IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,456 matching records.
AUTO-POLL // 2026-10-10 15:30 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P2 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P2
P2
COOL // 9 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2020-11-22 00:00 UTC
Other

IAM privilege escalation in multiple GCP services

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Composer, Dataflow, Dataproc, Dataprep and Data Fusion all used the Compute Engine default service account by default and relied on product-level IAM permissions without requiring the iam.serviceAccount.actAs permission, meaning that users of these services could elevate their privileges. Following disclosure, GCP changed these services to require this permission.

Vulnerabilities
P10
2020-10-17 00:00 UTC
Other

AI Hub Jupyter Notebook instance CSRF

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AI Hub Jupyter Notebook server lacked a check of the Origin header that led to a CSRF vulnerability. An attacker could have read sensitive data and execute arbitrary actions in customer environments.

Vulnerabilities
P0
2020-10-01 00:00 UTC
Other

Google Cloud Shell XSS to RCE Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Google Cloud Shell allowed escalation from XSS to full instance takeover as root. The attack exploited an XSS in the markdown preview functionality to read sensitive files, obtain the instance's private key and hostname, and gain SSH access as root. The issue affected the Eclipse Theia-based editor used in Cloud Shell.

Cloud SecurityVulnerabilities
P15
2020-06-15 00:00 UTC
Other

GKE and EKS CAP_NET_RAW metadata service MITM root privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An attacker with access to a hostNetwork=true container with CAP_NET_RAW capability can listen to all the traffic going through the host and inject arbitrary traffic, allowing to tamper with most unencrypted traffic (HTTP, DNS, DHCP, ...), and disrupt encrypted traffic. In GKE the host queries the metadata service at http://169[.]254.169.254 to get information, including the authorized SSH keys. By manipulating the metadata service responses and injecting our own SSH key, it is possible to gain…

Vulnerabilities
P10
2020-03-08 00:00 UTC
Other

Google wide domain check bypass

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Google's common JavaScript library allowed bypassing domain validation checks across multiple Google products. By using a backslash character in URLs, an attacker could make the regex parser and browser disagree on the authority (domain) portion of a URL, allowing injection of arbitrary domains that pass whitelisting checks.

Vulnerabilities
P0
2020-01-30 00:00 UTC
Other

Azure App Service RCE

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A Vulnerability in App Service could allow an unprivileged function run by the user to execute code in the context of NT AUTHORITY\system, thereby escaping the sandbox. This vulnerability allowed cross-account access when using the Free/Shared tier.

Cloud SecurityVulnerabilities
P15
2019-11-29 00:00 UTC
Other

Google Cloud Platform VRP Prize Writeup

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability was discovered in Google Cloud Platform's AI Hub service, allowing unrestricted file uploads. This could potentially lead to bypassing Same-Origin Policy by uploading SWF files, enabling CSRF attacks across browsers, and exploiting CVE-2014-8453 on IE with Adobe Reader installed. The issue resulted in a $1337 bounty reward.

Cloud SecurityVulnerabilitiesCVE-2014-8453
P5
2019-08-31 00:00 UTC
Other

Google App Engine RCE Worth $36k

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Researcher discovered access to non-production Google App Engine environments and internal APIs. This allowed configuring internal settings like Service Account IDs and quotas. Google considered it RCE due to their infrastructure. Access was blocked and a $36,337 reward issued.

Vulnerabilities
P15
2019-06-18 00:00 UTC
Other

IAM privilege escalation via undocumented CodeStar API

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The AWS CodeStar service had an undocumented API (codestar:CreateProjectFromTemplate) that allowed users with broadly-scoped CodeStar permissions to create a CodeStar project. As part of the creation process, AWS would create a new CodeStarWorker IAM policy & attach it to the user making the call. This policy granted full access to over 50 AWS services, including iam:AttachRolePolicy, iam:AttachUserPolicy and iam:PutRolePolicy permissions, which would allow the user to escalate to full administ…

Cloud SecurityVulnerabilities
P10
2018-01-30 07:00 UTC
Security Journalism

Deep Dive: Kaseya VSA Mining Payload

Huntress · indexed 2026-09-07 17:30 UTC

For many of us in the Managed Services Provider market, we were rocked with news of a vulnerability in Kaseya’s VSA product. The purpose of this blog is to shine technical light on what the Huntress ThreatOps team observed and analyzed thus far.

Vulnerabilities
P0
2016-04-06 00:00 UTC
Security Journalism

How My StubHub Account Got Hacked | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

If you have a StubHub account, you are open to a major vulnerability of having your StubHub hacked. Learn more about how you are at risk & how Huntress' Security Awareness Training can help.

Vulnerabilities
P0
47 48 49