IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,628 matching records.
AUTO-POLL // 2026-10-07 20:15 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7

RANSOMWARE
P6
P6
COOL // 75 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2021-05-10 12:00 UTC
Government

Active Cyber Defence (ACD) - the fourth year

UK NCSC Threat Reports · indexed 2026-08-15 18:50 UTC

The year four report covers 2020 and aims to highlight the achievements and efforts made by the Active Cyber Defence programme.

P0
2021-05-07 08:17 UTC
Other

Connecting the Bots

Group-IB · indexed 2026-09-07 17:30 UTC

Hancitor fuels Cuba Ransomware Operations

Ransomware
P15
2021-05-06 00:00 UTC
Security Journalism

Huntress Series B: Our Next Chapter of Growth

Huntress · indexed 2026-09-07 17:30 UTC

We’ve been focused on expanding our platform and helping you better protect your customers. And we’re just getting started.

P0
2021-04-30 00:00 UTC
Other

Password Reset Code Brute-Force Vulnerability in AWS Cognito

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in AWS Cognito's password reset function allowed attackers to brute-force the six-digit reset code, potentially leading to account takeovers. Using concurrent HTTP requests, an attacker could make up to 1587 guesses instead of the documented limit of 20. The issue affected accounts without multi-factor authentication and was fixed by AWS on April 20, 2021.

Cloud SecurityVulnerabilities
P0
2021-04-14 08:29 UTC
Other

Lazarus BTC Changer

Group-IB · indexed 2026-09-07 17:30 UTC

Back in action with JS sniffers redesigned to steal crypto

P0
2021-04-12 08:30 UTC
Other

Deep water: exploring phishing kits

Group-IB · indexed 2026-09-07 17:30 UTC

Group-IB's Computer Emergency Response Team built a solid phishing kit database, which helps Group-IB fight phishing that targets specific brands.

Phishing
P0
2021-04-08 08:42 UTC
Other

When Karma Comes Back

Group-IB · indexed 2026-09-07 17:30 UTC

The rise and fall of illicit cardshop breached twice in two years

P0
2021-04-06 00:00 UTC
Security Journalism

What Is a Persistent Foothold? | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

We hunt for persistent footholds, but what exactly does that mean? In this blog, we define what a foothold is and why it's a hacker favorite.

P0
2021-03-31 00:00 UTC
Security Journalism

Top Takeaways from hack_it 2021 | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

A recap of hack_it 2021, a virtual security training event packed with interactive exercises, malware analysis, hacking workshops and more.

Malware
P0
2021-03-23 00:00 UTC
Security Journalism

How Hackers Exploit Windows Administrative Shares

Huntress · indexed 2026-09-07 17:30 UTC

Windows' administrative shares feature is often overlooked by users, but not by hackers. Learn how attackers abuse administrative shares to propagate.

Microsoft
P0
2021-03-17 08:49 UTC
Other

Masters of disguise

Group-IB · indexed 2026-09-07 17:30 UTC

Let's hunt some bootkits

P0
2021-03-17 00:00 UTC
Other

Privilege escalation in GCP OS Login

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

GCP provides an OS Login service for managing SSH access to compute instances using IAM roles. An attacker could abuse this feature via LXD, Docker (if available on the target system) and DHCP poisoning of the metadata server to escalate their privileges on a Google Compute Engine VM.

Vulnerabilities
P10
2021-03-10 00:00 UTC
Other

AWS CloudShell terminal escape

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

If attacker controlled data is viewed in Cloudshell it could have led to code execution. This exact same issue existed in Azure previously.

Cloud Security
P0
2021-03-09 00:00 UTC
Other

Azure Linux VM extension credential leak

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in the Azure Linux VM extension mechanism allowed an unprivileged user to leak any Azure VM extension’s private data. An attacker could have abused this to gain credentials for the VM itself as well as credentials for extensions associated with the VM. Paired with the design of the VMAccess extension (an official Azure extension for managing VM credentials), this could have been used to achieve privilege escalation, as an unprivileged attacker would have been able to elevate the…

Cloud SecurityLinuxVulnerabilities
P10
2021-03-09 00:00 UTC
Security Journalism

Peeling Back the Layers of .NET Malware

Huntress · indexed 2026-09-07 17:30 UTC

Hackers always try to cover up their tracks. In this blog, we step through layers of obfuscation to uncover the real intent of a .NET malware sample.

Malware
P0
2021-03-02 00:00 UTC
Security Journalism

What Is Human-Powered Threat Hunting? | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

In this blog, we define what threat hunting is, the differences between human analysis and automation, plus an example of human-powered threat hunting.

P0
2021-03-01 09:02 UTC
Other

Inside Classiscam

Group-IB · indexed 2026-09-07 17:30 UTC

A deep dive into Classiscam: automated scam as a service designed to steal money and payment data

P0
2021-02-19 12:00 UTC
Government

Active Cyber Defence (ACD) - The Third Year

UK NCSC Threat Reports · indexed 2026-08-15 18:50 UTC

The year three report covers 2019 and aims to highlight the achievements and efforts made by the Active Cyber Defence programme.

P0
2021-02-15 00:00 UTC
Other

Azure Cloud Shell and Container Instances breakout

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An attacker could gain root privileges on their Azure Cloud Shell container, escape from the container, and then gain root privileges on the underlying node, the root cause being an insecure kubelet port (10250), among other cluster misconfigurations. Once they could access the node filesystem, an attacker could extract kubelet API credentials which allowed listing all pods and nodes in the cluster, including those belonging to other tenants. Moreover, an attacker could bypass RBAC policies in …

Cloud Security
P0
147 148 149 150 151