IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,456 matching records.
AUTO-POLL // 2026-10-10 12:35 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P2 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P2
P2
COOL // 7 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2025-07-21 21:34 UTC
Vendor Research

Introducing OSS Rebuild: Open Source, Rebuilt to Last

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Matthew Suozzo, Google Open Source Security Team (GOSST)Today we're excited to announce OSS Rebuild, a new project to strengthen trust in open source package ecosystems by reproducing upstream artifacts. As supply chain attacks continue to target widely-used dependencies, OSS Rebuild gives security teams powerful data to avoid compromise without burden on upstream maintainers.The project comprises:Automation to derive declarative build definitions for existing PyPI (Python), npm (JS/T…

MalwareSecurity ResearchVulnerabilities
P0
2025-07-08 17:36 UTC
Vendor Research

Advancing Protection in Chrome on Android

Google Online Security Blog · Google · indexed 2026-08-15 14:33 UTC

Posted by David Adrian, Javier Castro & Peter Kotwicz, Chrome Security Team Android recently announced Advanced Protection, which extends Google’s Advanced Protection Program to a device-level security setting for Android users that need heightened security—such as journalists, elected officials, and public figures. Advanced Protection gives you the ability to activate Google’s strongest security for mobile devices, providing greater peace of mind that you’re better protected against the most s…

Data BreachesMalwareMobile SecurityVulnerabilities
P0
2025-06-13 16:03 UTC
Vendor Research

Mitigating prompt injection attacks with a layered defense strategy

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Adam Gavish, Google GenAI Security TeamWith the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging attack vector is indirect prompt injections. Unlike direct prompt injections, where an attacker directly inputs malicious commands into a prompt, indirect prompt injections involve hidden malicious instructions within external data sources. These may include emails, documents, or…

AI SecurityMalwarePhishingSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities
P0
2025-05-22 00:00 UTC
Other

Remote Prompt Injection in GitLab Duo Leaks Source Code

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A remote prompt injection vulnerability in GitLab Duo allowed attackers to steal source code from private projects, manipulate code suggestions, and exfiltrate confidential information. The attack chain involved hidden prompts, HTML injection, and exploitation of Duo's access to private data. GitLab has since patched both the HTML and prompt injection vectors.

AI SecurityVulnerabilities
P0
2025-05-19 00:00 UTC
Other

AWS Security Tool Introduces Privilege Escalation Risk

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS's Account Assessment for AWS Organizations tool, designed to audit cross-account access, inadvertently introduced privilege escalation risks due to flawed deployment instructions. Customers were encouraged to deploy the tool in lower-sensitivity accounts, creating risky trust paths from insecure environments into highly sensitive ones. This could allow attackers to pivot from compromised development accounts into production and management accounts.

Cloud SecurityVulnerabilities
P10
2025-05-14 00:00 UTC
Government

Multiples vulnérabilités dans Ivanti Endpoint Manager Mobile (EPMM) (14 mai 2025)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

[Mise à jour du 15 mai 2025] Une preuve de concept est publiquement disponible sur Internet. [Publication initiale] Le 13 mai 2025, Ivanti a publié deux avis de sécurité concernant les vulnérabilités CVE-2025-4427 et CVE-2025-4428. L'utilisation combinée de ces deux vulnérabilités permet...

VulnerabilitiesCVE-2025-4427CVE-2025-4428
P5
2025-05-06 05:00 UTC
Security Journalism

Do Tigers Really Change Their Stripes?

Huntress · indexed 2026-09-07 17:30 UTC

Across the larger cybersecurity community, an often-used adage is that “threat actors always change their tactics.” However, when we really start to look at and track incident data, we begin to see that while some changes may be necessitated based on infrastructures and other challenges the threat actor may encounter, there are times when tactics remain consistent across incidents. Recent investigations into exploitation activity for CVE-2025-31151 and CVE-2025-30406 show similar TTPs across di…

DFIRThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2025-30406CVE-2025-31151
P5
2025-05-06 00:00 UTC
Other

Azure AZNFS-mount Utility Root Privilege Escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A critical vulnerability in AZNFS-mount utility, preinstalled on Azure HPC/AI images, allowed unprivileged users to escalate privileges to root on Linux machines. The flaw existed in versions up to 2.0.10 and involved a SUID binary. Azure classified it as low severity but fixed it in version 2.0.11.

