IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,620 matching records.
AUTO-POLL // 2026-10-07 18:30 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7

RANSOMWARE
P6
P6
COOL // 67 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2022-02-09 00:00 UTC
Security Journalism

Balancing the Scales of Cybersecurity and Insurance

Huntress · indexed 2026-09-07 17:30 UTC

As the importance of cybersecurity insurance grows, we examine how insurance policies have influenced cybersecurity stacks and visa versa.

P0
2022-02-08 00:00 UTC
Other

Oracle Apiary SSRF

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

By misusing the Apiary web service and taking advantage of Apiary's use of IMDSv1, a remote attacker is able to retrieve sensitive information from various endpoints and use it to gain more access and sensitive data of other hosts in the same environment.

P0
2022-02-07 13:37 UTC
Other

Cleaning the atmosphere

Group-IB · indexed 2026-09-07 17:30 UTC

Weak points in modern-day corporate email security

P0
2022-02-03 00:00 UTC
Other

Codebuild data exfiltration

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

When customers attach a CodeBuild project to their VPC, CodeBuild’s build container will apply the same network routing rules as defined in the customer’s VPC Security Group. However, CodeBuild EC2 hosts retained Internet connectivity via AWS's own VPC, thus allowing an attacker to bypass any custom VPC rules the customer had set up, and use CodeBuild for data exfiltration from the targeted environment. AWS later updated the CodeBuild service to block all outbound network access for newly creat…

Cloud Security
P0
2022-02-01 00:00 UTC
Security Journalism

What Is Managed Detection and Response? | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

What is managed detection and response (MDR) and why is it so important? Dive into the benefits of MDR services and how it can address critical security gaps.

P0
2022-01-28 13:42 UTC
Other

Shedding light on the dark web

Group-IB · indexed 2026-09-07 17:30 UTC

Cybersecurity analyst's guide on how to use machine learning to show cybercriminals' true colors

Cybercrime
P0
2022-01-20 00:00 UTC
Security Journalism

A Journey Back to the World of MSP Security | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Dima Kumets explains why he wanted to make his way back to the world of MSP security—and how he ended up as a Principal Product Manager at Huntress.

P0
2022-01-18 00:00 UTC
Security Journalism

Hot Takes and Cyber Predictions for 2022 | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

What cybersecurity trends will we see in this new year? In this blog, we share some hot takes and predictions for 2022.

P0
2022-01-13 00:00 UTC
Other

BreakingFormation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Read access of host of AWS internal Cloudformation service via XXE SSRF. The level of access with the compromised IAM role from there is unclear.

Cloud Security
P0
2022-01-13 00:00 UTC
Other

SuperGlue

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Compromise of internal AWS Glue service to assume the glue role in any AWS account that used glue.

Cloud Security
P0
2022-01-06 00:00 UTC
Other

AWS AI services ToS allow sharing of customer data

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Use of the AI services on AWS allows customer data to be moved outside of the regions it is used in and potentially shared with third-parties. Note: This issue is outside the scope of this database's usual criteria for inclusion, but has been kept for historic reasons, as it was included in the original CSP Security Mistakes dataset.

Cloud Security
P0
2021-12-30 00:00 UTC
Other

Bypassing Identity-Aware Proxy in Google Cloud

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Google Cloud Platform's Identity-Aware Proxy (IAP) allowed attackers to bypass authentication and access IAP-secured web applications. The exploit involved creating a malicious IAP-secured app using the target's OAuth client ID, configuring query parameter-based routing to capture redirect tokens, and using these tokens to hijack authorized sessions.

Cloud SecurityVulnerabilities
P0
2021-12-28 00:00 UTC
Other

Dataflow RCE via unauthenticated JMX service

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Dataflow worker nodes ran an unauthenticated Java Management Extensions (JMX) service that under certain circumstances would be exposed to the Internet, thus allowing unauthenticated remote code execution (RCE) as root in an unprivileged container. The impact of the vulnerability depended on which service account qA assigned to Dataflow worker nodes (by default, that would be the Google Compute Engine default service account, which has the project-wide Editor role assigned).

Vulnerabilities
P15
2021-12-28 00:00 UTC
Other

Google Cloud Shell command injection

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability was discovered in Cloud Shell that enabled command injection and remote shell access. The "Open in Cloud Shell" functionality allowed a user to provide values for both the "git_repo" and "go_get_repo" parameters, which would clone the target repo in the user's environment. While "git_repo" was validated against a list of trusted repos, "go_get_repo" was not. Therefore, an attacker could have supplied a trusted repository as "git_repo" and an arbitrary command in the "go_get_repo…

Cloud SecurityPhishingVulnerabilities
P0
2021-12-21 14:05 UTC
Other

Ready-made fraud

Group-IB · indexed 2026-09-07 17:30 UTC

Behind the scenes of targeted scams

Cybercrime
P0
143 144 145 146 147