IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,585 matching records.
AUTO-POLL // 2026-10-07 13:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P4 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7

RANSOMWARE
P4
P4
COOL // 32 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2023-12-07 00:00 UTC
Security Journalism

Exploring the Value of Indicators In Small Business Defense

Huntress · indexed 2026-09-07 17:30 UTC

Discover how leveraging technical indicators can boost cybersecurity effectiveness and empower small business defense. Read on for practical insights.

P0
2023-12-04 00:00 UTC
Security Journalism

CIS Controls Security Awareness Training | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Learn more about how Huntress' Managed Security Awareness Program can help your employees follow CIS control requirements.

P0
2023-11-30 00:00 UTC
Other

Google Workspace Domain-Wide Delegation Flaw

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Unit 42 researchers discovered a security risk in Google Workspace's domain-wide delegation feature that allows a GCP identity with necessary permissions to generate access tokens to impersonate Google Workspace users and access their data. This mismatch between GCP permissions and Google Workspace access could be exploited by malicious insiders or attackers with stolen credentials.

CybercrimeSecurity Research
P0
2023-11-21 00:00 UTC
Security Journalism

Key Insights from Huntress’ SMB Threat Report

Huntress · indexed 2026-09-07 17:30 UTC

Navigate the SMB threat landscape with Huntress’ SMB Threat Report. Gain insights into evolving cyber threats targeting SMBs. Read on for key insights.

P0
2023-11-16 00:00 UTC
Other

Extracting Managed Identity Credentials from Azure Functions

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Azure Function Apps allowed extraction of Managed Identity credentials from the encrypted startup context of Linux containers. This gave attackers with container access the ability to persist as the Managed Identity, breaking the intended security model. Microsoft has since patched the issue by encrypting the sensitive payload.

Cloud SecurityLinuxMicrosoftVulnerabilities
P0
2023-11-14 00:00 UTC
Other

Azure CLI Leaks Credentials in GitHub Actions Logs

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure CLI commands were found to leak sensitive information, including credentials, through GitHub Actions logs. The vulnerability affects multiple Azure CLI commands and could expose secrets in public and private repositories. Microsoft has issued updates to Azure CLI, Azure Pipelines, and GitHub Actions to address the issue.

Cloud SecurityMicrosoftVulnerabilities
P0
2023-11-14 00:00 UTC
Other

CLI Tools Leak Credentials in GitHub Actions Logs

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Palo Alto discovered that Azure CLI commands were found to leak sensitive credentials and environment variables in GitHub Actions logs. This issue affects both public and private repositories, potentially exposing secrets to unauthorized parties. The problem stems from the Azure CLI's design to echo back accessed/created/updated/deleted resource information, which can include sensitive data. Later research by Orca Security revealed that AWS CLI and Google Cloud CLI were affected by the same iss…

Cloud SecurityNetwork Security
P0
2023-11-09 00:00 UTC
Security Journalism

Bitter Pill | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress has uncovered a series of unauthorized access, revealing a threat actor using ScreenConnect to infiltrate multiple healthcare organizations.

Threat Actors
P0
2023-11-08 00:00 UTC
Other

Azure Automation Service Used for Cryptocurrency Mining

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

SafeBreach Labs researchers developed methods to leverage Microsoft Azure's Automation Service for free, undetectable cryptocurrency mining. They found three ways to execute miners: two using their own environment and Azure's resources for free, and one in a victim's environment undetected. The techniques could potentially be used for any task requiring code execution on Azure.

Cloud SecurityMicrosoft
P0
2023-11-06 00:00 UTC
Other

AWS AppFlow secrets disclosure

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AppFlow had an undocumented service called sandstoneconfigurationservicelambda. An undocumented field (awsOwnedManagedAppCredentialsArn) could be used during connector registration and connector updates. Specifying a victim's Secret ARN as that field disclosed the clientId and clientSecret, so long as the victim Secret ARN belonged to a connection profile which is of the type OAuth or contains clientId and clientSecret.

Cloud Security
P0
2023-11-06 00:00 UTC
Other

AWS AppFlow WooCommerce SSRF

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The AppFlow WooCommerce connector allowed specification of a full URL. The connector included details of response content when the URL offered an unexpected response. This means you could make arbitrary GET requests to any URL from the WooCommerce connector, and view the response content. The response in the error was truncated to 500 characters.

Cloud Security
P0
2023-11-03 00:00 UTC
Other

Hacking Google Bard via Prompt Injection

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Google Bard allowed for prompt injection and data exfiltration through its Extensions feature. By injecting malicious instructions into shared Google Docs, an attacker could force Bard to render images with exfiltrated chat history data in the URL. The exploit bypassed Content Security Policy using Google Apps Script.

AI SecurityVulnerabilities
P0
2023-11-02 00:00 UTC
Other

ApatchMe

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Amazon Managed Workflows for Apache Airflow (MWAA) and the Task instance details page in the Google Composer UI were not patched against CVE-2023-29247 (Stored XSS). This meant that post-authentication, a threat actor could have exploited this to store their JavaScript payload in the victim's managed Apache Airflow instance and run JavaScript on behalf of the victim (who could be an admin or another user with higher permissions than the threat actor, thereby leading to privilege escalation). Wi…

Threat ActorsVulnerabilitiesCVE-2023-29247
P15
2023-10-23 00:00 UTC
Government

[MàJ] Vulnérabilité dans Citrix NetScaler ADC et NetScaler Gateway (23 octobre 2023)

CERT-FR Alerts · indexed 2026-09-10 16:10 UTC

\[Mise à jour du 22 novembre 2023\] L'éditeur a publié un document \[3\] le 20 novembre 2023 listant les différents journaux à analyser ainsi que les éléments à rechercher pour identifier une activité pouvant être liée à une compromission. Par ailleurs, la CISA a publié un avis de sécurité le 21...

P0
2023-10-19 00:00 UTC
Other

Azure AI Playground data exfiltration

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

In Azure AI Playground, a Prompt Injection attack could cause an LLM to return markdown tags. This would have allowed an adversary whose data makes it into the chat context (e.g., via an uploaded file) to achieve exfiltration of the victim’s data by rendering hyperlinks. However, the severity of this issue is low, as there were no integrations that could pull remote content. This means Indirect Prompt Injection was not possible, and it would require the victim to copy the malicious prompt from …

AI SecurityCloud Security
P0
2023-10-19 00:00 UTC
Other

Vertex AI Studio data exfiltration

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

In Vertex AI Studio, a Prompt Injection attack could cause the LLM to return markdown tags. This could have allowed an adversary whose data makes it into the chat context (e.g., via an uploaded file) to achieve exfiltration of the victim’s data by rendering hyperlinks. However, the severity of this issue is low, as there were no integrations that could pull remote content. This means Indirect Prompt Injection was not possible, and it would require the victim to copy the malicious prompt from el…

AI SecurityCloud Security
P0
131 132 133 134 135