IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,456 matching records.
AUTO-POLL // 2026-10-10 13:35 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P2 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P2
P2
COOL // 7 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2024-04-26 00:00 UTC
Other

Azure tenant takeover via Microsoft application

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Microsoft Dynamics 365 Supply Chain Visibility allowed arbitrary takeover of Azure tenants via a malicious reply URL. Clicking a link could grant an attacker directory read access or full tenant control if clicked by a Global Admin, without requiring user consent.

Cloud SecurityMicrosoftVulnerabilities
P0
2024-04-25 00:00 UTC
Government

Multiples vulnérabilités dans les produits Cisco (25 avril 2024)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Le 24 avril 2024, Cisco a publié trois avis de sécurité concernant des vulnérabilités affectant les équipements de sécurité ASA et FTD. Deux d'entre eux concernent les vulnérabilités CVE-2024-20353 et CVE-2024-20359 qui sont activement exploitées dans le cadre d'attaques ciblées. La vulnérabilité...

VulnerabilitiesCVE-2024-20353CVE-2024-20359
P5
2024-04-15 00:00 UTC
Other

AWS Amplify IAM role publicly assumable exposure

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The AWS Amplify service was found to be misconfiguring IAM roles associated with Amplify projects. This misconfiguration caused these roles to be assumable by any other AWS account. Both the Amplify Studio and the Amplify CLI exhibited this behavior. Any Amplify project created using the Amplify CLI built between July 3, 2018 and August 8, 2019 had IAM roles that were assumable by anyone in the world. The same was true if the authentication component was removed from an Amplify project using th…

Cloud SecurityVulnerabilities
P0
2024-04-03 00:00 UTC
Other

Bazel supply chain vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Cycode discovered a CI/CD misconfiguration in the Bazel repo, which if exploited could have allowed an attacker to enact a supply chain attack against all Bazel users, which includes Google themselves and therefore likely GCP as well.

Vulnerabilities
P0
2024-04-03 00:00 UTC
Other

Critical GitLab Account Takeover Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

GitLab addressed a critical vulnerability, CVE-2023-7028, affecting managed SaaS gitlab.com instance as well as self-hosted versions 16.1 to 16.7.1. The flaw could allow account takeovers via unverified email password resets. Third party could intercept the password reset request, add their own email to the request and forward it. GitLab would then send the reset link to the added 3rd-party email. This is in effect an account takeover with only precondition of knowing victim email associated wi…

VulnerabilitiesCVE-2023-7028
P15
2024-03-21 00:00 UTC
Other

FlowFixation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A flaw in Amazon Managed Workflows for Apache Airflow (MWAA) could have allowed potential session hijacking and remote code execution. The issue stemmed from a combination of session fixation in the MWAA web management panel and an AWS domain configuration error leading to a cross-site scripting (XSS) attack. Attackers exploiting this could manipulate victims' configurations, trigger workflows, and potentially move laterally to other services within the cloud environment. The exploit of this bu…

Cloud SecurityVulnerabilities
P15
2024-03-07 00:00 UTC
Other

Synapse Analytics privilege escalation via intelligent caching

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Tenable Research discovered a privilege escalation flaw that allows a user to escalate privileges to that of the root user within the context of a Spark VM. This escalation was achieved because of a permissions issue with scripts utilized by the intelligent caching service (AKA "Vegas") present in the environment.

Vulnerabilities
P10
2024-02-23 00:00 UTC
Security Journalism

SlashAndGrab | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Adversaries have been VERY busy in the wake of the ScreenConnect vulnerabilities (CVE-2024-1709 & CVE-2024-1708). Here’s all the post-exploitation details, tradecraft, and tactics we’ve observed so far!

VulnerabilitiesCVE-2024-1708CVE-2024-1709
P5
2024-02-13 00:00 UTC
Other

Azure Site Recovery privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

When the ASR service is enabled, it uses an Automation Account with a System-Assigned Managed Identity to manage Site Recovery extensions on VMs. However, the Runbook (a set of scripts for managing extensions) executed by the Automation Account had its job output visible to users, and this output mistakenly included a cleartext Management-scoped Access Token for the System-Assigned Managed Identity, which possesses the Contributor role over the entire Azure subscription. Therefore, lower-privil…

Cloud SecurityVulnerabilities
P10
2024-02-09 00:00 UTC
Government

[MàJ] Vulnérabilité dans Fortinet FortiOS (09 février 2024)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

\[Mise à jour du 19 mars 2024\] Le CERT-FR a connaissance de codes d'exploitation publics et de nouvelles tentatives d'exploitation. Le 8 février 2024, Fortinet a publié l'avis de sécurité concernant la vulnérabilité critique CVE-2024-21762 affectant le VPN SSL de FortiOS. Cette vulnérabilité...

