IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 605 matching records.
AUTO-POLL // 2026-10-10 02:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P15 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P15
P15
WARM // 1 ARTICLE
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2023-06-21 00:00 UTC
Other

Critical Authentication Bypass in Google Cloud API Gateway

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A critical authentication bypass vulnerability was discovered in Google Cloud API Gateway, affecting its JWT authentication method. The flaw, stemming from a business logic bug in the ESPv2 service proxy, allowed attackers to bypass authentication controls by manipulating HTTP methods. This vulnerability impacted various authentication methods including Firebase, Auth0, Okta, and Google ID tokens.

Cloud SecurityVulnerabilities
P10
2023-06-20 00:00 UTC
Other

nOAuth

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Descope identified a possible misconfiguration in Azure AD which could lead to misuse of the "Log in with Microsoft" authentication method on a web app. If an application relies on email attribute claims for authentication (which is against best practice) and also merges user accounts without proper validation, an attacker could falsify an email claim to gain full control over the target account. Descope and Microsoft Microsoft identified several popular multi-tenant applications with users tha…

Cloud SecurityMicrosoft
P0
2023-06-14 00:00 UTC
Other

XSS in Azure Bastion and Container Registry

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Orca discovered vulnerabilities in Azure Bastion and Azure Container Registry that could have enabled an attacker to achieve Cross-Site Scripting (XSS) by using iframe postMessages. The vulnerabilities allowed embedding of endpoints within remote attacker-controlled servers using the iframe tag, thereby granting unauthorized access to the victim’s session in the affected service if they were tricked into navigating to an attacker-controlled website. The root cause was that certain web pages in …

Cloud Security
P0
2023-06-13 00:00 UTC
Other

Bucket Traversal in Google Cloud Storage Transfer Manager

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A bucket traversal vulnerability was discovered in the google.cloud.storage.transfer_manager.upload_chunks_concurrently() function of Google Cloud Storage. This issue could potentially allow unauthorized access to files in different buckets or directories within the same project.

Cloud SecurityVulnerabilities
P0
2023-06-12 00:00 UTC
Other

Azure App Services takeover via legacy API

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Binary Security found two vulnerabilities in the legacy Azure Resource Manager (ARM) REST API. The first vulnerability allowed an attacker with Reader access to an Azure Function, acting from a Windows host, to get an admin token that could be exchanged for a master key granting access to all operations in Kudu (the Functions deployment service). This would allow them to tamper with the function by deploying malicious code to it. The other vulnerability allowed an attacker with Reader access to…

Cloud SecurityMicrosoftVulnerabilities
P0
2023-06-07 00:00 UTC
Other

AWS Directory Service not checking PassRole on EnableRoleAccess

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS Directory Service didn't check the iam:PassRole permissions when using the EnableRoleAccess action. This could have been used for privilege escalation by an authenticated user with sufficient permissions (ds:EnableRoleAccess), if the role had a trust policy that allowed use by Directory Service.

Cloud SecurityVulnerabilities
P10
2023-05-18 00:00 UTC
Other

GuardDuty bypass via S3 permission modification

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Threat actors in possession of IAM active credentials that had the power to update S3 bucket policies could have bypassed GuardDuty’s S3 detections and silently updated permissions for S3 resources, resulting in a bucket configuration that allowed anonymous data access. This gap in GuardDuty’s alert coverage occurred only when S3’s Block Public Access was not enabled on the account or the bucket, and when KMS-based server-side bucket encryption was not in use. In order to trigger on opening pub…

Cloud SecurityThreat Actors
P0
2023-05-04 00:00 UTC
Other

API Management SSRF and path traversal vulnerabilities

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure API Management is an API gateway service meant to help organizations to create, manage, secure, and monitor APIs across all of their environments. Researchers found three high severity vulnerabilities in the service, two of which are SSRF (Server Side Request Forgery) vulnerabilities, and the third is a path traversal bug. The SSRF issues affected the Azure API Management CORS proxy (which handles schema retrieval) and hosting proxy (which routes API requests to the correct server). An at…

Cloud SecurityVulnerabilities
P0
2023-04-25 00:00 UTC
Other

MFA enforcement IAM policy bypass

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An AWS-recommended IAM policy that enforced MFA on access keys could have been bypassed due to a change implemented by AWS in November 2022 that allowed IAM users to assign multiple MFA devices to their account. Prior to this change, an attacker that had compromised credentials could not create and assign a new MFA device to bypass the MFA requirement as they would need to first deactivate the user’s existing MFA device. Organisations using SSO which enforces MFA, either via an external IdP or …

Cloud Security
P0
2023-04-19 00:00 UTC
Other

Asset Key Thief

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Asset Key Thief was a Google Cloud privilege escalation vulnerability that enabled principals with the "Cloud Asset Viewer" role (or other roles with the `cloudasset.assets.searchAllResources` permission) on the Cloud Asset Inventory API, at the Project, Folder, or Organization level to view and exfiltrate any user-managed Service Account private key under a project within the same Google Cloud environment that had been created or rotated up to a maximum of 12 hours ago. Access to Service Accou…

Cloud SecurityVulnerabilities
P10
2023-03-30 00:00 UTC
Other

Azure on-premises data gateway cross-tenant access

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure on-premises data gateway allows data transfer between an on-prem customer network and several Azure cloud services, and also enables a connected agent installed locally in an on-prem network to perform certain actions remotely. NetSPI discovered a deserialization issue in Microsoft Power Platform connectors that lead to RCE on several Azure backend servers that processed call backs from on-premises data gateways, effectively allowing unauthorized cross-tenant access.

