IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,580 matching records.
AUTO-POLL // 2026-10-07 12:35 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P3 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7

RANSOMWARE
P3
P3
COOL // 27 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2024-05-01 00:00 UTC
Security Journalism

LOLBin to INC Ransomware

Huntress · indexed 2026-09-07 17:30 UTC

Huntress has observed INC ransomware deployed in the past but recent activity indicates a possible continued shift in/or improvement of tactics employed by these threat actors.

RansomwareThreat Actors
P15
2024-04-29 00:00 UTC
Other

GraphNinja

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Microsoft Graph allowed attackers to conduct password-spray attacks without detection. The issue involved switching the 'common' authentication endpoint with that of an unrelated tenant, thereby avoiding the appearance of logon attempts in the victim's logs. This technique could allow attackers to validate user credentials through verbose error messages, but actual successful logons using these credentials would still be recorded in the victims' logs (regardless of endpoint).

MicrosoftNetwork SecurityVulnerabilities
P0
2024-04-26 00:00 UTC
Other

Azure tenant takeover via Microsoft application

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Microsoft Dynamics 365 Supply Chain Visibility allowed arbitrary takeover of Azure tenants via a malicious reply URL. Clicking a link could grant an attacker directory read access or full tenant control if clicked by a Global Admin, without requiring user consent.

Cloud SecurityMicrosoftVulnerabilities
P0
2024-04-25 00:00 UTC
Government

Multiples vulnérabilités dans les produits Cisco (25 avril 2024)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Le 24 avril 2024, Cisco a publié trois avis de sécurité concernant des vulnérabilités affectant les équipements de sécurité ASA et FTD. Deux d'entre eux concernent les vulnérabilités CVE-2024-20353 et CVE-2024-20359 qui sont activement exploitées dans le cadre d'attaques ciblées. La vulnérabilité...

VulnerabilitiesCVE-2024-20353CVE-2024-20359
P5
2024-04-25 00:00 UTC
Security Journalism

LightSpy Malware Variant Targeting macOS | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

There's a new variant of LightSpy malware targeting macOS. Here, Huntress' macOS researchers dive into the macOS variant of the LightSpy malware, after gaps in recent reports stating that the LightSpy malware strictly targets iOS.

AppleMalware
P0
2024-04-19 00:00 UTC
Security Journalism

It Costs How Much? | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Learn how managed EDRs can help SMBs offset limited cybersecurity budgets, thwart cyberattacks, and save money for the long term.

P0
2024-04-15 00:00 UTC
Other

AWS Amplify IAM role publicly assumable exposure

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The AWS Amplify service was found to be misconfiguring IAM roles associated with Amplify projects. This misconfiguration caused these roles to be assumable by any other AWS account. Both the Amplify Studio and the Amplify CLI exhibited this behavior. Any Amplify project created using the Amplify CLI built between July 3, 2018 and August 8, 2019 had IAM roles that were assumable by anyone in the world. The same was true if the authentication component was removed from an Amplify project using th…

Cloud SecurityVulnerabilities
P0
2024-04-12 00:00 UTC
Government

[MàJ] Vulnérabilité dans Palo Alto Networks GlobalProtect (12 avril 2024)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

\[Mise à jour du 10 mai 2024\] Le CERT-FR est intervenu pour le traitement d'une compromission par rançongiciel au sein d'une entité française. Dans le cadre de cette attaque, la vulnérabilité a été exploitée pour ensuite réaliser une latéralisation dans le système d'information de la victime et...

Network Security
P0
2024-04-11 00:00 UTC
Other

AWS Glue database password leakage

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A principal with the permissions glue:GetConnection and ec2:DescribeSubnets can retrieve the database password of a connection, since the password is loaded into the AWS console website when a connection's edit page is requested. The severity of this issue is low since it requires sufficient prior access.

Cloud Security
P0
2024-04-09 00:00 UTC
Other

AWS IAM Trust Policy Condition Evaluation Bug

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Tag variable names affected whether trust policy conditions were evaluated correctly. If the request tag referenced a principal tag called MemberRole in the JWT token, and the IAM role referenced a resource tag with the same variable name, the condition was always evaluated as true, regardless of whether the tag's values actually matched. Only role trust policies that used a variable substitution for both the request tag and the resource tag in the policy statement resulted in the policy evalua…

Cloud Security
P0
2024-04-03 00:00 UTC
Other

Bazel supply chain vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Cycode discovered a CI/CD misconfiguration in the Bazel repo, which if exploited could have allowed an attacker to enact a supply chain attack against all Bazel users, which includes Google themselves and therefore likely GCP as well.

