IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 605 matching records.
AUTO-POLL // 2026-10-10 04:05 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P15 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P15
P15
WARM // 1 ARTICLE
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2021-04-30 00:00 UTC
Other

Password Reset Code Brute-Force Vulnerability in AWS Cognito

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in AWS Cognito's password reset function allowed attackers to brute-force the six-digit reset code, potentially leading to account takeovers. Using concurrent HTTP requests, an attacker could make up to 1587 guesses instead of the documented limit of 20. The issue affected accounts without multi-factor authentication and was fixed by AWS on April 20, 2021.

Cloud SecurityVulnerabilities
P0
2021-03-10 00:00 UTC
Other

AWS CloudShell terminal escape

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

If attacker controlled data is viewed in Cloudshell it could have led to code execution. This exact same issue existed in Azure previously.

Cloud Security
P0
2021-03-09 00:00 UTC
Other

Azure Linux VM extension credential leak

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in the Azure Linux VM extension mechanism allowed an unprivileged user to leak any Azure VM extension’s private data. An attacker could have abused this to gain credentials for the VM itself as well as credentials for extensions associated with the VM. Paired with the design of the VMAccess extension (an official Azure extension for managing VM credentials), this could have been used to achieve privilege escalation, as an unprivileged attacker would have been able to elevate the…

Cloud SecurityLinuxVulnerabilities
P10
2021-02-15 00:00 UTC
Other

Azure Cloud Shell and Container Instances breakout

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An attacker could gain root privileges on their Azure Cloud Shell container, escape from the container, and then gain root privileges on the underlying node, the root cause being an insecure kubelet port (10250), among other cluster misconfigurations. Once they could access the node filesystem, an attacker could extract kubelet API credentials which allowed listing all pods and nodes in the cluster, including those belonging to other tenants. Moreover, an attacker could bypass RBAC policies in …

Cloud Security
P0
2020-12-20 00:00 UTC
Other

AWS SOC 2 type 2 failure (Fall 2020)

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Information about this issue is under NDA, but AWS customers can read about it on pages 120-121 of the report, which is available for download through AWS Artifact. Note: This issue is outside the scope of this database's usual criteria for inclusion, but has been kept for historic reasons, as it was included in the original CSP Security Mistakes dataset.

Cloud Security
P0
2020-11-12 00:00 UTC
Other

SSRF in Google Cloud Monitoring

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An SSRF bug in Google Cloud Monitoring's uptime check feature could have been used to leak the authentication token of the service account used for these checks. The issue was resolved but later bypassed by Omar Espino (@omespino), requiring another fix.

Cloud Security
P0
2020-10-19 00:00 UTC
Other

Route table modification to imitate metadata service

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An attacker with sufficient privileges in AWS to modify the route table and some other EC2 privileges, could pretend to be a metadata server and provide an attacker controlled bootup script to EC2s to move laterally.

Cloud Security
P0
2020-10-15 00:00 UTC
Other

Lack of internal change controls for IAM managed policies

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS have released or changed managed IAM policies in unexpected and insecure ways. Examples include: CheesepuffsServiceRolePolicy, AWSServiceRoleForThorInternalDevPolicy, AWSCodeArtifactReadOnlyAccess.json, AmazonCirrusGammaRoleForInstaller. The worst being the ReadOnlyAccess policy having almost all privileges removed and unexpected ones added.

Cloud Security
P0
2020-10-06 00:00 UTC
Other

Multiple issues in AWS IAM Authenticator for Kubernetes

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Amazon Elastic Kubernetes Service (EKS) uses IAM to provide authentication to the cluster through the AWS IAM Authenticator for Kubernetes (aws-iam-authenticator). Multiple issues were identified in the authenticator that could have allowed exploitation, namely (1) a lax regular expression used to verify presigned URLs; (2) HTTP client redirect follow (due to using Golang HTTP client in its default configuration); (3) use of the Golang URL.Query function (which silently drops parameters that Go…

Cloud Security
P0
2020-10-01 00:00 UTC
Other

Google Cloud Shell XSS to RCE Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Google Cloud Shell allowed escalation from XSS to full instance takeover as root. The attack exploited an XSS in the markdown preview functionality to read sensitive files, obtain the instance's private key and hostname, and gain SSH access as root. The issue affected the Eclipse Theia-based editor used in Cloud Shell.

Cloud SecurityVulnerabilities
P15
2020-09-28 00:00 UTC
Other

Encryption SDK vulnerabilities

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS KMS and all versions of AWS Encryption SDKs prior to version 2.0.0 were susceptible to information leakage (an attacker could create ciphertexts that would leak the user’s AWS account ID, encryption context, user agent, and IP address upon decryption), ciphertext forgery (an attacker could create ciphertexts that were accepted by other users) and lack of robustness (an attacker could create ciphertexts that decrypt to different plaintexts for different users).

Cloud Security
P0
2020-09-25 00:00 UTC
Other

CloudFormer review

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An audit of an AWS open-source project identified a great deal of issues, and as a result AWS made the decision to take it down.