Cloud SecurityLinuxVulnerabilities
P10
2025-04-29 00:00 UTC
Other

AWS Default Roles Can Lead to Service Takeover

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Research uncovered security flaws in default AWS service roles, granting overly broad permissions like full S3 access. This allows privilege escalation, cross-service access, and potential account compromise across services like SageMaker, Glue, and EMR. Attackers could exploit these roles to manipulate critical assets and move laterally within AWS environments. AWS has since updated default policies and documentation to mitigate risks.

Cloud SecurityVulnerabilities
P10
2025-04-28 00:00 UTC
Government

Vulnérabilité dans SAP NetWeaver (28 avril 2025)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Le 24 avril 2025, SAP a publié un bulletin de sécurité relatif à la vulnérabilité CVE-2025-31324 qui permet l'exécution de code arbitraire à distance pour un utilisateur non authentifié. Cette vulnérabilité est provoquée par un contournement de la politique de sécurité qui permet de télécharger...

VulnerabilitiesCVE-2025-31324
P5
2025-04-22 00:00 UTC
Other

Google Cloud ConfusedComposer Privilege Escalation Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Tenable discovered a privilege escalation vulnerability in Google Cloud Platform's Cloud Composer service, dubbed ConfusedComposer. It allowed users with composer.environments.update permission to escalate privileges to the default Cloud Build service account by injecting malicious PyPI packages. This could grant broad permissions across the victim's GCP project.

Cloud SecurityVulnerabilities
P10
2025-04-15 00:00 UTC
Other

Burning Data with Malicious Firewall Rules in Azure SQL

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Varonis Threat Labs discovered a vulnerability in Azure SQL Server allowing privileged users to create malicious firewall rules that can delete Azure resources when triggered by admin actions. The exploit involves manipulating rule names via TSQL to inject destructive commands, potentially leading to large-scale data loss in affected Azure accounts.

Cloud SecurityNetwork SecurityVulnerabilities
P0
2025-04-09 00:00 UTC
Other

Path Traversal in AWS SSM Agent Plugin ID Validation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A path traversal vulnerability in AWS SSM Agent's ValidatePluginId function allows attackers to create directories and execute scripts in unintended locations on the filesystem. This could lead to privilege escalation or other malicious activities, as files may be written to or executed from sensitive areas of the system with root privileges.

Cloud SecurityVulnerabilities
P10
2025-04-01 00:00 UTC
Other

ImageRunner: Privilege Escalation Vulnerability in GCP Cloud Run

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An attacker with `run.services.update` and `iam.serviceAccounts.actAs` permissions but without explicit registry access could deploy new revisions of Cloud Run services that pulled private container images stored in the same GCP project. This was possible because Cloud Run uses a service agent with the necessary registry read permissions to retrieve these images, regardless of the caller’s access level. By updating a service revision and injecting malicious commands into the container's argumen…

Vulnerabilities
P10
2025-03-26 00:00 UTC
Other

CodeQLEAKED - CodeQL Supply Chain Attack via Exposed Secret

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A publicly exposed GitHub token in CodeQL workflow artifacts could allow attackers to execute malicious code in repositories using CodeQL, potentially leading to source code exfiltration, secrets compromise, and supply chain attacks. The vulnerability stemmed from a debug artifact containing environment variables, which could be downloaded and exploited within a 1-2 second window.

