IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,585 matching records.
AUTO-POLL // 2026-10-07 13:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P4 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7

RANSOMWARE
P4
P4
COOL // 32 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2024-01-24 12:00 UTC
Government

The near-term impact of AI on the cyber threat

UK NCSC Threat Reports · indexed 2026-08-15 18:50 UTC

An NCSC assessment focusing on how AI will impact the efficacy of cyber operations and the implications for the cyber threat over the next two years.

P0
2024-01-24 00:00 UTC
Other

Google Cloud GKE Unsecure Sys:All Binding

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The system:authenticated group in Kubernetes is a special group that includes all authenticated entities, including human users and service accounts. Anyone who successfully authenticates to the Kubernetes API server, regardless of the authentication method used, will be automatically included in this unique group. Thus, it will share the same roles and permissions of the group. This misunderstanding then creates a significant security loophole when administrators unknowingly bind this group wi…

Cloud Security
P0
2024-01-18 00:00 UTC
Other

Amazon Q for Business Data Exfiltration

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An Indirect Prompt Injection attack can cause the LLM to return markdown tags. This allows an adversary who’s data makes it into the chat context (e.g via an uploaded file) to achieve data exfiltration of the victim’s data by rendering hyperlinks.

AI Security
P0
2024-01-16 00:00 UTC
Security Journalism

Full Transparency: Controlling Apple's TCC | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Dive into Apple's TCC framework, decoding its role in user privacy. Explore permissions, challenges, and the encryption safeguarding sensitive data.

Apple
P0
2024-01-12 00:00 UTC
Government

[MàJ] Multiples Vulnérabilités dans GitLab (12 janvier 2024)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

\[Mise à jour du 29 janvier 2024\] Le 25 janvier 2024, l'éditeur a publié un avis de sécurité concernant plusieurs vulnérabilités affectant GitLab CE et EE. La vulnérabilité CVE-2024-0402 est considérée critique avec un score CVSSv3 de 9,9. Elle permet à un attaquant authentifié d'écrire des...

VulnerabilitiesCVE-2024-0402
P5
2024-01-04 00:00 UTC
Security Journalism

Empowering the Hunt: All Your Security in One Place | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress unveils a powerful new platform UI for 2024! From SOC insights to triage feeds, all your security insights are now in a unified interface in the Huntress platform.

P0
2024-01-02 00:00 UTC
Security Journalism

Navigating Cybersecurity Challenges in Healthcare | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Discover essential strategies for healthcare cybersecurity in our latest blog. Learn how to navigate challenges, optimize resources, and safeguard patient data.

P0
2024-01-01 00:00 UTC
Other

Microsoft Healthcare Chatbot Vulnerabilities

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Multiple vulnerabilities in Microsoft's Azure Health Bot service were discovered, allowing access to sensitive infrastructure and confidential medical data. Issues included sandbox escapes, unrestricted code execution, access to authentication secrets, cross-tenant data exposure, and unauthorized deletion of resources. Microsoft quickly patched the vulnerabilities and restructured the service architecture for improved security.

Cloud SecurityMicrosoft
P0
2023-12-27 00:00 UTC
Other

Amazon Cognito Rate Limit Bypass Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A rate limit bypass vulnerability was discovered in Amazon Cognito, allowing attackers to potentially brute-force login credentials, password reset PINs, and MFA codes by sending requests in parallel. The vulnerability affected the main login flow, password reset function, and MFA process, potentially exposing user accounts to unauthorized access.

Vulnerabilities
P0
2023-12-20 00:00 UTC
Other

Azure Pipelines Agent poisoned pipeline execution

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Pipelines and GitHub Actions allow deployment of runners and agents using VM images sourced from a GitHub-managed repository (github.com/actions/runner-images). This repo was misconfigured to use self-hosted runners insecurely, in a way that could have allowed a malicious external contributor (i.e., anyone who had previously had at least one PR approved and merged in the repo) to poison the repository and achieve code execution on runners in the repo. This in turn could have theoretically…

Cloud Security
P0
2023-12-20 00:00 UTC
Other

Data Exfiltration Through CloudTrail

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

This scenario describes a potential data exfiltration technique using AWS CloudTrail. An attacker with access to CloudTrail logs could potentially extract sensitive information from logged events, including API calls and data modifications. This poses a risk to data confidentiality and could lead to unauthorized access to sensitive information.

Cloud Security
P0
2023-12-20 00:00 UTC
Other

Poisoning GitHub's Runner Images Supply Chain Attack

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A critical vulnerability in GitHub's actions/runner-images repository allowed arbitrary code execution on self-hosted runners, potentially enabling modification of GitHub's runner base images. The flaw stemmed from misconfigured self-hosted runners on a public repository with default workflow approval settings. The researcher gained persistence, accessed secrets, and could have inserted malicious code into GitHub's runner images used by customers.

Vulnerabilities
P10
2023-12-19 00:00 UTC
Other

AWS IAM Identity Center Expiry

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS IAM Identity Center exchanges third-party OIDC tokens for Identity Center-issued tokens. Identity Center relies on the jti claim in the third-party tokens to prevent replay attacks. Identity Center maintained a cache of previously-seen jti values for a fixed period (24 hours) and didn’t enforce that the third-party tokens had expiry claims. This meant that a token with a jti claim and without an exp claim could be replayed after >24 hours had passed.

Cloud SecurityMicrosoft
P0
2023-12-15 00:00 UTC
Other

Google OAuth Vulnerability Allows Indefinite Access

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Google OAuth allows employees to retain indefinite access to applications like Slack and Zoom after being removed from their company's Google organization. The issue stems from the ability to create Google accounts using corporate email aliases, which can't be off-boarded by the organization. This bypasses typical account removal processes and poses a significant security risk.

Vulnerabilities
P0
2023-12-13 00:00 UTC
Government

Vulnérabilité dans Apache Struts 2 (13 décembre 2023)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Le 4 décembre 2023, Apache a publié un avis de sécurité concernant la vulnérabilité critique CVE-2023-50164 concernant le cadriciel Struts 2. Cette vulnérabilité permet à un attaquant non authentifié de téléverser une porte dérobée sur un serveur vulnérable, et ainsi exécuter du code arbitraire à...

VulnerabilitiesCVE-2023-50164
P5
2023-12-12 00:00 UTC
Other

Control plane bypass in Azure OpenAI

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A way to manage Azure OpenAI deployments via the Data Plane was discovered, bypassing key security controls. This allows creation/modification/deletion of deployments without the usual protections of Resource Manager Locks, Azure Policy, and Entra ID authentication.

Cloud SecurityMicrosoft
P0
130 131 132 133 134