IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 163 matching records.
AUTO-POLL // 2026-10-09 22:50 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 62 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2025-09-15 17:01 UTC
Vendor Research

Supporting Rowhammer research to protect the DRAM ecosystem

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Daniel MoghimiRowhammer is a complex class of vulnerabilities across the industry. It is a hardware vulnerability in DRAM where repeatedly accessing a row of memory can cause bit flips in adjacent rows, leading to data corruption. This can be exploited by attackers to gain unauthorized access to data, escalate privileges, or cause denial of service. Hardware vendors have deployed various mitigations, such as ECC and Target Row Refresh (TRR) for DDR5 memory, to mitigate Rowhammer and e…

Security ResearchVulnerabilities
P10
2025-09-15 05:44 UTC
Other

Agneyastra to the Rescue: Protecting your Firebase Projects before the Tea spills out!

Red Hunt Labs · Bhavarth Karmarkar · indexed 2026-09-07 17:30 UTC

In July 2025, the Tea app 🔗, a mental health and social community platform, experienced a devastating breach that spilled 72,000 images (including 13,000 driver’s license and verification selfies) and over 1.1 million private direct messages onto the internet. The leaks first surfaced on 4chan and quickly spread across forums, torrents, and underground channels. This was not “just another API key leak.” Instead, it was a story about Firebase misconfigurations, poor data retention practices, an…

APT / Nation-StateSecurity ResearchVulnerabilities
P25
2025-07-21 21:34 UTC
Vendor Research

Introducing OSS Rebuild: Open Source, Rebuilt to Last

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Matthew Suozzo, Google Open Source Security Team (GOSST)Today we're excited to announce OSS Rebuild, a new project to strengthen trust in open source package ecosystems by reproducing upstream artifacts. As supply chain attacks continue to target widely-used dependencies, OSS Rebuild gives security teams powerful data to avoid compromise without burden on upstream maintainers.The project comprises:Automation to derive declarative build definitions for existing PyPI (Python), npm (JS/T…

MalwareSecurity ResearchVulnerabilities
P0
2025-06-13 16:03 UTC
Vendor Research

Mitigating prompt injection attacks with a layered defense strategy

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Adam Gavish, Google GenAI Security TeamWith the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging attack vector is indirect prompt injections. Unlike direct prompt injections, where an attacker directly inputs malicious commands into a prompt, indirect prompt injections involve hidden malicious instructions within external data sources. These may include emails, documents, or…

AI SecurityMalwarePhishingSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities
P0
2024-08-07 00:00 UTC
Other

Bucket Monopoly Attack on AWS Services

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Researchers discovered critical vulnerabilities in 6 AWS services that could allow attackers to breach accounts through malicious S3 buckets. By claiming predictable bucket names, attackers could inject code, steal data, or gain admin access. AWS has since fixed the issues, but the attack vector may still apply to other services and open source projects.

Cloud SecuritySecurity Research
P0
2024-08-07 00:00 UTC
Other

Privilege Elevation Vulnerability in Entra ID

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Semperis researchers discovered vulnerabilities in Microsoft applications that allowed privilege elevation in Entra ID beyond expected authorization controls. The most severe finding enabled adding users to privileged roles, including Global Administrator, without proper permissions. The issues affected Device Registration Service, Viva Engage, and Microsoft Rights Management Service. Microsoft has since resolved the vulnerabilities.

MicrosoftSecurity ResearchVulnerabilities
P0
2023-11-30 00:00 UTC
Other

Google Workspace Domain-Wide Delegation Flaw

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Unit 42 researchers discovered a security risk in Google Workspace's domain-wide delegation feature that allows a GCP identity with necessary permissions to generate access tokens to impersonate Google Workspace users and access their data. This mismatch between GCP permissions and Google Workspace access could be exploited by malicious insiders or attackers with stolen credentials.

CybercrimeSecurity Research
P0
2023-08-24 00:00 UTC
Other

Power Platform Privilege Escalation in Azure AD

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Secureworks researchers discovered an Azure AD application with an abandoned reply URL related to Microsoft Power Platform. An attacker could leverage this URL to redirect authorization codes, exchange them for access tokens, and call Power Platform API via a middle-tier service to obtain elevated privileges. Microsoft quickly addressed the issue by removing the identified abandoned reply URL from the Azure AD application.

Cloud SecurityMicrosoftSecurity ResearchVulnerabilities
P10
2020-08-18 00:00 UTC
Other

Dropping a Shell in Google Cloud SQL

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Researchers discovered vulnerabilities in Google Cloud SQL that allowed gaining unauthorized shell access to MySQL instances. By chaining SQL injection, parameter injection in mysqldump, and network spoofing, they were able to escape a Docker container and gain full access to the host VM running Cloud SQL.

Cloud SecuritySecurity Research
P0
4 5 6