IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,580 matching records.
AUTO-POLL // 2026-10-07 12:30 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P3 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7

RANSOMWARE
P3
P3
COOL // 27 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2024-03-05 00:00 UTC
Security Journalism

Please Allow Me to (Re)introduce Myself | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress has launched Huntress Security Awareness Training (SAT), a new and improved SAT solution tailored to the needs of underserved and resource-strapped organizations. It features memorable, story-driven episodes, making it easier for users to retain knowledge. And since it’s fully managed by Huntress, admins will enjoy it too. Most importantly, Huntress SAT was developed with one overall goal—elevate the security of your small- and medium-sized business (SMB).

P0
2024-03-04 00:00 UTC
Security Journalism

Insights: RMM Tools | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Over the past year, the Huntress team has posted a number of blog posts related to remote monitoring and management (RMM) tools being installed or abused by threat actors.

Threat Actors
P0
2024-03-01 00:00 UTC
Security Journalism

Navigate SocGholish with Huntress | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

In an era where cyber threats like SocGholish are becoming increasingly sophisticated, understanding and combating these attacks is crucial for digital safety. This post delves into leveraging Huntress for effectively handling SocGholish threats, outlining a step-by-step approach for IT professionals.

P0
2024-02-29 00:00 UTC
Security Journalism

Attacking MSSQL Servers, Pt. II | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

The publication of the first blog post led a Huntress SOC analyst to identify and escalate a second, similar incident. A deeper investigation into the activity made it clear that the Huntress SOC had obviated several Trigona ransomware attacks, protecting customers from the impact of a ransomware infection.

DFIRRansomware
P15
2024-02-28 00:00 UTC
Security Journalism

BlackCat Ransomware Affiliate TTPs | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

This blog post provides a detailed look at the TTPs of a ransomware affiliate operator. In this case, the endpoint had been moved to another infrastructure (as illustrated by various command lines, and confirmed by the partner), so while Huntress SOC analysts reported the activity to the partner, no Huntress customer was impacted by the ransomware deployment.

RansomwareThreat Intelligence
P15
2024-02-23 00:00 UTC
Security Journalism

SlashAndGrab | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Adversaries have been VERY busy in the wake of the ScreenConnect vulnerabilities (CVE-2024-1709 & CVE-2024-1708). Here’s all the post-exploitation details, tradecraft, and tactics we’ve observed so far!

VulnerabilitiesCVE-2024-1708CVE-2024-1709
P5
2024-02-20 00:00 UTC
Security Journalism

Detection Guidance for ConnectWise CWE-288 | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Stay secure with Huntress! Learn about critical vulnerabilities tied to ConnectWise, including CWE-288 authentication bypass. Patch now to version 23.9.8 for protection.

P15
2024-02-16 00:00 UTC
Security Journalism

Solving Endpoint Security Challenges with a Managed EDR | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Endpoint detection and response (EDR) is an essential endpoint security solution, but without the right time, resources, and knowledge to remediate threats, your EDR can quickly become a nuisance.

P0
2024-02-15 00:00 UTC
Security Journalism

The Health Sector is Under Attack. But You Can Fight Back. | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Healthcare organizations are facing cyber threats at an alarming rate, and as the U.S. Department of Health and Human Services (HHS) introduces new measures for cybersecurity, it’s also time for small- and mid-sized organizations to be proactive in their defense.

P0
2024-02-14 00:00 UTC
Security Journalism

Threat Intel Accelerates Detection and Response | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Evidence of a pre-existing exploit was rendered when the Huntress agent was added to an endpoint. Within minutes, and in part through the use of previously published threat intelligence, analysts were able to identify the issue and make recommendations to the customer to remediate the root cause.

