IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 605 matching records.
AUTO-POLL // 2026-10-10 04:05 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P15 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P15
P15
WARM // 1 ARTICLE
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2017-10-10 00:00 UTC
Other

AWS Java SDK XXE injection

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The AWS Java SDK was vulnerable to XML external entity (XXE) injection related to XML parsers.

Cloud Security
P0
2016-11-26 00:00 UTC
Other

Public admin access to Azure's Red Hat Update Infrastructure

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Full administrative access to the Azure Red Hat Enterprise Linux Appliance REST API was publicly exposed. It allowed malicious actors uploading packages that would be acquired by client virtual machines on their next yum update. The vulnerable infrastructure supplies all the packages for all Red Hat Enterprise Linux instances booted from the Azure marketplace.

Cloud SecurityLinux
P0
2016-11-16 00:00 UTC
Other

3rd party vendor confused deputy via AssumeRole

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

3rd party vendors can (and sometimes do) incorrectly implement sts:ExternalId in their AWS role trust policies, leading to confused deputy issues. These misconfigurations could allow customers to access other customers' data. Although vendors are responsible for ensuring their own configurations are correct, AWS could theoretically add mitigations to prevent and detect this issue.

Cloud Security
P0
2008-12-18 00:00 UTC
Other

Signature version 1 (SigV1) is insecure

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

When making authenticated API requests to AWS, the requests must be signed with your AWS access key. The initial signing algorithm, SigV1, was vulnerable to collisions. A person-in-the-middle attack would be able to modify signed requests via specially constructed collisions.

Cloud Security
P0
19 20 21