IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,615 matching records.
AUTO-POLL // 2026-10-07 16:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7

RANSOMWARE
P6
P6
COOL // 62 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2023-01-13 00:00 UTC
Other

Bypassing authorization in Google Cloud Workstations

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Several vulnerabilities were present in how Google Cloud Shell (ssh.cloud.google.com) handled OAuth credentials. These included an open-redirect vulnerability, where attackers could redirect users to malicious sites to capture their credentials, and a validation bypass that allowed tokens to be submitted to user-defined URIs, circumventing normal security checks. Additionally, Google Cloud Workstations did not correctly tie the state parameter to the session that generated it, which allowed val…

Cloud SecurityPhishingVulnerabilities
P0
2023-01-12 00:00 UTC
Other

Client-Side SSRF to Google Cloud Project Takeover

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Vertex AI Workbench allowed attackers to take over victims' Google Cloud projects through client-side SSRF. The initial bug involved unauthorized access to authentication tokens, which was later fixed. A bypass was later discovered (and also fixed) using open redirects in Feedburner and CSRF token manipulation.

Cloud SecurityVulnerabilities
P0
2023-01-12 00:00 UTC
Other

SSH key injection in Google Cloud Compute Engine

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Google Cloud Compute Engine (GCE) was vulnerable to SSH key injection by abusing an SSH-in-browser feature to change username and password. An attacker could send a specially-crafted link to a target user, and if the victim was logged into GCP and clicked the link, the attacker's SSH username and password would be added to the target machine, thereby allowing the attacker to log into it. This was possible because no random token or CSRF protection had been implemented for the abused feature. Fo…

Cloud Security
P0
2023-01-11 07:17 UTC
Other

Dark Pink

Group-IB · indexed 2026-09-07 17:30 UTC

New APT hitting Asia-Pacific, Europe that goes deeper and darker

APT / Nation-State
P0
2023-01-10 00:00 UTC
Security Journalism

Insistence on Persistence | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

In this blog, we'll explore our new Mac agent, what we look for and why—and where we’re heading.

P0
2023-01-06 00:00 UTC
Other

IAP CORS Misconfiguration Allows Email Disclosure

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A CORS misconfiguration in Google Cloud's Identity-Aware Proxy (IAP) could have allowed attackers to disclose the email address of an authenticated user in websites protected by IAP, by convincing the user to connect to an attacker-controlled domain. This vulnerability enabled attackers to exploit CORS settings to access sensitive email information of both authenticated and unauthenticated users (with the latter requiring additional social engineering).

Cloud SecurityVulnerabilities
P0
2022-12-29 00:00 UTC
Security Journalism

OWASSRF Explained | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress' analysis of a new exploit chain (called OWASSRF) that can lead to critical remote code execution on unpatched Exchange hosts.

MicrosoftVulnerabilities
P15
2022-12-22 00:00 UTC
Other

ACSESSED

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Cognitive Search (ACS) is a full-text search engine service. A new non-default feature allowed for a network control to bypassed, permitting an attacker to submit search queries to any other tenant's network-isolated ACS instance. However, abusing this required a valid API key to access the data plane of the target, along with a number of pieces of information about the target environment (such as the subscription ID and the name of the index to query).

Cloud Security
P0
2022-12-16 13:42 UTC
Other

Scam-free Christmas

Group-IB · indexed 2026-09-07 17:30 UTC

8 online scams to protect your customers from

P0
2022-12-15 00:00 UTC
Other

Azure Serverless Functions escape to host

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

In Azure Serverless Functions, a new container is generated by the host for every function, which is then terminated and deleted after several minutes. Palo Alto discovered that an API call was available to bind one path to another within the container (called "init_server_pkg_mount_BindMount") that could be called by a low-privileged user but executed with root privileges. This could enable a malicious tenant to escalate their privileges to root, and then escape their container by abusing the …

Cloud SecurityLinuxNetwork SecurityVulnerabilities
P0
2022-12-13 00:00 UTC
Other

ECR Public vulnerability in undocumented API

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Elastic Container Registry (ECR) Public could have allowed a malicious actor to delete, update, or create ECR Public images, layers, or tags in registries and repositories belonging to any other AWS account, by abusing undocumented API calls. A malicious actor could have exploited this to delete any or all images in the Amazon ECR Public Gallery or update the content of any existing image to inject malicious code on any machine that would pull and run it.

Cloud SecurityVulnerabilities
P0
2022-12-01 00:00 UTC
Other

Hell's Keychain

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

IBM Cloud Databases for PostgreSQL was vulnerable to an attack sequence comprised of PostgreSQL privilege escalation via SQL Injection and chaining of three secrets scattered in the service environment (a K8s service account token, a private container registry password, and CI/CD server credentials), which were abusable due to overly permissive network access to internal build servers. A malicious actor could have exploited this vulnerability to remotely execute code in other customers’ environ…

Vulnerabilities
P10
2022-11-29 00:00 UTC
Security Journalism

Incident Response: A Choose Your Own Adventure Exercise

Huntress · indexed 2026-09-07 17:30 UTC

Incident response is a lot like a choose your own adventure exercise. We cover the ground rules and talk about some incidents we’ve helped partners with.

DFIR
P0
2022-11-21 00:00 UTC
Other

AWS AppSync confused deputy via ServiceRoleArn

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The AWS AppSync service could be coerced to assume arbitrary roles in other customers' accounts which trusted the AppSync service. This was due to insufficient validation of a serviceRoleArn parameter (caused by a case-sensitivity parsing issue). With this vulnerability, if an adversary knew the ARN of the role associated with AppSync in the target account, they could use it invoke arbitrary AWS API calls.

Cloud SecurityVulnerabilities
P0
2022-11-15 00:00 UTC
Security Journalism

Do You Have a Security Hygiene Checklist in Place?

Huntress · indexed 2026-09-07 17:30 UTC

A strong security foundation is the cornerstone of any MSP’s success. Learn how to build this foundation—even if you're new to cybersecurity.

P0
2022-11-08 00:00 UTC
Security Journalism

Creating macOS Ransomware | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

With the beta release of the Huntress macOS agent, we wanted to share some of the Apple-y stuff we’ve been up to behind the scenes.

AppleRansomware
P15
2022-11-07 00:00 UTC
Other

Azure Devops account takeover via dangling subdomain takeover

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Binary Security discovered and registered two dangling cloudapp.azure.com subdomains corresponding to subdomains at visualstudio.com. Had these been discovered and registered by an attacker, this would have been equivalent to a 1-click vulnerability for Azure DevOps: the attacker could have crafted a URL referring to the sign-in API for Azure DevOps Services (app.vssps.visualstudio.com) using one of the two subdomains in the "reply_to" field (since subdomains of visualstudio.com would be allowe…

Cloud SecurityVulnerabilities
P0
138 139 140 141 142