AppleNetwork SecurityVulnerabilitiesCVE-2024-21762
P5
2024-02-06 00:00 UTC
Other

Azure HDInsight privilege escalation and DoS vulnerabilities

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Three privilege escalation and denial-of-service vulnerabilities were discovered in Azure HDinsight, related to their usage of Apache Oozie and Ambari. The root cause of at least one of these vulnerabilities is a flaw in Apache Oozie itself, leading to regex denial-of-service (ReDoS). The other two vulnerabilities could allow an authenticated attacker with HDI cluster access to gain cluster administrator privileges and perform any resource service management operation. The vulnerabilities were …

Cloud SecurityVulnerabilities
P15
2024-01-31 00:00 UTC
Other

Azure Devops Zero-Click CI/CD Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Legit Security found a zero-click vulnerability in Azure Pipelines that allows an attacker to access secrets and internal information and perform actions in elevated permissions in the context of a pipeline workflow. This could allow attackers to move laterally in the organization and initiate supply chain attacks. When a pipeline is triggered by a "pipeline resource trigger," it shows in the platform as "Automatically Triggered For …" Instead of running in fork default permissions, preventing …

Cloud SecurityVulnerabilities
P0
2024-01-12 00:00 UTC
Government

[MàJ] Multiples Vulnérabilités dans GitLab (12 janvier 2024)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

\[Mise à jour du 29 janvier 2024\] Le 25 janvier 2024, l'éditeur a publié un avis de sécurité concernant plusieurs vulnérabilités affectant GitLab CE et EE. La vulnérabilité CVE-2024-0402 est considérée critique avec un score CVSSv3 de 9,9. Elle permet à un attaquant authentifié d'écrire des...

VulnerabilitiesCVE-2024-0402
P5
2023-12-27 00:00 UTC
Other

Amazon Cognito Rate Limit Bypass Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A rate limit bypass vulnerability was discovered in Amazon Cognito, allowing attackers to potentially brute-force login credentials, password reset PINs, and MFA codes by sending requests in parallel. The vulnerability affected the main login flow, password reset function, and MFA process, potentially exposing user accounts to unauthorized access.

Vulnerabilities
P0
2023-12-20 00:00 UTC
Other

Poisoning GitHub's Runner Images Supply Chain Attack

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A critical vulnerability in GitHub's actions/runner-images repository allowed arbitrary code execution on self-hosted runners, potentially enabling modification of GitHub's runner base images. The flaw stemmed from misconfigured self-hosted runners on a public repository with default workflow approval settings. The researcher gained persistence, accessed secrets, and could have inserted malicious code into GitHub's runner images used by customers.

Vulnerabilities
P10
2023-12-15 00:00 UTC
Other

Google OAuth Vulnerability Allows Indefinite Access

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Google OAuth allows employees to retain indefinite access to applications like Slack and Zoom after being removed from their company's Google organization. The issue stems from the ability to create Google accounts using corporate email aliases, which can't be off-boarded by the organization. This bypasses typical account removal processes and poses a significant security risk.

Vulnerabilities
P0
2023-12-13 00:00 UTC
Government

Vulnérabilité dans Apache Struts 2 (13 décembre 2023)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Le 4 décembre 2023, Apache a publié un avis de sécurité concernant la vulnérabilité critique CVE-2023-50164 concernant le cadriciel Struts 2. Cette vulnérabilité permet à un attaquant non authentifié de téléverser une porte dérobée sur un serveur vulnérable, et ainsi exécuter du code arbitraire à...

VulnerabilitiesCVE-2023-50164
P5
2023-11-16 00:00 UTC
Other

Extracting Managed Identity Credentials from Azure Functions

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Azure Function Apps allowed extraction of Managed Identity credentials from the encrypted startup context of Linux containers. This gave attackers with container access the ability to persist as the Managed Identity, breaking the intended security model. Microsoft has since patched the issue by encrypting the sensitive payload.

Cloud SecurityLinuxMicrosoftVulnerabilities
P0
2023-11-14 00:00 UTC
Other

Azure CLI Leaks Credentials in GitHub Actions Logs

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure CLI commands were found to leak sensitive information, including credentials, through GitHub Actions logs. The vulnerability affects multiple Azure CLI commands and could expose secrets in public and private repositories. Microsoft has issued updates to Azure CLI, Azure Pipelines, and GitHub Actions to address the issue.

Cloud SecurityMicrosoftVulnerabilities
P0
2023-11-03 00:00 UTC
Other

Hacking Google Bard via Prompt Injection

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Google Bard allowed for prompt injection and data exfiltration through its Extensions feature. By injecting malicious instructions into shared Google Docs, an attacker could force Bard to render images with exfiltrated chat history data in the URL. The exploit bypassed Content Security Policy using Google Apps Script.

AI SecurityVulnerabilities
P0
2023-11-02 00:00 UTC
Other

ApatchMe

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Amazon Managed Workflows for Apache Airflow (MWAA) and the Task instance details page in the Google Composer UI were not patched against CVE-2023-29247 (Stored XSS). This meant that post-authentication, a threat actor could have exploited this to store their JavaScript payload in the victim's managed Apache Airflow instance and run JavaScript on behalf of the victim (who could be an admin or another user with higher permissions than the threat actor, thereby leading to privilege escalation). Wi…

Threat ActorsVulnerabilitiesCVE-2023-29247
P15
2023-08-24 00:00 UTC
Other

Power Platform Privilege Escalation in Azure AD

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Secureworks researchers discovered an Azure AD application with an abandoned reply URL related to Microsoft Power Platform. An attacker could leverage this URL to redirect authorization codes, exchange them for access tokens, and call Power Platform API via a middle-tier service to obtain elevated privileges. Microsoft quickly addressed the issue by removing the identified abandoned reply URL from the Azure AD application.

Cloud SecurityMicrosoftSecurity ResearchVulnerabilities
P10
43 44 45 46 47