Vulnerabilities
P0
2024-04-03 00:00 UTC
Other

Critical GitLab Account Takeover Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

GitLab addressed a critical vulnerability, CVE-2023-7028, affecting managed SaaS gitlab.com instance as well as self-hosted versions 16.1 to 16.7.1. The flaw could allow account takeovers via unverified email password resets. Third party could intercept the password reset request, add their own email to the request and forward it. GitLab would then send the reset link to the added 3rd-party email. This is in effect an account takeover with only precondition of knowing victim email associated wi…

VulnerabilitiesCVE-2023-7028
P15
2024-03-28 00:00 UTC
Security Journalism

MSSQL to ScreenConnect | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress continues to see MSSQL server systems being attacked, and in recent incidents have seen overlap with previous incidents, not only in the use of LOLBins, but also in IP addresses used by the threat actor.

Threat Actors
P0
2024-03-27 00:00 UTC
Other

Flaw in Bedrock's Foundation Model Access Control

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A flaw in AWS Bedrock's foundation model access control allowed unauthorized subscriptions to certain models, bypassing IAM policies using the aws-marketplace:ProductId condition key. This could lead to compliance issues and financial risks. AWS has since fixed the issue and notified affected customers.

Cloud Security
P0
2024-03-26 00:00 UTC
Security Journalism

How Huntress Managed EDR Stands Against the Competition | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Depending on which EDR solution you choose, capabilities and outcomes can differ greatly. Huntress looks at what differentiates Huntress Managed EDR from competitors, reviewing key features and benefits.

P0
2024-03-24 00:00 UTC
Other

IAM Policy Flaw Allowed Unauthorized Access to Bedrock Models

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

TrustOnCloud identified a flaw in how AWS Bedrock enforces IAM access controls using the aws-marketplace:ProductId condition key, which is meant to restrict subscriptions to specific foundation models. Their testing revealed that some Bedrock models, including those from Cohere and Stability AI, were not consistently blocked or allowed as intended by IAM policies, posing potential compliance and cost risks. AWS acknowledged and fixed the issue, notifying affected customers and updating testing …

Cloud Security
P0
2024-03-21 00:00 UTC
Other

FlowFixation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A flaw in Amazon Managed Workflows for Apache Airflow (MWAA) could have allowed potential session hijacking and remote code execution. The issue stemmed from a combination of session fixation in the MWAA web management panel and an AWS domain configuration error leading to a cross-site scripting (XSS) attack. Attackers exploiting this could manipulate victims' configurations, trigger workflows, and potentially move laterally to other services within the cloud environment. The exploit of this bu…

Cloud SecurityVulnerabilities
P15
2024-03-21 00:00 UTC
Security Journalism

7 Don’ts of Security Awareness Training

Huntress · indexed 2026-09-07 17:30 UTC

Many security awareness training solutions aren’t easy to manage, and worse, they affect knowledge retention. Let’s review the common SAT features that diminish your ability to improve your security posture.

P0
2024-03-20 00:00 UTC
Security Journalism

Managing Attack Surface | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress recently detected interesting activity on an endpoint; a threat actor was attempting to establish a foothold on an endpoint by using commands issued via MSSQL to upload a reverse shell accessible from the web server. All attempts were obviated by MAV and process detections, but boy-howdy, did they try!

Threat Actors
P0
2024-03-13 00:00 UTC
Security Journalism

Using Backup Utilities for Data Exfiltration | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

“Double extortion” attacks, often perpetrated by ransomware threat actors, include data exfiltration prior to file encryption. Huntress analysts have observed various means of data exfiltration, but recently observed the use of a legitimate backup application seen by others to be associated with a Noberus/ALPHV ransomware affiliate.

RansomwareThreat Actors
P15
2024-03-11 00:00 UTC
Security Journalism

Full Transparency: Controlling Apple's TCC (Part 2) | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

The primary goal of Apple's Transparency, Consent, and Control (TCC) is to empower users with transparency regarding how their data is accessed and used by applications. In this Part 2, dig even deeper into the mechanism that runs TCC and what's happening in the background.

Apple
P0
2024-03-07 00:00 UTC
Other

Synapse Analytics privilege escalation via intelligent caching

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Tenable Research discovered a privilege escalation flaw that allows a user to escalate privileges to that of the root user within the context of a Spark VM. This escalation was achieved because of a permissions issue with scripts utilized by the intelligent caching service (AKA "Vegas") present in the environment.

Vulnerabilities
P10
2024-03-07 00:00 UTC
Security Journalism

Time Travelers Busted: How to Detect Impossible Travel | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Impossible Travel is one of the earliest indicators of user compromise, and it works against any user-centric event that can be tied back to a location. Huntress goes in-depth on this problem, explaining how it works, revealing challenges surrounding it, and offering real-world examples occurring within Microsoft 365.

Microsoft
P0
128 129 130 131 132