IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 605 matching records.
AUTO-POLL // 2026-10-10 00:35 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10
NO DATA
--
NO INTEL
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-08-26 19:32 UTC
Vendor Research

ICYMI: July 2026 @AWS Security

AWS Security Blog · Rodolfo Brenes · indexed 2026-08-26 19:40 UTC

If you found time for a bit of vacation this summer, you might be in catch-up mode. Here’s a list to help: all the expert blog posts, new service capabilities, code samples, and workshops, in case you missed it, from July 2026. AWS Security Blog post This month’s AWS Security Blog posts covered AI agent […]

AI SecurityCloud Security
P0
2026-08-26 17:39 UTC
Vendor Research

Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation

AWS Security Blog · Nisha Kashyap · indexed 2026-08-26 18:00 UTC

A single alert from one security service tells you something happened. Read that signal alongside activity from other services and your own business context, and you will know whether what happened is part of a multi-stage attack. Consider a short sequence. An identity calls GetCallerIdentity from a source address it hasn’t previously used. Within minutes, […]

Cloud Security
P0
2026-08-26 11:55 UTC
Security Journalism

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 13:10 UTC

The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint of the mwEmbed player

Cloud SecurityVulnerabilitiesCVE-2026-19912CVE-2026-19913
P5
2026-08-25 21:53 UTC
Vendor Research

Fast Track ISM-ready cloud environments and IRAP Assessments with Landing Zone Accelerator on AWS

AWS Security Blog · Kevin Donohue · indexed 2026-08-25 21:55 UTC

This post announces the availability of a new independent assessment report available on AWS Artifact analyzing how Landing Zone Accelerator on AWS (LZA) can automatically deploy multi-account environments in Amazon Web Services (AWS) with Australian Government Information Security Manual (ISM) security controls coverage at scale. The report includes findings from an independent third-party analysis conducted […]

Cloud Security
P0
2026-08-25 08:34 UTC
Security Journalism

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 09:40 UTC

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by Patchstack, are listed below - CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation

Cloud SecurityVulnerabilitiesCVE-2026-61979
P15
2026-08-24 07:23 UTC
Other

TikTok Settles U.S. Child Privacy Case for $400 Million

Security Affairs · Pierluigi Paganini · indexed 2026-08-24 07:35 UTC

TikTok will pay $400 million to settle U.S. claims that it violated child privacy laws by collecting data from users under 13. The U.S. Department of Justice announced that TikTok will pay $400 million to settle a 2024 lawsuit over children’s privacy. “Today, the Department of Justice announced a $400 million settlement with TikTok, ByteDance, […]

Cloud SecurityLaw Enforcement
P0
2026-08-22 14:32 UTC
Security Journalism

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-22 15:15 UTC

The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country. As part of the settlement, the social media platform will pay $300 million immediately, and an additional $100 million "upon entry of an order vacating a prior consent decree entered against

Cloud SecurityLaw Enforcement
P0
2026-08-21 12:30 UTC
Other

Six Maximum-Severity Flaws Found in Cisco Products

Security Affairs · Pierluigi Paganini · indexed 2026-08-21 12:40 UTC

Cisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited. Cisco released another batch of security fixes for its Crosswork platforms and Secure Workload software, part of what it’s calling an ongoing internal security review, and the CVSS scores in this round are unusually severe. […]

Cloud SecurityVulnerabilities
P10
2026-08-21 12:25 UTC
Security Journalism

CISA orders feds to patch actively exploited TrueConf Server flaws

BleepingComputer · Sergiu Gatlan · indexed 2026-08-21 12:35 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. [...]

Cloud Security
P25
2026-08-21 10:03 UTC
Security Journalism

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-21 11:25 UTC

Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below -

Cloud SecurityVulnerabilities
P5
2026-08-21 08:22 UTC
Other

U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-21 09:40 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: TrueConf Server is an on-premises video conferencing and unified communications platform developed by TrueConf. Organizations can deploy it on their […]

Cloud Security
P30
2026-08-20 21:35 UTC
Vendor Research

Issue with AWS-LC: an open-source, general-purpose cryptographic library (CVE-2026-3336, CVE-2026-3337, CVE-2026-3338)

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-005-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/03/02 14:30 PM PST Description: AWS-LC is an open-source, general-purpose cryptographic library. We identified three distinct issues: - CVE-2026-3336: PKCS7_verify Certificate Chain Validation Bypass in AWS-LC Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers,…

Cloud SecurityVulnerabilitiesCVE-2026-3336CVE-2026-3337CVE-2026-3338
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-1386 - Arbitrary Host File Overwrite via Symlink in Firecracker Jailer

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-003-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/01/23 12:30 PM PST Description: Firecracker is an open source virtualization technology that is purpose-built for creating and managing secure, multi-tenant container and function-based services. Firecracker runs in user space and uses the Linux Kernel-based Virtual Machine (KVM) to create microVMs. Each Firecracker microVM is further isolated with common Linux user-space security barriers b…

Cloud SecurityLinuxVulnerabilitiesCVE-2026-1386
P5
2026-08-20 21:35 UTC
Vendor Research

Arbitrary code execution via crafted project files in Kiro IDE

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-009-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/03/17 12:15 PM PDT Description: Kiro is an AI-powered IDE for agentic software development. We identified CVE-2026-4295, where improper trust boundary enforcement allowed arbitrary code execution when a user opened a maliciously crafted project directory. Impacted versions: < 0.8.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security…

