
P10
2024-11-09 00:00 UTC
Other

Sketchy Cheat Sheet

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Multiple vulnerabilities were discovered in Google's Cloud Architecture Diagramming Tool, including XSS, unauthorized access to user data, and misconfigured storage buckets. The issues allowed accessing sensitive customer information and potentially executing arbitrary code. Google ultimately decommissioned the service due to the severity of the flaws.

Cloud Security
P0
2024-11-08 00:00 UTC
Other

Issue with data.all Framework Multiple CVEs

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Multiple security vulnerabilities were identified in data.all, an open source development framework for building data marketplaces on AWS. The issues affect versions 1.0.0 through 2.6.0 and include problems with authentication token invalidation, unauthorized operations on DataSets and Environments, incorrect object-level authorizations, potential access to sensitive data via logs, and unauthorized mutating update operations on notification records.

Cloud Security
P0
2024-11-07 07:55 UTC
Other

Run from Chase Cyber Threats

Group-IB · indexed 2026-09-07 17:30 UTC

Waiting for risks to be presented to you rather than actively hunting them down? After reading this, you might consider a shift in approach to improve detection and proactively counter sophisticated attacks.

P0
2024-11-07 00:00 UTC
Security Journalism

Lead the Pack with SAT Leaderboards | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Leaderboards and Manager Notifications are the new way to motivate learners and track progress in Huntress Managed SAT.

P0
2024-11-01 00:00 UTC
Other

Confused Deputy Vulnerability in Amazon DataZone

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Amazon DataZone allowed potential attackers to assume roles in AWS accounts by exploiting a confused deputy problem. This could have granted unauthorized access to sensitive data managed by DataZone or other AWS services accessible by the IAM role trusting DataZone. The issue has been resolved, with no customers reportedly impacted.

Cloud SecurityVulnerabilities
P0
2024-11-01 00:00 UTC
Other

Repo swatting attack deletes/blocks GitHub and GitLab accounts

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A technique called "repo swatting" allows attackers to delete GitHub and block GitLab accounts by exploiting file upload features and abuse reporting mechanisms. Attackers upload malicious files to a target's repository, then report the account for hosting malicious content, potentially resulting in account deletion. The vulnerability was partially mitigated by October 2024 via changes in upload URL paths and requirement for each uploader to be authenticated (in GitHub).

Vulnerabilities
P0
2024-10-30 05:44 UTC
Other

Delivery Deception: Escalating cybercriminal tactics in the Balkan region

Group-IB · indexed 2026-09-07 17:30 UTC

Explore our latest findings on the surge of cyberattacks in the Balkan region, focusing on threats to financial institutions and critical infrastructure. Discover how phishing scams impersonating postal services are targeting citizens in Croatia, Romania, Serbia, and Slovenia, and learn about the implications for public safety and security. Stay informed and protected against the rising tide of cybercrime.

CybercrimePhishing
P0
2024-10-28 12:00 UTC
Government

Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024

NIST Cybersecurity Insights · Amy Mahn · indexed 2026-08-15 20:45 UTC

This blog is part of a larger NIST series during the month of October for Cybersecurity Awareness Month , called 'Staff Stories Spotlight.' Throughout the month of October this year, Q&A style blogs will be published featuring some of our unique staff members who have interesting backgrounds, stories to tell, and projects in the world of cybersecurity. This year’s Cybersecurity Awareness Month theme is ‘Secure our World.’ How does this theme resonate with you, as someone working in cybersecurit…

P0
2024-10-25 08:08 UTC
Other

Global iGaming? Tailor Your Security with Group-IB Fraud Protection

Group-IB · indexed 2026-09-07 17:30 UTC

With Group-IB Fraud Protection, you can navigate the complexities of global iGaming regulations and risk. Tailor security measures for each market, optimize costs, and maximize growth. Learn how our advanced fraud detection and prevention tools can protect your players and profits.

Cybercrime
P0
2024-10-24 00:00 UTC
Other

AWS CDK Bucket Squatting Risk

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The AWS Cloud Development Kit (CDK) is a way of deploying infrastructure-as-code. The vulnerability involves AWS CDK’s use of a predictable S3 bucket name format (cdk-{Qualifier}-assets-{Account-ID}-{Region}), where the default “random” qualifier (hnb659fds) is common and easily guessed. If an AWS customer deletes this bucket and reuses CDK, an attacker who claims the bucket can inject malicious CloudFormation templates, potentially gaining admin access. Attackers supposedly only need the AWS a…

Cloud SecurityVulnerabilities
P0
122 123 124 125 126