IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,633 matching records.
AUTO-POLL // 2026-10-07 21:55 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7

RANSOMWARE
P5
P5
COOL // 80 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2020-04-23 00:00 UTC
Other

GuardDuty detection bypass via cloudtrail

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

GuardDuty detected CloudTrail being outright disabled, but did not detect if an attacker with the necessary permissions filtered out all events from CloudTrail via PutEventSelectors, resulting in defenders having no logs to review. AWS fixed this issue by adding a GuardDuty detection that triggers if PutEventSelectors is used to disable all event types.

Cloud SecurityMicrosoft
P0
2020-03-11 00:00 UTC
Other

GCP Cloudshell Cross-Site WebSocket Hijacking (CSWSH)

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Google Cloudshell leveraged websockets without validating that the origin matched the current instance host. An attacker could therefore host a CSWSH attack on a Cloudshell instance they own, disabling authentication via access to the underlying VM. They could then start the OAuth process with a spoofed host header, using phishing to get the target Cloud Shell user into following a redirection link, completing the OAuth process and ending in successful CSWSH, which would allow the attacker to h…

Cloud SecurityPhishing
P0
2020-03-08 00:00 UTC
Other

Google wide domain check bypass

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Google's common JavaScript library allowed bypassing domain validation checks across multiple Google products. By using a backslash character in URLs, an attacker could make the regex parser and browser disagree on the authority (domain) portion of a URL, allowing injection of arbitrary domains that pass whitelisting checks.

Vulnerabilities
P0
2020-01-30 00:00 UTC
Other

Azure App Service RCE

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A Vulnerability in App Service could allow an unprivileged function run by the user to execute code in the context of NT AUTHORITY\system, thereby escaping the sandbox. This vulnerability allowed cross-account access when using the Free/Shared tier.

Cloud SecurityVulnerabilities
P15
2020-01-23 00:00 UTC
Other

AWS uploaded sensitive data to public GitHub bucket

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An AWS employee pushed sensitive data to a public github bucket, including customer information and credentials. Note: This issue is outside the scope of this database's usual criteria for inclusion, but has been kept for historic reasons, as it was included in the original CSP Security Mistakes dataset.

Cloud Security
P0
2020-01-12 00:00 UTC
Other

GCP Speech to Text Information Disclosure

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

GCP's Speech-to-Text "operations/list" and "operations/get" APIs would return data that did not belong to the caller when no parameters were provided. It is unclear whether this was cross-customer data disclosure, or potentially test or internal data.

P0
2019-12-19 00:00 UTC
Other

GCP Stackdriver Debugger SSRF

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An SSRF bug in GCP's Stackdriver Debugger feature's code import could have been used to leak the authentication token of the user to an attacker-controlled server. Exploitation would require that the user had previously configured a specific code hosting service (such as GitHub), and could be tricked into clicking a malicious link.

P0
2019-12-16 00:00 UTC
Other

GCP Cloudshell Vulnerabilities

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Wouter ter Maat discovered 9 vulnerabilities in GCP Cloudshell that could allow an attacker to access resources in another customer's environment.

P0
2019-12-15 00:00 UTC
Other

GCP Cloudshell XSS and CSRF bugs

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

GCP Cloudshell has been affected by various XSS and CSRF vulnerabilities stemming from different root causes related to authentication handling, markdown editing, file uploading and more. Explotiation of these vulnerabilities normally requires user interaction through social engineering (convincing a potential victim to click a malicious link).

P0
2019-11-29 00:00 UTC
Other

Google Cloud Platform VRP Prize Writeup

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability was discovered in Google Cloud Platform's AI Hub service, allowing unrestricted file uploads. This could potentially lead to bypassing Same-Origin Policy by uploading SWF files, enabling CSRF attacks across browsers, and exploiting CVE-2014-8453 on IE with Adobe Reader installed. The issue resulted in a $1337 bounty reward.

Cloud SecurityVulnerabilitiesCVE-2014-8453
P5
2019-11-18 14:41 UTC
Other

Group-IB unveils its Graph

Group-IB · indexed 2026-09-07 17:30 UTC

The story about Group-IB searching for graph analysis solution and creating its own unique instrument

P0
2019-11-15 00:00 UTC
Security Journalism

Assisted Remediation in Action | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Learn how Huntress helped an MSP partner contain and remediate an Emotet/TrickBot infection with Assisted Remediation.

P0
2019-10-04 13:23 UTC
Other

No Time to Waste

Group-IB · indexed 2026-09-07 17:30 UTC

How Windows 10 Timeline Can Help Forensic Experts

Microsoft
P0
150 151 152 153 154