IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,456 matching records.
AUTO-POLL // 2026-10-10 14:30 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P2 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P2
P2
COOL // 8 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2023-02-14 00:00 UTC
Other

Azure App Service on Azure Stack Hub privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A privilege escalation vulnerability was discovered in Azure App Service on Azure Stack Hub (an on-prem private cloud offering). To exploit this vulnerability, an attacker must have access to the targeted worker role and the ability to deploy a malicious application within the worker. The attack itself is carried out locally on the worker role where a malicious application has been deployed. Exploiting this vulnerability could grant an attacker the ability to access and modify content of a targ…

Cloud SecurityVulnerabilities
P10
2023-01-19 00:00 UTC
Other

EmojiDeploy

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Multiple Azure Web services use a source control management (SCM) panel powered by Kudu and enabled by default. These services were all susceptible to a CSRF vulnerability due to an overly-permissive regular expression (regex) in a filter for malformed origins. This allowed origin bypass when using a domain name structured as 'victim.scm.azurewebsites.net._.attacker.com' (note the use of '._.', which looks like an emoji). Thus, if a target Azure user were tricked into visiting a specially craft…

Cloud SecurityVulnerabilities
P15
2023-01-18 00:00 UTC
Other

Azure AD Flaw Allowed SAML Token Persistence

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Azure Active Directory allowed users to retain access to SAML applications after their assignment was removed. Attackers could exploit this to establish persistence and elevate privileges on targeted SAML applications. The flaw was triggered by chaining sign-in with additional application and specific parameters in the token request, bypassing user assignment verification.

Cloud SecurityVulnerabilities
P0
2023-01-15 00:00 UTC
Other

XSS in Google Cloud Theia notebooks

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

This vulnerability chain exploits a Cross-Site Scripting (XSS) flaw (CVE-2021-41038) within the Theia IDE used in Google Vertex AI Workbench. An attacker could inject malicious JavaScript code into the Theia IDE. This code could then be used to steal the OAuth token associated with the project's default Compute Engine service account, because when a user-managed Vertex AI Workbench instance is created, it utilizes the project's default Compute Engine service account. At the time, this default s…

Cloud SecurityVulnerabilitiesCVE-2021-41038
P5
2023-01-13 00:00 UTC
Other

Bypassing authorization in Google Cloud Workstations

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Several vulnerabilities were present in how Google Cloud Shell (ssh.cloud.google.com) handled OAuth credentials. These included an open-redirect vulnerability, where attackers could redirect users to malicious sites to capture their credentials, and a validation bypass that allowed tokens to be submitted to user-defined URIs, circumventing normal security checks. Additionally, Google Cloud Workstations did not correctly tie the state parameter to the session that generated it, which allowed val…

Cloud SecurityPhishingVulnerabilities
P0
2023-01-12 00:00 UTC
Other

Client-Side SSRF to Google Cloud Project Takeover

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Vertex AI Workbench allowed attackers to take over victims' Google Cloud projects through client-side SSRF. The initial bug involved unauthorized access to authentication tokens, which was later fixed. A bypass was later discovered (and also fixed) using open redirects in Feedburner and CSRF token manipulation.

Cloud SecurityVulnerabilities
P0
2023-01-06 00:00 UTC
Other

IAP CORS Misconfiguration Allows Email Disclosure

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A CORS misconfiguration in Google Cloud's Identity-Aware Proxy (IAP) could have allowed attackers to disclose the email address of an authenticated user in websites protected by IAP, by convincing the user to connect to an attacker-controlled domain. This vulnerability enabled attackers to exploit CORS settings to access sensitive email information of both authenticated and unauthenticated users (with the latter requiring additional social engineering).

Cloud SecurityVulnerabilities
P0
2022-12-29 00:00 UTC
Security Journalism

OWASSRF Explained | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress' analysis of a new exploit chain (called OWASSRF) that can lead to critical remote code execution on unpatched Exchange hosts.

