IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,617 matching records.
AUTO-POLL // 2026-10-07 17:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7

RANSOMWARE
P6
P6
COOL // 64 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2022-06-14 00:00 UTC
Security Journalism

Triangulation | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

This blog dives into triangulation as a guiding concept during investigations and reporting.

DFIR
P0
2022-06-13 00:00 UTC
Other

Privilege escalation and file poisoning in Synapse Analytics

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Tenable Research discovered a privilege escalation flaw that allows a user to escalate privileges to that of the root user within the context of a Spark VM. They also discovered a separate flaw that allows a user to poison the hosts file on all nodes in their Spark pool, which would allow an attacker to redirect subsets of traffic and snoop on services users generally do not have access to.

Vulnerabilities
P10
2022-06-09 15:53 UTC
Other

Swiss Army Knife Phishing

Group-IB · indexed 2026-09-07 17:30 UTC

Group-IB identifies massive campaign capable of targeting clients of major Vietnamese banks

Phishing
P0
2022-05-31 00:00 UTC
Other

MWAA logs leak tokens and hostnames

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Two API calls used by Amazon Managed Workflows for Apache Airflow (MWAA) to convert AWS IAM credentials into tokens that can be used to login to Airflow (CreateCliToken and CreateWebLoginToken) were logging the tokens to Cloudtrail. The event included the hostname for the airflow server, so everything required to login to Airflow was in the event. However, the issue was largely mitigated by the fact that the tokens are only valid for 60 seconds and CloudTrail delivers logs on average about ever…

Cloud Security
P0
2022-05-31 00:00 UTC
Security Journalism

Out of Sight, Top of Mind | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

It can be difficult to demonstrate the value of cybersecurity when your stack is doing its job. Here is how you can show the hidden value of cybersecurity.

P0
2022-05-24 00:00 UTC
Security Journalism

The Mechanics of Defense Evasion | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Continuing our blog series on defense evasion, this blog dives into some practical, real-world examples of defense evasion in action.

P0
2022-05-17 00:00 UTC
Other

ELB Cache mechanism HTTP header smuggling

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

While testing rate-limiter protection, The researcher noticed that when forcing HTTP/1 requests and injecting a space after `X-Forwarded-For` he was able to override this specific header, letting him impersonate any IP. Any internal header could have beem overridden, also the one that should not be exposed/forwarded by the client, such as `CloudFront-Viewer-Country-Region` or any other `CloudFront` enhanced header. This special security issue was affecting all AWS users with that a specific set…

Cloud Security
P0
2022-05-17 00:00 UTC
Security Journalism

How Huntress Protects SMBs | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Learn how The Huntress Managed Security Platform is built to equip SMBs with the ability to swiftly and accurately mitigate threats.

P0
2022-05-16 00:00 UTC
Security Journalism

Huntress API Is Now in Public Beta!

Huntress · indexed 2026-09-07 17:30 UTC

Read about our latest addition, API, and how it enables MSPs and IT administrators to monitor, manage and maintain their cybersecurity stack how they want.

P0
2022-05-10 12:00 UTC
Government

ACD - The Fifth Year

UK NCSC Threat Reports · indexed 2026-08-15 18:50 UTC

Key findings from the 5th year of the Active Cyber Defence (ACD) programme.

P0
2022-05-10 00:00 UTC
Security Journalism

Evicting the Adversary | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

This blog shows how to catch an adversary moving from machine to machine, how to terminate this movement and how to evict the adversary from your network.

P0
2022-05-09 00:00 UTC
Other

Synlapse

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Synapse Analytics and Azure Data Factory were vulnerable to cross-tenant access and code execution. This was made possible via a combination of (1) a shell injection RCE vulnerability in the integration runtime, (2) credentials for multiple customers stored on a shared host and (3) an insecure management server API.

Cloud SecurityVulnerabilities
P15
2022-05-05 00:00 UTC
Security Journalism

One Year Later | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

We recap some of the lessons we have learned over the past year thanks to the Colonial Pipeline attack.

P0
2022-05-04 12:00 UTC
Government

Threat report on application stores

UK NCSC Threat Reports · indexed 2026-08-15 18:50 UTC

This report outlines the risks associated with the use of official and third party app stores.

P0
2022-05-03 00:00 UTC
Security Journalism

What Is Defense Evasion? | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

An introduction to defense evasion as an attack tactic. Read on to explore what defense evasion is and why it’s important to understand how it’s used.

P0
2022-05-01 00:00 UTC
Other

AWS package backfill attack

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Two malicious versions were created of packages previously used by AWS. The packages were officially authored and maintained by AWS before they were removed by their legitimate author, and once the packages were removed, their names became available and the two packages were then populated with malicious code. If AWS-deployed software had any dependencies on these packages, this would have led to a dependency confusion attack.

Cloud Security
P0
2022-04-28 00:00 UTC
Other

ExtraReplica

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A chain of critical vulnerabilities was discovered in Azure Database for PostgreSQL Flexible Server, allowing unauthorized read access to other customers’ PostgreSQL databases, thus bypassing tenant isolation. If exploited, a malicious actor could have replicated and gained read access to Azure PostgreSQL Flexible Server customer databases.

Cloud Security
P0
2022-04-26 00:00 UTC
Security Journalism

Bring Your Own Command & Control (BYOC2)

Huntress · indexed 2026-09-07 17:30 UTC

Sometimes hackers can be overly confident in their malware. Take a journey with us through a malware sample that contains no obfuscation whatsoever.

Malware
P0
2022-04-20 00:00 UTC
Other

AWS SSM agent local privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The Amazon SSM Agent (used for managing EC2 instances via Amazon Systems Manager) created a world-writable sudoers file, which would have allowed local attackers to inject Sudo rules and escalate privileges to root. This could occur in certain situations involving a race condition.

Cloud SecurityVulnerabilities
P10
2022-04-14 11:36 UTC
Other

Old Gremlins, new methods

Group-IB · indexed 2026-09-07 17:30 UTC

Russian-speaking ransomware gang OldGremlin resumes attacks in Russia

Ransomware
P15
141 142 143 144 145