IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,456 matching records.
AUTO-POLL // 2026-10-10 14:30 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P2 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P2
P2
COOL // 8 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2023-08-04 00:00 UTC
Other

Power Platform Custom Code information disclosure

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Power Platform could lead to unauthorized access to Custom Code functions used for custom connectors, thereby allowing cross-tenant information disclosure of secrets or other sensitive information if these were embedded in a Custom Code function. The issue occurred as a result of insufficient access control to Azure Function hosts, which are launched as part of the creation and operation of custom connectors in Microsoft’s Power Platform. An attacker who determined the hostna…

Cloud SecurityMicrosoftVulnerabilities
P0
2023-07-18 00:00 UTC
Other

Bad.Build

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An information disclosure vulnerability in the Google Cloud Build service could have allowed an attacker to view sensitive logs if they had gained prior access to a GCP environment and had permission to create a new Cloud Build instance (cloudbuild.builds.create) or permission to directly impersonate the Cloud Build default service account (which is highly privileged by design and therefore considered to be a known privilege escalation vector in GCP). An attacker could then potentially use this…

Cloud SecurityVulnerabilities
P10
2023-06-27 00:00 UTC
Other

Azure Front Door client-side desync

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A client-side desync vulnerability was discovered in Front Door, one of Azure's CDN solutions, caused by mishandling of the 'Content-Length' header in HTTP requests. Exploiting this vulnerability would most likely require user interaction through social engineering (such as clicking on a malicious link), but could allow an attacker to steal session cookies or forge responses to victim requests.

Cloud SecurityVulnerabilities
P0
2023-06-21 00:00 UTC
Other

Critical Authentication Bypass in Google Cloud API Gateway

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A critical authentication bypass vulnerability was discovered in Google Cloud API Gateway, affecting its JWT authentication method. The flaw, stemming from a business logic bug in the ESPv2 service proxy, allowed attackers to bypass authentication controls by manipulating HTTP methods. This vulnerability impacted various authentication methods including Firebase, Auth0, Okta, and Google ID tokens.

Cloud SecurityVulnerabilities
P10
2023-06-13 00:00 UTC
Other

Bucket Traversal in Google Cloud Storage Transfer Manager

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A bucket traversal vulnerability was discovered in the google.cloud.storage.transfer_manager.upload_chunks_concurrently() function of Google Cloud Storage. This issue could potentially allow unauthorized access to files in different buckets or directories within the same project.

Cloud SecurityVulnerabilities
P0
2023-06-12 00:00 UTC
Other

Azure App Services takeover via legacy API

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Binary Security found two vulnerabilities in the legacy Azure Resource Manager (ARM) REST API. The first vulnerability allowed an attacker with Reader access to an Azure Function, acting from a Windows host, to get an admin token that could be exchanged for a master key granting access to all operations in Kudu (the Functions deployment service). This would allow them to tamper with the function by deploying malicious code to it. The other vulnerability allowed an attacker with Reader access to…

Cloud SecurityMicrosoftVulnerabilities
P0
2023-06-07 00:00 UTC
Other

AWS Directory Service not checking PassRole on EnableRoleAccess

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS Directory Service didn't check the iam:PassRole permissions when using the EnableRoleAccess action. This could have been used for privilege escalation by an authenticated user with sufficient permissions (ds:EnableRoleAccess), if the role had a trust policy that allowed use by Directory Service.

Cloud SecurityVulnerabilities
P10
2023-06-02 00:00 UTC
Other

Privilege escalation in GCP Cloud SQL

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability was discovered in Cloud SQL for SQL Server that allowed customer administrator accounts to create triggers in the tempdb database and use those to gain sysadmin privileges in the instance. The sysadmin privileges would give the attacker access to system databases and partial access to the machine running that SQL Server instance.

Vulnerabilities
P10
2023-05-24 00:00 UTC
Other

Cloud SQL for SQL Server privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability discovered in GCP's Cloud SQL service allowed customer administrator accounts to create triggers in the tempdb database and use those to gain sysadmin privileges in the instance. This could be abused to result in complete control of the database engine and access to the host OS. An attacker could have listed and accessed files in the host OS, including any secrets on the machine, as well as gaining access to service agents. However, it is unclear from the report if this level of…

Vulnerabilities
P10
2023-05-04 00:00 UTC
Other

API Management SSRF and path traversal vulnerabilities

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure API Management is an API gateway service meant to help organizations to create, manage, secure, and monitor APIs across all of their environments. Researchers found three high severity vulnerabilities in the service, two of which are SSRF (Server Side Request Forgery) vulnerabilities, and the third is a path traversal bug. The SSRF issues affected the Azure API Management CORS proxy (which handles schema retrieval) and hosting proxy (which routes API requests to the correct server). An at…

Cloud SecurityVulnerabilities
P0
2023-04-21 00:00 UTC
Other

GhostToken

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Google users can find and install third-party OAuth applications from Google Marketplace that are integrated with Google Workspace. Each OAuth application client in Google is associated with a GCP project. A bug in the way a GCP project enters a "pending deletion" state when deleted, could have allowed threat actors to make a malicious application invisible and unremovable from the user's account. If an attacker had managed to install an application in an account (e.g., through a phishing attac…