MicrosoftVulnerabilities
P15
2022-12-15 00:00 UTC
Other

Azure Serverless Functions escape to host

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

In Azure Serverless Functions, a new container is generated by the host for every function, which is then terminated and deleted after several minutes. Palo Alto discovered that an API call was available to bind one path to another within the container (called "init_server_pkg_mount_BindMount") that could be called by a low-privileged user but executed with root privileges. This could enable a malicious tenant to escalate their privileges to root, and then escape their container by abusing the …

Cloud SecurityLinuxNetwork SecurityVulnerabilities
P0
2022-12-13 00:00 UTC
Other

ECR Public vulnerability in undocumented API

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Elastic Container Registry (ECR) Public could have allowed a malicious actor to delete, update, or create ECR Public images, layers, or tags in registries and repositories belonging to any other AWS account, by abusing undocumented API calls. A malicious actor could have exploited this to delete any or all images in the Amazon ECR Public Gallery or update the content of any existing image to inject malicious code on any machine that would pull and run it.

Cloud SecurityVulnerabilities
P0
2022-12-01 00:00 UTC
Other

Hell's Keychain

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

IBM Cloud Databases for PostgreSQL was vulnerable to an attack sequence comprised of PostgreSQL privilege escalation via SQL Injection and chaining of three secrets scattered in the service environment (a K8s service account token, a private container registry password, and CI/CD server credentials), which were abusable due to overly permissive network access to internal build servers. A malicious actor could have exploited this vulnerability to remotely execute code in other customers’ environ…

Vulnerabilities
P10
2022-11-21 00:00 UTC
Other

AWS AppSync confused deputy via ServiceRoleArn

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The AWS AppSync service could be coerced to assume arbitrary roles in other customers' accounts which trusted the AppSync service. This was due to insufficient validation of a serviceRoleArn parameter (caused by a case-sensitivity parsing issue). With this vulnerability, if an adversary knew the ARN of the role associated with AppSync in the target account, they could use it invoke arbitrary AWS API calls.

Cloud SecurityVulnerabilities
P0
2022-11-07 00:00 UTC
Other

Azure Devops account takeover via dangling subdomain takeover

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Binary Security discovered and registered two dangling cloudapp.azure.com subdomains corresponding to subdomains at visualstudio.com. Had these been discovered and registered by an attacker, this would have been equivalent to a 1-click vulnerability for Azure DevOps: the attacker could have crafted a URL referring to the sign-in API for Azure DevOps Services (app.vssps.visualstudio.com) using one of the two subdomains in the "reply_to" field (since subdomains of visualstudio.com would be allowe…

Cloud SecurityVulnerabilities
P0
2022-11-01 00:00 UTC
Other

CosMiss

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Cosmos DB notebooks lacked an authentication check, meaning that if an attacker somehow had prior knowledge of a notebook’s temporary ‘forwardingId’ (a 128bit cryptographically random GUID assigned to a short-lived workspace that expires after an hour), they could gain full permissions on the notebook, including read and write access and the ability to modify the file system of the container running the notebook. These permissions would suffice for an attacker to obtain remote code execution (R…

Vulnerabilities
P15
2022-10-31 00:00 UTC
Security Journalism

ConnectWise/R1Soft RCE & Supply Chain Risks | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress has validated an initial report for an authentication bypass and sensitive file leak present in the Java framework “ZK”, used within the ConnectWise R1Soft software Server Backup Manager SE.

Vulnerabilities
P25
2022-10-25 00:00 UTC
Other

Azure CLI code injection vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure CLI contained a code injection vulnerability that could be exploited in a scenario where the host runs a command where parameter values have been provided by an external untrusted source - these could be specially crafted in such a way as to exploit the vulnerability, leading to remote code execution on the host. The vulnerability is only applicable when the Azure CLI command is run on a Windows machine and with any version of PowerShell and when the parameter value contains the `&` or `|…

Cloud SecurityMicrosoftVulnerabilities
P15
2022-10-24 00:00 UTC
Other

Docker Command Escaping in GitHub Actions Runner

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in the GitHub Actions Runner allowed untrusted inputs in environment variables to escape and modify docker command invocations. This affected jobs using container actions, job containers, or service containers. The issue has been patched in multiple versions of the runner.