Vulnerabilities
P0
2025-03-25 00:00 UTC
Other

Entra ID Bug Creates Immutable Users

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A bug in Entra ID restricted management administrative units allowed creating immutable users that couldn't be modified or disabled, even by Global Administrators. This could enable an attacker to protect a compromised account from containment. The issue was caused by a timing vulnerability when removing users from restricted AUs and required specific steps to remediate affected accounts.

MicrosoftVulnerabilities
P0
2025-03-10 00:00 UTC
Other

Azure API Connections Expose Backend Secrets

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure API Connections were found to allow any reader on a subscription to access backend resources through a proxy endpoint, potentially exposing secrets from Key Vaults, databases, and third-party services. This vulnerability affects various Azure services and external APIs, enabling privilege escalation and unauthorized access to sensitive information.

Cloud SecurityVulnerabilities
P10
2025-03-04 00:00 UTC
Other

Issue with AWS Temporary Elevated Access Management

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in AWS Temporary Elevated Access Management (TEAM) allows users to modify valid requests and spoof approvals due to improper input validation. This affects versions prior to 1.2.2 of TEAM for AWS IAM Identity Center. AWS has released a fix in version 1.2.2 and recommends customers upgrade to the latest release.

Cloud SecurityVulnerabilities
P0
2025-01-24 00:00 UTC
Other

Entra ID Allows Users to Update Principal Names

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A configuration change in Entra ID allowed unprivileged users to update their own User Principal Names (UPNs) through interfaces like the Entra admin center and PowerShell. This could lead to impersonation risks. Microsoft quickly fixed the issue after it was reported. The vulnerability affected synchronized hybrid environments as well.

MicrosoftVulnerabilities
P0
2025-01-23 00:00 UTC
Other

AWS Sign-in IAM User Login Flow Username Enumeration

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in AWS IAM Sign-in login flow could allow attackers to enumerate IAM usernames by measuring server response times. This issue affected AWS Sign-in IAM User login flow prior to January 16, 2025. AWS has since introduced a delay in response times across all authentication failure scenarios to mitigate the vulnerability.

AppleCloud SecurityVulnerabilities
P0
2025-01-16 00:00 UTC
Other

CloudWatch Dashboard Sharing Exposes EC2 Tags

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in AWS CloudWatch dashboard sharing allowed viewers to access EC2 instance tags and potentially invoke Lambda functions in the source account. The issue stemmed from a logic bug in the AWS Console combined with a "fail open" condition in Amazon Cognito. AWS has since patched the vulnerability.

Cloud SecurityVulnerabilities
P0
2025-01-14 00:00 UTC
Government

[MàJ] Vulnérabilité dans les produits Fortinet (14 janvier 2025)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

\[Mise à jour du 28 janvier 2025\] Une preuve de concept permettant l'exploitation de cette vulnérabilité est disponible publiquement. Le 14 janvier 2025, Fortinet a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-55591 affectant FortiOS et FortiProxy. Elle permet à un...

AppleNetwork SecurityVulnerabilitiesCVE-2024-55591
P5
2025-01-09 00:00 UTC
Government

[MàJ] Vulnérabilité dans les produits Ivanti (09 janvier 2025)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Une vulnérabilité jour-zéro de type débordement de pile a été découverte dans Ivanti Connect Secure (ICS), Policy Secure (IPS), Neurons for Zero Trust Access (ZTA) gateways. Cette vulnérabilité, d'identifiant CVE-2025-0282, permet à un attaquant non authentifié de provoquer une exécution de code...

VulnerabilitiesCVE-2025-0282
P5
2025-01-08 00:00 UTC
Other

Hijacking Azure Machine Learning Notebooks

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Machine Learning notebooks can be hijacked by attackers with Storage Account access to inject malicious code. A now-fixed vulnerability allowed Reader role escalation to code execution. The article details the attack methods, including modifying notebooks, obtaining managed identity tokens, and exfiltrating data. It also introduces a tool for dumping AML workspace credentials.

Cloud SecurityVulnerabilities
P0
41 42 43 44 45