IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,598 matching records.
AUTO-POLL // 2026-10-07 16:05 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P3 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7

RANSOMWARE
P3
P3
COOL // 45 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2023-04-03 00:00 UTC
Other

App Runner cross-tenant observability config info leak

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The API action ListObservabilityConfigurationsForAccount did not properly validate the "AccountId" parameter that was passed to it. As a result, any account ID could be provided and the API would return the information for that account. This would leak minor information about the observability configuration for App Runner in the account.

P0
2023-04-03 00:00 UTC
Other

App Runner cross-tenant VPC connectors info leak

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The API action ListVpcConnectorsForAccount did not properly validate the "AccountId" parameter that was passed to it. As a result, any account ID could be provided and the API would return the information for that account. This would leak minor information about the VPC configuration for App Runner in the account including the subnet ID, security group ID, and the VPC Connector ARN.

P0
2023-03-31 10:59 UTC
Other

36gate: supply chain attack

Group-IB · indexed 2026-09-07 17:30 UTC

What is known about the 3CX supply chain incident and how to defend against it?

P0
2023-03-30 00:00 UTC
Other

Azure on-premises data gateway cross-tenant access

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure on-premises data gateway allows data transfer between an on-prem customer network and several Azure cloud services, and also enables a connected agent installed locally in an on-prem network to perform certain actions remotely. NetSPI discovered a deserialization issue in Microsoft Power Platform connectors that lead to RCE on several Azure backend servers that processed call backs from on-premises data gateways, effectively allowing unauthorized cross-tenant access.

Cloud SecurityMicrosoftVulnerabilities
P15
2023-03-30 00:00 UTC
Other

RCE vulnerability in Azure Pipelines

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Legit Security found an RCE vulnerability in Azure Pipelines that could have allowed an attacker to gain complete control of variables and tasks by exploiting logging commands. This would have enabled them to execute malicious code in a context of a pipeline workflow, which would have granted them access to sensitive secrets such as cloud deployment keys, move laterally in the organization, and potentially initiate supply chain attacks. To exploit this vulnerability, an attacker would have need…

Cloud SecurityVulnerabilities
P15
2023-03-30 00:00 UTC
Security Journalism

3CX VoIP Software Compromise & Supply Chain Threats | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

The 3CX VoIP Desktop Application has been compromised to deliver malware via legitimate 3CX updates. Huntress has been investigating this incident and working to validate and assess the current supply chain threat to the security community.

Malware
P0
2023-03-23 00:00 UTC
Other

Azure Function Apps privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Undocumented APIs used by the Azure Function Apps Portal could have allowed an attacker with existing access to a Reader role on a Function App to escalate their privileges and gain write permissions through arbitrary file reads on Function App containers. For Windows containers, this would only grant an attacker the ability to extract ASP.NET encryption keys (the impact of which remains unclear), but for Linux containers it would have allowed an attacker to read environmental variables contain…

Cloud SecurityLinuxMicrosoftVulnerabilities
P25
2023-03-21 00:00 UTC
Security Journalism

macOS (Not)ifications | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

In this blog, we dive into macOS notifications—and the intentional design behind them.

Apple
P0
2023-03-20 00:00 UTC
Other

Partial CloudTrail logging in AWS Control Tower

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS Control Tower was not properly logging to CloudTrail when API calls failed due to a lack of permissions. This could have helped an adversary with existing access to a victim AWS environment avoid detection while enumerating privileges, since any unsuccessful API calls would not generate "access denied" log entries.

Cloud Security
P0
2023-03-19 00:00 UTC
Other

CloudTrail bypass for AWS Service Catalog

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Due to an exposed development endpoint, it was possible to bypass CloudTrail logging for both read and write API actions for the Service Catalog service. This could have enabled adversaries to alter Service Catalog resources undetected after gaining a foothold in a victim AWS environment.

Cloud Security
P0
2023-03-16 00:00 UTC
Security Journalism

Addressing Initial Access | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Series of blog posts that share the breadth and depth of Huntress’ experience to assist others in reducing their attack surface, and inhibiting or even obviating cyber attacks.

