IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,456 matching records.
AUTO-POLL // 2026-10-10 15:30 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P2 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P2
P2
COOL // 9 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2022-05-09 00:00 UTC
Other

Synlapse

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Synapse Analytics and Azure Data Factory were vulnerable to cross-tenant access and code execution. This was made possible via a combination of (1) a shell injection RCE vulnerability in the integration runtime, (2) credentials for multiple customers stored on a shared host and (3) an insecure management server API.

Cloud SecurityVulnerabilities
P15
2022-04-20 00:00 UTC
Other

AWS SSM agent local privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The Amazon SSM Agent (used for managing EC2 instances via Amazon Systems Manager) created a world-writable sudoers file, which would have allowed local attackers to inject Sudo rules and escalate privileges to root. This could occur in certain situations involving a race condition.

Cloud SecurityVulnerabilities
P10
2022-04-11 00:00 UTC
Other

AWS RDS local file read

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability was discovered in the Aurora PostgreSQL log_fdw extension for Amazon Relational Database Service (RDS), allowing an attacker to read files on the EC2 host and obtain credentials for an internal AWS service.

Cloud SecurityVulnerabilities
P0
2022-03-09 00:00 UTC
Other

Logic Apps privilege escalation to root

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Logic Apps use API Connections to authenticate actions to services. Having Contributor access to an Azure Resource Manager (ARM) API Connection would allow someone to create arbitrary role assignments as the connected user. This was supposed to be limited to actions at the Resource Group level, but an attacker could escape to the Subscription or Root level with a path traversal payload. The root cause of this behavior was that such a payload would meet the Swagger API definition, and it w…

Cloud SecurityVulnerabilities
P10
2022-02-15 00:00 UTC
Other

Cognito User Group spoofing

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Opsmorph discovered an improper access control vulnerability in authorization logic common in applications built on AWS. The vulnerability means a user with permission to create a new Cognito User Group could fool authorization checks into thinking that the user is in any other existing Cognito User Group in the same User Pool, referred to as user group spoofing. When API Gateway is secured with a Cognito User Pool Authorizer it concatenates group names from the identity token into a comma sepa…

Cloud SecurityVulnerabilities
P0
2021-12-30 00:00 UTC
Other

Bypassing Identity-Aware Proxy in Google Cloud

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Google Cloud Platform's Identity-Aware Proxy (IAP) allowed attackers to bypass authentication and access IAP-secured web applications. The exploit involved creating a malicious IAP-secured app using the target's OAuth client ID, configuring query parameter-based routing to capture redirect tokens, and using these tokens to hijack authorized sessions.

Cloud SecurityVulnerabilities
P0
2021-12-28 00:00 UTC
Other

Dataflow RCE via unauthenticated JMX service

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Dataflow worker nodes ran an unauthenticated Java Management Extensions (JMX) service that under certain circumstances would be exposed to the Internet, thus allowing unauthenticated remote code execution (RCE) as root in an unprivileged container. The impact of the vulnerability depended on which service account qA assigned to Dataflow worker nodes (by default, that would be the Google Compute Engine default service account, which has the project-wide Editor role assigned).

Vulnerabilities
P15
2021-12-28 00:00 UTC
Other

Google Cloud Shell command injection

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability was discovered in Cloud Shell that enabled command injection and remote shell access. The "Open in Cloud Shell" functionality allowed a user to provide values for both the "git_repo" and "go_get_repo" parameters, which would clone the target repo in the user's environment. While "git_repo" was validated against a list of trusted repos, "go_get_repo" was not. Therefore, an attacker could have supplied a trusted repository as "git_repo" and an arbitrary command in the "go_get_repo…

Cloud SecurityPhishingVulnerabilities
P0
2021-12-07 00:00 UTC
Other

LPE vulnerability in Eltima (3rd-party cloud desktop driver)

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Several cloud desktop solutions rely on a 3rd-party library called Eltima SDK to provide USB over Ethernet capabilities, to allow users to connect and share local devices such as webcams. SentinelLabs discovered vulnerabilities in Eltima drivers, including proprietary versions used by several cloud services (among them AWS Workspaces), that would allow unprivileged users to escalate privileges to kernel mode.

