IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,630 matching records.
AUTO-POLL // 2026-10-07 21:05 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7

RANSOMWARE
P5
P5
COOL // 77 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2021-02-15 00:00 UTC
Other

Azure Cloud Shell and Container Instances breakout

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An attacker could gain root privileges on their Azure Cloud Shell container, escape from the container, and then gain root privileges on the underlying node, the root cause being an insecure kubelet port (10250), among other cluster misconfigurations. Once they could access the node filesystem, an attacker could extract kubelet API credentials which allowed listing all pods and nodes in the cluster, including those belonging to other tenants. Moreover, an attacker could bypass RBAC policies in …

Cloud Security
P0
2021-01-26 09:13 UTC
Other

The source of everything

Group-IB · indexed 2026-09-07 17:30 UTC

Forensic examination of incidents involving source code leaks

P0
2021-01-26 00:00 UTC
Security Journalism

Huntress Service: Managed Antivirus | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Read about Huntress’ Managed Antivirus service and how it enables MSPs and IT admins to strengthen endpoint protection and rebalance their cyber stack.

P0
2021-01-12 00:00 UTC
Security Journalism

Malware Under The Microscope: Manual Analysis

Huntress · indexed 2026-09-07 17:30 UTC

Learn manual malware analysis techniques used by threat researchers. Explore static & dynamic analysis, reverse engineering tools, and real-world investigation methods.

DFIRMalware
P0
2020-12-30 00:00 UTC
Other

GKE gVisor sandbox escape

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A bug in the GKE gVisor sandbox's network policy implementation allowed access to the Google Compute Engine metadata API.

P0
2020-12-29 00:00 UTC
Security Journalism

Redefining Beta | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

At Huntress, beta means learning. Our goal is to accelerate and streamline security defense, which means releasing what we’re working on often.

P0
2020-12-23 09:19 UTC
Other

New attacks by UltraRank group

Group-IB · indexed 2026-09-07 17:30 UTC

As part of UltraRank's new campaign, Group-IB Threat Intelligence team discovered 12 eCommerce websites infected with their JavaScript-sniffer.

Threat Intelligence
P0
2020-12-20 00:00 UTC
Other

AWS SOC 2 type 2 failure (Fall 2020)

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Information about this issue is under NDA, but AWS customers can read about it on pages 120-121 of the report, which is available for download through AWS Artifact. Note: This issue is outside the scope of this database's usual criteria for inclusion, but has been kept for historic reasons, as it was included in the original CSP Security Mistakes dataset.

Cloud Security
P0
2020-12-07 09:23 UTC
Other

The footprints of Raccoon

Group-IB · indexed 2026-09-07 17:30 UTC

A story about operators of JS-sniffer FakeSecurity distributing Raccoon stealer

Malware
P0
2020-12-02 00:00 UTC
Security Journalism

Rapid Response: TrickBoot | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

TrickBot has unleashed yet another module in its growing arsenal specifically targeting firmware vulnerabilities, named TrickBoot.

P0
2020-11-27 00:00 UTC
Security Journalism

I Have a Lot to be Thankful for in 2020

Huntress · indexed 2026-09-07 17:30 UTC

Huntress CEO Kyle Hanslovan has a lot to be thankful for in 2020 — and it starts with the MSP community.

P0
2020-11-22 00:00 UTC
Other

GCP Default compute account is project Editor

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

When the compute API is enabled on a GCP Project, the default compute account is created. This account gets the primitive role Editor assigned by default, which allows for a wide variety of privilege excalation and resource abuse in the project. Especially, all new VMs created inherit this permissions by default. This issue is arguably a technical decision by GCP, but the documents advise customers to undo this.

P0
2020-11-22 00:00 UTC
Other

IAM privilege escalation in multiple GCP services

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Composer, Dataflow, Dataproc, Dataprep and Data Fusion all used the Compute Engine default service account by default and relied on product-level IAM permissions without requiring the iam.serviceAccount.actAs permission, meaning that users of these services could elevate their privileges. Following disclosure, GCP changed these services to require this permission.

Vulnerabilities
P10
2020-11-18 00:00 UTC
Security Journalism

Huntress Service: Partner Enablement | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Even the best cybersecurity tools won’t configure and sell themselves. That's why we're thrilled to introduce a new Huntress service: Partner Enablement!

P0
2020-11-12 00:00 UTC
Other

SSRF in Google Cloud Monitoring

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An SSRF bug in Google Cloud Monitoring's uptime check feature could have been used to leak the authentication token of the service account used for these checks. The issue was resolved but later bypassed by Omar Espino (@omespino), requiring another fix.

Cloud Security
P0
2020-11-01 13:38 UTC
Other

Big Game Hunting: Now in Russia

Group-IB · indexed 2026-09-07 17:30 UTC

Top Russian companies and banks under attack from OldGremlin - a group controlling TinyCryptor ransomware

Ransomware
P15
2020-10-19 00:00 UTC
Other

Route table modification to imitate metadata service

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An attacker with sufficient privileges in AWS to modify the route table and some other EC2 privileges, could pretend to be a metadata server and provide an attacker controlled bootup script to EC2s to move laterally.

Cloud Security
P0
2020-10-17 00:00 UTC
Other

AI Hub Jupyter Notebook instance CSRF

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AI Hub Jupyter Notebook server lacked a check of the Origin header that led to a CSRF vulnerability. An attacker could have read sensitive data and execute arbitrary actions in customer environments.

Vulnerabilities
P0
2020-10-17 00:00 UTC
Other

Enumeration of Privileges Without Being Logged to CloudTrail

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An attacker who gained access to IAM credentials could enumerate a subset of the privileges they had access to without logging to CloudTrail. This would allow them to perform the typically noisy permission enumeration process undetected.

P0
2020-10-15 00:00 UTC
Other

Lack of internal change controls for IAM managed policies

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS have released or changed managed IAM policies in unexpected and insecure ways. Examples include: CheesepuffsServiceRolePolicy, AWSServiceRoleForThorInternalDevPolicy, AWSCodeArtifactReadOnlyAccess.json, AmazonCirrusGammaRoleForInstaller. The worst being the ReadOnlyAccess policy having almost all privileges removed and unexpected ones added.

Cloud Security
P0
148 149 150 151 152