P0
2023-03-14 00:00 UTC
Other

Super FabriXss

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Service Fabric Explorer (SFX) was affected by an XSS vulnerability that could have allowed a malicious script to be reflected off a web application. After a potential victim clicked on a crafted malicious URL, the attacker could remotely toggle the ‘Cluster’ Event Type setting under the Events tab. This could lead to unauthenticated remote code execution on a container hosted on a Service Fabric node.

Cloud SecurityVulnerabilities
P15
2023-03-08 00:00 UTC
Other

Imposter commits vulnerability in GitHub Actions

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in GitHub Actions allows bypassing workflow settings using commits from forked repositories (rather than commits of the main action repo). This "imposter commits" issue can potentially introduce untrusted code into CI/CD pipelines, posing a risk to the security of the software supply chain. The vulnerability stems from GitHub's handling of forked repositories and how commits are shared between forks and parent repositories. A partial solution to this was GitHub prohibiting parti…

Vulnerabilities
P0
2023-03-07 00:00 UTC
Security Journalism

How To Get Buy-In for an EDR Purchase

Huntress · indexed 2026-09-07 17:30 UTC

EDR is a baseline for security controls these days. Learn which questions to ask and answers to give when seeking buy-in to add or replace an EDR in your security stack.

P0
2023-03-06 00:00 UTC
Other

Unauthorized access to Codespace secrets in GitHub

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in GitHub's Repository Security Advisory feature allowed unauthorized users to access plaintext Codespace secrets of any organization, including GitHub itself. The issue stemmed from the new beta feature that allows external users to report vulnerabilities to public repositories, inadvertently granting access to sensitive organization-level secrets.

Vulnerabilities
P0
2023-02-25 00:00 UTC
Other

AWS CodeBuild Token Leakage

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An attacker with elevated permissions in CodeBuild could leak the configured credentials for Github/Bitbucket. This was possible by configuring the http_proxy and https_proxy variables, which would allow you to capture the credentials via MITM.

Cloud Security
P0
2023-02-25 00:00 UTC
Other

Overprivileged CodeBuild default ECR IAM policy

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

For AWS CodeBuild, when using a custom container image stored in ECR and the project service role for the credentials to pull the image, the default IAM policy attached to the role to allow pulling the container was over-privileged and allowed the CodeBuild container to overwrite its own build image. An attacker with the ability to read the container credentials from the meta-data service or run commands within the container could thereby overwrite the container to gain persistence within the C…

Cloud Security
P0
2023-02-20 09:52 UTC
Other

Bad Behaviour: How to detect banking trojans

Group-IB · indexed 2026-09-07 17:30 UTC

Mobile banking users are being manipulated by attackers to authorize fraudulent transactions. Learn what financial service providers can do to render these organized crimes powerless.

CybercrimeMalware
P0
2023-02-15 00:00 UTC
Other

Azure AD B2C cryptographic flaw allowing account compromise

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Active Directory B2C service (AD B2C) mistakenly implemented RSA key authentication using the public part of the key pair instead of the private one. This cryptographic flaw could have allowed an unauthenticated attacker to craft an OAuth refresh token for any AD B2C user account if they knew their public key. Moreover, every AD B2C user's public key was recoverable through an unrelated vulnerability (though asymmetric cryptography should not rely on public key secrecy regardless). An att…

Cloud SecurityVulnerabilities
P0
2023-02-14 00:00 UTC
Other

AWS EC2 Autoscaling Privilege Escalation Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A privilege escalation vulnerability in Amazon EC2 Autoscaling was identified. The CreateLaunchConfiguration action lacked PassRole validation, allowing users to launch EC2 instances with unauthorized roles. AWS fixed the issue for both CreateLaunchConfiguration and CreateAutoScalingGroup actions, implementing proper PassRole validation when using the instance-id option.

Cloud SecurityVulnerabilities
P10
2023-02-14 00:00 UTC
Other

Azure App Service on Azure Stack Hub privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A privilege escalation vulnerability was discovered in Azure App Service on Azure Stack Hub (an on-prem private cloud offering). To exploit this vulnerability, an attacker must have access to the targeted worker role and the ability to deploy a malicious application within the worker. The attack itself is carried out locally on the worker role where a malicious application has been deployed. Exploiting this vulnerability could grant an attacker the ability to access and modify content of a targ…

Cloud SecurityVulnerabilities
P10
136 137 138 139 140