PhishingThreat ActorsVulnerabilities
P0
2023-04-19 00:00 UTC
Other

Asset Key Thief

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Asset Key Thief was a Google Cloud privilege escalation vulnerability that enabled principals with the "Cloud Asset Viewer" role (or other roles with the `cloudasset.assets.searchAllResources` permission) on the Cloud Asset Inventory API, at the Project, Folder, or Organization level to view and exfiltrate any user-managed Service Account private key under a project within the same Google Cloud environment that had been created or rotated up to a maximum of 12 hours ago. Access to Service Accou…

Cloud SecurityVulnerabilities
P10
2023-04-19 00:00 UTC
Other

BrokenSesame

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

ApsaraDB and AnalyticDB contained several vulnerabilities in their PostgreSQL offerings which ultimately allowed unauthorized access to other tenants' databases and the ability to perform a supply-chain attack on both services, which in turn would have allowed remote code execution (RCE) as well. Both services implemented multi-tenancy through a shared K8s cluster, but contained several bugs related to tenant isolation which an attacker could chain together to achieve the above impact. In Apsar…

Vulnerabilities
P25
2023-03-30 00:00 UTC
Other

Azure on-premises data gateway cross-tenant access

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure on-premises data gateway allows data transfer between an on-prem customer network and several Azure cloud services, and also enables a connected agent installed locally in an on-prem network to perform certain actions remotely. NetSPI discovered a deserialization issue in Microsoft Power Platform connectors that lead to RCE on several Azure backend servers that processed call backs from on-premises data gateways, effectively allowing unauthorized cross-tenant access.

Cloud SecurityMicrosoftVulnerabilities
P15
2023-03-30 00:00 UTC
Other

RCE vulnerability in Azure Pipelines

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Legit Security found an RCE vulnerability in Azure Pipelines that could have allowed an attacker to gain complete control of variables and tasks by exploiting logging commands. This would have enabled them to execute malicious code in a context of a pipeline workflow, which would have granted them access to sensitive secrets such as cloud deployment keys, move laterally in the organization, and potentially initiate supply chain attacks. To exploit this vulnerability, an attacker would have need…

Cloud SecurityVulnerabilities
P15
2023-03-23 00:00 UTC
Other

Azure Function Apps privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Undocumented APIs used by the Azure Function Apps Portal could have allowed an attacker with existing access to a Reader role on a Function App to escalate their privileges and gain write permissions through arbitrary file reads on Function App containers. For Windows containers, this would only grant an attacker the ability to extract ASP.NET encryption keys (the impact of which remains unclear), but for Linux containers it would have allowed an attacker to read environmental variables contain…

Cloud SecurityLinuxMicrosoftVulnerabilities
P25
2023-03-14 00:00 UTC
Other

Super FabriXss

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Service Fabric Explorer (SFX) was affected by an XSS vulnerability that could have allowed a malicious script to be reflected off a web application. After a potential victim clicked on a crafted malicious URL, the attacker could remotely toggle the ‘Cluster’ Event Type setting under the Events tab. This could lead to unauthenticated remote code execution on a container hosted on a Service Fabric node.

Cloud SecurityVulnerabilities
P15
2023-03-08 00:00 UTC
Other

Imposter commits vulnerability in GitHub Actions

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in GitHub Actions allows bypassing workflow settings using commits from forked repositories (rather than commits of the main action repo). This "imposter commits" issue can potentially introduce untrusted code into CI/CD pipelines, posing a risk to the security of the software supply chain. The vulnerability stems from GitHub's handling of forked repositories and how commits are shared between forks and parent repositories. A partial solution to this was GitHub prohibiting parti…

Vulnerabilities
P0
2023-03-06 00:00 UTC
Other

Unauthorized access to Codespace secrets in GitHub

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in GitHub's Repository Security Advisory feature allowed unauthorized users to access plaintext Codespace secrets of any organization, including GitHub itself. The issue stemmed from the new beta feature that allows external users to report vulnerabilities to public repositories, inadvertently granting access to sensitive organization-level secrets.

Vulnerabilities
P0
2023-02-15 00:00 UTC
Other

Azure AD B2C cryptographic flaw allowing account compromise

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Active Directory B2C service (AD B2C) mistakenly implemented RSA key authentication using the public part of the key pair instead of the private one. This cryptographic flaw could have allowed an unauthenticated attacker to craft an OAuth refresh token for any AD B2C user account if they knew their public key. Moreover, every AD B2C user's public key was recoverable through an unrelated vulnerability (though asymmetric cryptography should not rely on public key secrecy regardless). An att…

Cloud SecurityVulnerabilities
P0
2023-02-14 00:00 UTC
Other

AWS EC2 Autoscaling Privilege Escalation Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A privilege escalation vulnerability in Amazon EC2 Autoscaling was identified. The CreateLaunchConfiguration action lacked PassRole validation, allowing users to launch EC2 instances with unauthorized roles. AWS fixed the issue for both CreateLaunchConfiguration and CreateAutoScalingGroup actions, implementing proper PassRole validation when using the instance-id option.

Cloud SecurityVulnerabilities
P10
44 45 46 47 48