Threat Intelligence
P0
2024-02-13 00:00 UTC
Other

Azure Site Recovery privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

When the ASR service is enabled, it uses an Automation Account with a System-Assigned Managed Identity to manage Site Recovery extensions on VMs. However, the Runbook (a set of scripts for managing extensions) executed by the Automation Account had its job output visible to users, and this output mistakenly included a cleartext Management-scoped Access Token for the System-Assigned Managed Identity, which possesses the Contributor role over the entire Azure subscription. Therefore, lower-privil…

Cloud SecurityVulnerabilities
P10
2024-02-09 00:00 UTC
Government

[MàJ] Vulnérabilité dans Fortinet FortiOS (09 février 2024)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

\[Mise à jour du 19 mars 2024\] Le CERT-FR a connaissance de codes d'exploitation publics et de nouvelles tentatives d'exploitation. Le 8 février 2024, Fortinet a publié l'avis de sécurité concernant la vulnérabilité critique CVE-2024-21762 affectant le VPN SSL de FortiOS. Cette vulnérabilité...

AppleNetwork SecurityVulnerabilitiesCVE-2024-21762
P5
2024-02-08 00:00 UTC
Security Journalism

Attacking MSSQL Servers | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

In addition to social engineering attacks, threat actors target organizations' attack surface, looking for exposed services and applications to gain access into an infrastructure. Microsoft SQL database servers have long been a target for attackers.

MicrosoftThreat Actors
P0
2024-02-06 00:00 UTC
Other

Azure HDInsight privilege escalation and DoS vulnerabilities

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Three privilege escalation and denial-of-service vulnerabilities were discovered in Azure HDinsight, related to their usage of Apache Oozie and Ambari. The root cause of at least one of these vulnerabilities is a flaw in Apache Oozie itself, leading to regex denial-of-service (ReDoS). The other two vulnerabilities could allow an authenticated attacker with HDI cluster access to gain cluster administrator privileges and perform any resource service management operation. The vulnerabilities were …

Cloud SecurityVulnerabilities
P15
2024-02-05 00:00 UTC
Government

[MàJ] Incident affectant les solutions AnyDesk (05 février 2024)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

\[Mise à jour du 27 février 2024\] Le 29 janvier 2024 l'ANSSI a été alertée par le BSI que l'éditeur AnyDesk Software GmbH a été victime d'une fuite de données. Le code source des applications développées par l'éditeur ainsi que des certificats et clés privées pourraient avoir été dérobés. De...

P0
2024-02-02 00:00 UTC
Security Journalism

Threat Advisory | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress is tracking concerns regarding the AnyDesk remote control software and provider.

P0
2024-01-31 00:00 UTC
Other

Azure Devops Zero-Click CI/CD Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Legit Security found a zero-click vulnerability in Azure Pipelines that allows an attacker to access secrets and internal information and perform actions in elevated permissions in the context of a pipeline workflow. This could allow attackers to move laterally in the organization and initiate supply chain attacks. When a pipeline is triggered by a "pipeline resource trigger," it shows in the platform as "Automatically Triggered For …" Instead of running in fork default permissions, preventing …

Cloud SecurityVulnerabilities
P0
2024-01-24 12:00 UTC
Government

The near-term impact of AI on the cyber threat

UK NCSC Threat Reports · indexed 2026-08-15 18:50 UTC

An NCSC assessment focusing on how AI will impact the efficacy of cyber operations and the implications for the cyber threat over the next two years.

P0
2024-01-24 00:00 UTC
Other

Google Cloud GKE Unsecure Sys:All Binding

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The system:authenticated group in Kubernetes is a special group that includes all authenticated entities, including human users and service accounts. Anyone who successfully authenticates to the Kubernetes API server, regardless of the authentication method used, will be automatically included in this unique group. Thus, it will share the same roles and permissions of the group. This misunderstanding then creates a significant security loophole when administrators unknowingly bind this group wi…

Cloud Security
P0
2024-01-18 00:00 UTC
Other

Amazon Q for Business Data Exfiltration

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An Indirect Prompt Injection attack can cause the LLM to return markdown tags. This allows an adversary who’s data makes it into the chat context (e.g via an uploaded file) to achieve data exfiltration of the victim’s data by rendering hyperlinks.

AI Security
P0
129 130 131 132 133