Cloud SecurityMicrosoftVulnerabilities
P15
2023-03-30 00:00 UTC
Other

RCE vulnerability in Azure Pipelines

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Legit Security found an RCE vulnerability in Azure Pipelines that could have allowed an attacker to gain complete control of variables and tasks by exploiting logging commands. This would have enabled them to execute malicious code in a context of a pipeline workflow, which would have granted them access to sensitive secrets such as cloud deployment keys, move laterally in the organization, and potentially initiate supply chain attacks. To exploit this vulnerability, an attacker would have need…

Cloud SecurityVulnerabilities
P15
2023-03-23 00:00 UTC
Other

Azure Function Apps privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Undocumented APIs used by the Azure Function Apps Portal could have allowed an attacker with existing access to a Reader role on a Function App to escalate their privileges and gain write permissions through arbitrary file reads on Function App containers. For Windows containers, this would only grant an attacker the ability to extract ASP.NET encryption keys (the impact of which remains unclear), but for Linux containers it would have allowed an attacker to read environmental variables contain…

Cloud SecurityLinuxMicrosoftVulnerabilities
P25
2023-03-20 00:00 UTC
Other

Partial CloudTrail logging in AWS Control Tower

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS Control Tower was not properly logging to CloudTrail when API calls failed due to a lack of permissions. This could have helped an adversary with existing access to a victim AWS environment avoid detection while enumerating privileges, since any unsuccessful API calls would not generate "access denied" log entries.

Cloud Security
P0
2023-03-19 00:00 UTC
Other

CloudTrail bypass for AWS Service Catalog

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Due to an exposed development endpoint, it was possible to bypass CloudTrail logging for both read and write API actions for the Service Catalog service. This could have enabled adversaries to alter Service Catalog resources undetected after gaining a foothold in a victim AWS environment.

Cloud Security
P0
2023-03-14 00:00 UTC
Other

Super FabriXss

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Service Fabric Explorer (SFX) was affected by an XSS vulnerability that could have allowed a malicious script to be reflected off a web application. After a potential victim clicked on a crafted malicious URL, the attacker could remotely toggle the ‘Cluster’ Event Type setting under the Events tab. This could lead to unauthenticated remote code execution on a container hosted on a Service Fabric node.

Cloud SecurityVulnerabilities
P15
2023-02-25 00:00 UTC
Other

AWS CodeBuild Token Leakage

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An attacker with elevated permissions in CodeBuild could leak the configured credentials for Github/Bitbucket. This was possible by configuring the http_proxy and https_proxy variables, which would allow you to capture the credentials via MITM.

Cloud Security
P0
2023-02-25 00:00 UTC
Other

Overprivileged CodeBuild default ECR IAM policy

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

For AWS CodeBuild, when using a custom container image stored in ECR and the project service role for the credentials to pull the image, the default IAM policy attached to the role to allow pulling the container was over-privileged and allowed the CodeBuild container to overwrite its own build image. An attacker with the ability to read the container credentials from the meta-data service or run commands within the container could thereby overwrite the container to gain persistence within the C…

Cloud Security
P0
2023-02-15 00:00 UTC
Other

Azure AD B2C cryptographic flaw allowing account compromise

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Active Directory B2C service (AD B2C) mistakenly implemented RSA key authentication using the public part of the key pair instead of the private one. This cryptographic flaw could have allowed an unauthenticated attacker to craft an OAuth refresh token for any AD B2C user account if they knew their public key. Moreover, every AD B2C user's public key was recoverable through an unrelated vulnerability (though asymmetric cryptography should not rely on public key secrecy regardless). An att…

Cloud SecurityVulnerabilities
P0
2023-02-14 00:00 UTC
Other

AWS EC2 Autoscaling Privilege Escalation Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A privilege escalation vulnerability in Amazon EC2 Autoscaling was identified. The CreateLaunchConfiguration action lacked PassRole validation, allowing users to launch EC2 instances with unauthorized roles. AWS fixed the issue for both CreateLaunchConfiguration and CreateAutoScalingGroup actions, implementing proper PassRole validation when using the instance-id option.

