IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 605 matching records.
AUTO-POLL // 2026-10-09 22:15 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 62 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-09-24 06:32 UTC
Security Journalism

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 08:35 UTC

Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses. "The campaign compromised 7 accounts –

Cloud SecurityMicrosoftSecurity Research
P0
2026-09-23 23:07 UTC
Vendor Research

ICYMI: August 2026 @AWS Security

AWS Security Blog · Rodolfo Brenes · indexed 2026-09-23 23:25 UTC

Read all about the latest AWS security features, compliance updates, and hands-on resources in our monthly digest posts. You’ll find expert blog posts, new service capabilities, code samples, and workshops. AWS Security Blog posts August brought 20 AWS Security Blog posts organized across seven categories. Identity and access management led the month with five posts […]

Cloud Security
P0
2026-09-23 20:37 UTC
Other

U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-23 21:00 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-85102 resides in the VPN negotiation process and lets an unauthenticated attacker bypass security checks […]

Cloud SecurityNetwork SecurityVulnerabilitiesCVE-2026-85102
P35
2026-09-23 14:45 UTC
Vendor Research

Supporting ASD’s multi-factor authentication campaign: Why MFA matters more than ever

AWS Security Blog · Grace Zhang · indexed 2026-09-23 15:00 UTC

The Australian Signals Directorate (ASD) has this month issued a clear call to action through its Multi-factor authentication: Switch it on campaign, urging businesses, organisations, and individuals to enable multi-factor authentication (MFA) across their online accounts. At AWS, we strongly support this message. As threat actors continue to target credentials through phishing, credential stuffing, and […]

Cloud SecurityNetwork SecurityPhishingThreat Actors
P0
2026-09-23 14:01 UTC
Security Journalism

How One Kubernetes YAML Can Hand Over a GCP Organization

BleepingComputer · Sponsored by Varonis · indexed 2026-09-23 14:15 UTC

A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into a path to organization-wide privilege escalation. [...]

Cloud SecurityVulnerabilities
P10
2026-09-23 10:36 UTC
Security Journalism

Chrome 154 Patches 108 Vulnerabilities

Security Week · Ionut Arghire · indexed 2026-09-23 10:50 UTC

The browser update resolves several critical-severity memory safety and memory corruption flaws. The post Chrome 154 Patches 108 Vulnerabilities appeared first on SecurityWeek.

Cloud Security
P0
2026-09-22 20:08 UTC
Vendor Research

CVE-2026-94450 - Potential denial of service when configured to send Retry packets in s2n-quic

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-22 20:10 UTC

Bulletin ID: 2026-116-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/22/2026 13:00 PM PDT Description: s2n-quic is a Rust implementation of the QUIC protocol. We identified CVE-2026-94450, an issue with improper validation of the Destination Connection ID length when a server is configured to send Retry packets. s2n-quic 1.88.0 and earlier allow an unauthenticated user to shut down a server endpoint via a single crafted UDP datagram. No AWS services are affecte…

Cloud SecurityVulnerabilitiesCVE-2026-94450
P5
2026-09-22 17:10 UTC
Vendor Research

CVE-2026-94384 - Missing Authorization in AmazonConnectSalesforceLambda sfExecuteAWSService

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-22 17:20 UTC

Bulletin ID: 2026-115-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/22/2026 10:00 AM PDT Description: Amazon Connect Salesforce Lambda (AmazonConnectSalesforceLambda) is a Serverless Application Repository application that provides Lambda functions for integrating Amazon Connect with Salesforce. We identified CVE-2026-94384, a missing authorization issue in the sfExecuteAWSService Lambda function, which is used only during initial setup. The function dispatche…

Cloud SecurityVulnerabilitiesCVE-2026-94384
P5
2026-09-22 05:31 UTC
Security Journalism

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 06:55 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating

Cloud SecurityNetwork SecurityVulnerabilitiesCVE-2026-7273
P35
2026-09-21 15:33 UTC
Vendor Research

Transforming Bedrock Guardrails events into OCSF with CloudWatch

AWS Security Blog · Dhananjay Karanjkar · indexed 2026-09-21 16:00 UTC

Security teams investigating possible AI-related security events need guardrail intervention data alongside their existing security telemetry. When a guardrail identifies or blocks a prompt injection attempt or redacts sensitive data, that intervention carries additional investigative value comparable to a failed sign-in or a network intrusion alert. AWS Bedrock publishes this telemetry to AWS CloudWatch metrics […]

AI SecurityCloud Security
P0
2026-09-21 10:00 UTC
Vendor Research

From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies

Palo Alto Networks Unit 42 · Margaret Kelley · indexed 2026-09-21 10:15 UTC

We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies. The post From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies appeared first on Unit 42.

Cloud Security
P0
2026-09-21 07:28 UTC
Other

UK Police Data Faces Long-Standing Microsoft Cloud Security Concerns

Security Affairs · Pierluigi Paganini · indexed 2026-09-21 08:25 UTC

A 2017 UK assessment warned that police data on Microsoft Azure could face foreign access risks. The risks may still exist. A Guardian investigation has surfaced a 2017 document signed off by then City of London police commissioner Ian Dyson, who also held the title of senior information risk owner for the entire country. That […]

Cloud SecurityDFIRMicrosoft
P0
2 3 4 5 6