Cloud Security
P0
2020-09-22 00:00 UTC
Other

CloudFormation resource provider credentials leak

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

CloudFormation allows the use of Lambda-backed resource providers, wherein Lambda can be used to write custom provisioning logic to be executed during CloudFormation stack operations. The aforementioned Lambda functions were executed in an AWS-managed account (thus effectively allowing arbitrary code execution in that account), and were passed a set of credentials ("platformCredentials") for a role in this account that had several EventBridge permissions. These were sufficient for an attacker t…

Cloud SecurityData Breaches
P0
2020-08-18 00:00 UTC
Other

Dropping a Shell in Google Cloud SQL

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Researchers discovered vulnerabilities in Google Cloud SQL that allowed gaining unauthorized shell access to MySQL instances. By chaining SQL injection, parameter injection in mysqldump, and network spoofing, they were able to escape a Docker container and gain full access to the host VM running Cloud SQL.

Cloud SecuritySecurity Research
P0
2020-08-18 00:00 UTC
Other

Google Cloud Shell Bugs Expose User Credentials

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Three vulnerabilities in Google Cloud Shell were discovered, allowing attackers to execute arbitrary code and potentially steal user credentials. The bugs affected Ruby gemspec parsing, TypeScript plugin loading, and Go binary path manipulation in Cloud Run. These issues arose from mismatches between Cloud Shell's threat model and the assumptions of its underlying open-source components.

Cloud Security
P0
2020-07-27 00:00 UTC
Other

CloudTrail S3 data events leak bucket Account ID

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Using CloudTrail S3 data events, it was possible to determine the AWS account ID of any existing S3 bucket by calling any S3 API, getting denied, and looking at the value in the resource key in error message that showed up in CloudTrail.

Cloud Security
P0
2020-04-23 00:00 UTC
Other

GuardDuty detection bypass via cloudtrail

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

GuardDuty detected CloudTrail being outright disabled, but did not detect if an attacker with the necessary permissions filtered out all events from CloudTrail via PutEventSelectors, resulting in defenders having no logs to review. AWS fixed this issue by adding a GuardDuty detection that triggers if PutEventSelectors is used to disable all event types.

Cloud SecurityMicrosoft
P0
2020-03-11 00:00 UTC
Other

GCP Cloudshell Cross-Site WebSocket Hijacking (CSWSH)

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Google Cloudshell leveraged websockets without validating that the origin matched the current instance host. An attacker could therefore host a CSWSH attack on a Cloudshell instance they own, disabling authentication via access to the underlying VM. They could then start the OAuth process with a spoofed host header, using phishing to get the target Cloud Shell user into following a redirection link, completing the OAuth process and ending in successful CSWSH, which would allow the attacker to h…

Cloud SecurityPhishing
P0
2020-01-30 00:00 UTC
Other

Azure App Service RCE

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A Vulnerability in App Service could allow an unprivileged function run by the user to execute code in the context of NT AUTHORITY\system, thereby escaping the sandbox. This vulnerability allowed cross-account access when using the Free/Shared tier.

Cloud SecurityVulnerabilities
P15
2020-01-23 00:00 UTC
Other

AWS uploaded sensitive data to public GitHub bucket

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An AWS employee pushed sensitive data to a public github bucket, including customer information and credentials. Note: This issue is outside the scope of this database's usual criteria for inclusion, but has been kept for historic reasons, as it was included in the original CSP Security Mistakes dataset.

Cloud Security
P0
2019-11-29 00:00 UTC
Other

Google Cloud Platform VRP Prize Writeup

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability was discovered in Google Cloud Platform's AI Hub service, allowing unrestricted file uploads. This could potentially lead to bypassing Same-Origin Policy by uploading SWF files, enabling CSRF attacks across browsers, and exploiting CVE-2014-8453 on IE with Adobe Reader installed. The issue resulted in a $1337 bounty reward.

Cloud SecurityVulnerabilitiesCVE-2014-8453
P5
2019-08-15 00:00 UTC
Other

Lake Formation data lake admin override

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Shortly after Lake Formation was made generally available, a bug was discovered that gave anyone the ability to view and override data lake admins for any account (an attacker would have only needed to know the target account number in advance). The root cause was in the Catalog ID, which references the Glue metadata store that Lake Formation uses to store its configuration - none of the methods that used this field actually checked for permissions on the account it was accessing, only the sour…

Cloud Security
P0
2019-06-18 00:00 UTC
Other

IAM privilege escalation via undocumented CodeStar API

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The AWS CodeStar service had an undocumented API (codestar:CreateProjectFromTemplate) that allowed users with broadly-scoped CodeStar permissions to create a CodeStar project. As part of the creation process, AWS would create a new CodeStarWorker IAM policy & attach it to the user making the call. This policy granted full access to over 50 AWS services, including iam:AttachRolePolicy, iam:AttachUserPolicy and iam:PutRolePolicy permissions, which would allow the user to escalate to full administ…

Cloud SecurityVulnerabilities
P10
2019-01-09 00:00 UTC
Other

Azure Cloud Shell terminal escape

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

If attacker controlled data is viewed in Cloudshell it could have led to code execution. This exact same issue was later discovered in AWS as well.

Cloud Security
P0
2017-11-07 00:00 UTC
Other

Bypassable and overly-privileged IAM policies

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS has previously provided managed policies or guidance in documentation for policies with mistakes that allow them to be bypassed. Additionally, some policies are over-privileged. Date of disclosure is for the first issue of this type, while references provide other examples by various individuals.

Cloud Security
P0
18 19 20 21