IntelFreed A CYBERSECURITY INTELLIGENCE FEED

NEWS

Cybersecurity reportings, advisories, and research. 146 matching records.
Last update // 2026-08-22 04:00 UTC
CYBER INTEL TEMPERATURE
For today's cybersecurity intelligence
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
RESET
2026-08-21 15:52 UTC
Security Journalism

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-21 16:40 UTC

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a

LinuxMicrosoft
P0
2026-08-21 14:54 UTC
Security Journalism

Microsoft blames Windows gaming issues on RGB lighting devices

BleepingComputer · Sergiu Gatlan · indexed 2026-08-21 15:05 UTC

Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. [...]

Microsoft
P0
2026-08-21 06:06 UTC
Security Journalism

Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-21 06:45 UTC

Update: The story was updated after publication to note that the vulnerability has not been exploited. Although the security bulletin originally marked the "Exploited" field under the Exploitability Assessment table as "Yes," on August 21, 2026, Microsoft corrected the "Exploited" status to "No" after The Hacker News contacted the company for comment. It also noted, "this vulnerability was not

MicrosoftVulnerabilities
P15
2026-08-21 02:47 UTC
Community

Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)

SANS Internet Storm Center · indexed 2026-08-21 02:55 UTC

In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what's left would be handy. Something quicker than scrolling through the web interface through thousands of accounts ...
 This is that method.
 Also, remember when we discussed yesterday about the beta graph commands in the Microsoft.Graph.Beta library? We'll use one of those beta commands here!

Microsoft
P0
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project Directory on Windows

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-074-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 12:30 PM PDT Description: Kiro is an agentic IDE and command-line interface users install on their desktop. We identified CVE-2026-18656 and CVE-2026-18657, an issue where an uncontrolled search path element on Windows might allow an actor to execute arbitrary code via a maliciously crafted project directory containing a planted executable that is resolved before the system PATH when a…

Cloud SecurityMicrosoftVulnerabilitiesCVE-2026-18656CVE-2026-18657
P5
2026-08-20 21:35 UTC
Vendor Research

Issues with Amazon Athena ODBC Driver

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-013-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/03 13:00 PM PDT Description: The Amazon Athena ODBC driver implements standard ODBC application program interfaces (APIs). The ODBC driver provides access to Amazon Athena from any C/C++ application. The Amazon Athena ODBC driver provides 64-bit ODBC drivers for Windows, Linux and MAC operating systems. We identified the following: - CVE-2026-5485: OS command injection in browser-based au…

Cloud SecurityLinuxMicrosoftVulnerabilitiesCVE-2026-35558CVE-2026-35559CVE-2026-35560CVE-2026-35561CVE-2026-35562CVE-2026-5485
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-14471 - Authenticated SQL injection in the metrics-service retention policy subsystem of mcp-gateway-registry

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-052-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/06/2026 13:45 PM PDT Description: Amazon mcp-gateway-registry is an open-source gateway and registry for Model Context Protocol (MCP) servers, providing centralized discovery, authentication/authorization, and proxying of MCP tools for AI agents. We identified CVE-2026-14471, an issue in the metrics-service retention policy management component where a caller-supplied table_name value is inter…

AI SecurityCloud SecurityLaw EnforcementMicrosoftVulnerabilitiesCVE-2026-14471
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-10740 - Excessive memory allocation in s2n-quic

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-041-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/10/2026 10:45 AM PDT Description: AWS CDK (aws-cdk-lib) is an open-source framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified CVE-2026-11417, an OS command injection issue in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) that may allow an actor who controls the value of one or more bun…

Cloud SecurityMicrosoftVulnerabilitiesCVE-2026-10740CVE-2026-11417
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-7461 - OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-024-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/30 13:30 PM PDT Description: Amazon Elastic Container Service (Amazon ECS) is a fully managed container orchestration service that enables customers to deploy, manage, and scale containerized applications. The Amazon ECS agent supports mounting FSx for Windows File Server volumes in task definitions on Windows EC2 instances. We identified CVE-2026-7461, a command injection issue in FSx vo…