Cloud SecurityVulnerabilitiesCVE-2026-4295
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-4270 - AWS API MCP File Access Restriction Bypass

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-007-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/03/16 09:15 AM PDT Description: The AWS API MCP Server is an open source Model Context Protocol (MCP) server that enables AI assistants to interact with AWS services and resources through AWS CLI commands. It provides programmatic access to manage your AWS infrastructure while maintaining proper security controls. This server acts as a bridge between AI assistants and AWS services, allowing …

Cloud SecurityVulnerabilitiesCVE-2026-4270
P5
2026-08-20 21:35 UTC
Vendor Research

Security Findings in SageMaker Python SDK

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-004-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/02/02 14:30 PM PST Description: CVE-2026-1777 - Exposed HMAC in SageMaker Python SDK SageMaker Python SDK’s remote functions feature uses a per‑job HMAC key to protect the integrity of serialized functions, arguments, and results stored in S3. We identified an issue where the HMAC secret key is stored in environment variables and disclosed via the DescribeTrainingJob API. This allows third p…

Cloud SecurityVulnerabilitiesCVE-2026-1777CVE-2026-1778
P5
2026-08-20 21:35 UTC
Vendor Research

Unanchored ACCOUNT_ID webhook filters for CodeBuild

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-002-AWS Scope: AWS Content Type: Informational Publication Date: 2026/01/15 07:03 AM PST Description: A security research team identified a configuration issue affecting the following AWS-managed open source GitHub repositories that could have resulted in the introduction of inappropriate code: - aws-sdk-js-v3 - aws-lc - amazon-corretto-crypto-provider - awslabs/open-data-registry Specifically, researchers identified the above repositories' configured regular expressions for A…

Cloud SecuritySecurity Research
P0
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-0830 - Command Injection in Kiro GitLab Merge Request Helper

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-001-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/01/09 13:15 PM PST Description: Kiro is an agentic IDE users install on their desktop. We identified CVE-2026-0830 where opening a maliciously crafted workspace may lead to arbitrary command injection in Kiro IDE before Kiro version 0.6.18. This may occur if the workspace has specially crafted folder names within the workspace containing injected commands. Resolution: Kiro IDE

Cloud SecurityVulnerabilitiesCVE-2026-0830
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-4269 - Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-008-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/03/16 11:15 AM PDT Description: A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. Impacted versions: All versions of Bedrock AgentCore Starter Toolkit versions before v0.1.13. This issue only affects users of the Bedrock Agent…

Cloud SecurityVulnerabilitiesCVE-2026-4269
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-4428: Issues with AWS-LC - CRL Distribution Point Scope Check Logic Error

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-010-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/03/19 13:30 PM PDT Description: AWS-LC is a general-purpose cryptographic library maintained by AWS. We identified CVE-2026-4428 affecting X.509 certificate verification. A logic error in the CRL (Certificate Revocation List) distribution point matching in AWS-LC allows a revoked certificate to bypass revocation checks during certificate validation, when the application enables CRL checking …

Cloud SecurityVulnerabilitiesCVE-2026-4428
P5
2026-08-20 21:35 UTC
Vendor Research

Issues in tough library and tuftool CLI utility

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-019-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/24 13:30 AM PDT Description: Multiple security issues have been identified in the tough library and tuftool CLI utility. tough is a Rust library used for generating, signing, and managing TUF (The Update Framework) repositories, and tuftool is the command-line interface for repository management Operations. The following issues have been identified: - CVE-2026-6966 - CVE-2026-6967 - CVE-2…

Cloud SecurityVulnerabilitiesCVE-2026-6966CVE-2026-6967CVE-2026-6968
P5
2026-08-20 21:35 UTC
Vendor Research

MariaDB Server Audit Plugin Comment Handling Bypass

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-006-AWS Scope: AWS Content Type: Informational Publication Date: 2026/03/03 10:15 AM PST Description: Amazon RDS/Aurora is a managed relational database service. We identified CVE-2026-3494. In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (‐‐) or hash (#) style comment…

Cloud SecurityVulnerabilitiesCVE-2026-3494
P5
2026-08-20 18:40 UTC
Vendor Research

AWS Network Firewall now supports rule hit count

AWS Security Blog · Preetkumar Shah · indexed 2026-08-20 18:45 UTC

As firewall rule sets grow in complexity, security teams face a common challenge: manual log analysis is used to determine which rules are actively matching traffic and which are consuming capacity without being triggered. This lack of visibility creates operational and compliance gaps. Organizations with governance policies that require removal of dormant rules after a […]

Cloud SecurityNetwork Security
P0
2026-08-20 13:35 UTC
Security Journalism

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 14:30 UTC

Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess

Cloud SecurityVulnerabilities
P10
2026-08-20 11:05 UTC
Security Journalism

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 11:15 UTC

Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrument command bus. The chain, tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 on the CVSS v3.1 scoring system, impacts AIT-GUI

Cloud SecuritySecurity ResearchVulnerabilities
P0
2026-08-19 11:34 UTC
Security Journalism

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 13:35 UTC

Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed working directory containing 2,616 files

Cloud SecuritySecurity Research
P0
2026-08-19 11:01 UTC
Security Journalism

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 11:35 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting Apple macOS that could allow an

AppleCloud SecurityMicrosoftVulnerabilitiesCVE-2026-65400
P55
8 9 10 11 12