Cloud SecurityVulnerabilities
P10
2023-02-14 00:00 UTC
Other

Azure App Service on Azure Stack Hub privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A privilege escalation vulnerability was discovered in Azure App Service on Azure Stack Hub (an on-prem private cloud offering). To exploit this vulnerability, an attacker must have access to the targeted worker role and the ability to deploy a malicious application within the worker. The attack itself is carried out locally on the worker role where a malicious application has been deployed. Exploiting this vulnerability could grant an attacker the ability to access and modify content of a targ…

Cloud SecurityVulnerabilities
P10
2023-02-06 00:00 UTC
Other

AWS Console rate limit bypass

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS applies a rate limit to authentication requests made to the AWS Console in an effort to prevent brute-force and credential stuffing attacks. However, a weakness was discovered in the AWS Console authentication flow that allowed a partial bypass of this rate limit by pausing for 5 seconds every 30 attempts. This would enable an attacker to continuously attempt more than 280 passwords per minute (4.6 per second) against IAM users, which could have resulted in account compromise of users witho…

Cloud Security
P0
2023-01-19 00:00 UTC
Other

EmojiDeploy

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Multiple Azure Web services use a source control management (SCM) panel powered by Kudu and enabled by default. These services were all susceptible to a CSRF vulnerability due to an overly-permissive regular expression (regex) in a filter for malformed origins. This allowed origin bypass when using a domain name structured as 'victim.scm.azurewebsites.net._.attacker.com' (note the use of '._.', which looks like an emoji). Thus, if a target Azure user were tricked into visiting a specially craft…

Cloud SecurityVulnerabilities
P15
2023-01-18 00:00 UTC
Other

Azure AD Flaw Allowed SAML Token Persistence

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Azure Active Directory allowed users to retain access to SAML applications after their assignment was removed. Attackers could exploit this to establish persistence and elevate privileges on targeted SAML applications. The flaw was triggered by chaining sign-in with additional application and specific parameters in the token request, bypassing user assignment verification.

Cloud SecurityVulnerabilities
P0
2023-01-17 00:00 UTC
Other

AWS CloudTrail bypass for specific IAM actions

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Through an undocumented API service called 'iamadmin', attackers could invoke any of 13 read-only IAM actions without the activity being being logged to CloudTrail. These actions included listing group policies (iam:ListGroupPolicies), listing access keys (iam:ListAccessKeys), retrieving information about a role (iam:GetRole), and more. This could have enabled adversaries to perform enumeration and reconnaissance activity undetected after gaining a foothold in a victim AWS environment.

Cloud Security
P0
2023-01-17 00:00 UTC
Other

Multiple SSRF vulnerablities in Azure services

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

SSRF vulnerabilities were discovered in four Azure services: unauthenticated SSRF in Azure Digital Twins Explorer and Azure Functions, and authenticated SSRF in Azure API Management Service and Azure Machine Learning Service. All four vulnerabilities were full (non-blind) SSRF. The impact of these vulnerabilities was limited: while they would have allowed an adversary to scan local ports and find new services, endpoints, and files; they would not have allowed them to access metadata, connect to…

Cloud Security
P0
2023-01-15 00:00 UTC
Other

XSS in Google Cloud Theia notebooks

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

This vulnerability chain exploits a Cross-Site Scripting (XSS) flaw (CVE-2021-41038) within the Theia IDE used in Google Vertex AI Workbench. An attacker could inject malicious JavaScript code into the Theia IDE. This code could then be used to steal the OAuth token associated with the project's default Compute Engine service account, because when a user-managed Vertex AI Workbench instance is created, it utilizes the project's default Compute Engine service account. At the time, this default s…

Cloud SecurityVulnerabilitiesCVE-2021-41038
P5
2023-01-13 00:00 UTC
Other

Bypassing authorization in Google Cloud Workstations

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Several vulnerabilities were present in how Google Cloud Shell (ssh.cloud.google.com) handled OAuth credentials. These included an open-redirect vulnerability, where attackers could redirect users to malicious sites to capture their credentials, and a validation bypass that allowed tokens to be submitted to user-defined URIs, circumventing normal security checks. Additionally, Google Cloud Workstations did not correctly tie the state parameter to the session that generated it, which allowed val…

Cloud SecurityPhishingVulnerabilities
P0
2023-01-12 00:00 UTC
Other

Client-Side SSRF to Google Cloud Project Takeover

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Vertex AI Workbench allowed attackers to take over victims' Google Cloud projects through client-side SSRF. The initial bug involved unauthorized access to authentication tokens, which was later fixed. A bypass was later discovered (and also fixed) using open redirects in Feedburner and CSRF token manipulation.

Cloud SecurityVulnerabilities
P0
2023-01-12 00:00 UTC
Other

SSH key injection in Google Cloud Compute Engine

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Google Cloud Compute Engine (GCE) was vulnerable to SSH key injection by abusing an SSH-in-browser feature to change username and password. An attacker could send a specially-crafted link to a target user, and if the victim was logged into GCP and clicked the link, the attacker's SSH username and password would be added to the target machine, thereby allowing the attacker to log into it. This was possible because no random token or CSRF protection had been implemented for the abused feature. Fo…

Cloud Security
P0
15 16 17 18 19