IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,633 matching records.
AUTO-POLL // 2026-10-07 21:55 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7

RANSOMWARE
P5
P5
COOL // 80 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2019-10-04 00:00 UTC
Other

ALB HTTP request smuggling

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

ALBs found vulnerable to HTTP request smuggling (desync attack).

P0
2019-10-03 15:00 UTC
Security Journalism

Huntress Development Notes: Updating the Updater

Huntress · indexed 2026-09-07 17:30 UTC

If you’ve ever taken a look inside the Huntress Agent directory you may have noticed the file wyUpdate.exe.

P0
2019-08-31 00:00 UTC
Other

Google App Engine RCE Worth $36k

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Researcher discovered access to non-production Google App Engine environments and internal APIs. This allowed configuring internal settings like Service Account IDs and quotas. Google considered it RCE due to their infrastructure. Access was blocked and a $36,337 reward issued.

Vulnerabilities
P15
2019-08-15 00:00 UTC
Other

Lake Formation data lake admin override

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Shortly after Lake Formation was made generally available, a bug was discovered that gave anyone the ability to view and override data lake admins for any account (an attacker would have only needed to know the target account number in advance). The root cause was in the Catalog ID, which references the Glue metadata store that Lake Formation uses to store its configuration - none of the methods that used this field actually checked for permissions on the account it was accessing, only the sour…

Cloud Security
P0
2019-06-18 00:00 UTC
Other

IAM privilege escalation via undocumented CodeStar API

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The AWS CodeStar service had an undocumented API (codestar:CreateProjectFromTemplate) that allowed users with broadly-scoped CodeStar permissions to create a CodeStar project. As part of the creation process, AWS would create a new CodeStarWorker IAM policy & attach it to the user making the call. This policy granted full access to over 50 AWS services, including iam:AttachRolePolicy, iam:AttachUserPolicy and iam:PutRolePolicy permissions, which would allow the user to escalate to full administ…

Cloud SecurityVulnerabilities
P10
2019-06-04 16:00 UTC
Security Journalism

Keeping up with BlueKeep

Huntress · indexed 2026-09-07 17:30 UTC

Remote Desktop Services (RDS) benefit employees and IT administrators alike. With employees often working from anywhere, remote desktop reduces the physical burden of carrying a work laptop home 🏠. It also makes updating and managing systems easier, which can alleviate the administrative burden when handling a large network.

P0
2019-05-30 17:00 UTC
Security Journalism

Deep Dive: A LNK in the Chain

Huntress · indexed 2026-09-07 17:30 UTC

Read this blog to learn more about what the Huntress team discovered with LNK.

P0
2019-05-24 00:00 UTC
Other

VPC Hosted Zones unauditable

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

For 6 years, it was not possible to see what hosted zones an attacker may have created in an account. This issue could be viewed as a business decision that adding the ability to viewing this data was not worthwhile, but the delay is significant and would allow someone that had compromised an environment to maintain a backdoor.

Malware
P0
2019-05-16 17:00 UTC
Security Journalism

Incident Education: Sales Ammo for the IT Arsenal

Huntress · indexed 2026-09-07 17:30 UTC

As a technical founder of a product startup, I’m as anti-FUD as it gets. However, the past three years have taught me how education can be a snake-oil free alternative.

P0
2019-05-08 14:48 UTC
Other

Following the RTM

Group-IB · indexed 2026-09-07 17:30 UTC

Forensic examination of a computer infected with a banking trojan

Malware
P0
2019-04-26 14:58 UTC
Other

Meet the JS-Sniffers 4: CoffeMokko Family

Group-IB · indexed 2026-09-07 17:30 UTC

Group-IB researchers have discovered 38 families of JS-sniffers, whereas only 12 were known previously.

P0
2019-04-19 15:18 UTC
Other

Meet the JS-Sniffers 2: G-Analytics Family

Group-IB · indexed 2026-09-07 17:30 UTC

Group-IB discovered that the stolen payment cards data is sold through an underground store specially created for this purpose.

P0
2019-04-09 15:22 UTC
Other

Meet the JS-Sniffers: ReactGet Family

Group-IB · indexed 2026-09-07 17:30 UTC

ReactGet is one of the most interesting families of JS-sniffers, designed to steal banking cards data from online stores.

P0
2019-03-26 05:00 UTC
Security Journalism

Rapid Response: ASUS Live Update Attack (Operation ShadowHammer)

Huntress · indexed 2026-09-07 17:30 UTC

Periodically, a large scale cybersecurity issue requires “all hands on deck” from the Huntress Team (see WannaCry, Kaseya Cryptominer, GANDGRAB outbreak). The unfolding ASUS Live Update fiasco also happens to be one of those moments. We’ve created this blog is to provide simple answers to a complex supply chain attack affecting global IT Departments.

P0
2019-02-05 13:28 UTC
Other

The end of torrents era in Russia

Group-IB · indexed 2026-09-07 17:30 UTC

Currently, a total of 80% of pirated films and almost 90% of TV series are being watched online

P0
2019-01-20 00:00 UTC
Other

Impersonate GCP Organization Through the Organizations Update Method

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A GCP Organizations name could be changed through the (deprecated) organizations.update method in the Resource Manager, even though the documentation said the "displayName" was read-only. With this, I could have my own organization and name it as another one and confuse users: - Rename an organization ".com" - Share it with "domain:.com" (Effectively sharing it with every Google user with a @.com account) - Profit from unsuspecting users creating resources in my organization, specially billing …

P0
2019-01-09 00:00 UTC
Other

Azure Cloud Shell terminal escape

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

If attacker controlled data is viewed in Cloudshell it could have led to code execution. This exact same issue was later discovered in AWS as well.

Cloud Security
P0
2018-12-30 21:00 UTC
Security Journalism

Failing to Revive AUTOEXEC.BAT on Windows 7 & 10

Huntress · indexed 2026-09-07 17:30 UTC

Does AUTOEXEC.BAT still run on modern Windows? We test Windows 7/10, explore registry persistence, and revisit how attackers maintain access today.

Microsoft
P0
2018-11-28 00:00 UTC
Other

Resource policy confused deputy issue with services

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Resource policies lacked a way of restricting service access to only your own account, allowing an attacker to leverage a service to potentially access your resources. Originally discovered by Dan Peebles and presented at re:Invent in 2018, this issue did not gain enough attention to be fixed until Shir Tamari and Ami Luttwak from Wiz presented it at Black Hat 2021.

P0
2018-08-16 20:00 UTC
Security Journalism

Attackers Abuse Trust with Indirection

Huntress · indexed 2026-09-07 17:30 UTC

Preventive security products like antivirus have made major strides in their ability to detect malicious behaviors as opposed to weak/static signatures. When implemented properly, these heuristics are capable of discovering even the most cleverly obfuscated routines. But don’t ring the victory bells yet. This cat-and-mouse game is just getting started…

P0
151 152 153 154 155