IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,574 matching records.
AUTO-POLL // 2026-10-07 11:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P3 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7

RANSOMWARE
P3
P3
COOL // 21 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2024-07-23 00:00 UTC
Security Journalism

When Trust Becomes a Trap: Foiling a Medical Software Hack | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Hackers cloned a legitimate medical image viewer site to distribute malware, but thanks to Huntress, the threat was detected in time. Dive into the incident and see how we uncovered the deception and averted disaster.

Malware
P0
2024-07-16 18:33 UTC
Other

Detecting Process Injection

Black Lantern Security · Adeem Mawani · indexed 2026-09-07 17:30 UTC

Evasion Techniques and Detection Strategies for Memory-Resident Malware

Malware
P0
2024-07-16 00:00 UTC
Other

AWS Client VPN buffer overflow

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The AWS Client VPN service was found to be affected by two vulnerabilities which could potentially allow malicious actors with access to a user’s device to execute arbitrary commands with elevated privileges, including escalating to root access. Both vulnerabilities stem from buffer overflow issues, a common programming error that can be exploited to overwrite memory and gain unauthorized control over a system. The impact of these vulnerabilities is severe, as successful exploitation could lead…

Cloud SecurityMalwareNetwork Security
P0
2024-07-15 12:00 UTC
Government

Protecting Trained Models in Privacy-Preserving Federated Learning

NIST Cybersecurity Insights · Joseph Near, David Darais · indexed 2026-08-15 20:45 UTC

This post is part of a series on privacy-preserving federated learning. The series is a collaboration between NIST and the UK government’s Responsible Technology Adoption Unit (RTA), previously known as the Centre for Data Ethics and Innovation. Learn more and read all the posts published to date at NIST’s Privacy Engineering Collaboration Space or RTA’s blog . The last two posts in our series covered techniques for input privacy in privacy-preserving federated learning in the context of horizo…

P0
2024-07-15 00:00 UTC
Other

Unauthorized Access to AWS Account Findings in Microsoft Defender for Cloud

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Microsoft Defender for Cloud at one point provided customers with a flawed configuration template through their public GitHub repository. This template creates resources in the customer's AWS account so that Microsoft Defender for Cloud can scan it. In the rare cases in which this template was deployed, under certain, limited circumstances, Defender for Cloud's security findings for these AWS accounts could be disclosed to unauthorized third parties.

Cloud SecurityMicrosoft
P0
2024-07-10 00:00 UTC
Security Journalism

9 Pro Tips for Better Endpoint Security | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Secure endpoints are critical to your cyber defenses. Here’s a list of endpoint security tips every IT and security professional should know.

P0
2024-07-02 00:00 UTC
Security Journalism

Hackers Are Hiding in Plain Sight | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Cybercriminals are now blending into legitimate systems. Huntress’ 2024 Cyber Threat Report reveals the latest unsettling trends and tactics we observed, including the misuse of remote monitoring tools and cloud storage services.

P0
2024-07-01 00:00 UTC
Government

Vulnérabilité dans OpenSSH (01 juillet 2024)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Le 1 juillet 2024, OpenSSH a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-6387. Cette vulnérabilité permet à un attaquant non authentifié d'exécuter du code arbitraire à distance avec les privilèges *root*. L'éditeur précise que les versions 8.5p1 à 9.7p1 sont...

VulnerabilitiesCVE-2024-6387
P5
2024-06-26 00:00 UTC
Security Journalism

Accidental vs. Intentional Data Loss in Healthcare | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Healthcare must protect sensitive data from accidental equipment loss, data theft, and insider attacks. Learn practical steps and solutions to enhance your security and maintain patient trust.

P0
2024-06-24 15:57 UTC
Security Journalism

Huntress and Our Culture of BElonging | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress Chief People Officer Todd Riesterer discusses how we curate a culture of BElonging, built on pillars of humaneness, equity, and diversity.

P0
2024-06-24 00:00 UTC
Security Journalism

Tailored Cybersecurity vs. Bundles like K365 | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Here’s why bundling cybersecurity products and services like Kaseya K365 aren’t always the best value for your organization. Learn how to avoid common pitfalls and choose more effective EDR and MDR solutions.

P0
2024-06-18 00:00 UTC
Security Journalism

Here’s to the Future | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress CEO Kyle Hanslovan highlights the cybersecurity leader's Series D funding and how this investment will benefit partners moving forward.

P0
2024-06-17 00:00 UTC
Other

Azure Machine Learning SSRF

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Certain API endpoints on ml.azure.com and ai.azure.com used for adding/viewing data connections could be leveraged for server side request forgeries (SSRF). While they do have protections to restrict making requests to internal hosts, it was possible to circumvent those protections using a 301 or 302 redirect response which points to a sensitive host.

Cloud Security
P0
2024-06-17 00:00 UTC
Other

GCP HMAC Keys do not log creation, deletion or usage

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Cloud Audit Logs do not capture actions mediated through the cloud console private API service (cloudconsole-pa). Consequently, there is no logging of HMAC key creation or deletion linked to user accounts. This absence of logs hampers defenders' ability to alert or monitor the creation of HMAC keys for user accounts, posing a persistence risk, or their deletion, presenting a denial of service risk.

Microsoft
P0
2024-06-17 00:00 UTC
Other

GCP HMAC Keys are not discoverable or revokable other than for self

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

GCP administrators face challenges in managing HMAC keys within their organizations, lacking visibility into which user accounts have generated these keys and whether they are actively being used to access storage objects. Additionally, there's a lack of functionality to revoke keys associated with other users, restricting their ability to enforce security policies effectively. Similarly, GCP incident response teams rely on Cloud Logging to monitor Cloud Storage object access, but they lack spe…

DFIR
P0
2024-06-14 00:00 UTC
Other

GitHub Copilot Chat Vulnerable to Data Exfiltration

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

GitHub Copilot Chat VS Code Extension was vulnerable to data exfiltration via prompt injection when analyzing untrusted source code. The vulnerability allowed attackers to access previous conversation turns and append information from the chat history to an image URL, which was then automatically retrieved by Copilot, sending the data to the attacker.

AI SecurityVulnerabilities
P0
2024-06-13 00:00 UTC
Security Journalism

Debunking 5 Major macOS Myths | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Let Huntress debunk the biggest Mac security myths. macOS is now a popular target for hackers, so learn the truth about its vulnerabilities and discover practical steps to enhance protection against cyber threats.

Apple
P0
2024-06-12 12:00 UTC
Government

NIST’s International Cybersecurity and Privacy Engagement Update – Mexico City, RSA Conference, and More

NIST Cybersecurity Insights · Amy Mahn · indexed 2026-08-15 20:45 UTC

The last few months have brought even more opportunities for NIST to engage with our international partners to enhance cybersecurity. Here are some updates on our recent international engagement: Conversations have continued with our partners throughout the world on the recent release of the Cybersecurity Framework Version 2.0 . NIST international engagement continues through our support to the Department of State and the International Trade Administration (ITA) during numerous international di…

P0
126 127 128 129 130