IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,597 matching records.
AUTO-POLL // 2026-10-07 15:20 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P4 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7

RANSOMWARE
P4
P4
COOL // 44 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2023-05-30 00:00 UTC
Security Journalism

Threat Advisory: XMRig Cryptomining By Way Of TeamViewer

Huntress · indexed 2026-09-07 17:30 UTC

Huntress has recently seen an uptick in compromised TeamViewer accounts being used to install the XMRig cryptocurrency miner. Dive into the analysis here.

P0
2023-05-24 00:00 UTC
Other

Cloud SQL for SQL Server privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability discovered in GCP's Cloud SQL service allowed customer administrator accounts to create triggers in the tempdb database and use those to gain sysadmin privileges in the instance. This could be abused to result in complete control of the database engine and access to the host OS. An attacker could have listed and accessed files in the host OS, including any secrets on the machine, as well as gaining access to service agents. However, it is unclear from the report if this level of…

Vulnerabilities
P10
2023-05-23 00:00 UTC
Security Journalism

MM vs MDM for macOS: What's the Difference? | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Is RMM the same as MDM? Learn the key differences between RMM and MDM for macOS management and how Huntress works with both to keep your endpoints secure.

Apple
P0
2023-05-18 00:00 UTC
Other

GuardDuty bypass via S3 permission modification

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Threat actors in possession of IAM active credentials that had the power to update S3 bucket policies could have bypassed GuardDuty’s S3 detections and silently updated permissions for S3 resources, resulting in a bucket configuration that allowed anonymous data access. This gap in GuardDuty’s alert coverage occurred only when S3’s Block Public Access was not enabled on the account or the bucket, and when KMS-based server-side bucket encryption was not in use. In order to trigger on opening pub…

Cloud SecurityThreat Actors
P0
2023-05-04 00:00 UTC
Other

API Management SSRF and path traversal vulnerabilities

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure API Management is an API gateway service meant to help organizations to create, manage, secure, and monitor APIs across all of their environments. Researchers found three high severity vulnerabilities in the service, two of which are SSRF (Server Side Request Forgery) vulnerabilities, and the third is a path traversal bug. The SSRF issues affected the Azure API Management CORS proxy (which handles schema retrieval) and hosting proxy (which routes API requests to the correct server). An at…

Cloud SecurityVulnerabilities
P0
2023-04-25 00:00 UTC
Other

MFA enforcement IAM policy bypass

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An AWS-recommended IAM policy that enforced MFA on access keys could have been bypassed due to a change implemented by AWS in November 2022 that allowed IAM users to assign multiple MFA devices to their account. Prior to this change, an attacker that had compromised credentials could not create and assign a new MFA device to bypass the MFA requirement as they would need to first deactivate the user’s existing MFA device. Organisations using SSO which enforces MFA, either via an external IdP or …

Cloud Security
P0
2023-04-25 00:00 UTC
Security Journalism

Endpoint Security In a macOS World | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

It would take hours to cover everything endpoint security can do, but this blog covers it in a few aspects: a high-level overview, a deeper dive and how detection engineers can leverage it.

Apple
P0
2023-04-21 00:00 UTC
Other

GhostToken

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Google users can find and install third-party OAuth applications from Google Marketplace that are integrated with Google Workspace. Each OAuth application client in Google is associated with a GCP project. A bug in the way a GCP project enters a "pending deletion" state when deleted, could have allowed threat actors to make a malicious application invisible and unremovable from the user's account. If an attacker had managed to install an application in an account (e.g., through a phishing attac…

PhishingThreat ActorsVulnerabilities
P0
2023-04-19 12:00 UTC
Government

The threat from commercial cyber proliferation

UK NCSC Threat Reports · indexed 2026-08-15 18:50 UTC

Report informing readers about the threat to UK industry and society from commercial cyber tools and services.

P0
2023-04-19 00:00 UTC
Other

Asset Key Thief

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Asset Key Thief was a Google Cloud privilege escalation vulnerability that enabled principals with the "Cloud Asset Viewer" role (or other roles with the `cloudasset.assets.searchAllResources` permission) on the Cloud Asset Inventory API, at the Project, Folder, or Organization level to view and exfiltrate any user-managed Service Account private key under a project within the same Google Cloud environment that had been created or rotated up to a maximum of 12 hours ago. Access to Service Accou…

Cloud SecurityVulnerabilities
P10
2023-04-19 00:00 UTC
Other

BrokenSesame

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

ApsaraDB and AnalyticDB contained several vulnerabilities in their PostgreSQL offerings which ultimately allowed unauthorized access to other tenants' databases and the ability to perform a supply-chain attack on both services, which in turn would have allowed remote code execution (RCE) as well. Both services implemented multi-tenancy through a shared K8s cluster, but contained several bugs related to tenant isolation which an attacker could chain together to achieve the above impact. In Apsar…

Vulnerabilities
P25
2023-04-18 07:56 UTC
Other

SimpleHarm: Tracking MuddyWater’s infrastructure

Group-IB · indexed 2026-09-07 17:30 UTC

Group-IB analysts discovered the new MuddyWater infrastructure while researching the pro-state group’s use of the legitimate SimpleHelp tool.

P0
2023-04-11 00:00 UTC
Security Journalism

Traitorware and Living Off the Land | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Your security tools are just as likely to be attacked as anything else. This blog dives into traitorware and how it's used to live off the land.

P0
2023-04-03 00:00 UTC
Other

App Runner cross-tenant observability config info leak

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The API action ListObservabilityConfigurationsForAccount did not properly validate the "AccountId" parameter that was passed to it. As a result, any account ID could be provided and the API would return the information for that account. This would leak minor information about the observability configuration for App Runner in the account.

P0
135 136 137 138 139