IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,630 matching records.
AUTO-POLL // 2026-10-07 21:05 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7

RANSOMWARE
P5
P5
COOL // 77 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2020-10-06 00:00 UTC
Other

Multiple issues in AWS IAM Authenticator for Kubernetes

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Amazon Elastic Kubernetes Service (EKS) uses IAM to provide authentication to the cluster through the AWS IAM Authenticator for Kubernetes (aws-iam-authenticator). Multiple issues were identified in the authenticator that could have allowed exploitation, namely (1) a lax regular expression used to verify presigned URLs; (2) HTTP client redirect follow (due to using Golang HTTP client in its default configuration); (3) use of the Golang URL.Query function (which silently drops parameters that Go…

Cloud Security
P0
2020-10-01 00:00 UTC
Other

Google Cloud Shell XSS to RCE Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Google Cloud Shell allowed escalation from XSS to full instance takeover as root. The attack exploited an XSS in the markdown preview functionality to read sensitive files, obtain the instance's private key and hostname, and gain SSH access as root. The issue affected the Eclipse Theia-based editor used in Cloud Shell.

Cloud SecurityVulnerabilities
P15
2020-09-28 00:00 UTC
Other

Encryption SDK vulnerabilities

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS KMS and all versions of AWS Encryption SDKs prior to version 2.0.0 were susceptible to information leakage (an attacker could create ciphertexts that would leak the user’s AWS account ID, encryption context, user agent, and IP address upon decryption), ciphertext forgery (an attacker could create ciphertexts that were accepted by other users) and lack of robustness (an attacker could create ciphertexts that decrypt to different plaintexts for different users).

Cloud Security
P0
2020-09-28 00:00 UTC
Other

S3 bucket tagging not restricted

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Lack of the privilege s3:PutBucketTagging did not restrict the ability to tag S3 buckets.

P0
2020-09-25 00:00 UTC
Other

CloudFormer review

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An audit of an AWS open-source project identified a great deal of issues, and as a result AWS made the decision to take it down.

Cloud Security
P0
2020-09-22 00:00 UTC
Other

CloudFormation resource provider credentials leak

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

CloudFormation allows the use of Lambda-backed resource providers, wherein Lambda can be used to write custom provisioning logic to be executed during CloudFormation stack operations. The aforementioned Lambda functions were executed in an AWS-managed account (thus effectively allowing arbitrary code execution in that account), and were passed a set of credentials ("platformCredentials") for a role in this account that had several EventBridge permissions. These were sufficient for an attacker t…

Cloud SecurityData Breaches
P0
2020-09-10 13:46 UTC
Other

Lock Like a Pro

Group-IB · indexed 2026-09-07 17:30 UTC

Dive in Recent ProLock's Big Game Hunting

P0
2020-08-26 00:00 UTC
Other

GCP service accounts and projects information leak

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

It was possible to list IAM service accounts of any GCP project, given only its ID, by forging a pageToken for the projects.serviceAccounts.list method of the IAM API. Due to the design of certain services in GCP, this issue could lead to exposure of sensitive information related to a project, and could be further used to enumerate unsecured resources in the platform, such as App Engine apps, Container Registry repositories, etc.

P0
2020-08-20 00:00 UTC
Security Journalism

Hiding in Plain Sight: Part 2

Huntress · indexed 2026-09-07 17:30 UTC

As a follow-up to our previous post, we recently uncovered a really peculiar piece of malware that works through a lot of different layers of abstraction.

Malware
P0
2020-08-18 00:00 UTC
Other

Dropping a Shell in Google Cloud SQL

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Researchers discovered vulnerabilities in Google Cloud SQL that allowed gaining unauthorized shell access to MySQL instances. By chaining SQL injection, parameter injection in mysqldump, and network spoofing, they were able to escape a Docker container and gain full access to the host VM running Cloud SQL.

Cloud SecuritySecurity Research
P0
2020-08-18 00:00 UTC
Other

Google Cloud Shell Bugs Expose User Credentials

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Three vulnerabilities in Google Cloud Shell were discovered, allowing attackers to execute arbitrary code and potentially steal user credentials. The bugs affected Ruby gemspec parsing, TypeScript plugin loading, and Go binary path manipulation in Cloud Run. These issues arose from mismatches between Cloud Shell's threat model and the assumptions of its underlying open-source components.

Cloud Security
P0
2020-07-27 00:00 UTC
Other

CloudTrail S3 data events leak bucket Account ID

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Using CloudTrail S3 data events, it was possible to determine the AWS account ID of any existing S3 bucket by calling any S3 API, getting denied, and looking at the value in the resource key in error message that showed up in CloudTrail.

Cloud Security
P0
2020-07-23 12:00 UTC
Government

The cyber threat to sports organisations

UK NCSC Threat Reports · indexed 2026-08-15 18:50 UTC

The NCSC report highlights the cyber threats faced by the sports sector and suggests how to stop or lessen their impact on organisations.

P0
2020-07-21 00:00 UTC
Security Journalism

Huntress Service: External Recon | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Read about the value of Huntress' External Recon service, which highlights open ports and services that are exposed to the Internet.

P0
2020-07-14 12:00 UTC
Government

Summary of the NCSC analysis of May 2020 US sanction

UK NCSC Threat Reports · indexed 2026-08-15 18:50 UTC

A summary of the NCSC’s analysis of the May 2020 US sanction which caused the NCSC to modify the scope of its security mitigation strategy for Huawei.

P0
2020-07-01 00:00 UTC
Other

XSS on EC2 web console

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Display of EC2 tags had XSS

P0
2020-06-22 00:00 UTC
Security Journalism

Evolving the Hunt: Removing Obstacles to Innovation

Huntress · indexed 2026-09-07 17:30 UTC

At Huntress, our goal is not only to chase after changing threats but to remove obstacles that get in the way of new security innovation.

P0
2020-06-18 00:00 UTC
Security Journalism

Hiding In Plain Sight | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

There’s no end to the stealthy ways in which attackers develop and execute their tradecraft. In this case, it's as simple as hiding in plain sight.

P0
2020-06-15 00:00 UTC
Other

GKE and EKS CAP_NET_RAW metadata service MITM root privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An attacker with access to a hostNetwork=true container with CAP_NET_RAW capability can listen to all the traffic going through the host and inject arbitrary traffic, allowing to tamper with most unencrypted traffic (HTTP, DNS, DHCP, ...), and disrupt encrypted traffic. In GKE the host queries the metadata service at http://169[.]254.169.254 to get information, including the authorized SSH keys. By manipulating the metadata service responses and injecting our own SSH key, it is possible to gain…

Vulnerabilities
P10
149 150 151 152 153