Vulnerabilities
P0
2022-10-11 00:00 UTC
Other

Azure Arc-enabled Kubernetes privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Arc allows customers to connect on-premises Kubernetes clusters to Azure. This is facilitated by middleware (the Azure Arc-enabled Kubernetes agent) which includes a "cluster connect" feature in the form of a reverse proxy. A vulnerability in this feature could allow an unauthenticated user to elevate their privileges and potentially gain remote administrative control over any Azure Arc-enabled cluster, as long as they know its randomly generated external DNS endpoint. Azure Stack Edge de…

Cloud SecurityVulnerabilities
P10
2022-09-01 00:00 UTC
Other

Synapse Spark LPE

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Synapse Analytics is an analytics service for processing data using various runtimes, among them Apache Spark. Synapse provided users the capability to mount Azure File Shares to their Apache Spark Pools via a script called filesharemount.sh that would execute with elevated privileges. This script would mount the File Share to the /synfs directory. There was a race condition in the script where, if successfully exploited, a user could execute the chown command to change the ownership of a…

Cloud SecurityMicrosoftVulnerabilities
P0
2022-08-17 00:00 UTC
Other

Remote Code Execution via GitHub Import

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A critical vulnerability in GitLab's GitHub import feature allows remote code execution. The issue stems from improper handling of Sawyer::Resource objects, enabling injection of Redis commands. This can be escalated to execute arbitrary bash commands on the SaaS managed service as well as self-hosted GitLab servers, potentially leading to full system compromise.

Vulnerabilities
P25
2022-08-12 00:00 UTC
Other

Actions Core Delimiter Injection Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The @actions/core package had a delimiter injection vulnerability in the exportVariable function. Attackers could use a known delimiter to break out of a specific variable and assign values to other arbitrary variables. This may have allowed modification of path or environment variables without the intention of workflow or action authors.

Vulnerabilities
P0
2022-08-11 00:00 UTC
Other

Cloud SQL escape to host

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

In GCP's case, they introduced a modification to the Cloud SQL's PostgreSQL engine allowing the role assigned to the tenant (cloudsqlsuperuser) to arbitrarily change the ownership of a table to any user or role in the database. Thus, an attacker could (1) create a new table, (2) create an index function with a malicious payload, and (3) change the table owner to GCP’s superuser role (cloudsqladmin). Next, by initiating an ANALYZE command, the malicious function is executed with GCP’s superuser …

Cloud SecurityVulnerabilities
P10
2022-08-10 00:00 UTC
Other

Google Cloud Shell command injection

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability was discovered in Cloud Shell that enabled command injection and remote shell access. By manipulating the "project" parameter, an attacker could have cause an unencoded Python script execution flaw. Exploiting this flaw, they could inject a command to display the contents of the "/etc/passwd" file, successfully execute arbitrary commands and obtain remote shell access. However, the impact of this is unclear, as an attacker would seemingly only be able to gain such a remote shell…

Cloud SecurityVulnerabilities
P0
2022-07-16 00:00 UTC
Other

Persistence Vulnerability in GCP Cloud Workstations

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A critical security flaw in Google Cloud Platform's Cloud Workstations allows unauthorized access and privilege escalation. The vulnerability stems from persistent session management, enabling users to access and exploit credentials of higher-privileged users. This can lead to impersonation, creation of new service accounts with elevated permissions, and bypassing of access controls.

Cloud SecurityVulnerabilities
P10
2022-07-12 00:00 UTC
Other

Microsoft Azure Site Recovery DLL hijacking

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The Microsoft Azure Site Recovery suite contained a DLL hijacking flaw that allowed for privilege escalation from any low privileged user to SYSTEM on hosts where this service was installed. Incorrect permissions on the cxprocessserver service's executable directory allowed new files to be created in it by any user. Since the service ran automatically and with SYSTEM privileges and attempted to load DLLs from the directory, this allowed for a DLL hijacking / planting attack.

Cloud SecurityMicrosoftVulnerabilities
P10
2022-06-28 00:00 UTC
Other

FabricScape (CVE-2022-30137) - Azure Service Fabric privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Service Fabric allows Linux containers to escalate their privileges in order to gain root privileges on the node, and then compromise all of the nodes in the cluster. An attacker would need to have read/write access to the cluster, and the vulnerability could be exploited on containers that are configured to have runtime access, but this is granted by default to every container. Though the bug exists in both the Windows and Linux versions, it is only exploitable on Linux.

Cloud SecurityLinuxMicrosoftVulnerabilitiesCVE-2022-30137
P15
2022-06-13 00:00 UTC
Other

Privilege escalation and file poisoning in Synapse Analytics

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Tenable Research discovered a privilege escalation flaw that allows a user to escalate privileges to that of the root user within the context of a Spark VM. They also discovered a separate flaw that allows a user to poison the hosts file on all nodes in their Spark pool, which would allow an attacker to redirect subsets of traffic and snoop on services users generally do not have access to.

Vulnerabilities
P10
45 46 47 48 49