Cloud SecurityMicrosoftVulnerabilitiesCVE-2026-7461
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-7791 - Local Privilege Escalation via TOCTOU Race Condition in Amazon WorkSpaces Skylight Agent

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-025-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/05/04 15:30 PM PDT Description: Amazon Skylight Workspace Config Service ( slwsconfigservice) is a critical background service within Amazon WorkSpaces that manages system configuration, monitors health, and updates components. We identified CVE-2026-7791 which allows a local non-admin authenticated user to escalate privileges to SYSTEM by exploiting a race condition in the Skylight Workspac…

Cloud SecurityMicrosoftVulnerabilitiesCVE-2026-7791
P15
2026-08-20 14:01 UTC
Vendor Research

Frequently asked questions about the active threat to Siemens S7 Series PLCs

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-20 14:10 UTC

A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors.Key TakeawaysUnattributed threat actors are exploiting known weaknesses and unnecessary internet exposure to conduct reconnaissance and possible pre-positioning for future disruptive attacks against Siemens S7 Series PLCs.The attackers are leveraging AI to build and refine…

DFIRICS / OTLaw EnforcementMicrosoftThreat ActorsVulnerabilities
P25
2026-08-20 14:00 UTC
Vendor Research

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-20 14:40 UTC

Written by: Gabby Roncone, Wesley Shields Overview Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States. Examples of these techniques can be found in our previous blog on UNC6293’s phishing operations. We now track an additio…

APT / Nation-StateMalwareMicrosoftPhishingThreat Intelligence
P0
2026-08-20 12:45 UTC
Community

Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)

SANS Internet Storm Center · indexed 2026-08-20 12:00 UTC

Microsoft Graph is a newer API that is meant to replace several others.  OK, it's at version 2.3.9, so it's not all that new, but it's new enough that lots of folks (and commercial tools) aren't using it yet.   It allows you to Get and Set info from/to M365, Entra Users and Entra managed machines for starters.  Let's dig in!

Microsoft
P0
2026-08-20 06:51 UTC
Security Journalism

Microsoft says August Windows updates may cause gaming issues

BleepingComputer · Sergiu Gatlan · indexed 2026-08-20 06:55 UTC

Microsoft is investigating a potential issue with the August 2026 updates that may prevent some games from launching or cause them to crash on affected Windows 11 systems. [...]

Microsoft
P0
2026-08-19 17:30 UTC
Vendor Research

Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026

Microsoft Security Blog · Ran Rosin · indexed 2026-08-19 18:05 UTC

Microsoft is named a visionary leader in the 2026 Frost Radar for Cloud Workload Protection Platforms, recognized for unified runtime security with Microsoft Defender for Cloud. The post Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 appeared first on Microsoft Security Blog.

Microsoft
P0
2026-08-19 13:12 UTC
Security Journalism

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 13:35 UTC

A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previously documented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. SilkParasite, first discovered in late 2025, is assessed to be a

APT / Nation-StateMicrosoft
P0
2026-08-19 11:14 UTC
Security Journalism

Microsoft fixes known issue causing Windows Defender crashes

BleepingComputer · Sergiu Gatlan · indexed 2026-08-19 11:35 UTC

Microsoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems. [...]

Microsoft
P5
2026-08-19 11:01 UTC
Security Journalism

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 11:35 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting Apple macOS that could allow an

AppleCloud SecurityMicrosoftVulnerabilitiesCVE-2026-65400
P55
2026-08-19 08:55 UTC
Other

Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains

Security Affairs · Pierluigi Paganini · indexed 2026-08-19 09:50 UTC

Microsoft tracked over 30 MacSync Stealer domains by focusing on behavioral patterns, revealing a campaign targeting passwords, keys, wallets and other data. Domain blocking is a losing game when the thing you’re blocking can register a new domain faster than you can add it to a list. That’s the exact problem Microsoft Defender Experts ran […]

MalwareMicrosoft
P0
2026-08-19 07:19 UTC
Other

U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-19 07:35 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-33824 is a Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution […]

AppleCloud SecurityMicrosoftVulnerabilitiesCVE-2026-33824
P50
1 2 3