Cloud SecurityLinuxVulnerabilities
P0
2021-12-02 00:00 UTC
Other

AWS SageMaker Jupyter Notebook instance CSRF

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS SageMaker Notebook server lacked a check of the Origin header that led to a CSRF vulnerability. An attacker could have read sensitive data and execute arbitrary actions in customer environments. The exact same issue existed in GCP previously.

Cloud SecurityVulnerabilities
P0
2021-09-22 00:00 UTC
Other

Predictible seed in Anthos Identity Service LDAP module

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability was discovered in the Anthos Identity Service (AIS) LDAP module of Anthos clusters on VMware versions 1.8 and 1.8.1 where a seed key used in generating keys is predictable. With this vulnerability, an authenticated user could add arbitrary claims and escalate privileges indefinitely.

Vulnerabilities
P0
2021-09-21 00:00 UTC
Other

AWS Workspace client RCE

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

If a user with AWS WorkSpaces 3.0.10-3.1.8 installed visits a page in their web browser with attacker controlled content, the attacker can get zero click RCE under common circumstances.

Cloud SecurityVulnerabilities
P15
2021-08-26 00:00 UTC
Other

ChaosDB

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure's Cosmos DB database service was vulnerable to remote account takeover. Any Azure user could gain full admin access to other customers' Cosmos DB instances without authorization. The vulnerability had a trivial exploit that doesn't require any previous access to the target environment.

Cloud SecurityVulnerabilities
P0
2021-06-13 00:00 UTC
Other

Privilege escalation on Dialogflow cloud platform

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A privilege escalation vulnerability was discovered in Google's Dialogflow cloud platform. When downgrading a user's role from Developer to Reviewer, the permissions were not properly updated, allowing the user to retain Developer-level access. This issue persisted in the Google Cloud Console, where role changes resulted in additive permissions instead of replacements.

Cloud SecurityVulnerabilities
P10
2021-06-01 00:00 UTC
Other

OMIGOD

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure forces the install of an agent on Linux VMs, which contained a vulnerability that would grant root RCE if an attacker could send a web request to them. Initially, Microsoft did not update the agent automatically, and so customers had to patch manually, but a few days later they began patching some services remotely.

Cloud SecurityLinuxMicrosoftVulnerabilities
P15
2021-04-30 00:00 UTC
Other

Password Reset Code Brute-Force Vulnerability in AWS Cognito

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in AWS Cognito's password reset function allowed attackers to brute-force the six-digit reset code, potentially leading to account takeovers. Using concurrent HTTP requests, an attacker could make up to 1587 guesses instead of the documented limit of 20. The issue affected accounts without multi-factor authentication and was fixed by AWS on April 20, 2021.

Cloud SecurityVulnerabilities
P0
2021-03-17 00:00 UTC
Other

Privilege escalation in GCP OS Login

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

GCP provides an OS Login service for managing SSH access to compute instances using IAM roles. An attacker could abuse this feature via LXD, Docker (if available on the target system) and DHCP poisoning of the metadata server to escalate their privileges on a Google Compute Engine VM.

Vulnerabilities
P10
2021-03-09 00:00 UTC
Other

Azure Linux VM extension credential leak

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in the Azure Linux VM extension mechanism allowed an unprivileged user to leak any Azure VM extension’s private data. An attacker could have abused this to gain credentials for the VM itself as well as credentials for extensions associated with the VM. Paired with the design of the VMAccess extension (an official Azure extension for managing VM credentials), this could have been used to achieve privilege escalation, as an unprivileged attacker would have been able to elevate the…

Cloud SecurityLinuxVulnerabilities
P10
46 47 48 49