IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,785 matching records.
AUTO-POLL // 2026-10-11 22:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 11

ACTIVE EXPLOITATION
P5
P5
COOL // 6 ARTICLES
SAT
Oct 10

RANSOMWARE
P1
P1
COOL // 11 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
RESET
2025-04-17 05:00 UTC
Security Journalism

Tales of Too Many RMMs

Huntress · indexed 2026-09-07 17:30 UTC

In a highly interconnected world, remote monitoring and management (RMM) tools are critical to reducing cost and increasing efficiencies. However, these tools pose challenges and even significant risk if not properly managed.

P0
2025-04-16 05:00 UTC
Security Journalism

Why App Allowlisting & Zero Trust Alone Won't Save You | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

App Allowlisting is a good preventative software tool, but it's not enough. Learn why a layered security approach with detection and response is crucial to protect against today's cyber threats.

P0
2025-04-15 00:00 UTC
Other

Burning Data with Malicious Firewall Rules in Azure SQL

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Varonis Threat Labs discovered a vulnerability in Azure SQL Server allowing privileged users to create malicious firewall rules that can delete Azure resources when triggered by admin actions. The exploit involves manipulating rule names via TSQL to inject destructive commands, potentially leading to large-scale data loss in affected Azure accounts.

Cloud SecurityNetwork SecurityVulnerabilities
P0
2025-04-11 08:50 UTC
Other

CISOs Top Order Of Business: Cyber Risk Reduction & Management

Group-IB · indexed 2026-09-07 17:30 UTC

For modern CISOs, cyber risk management and reduction are nonstop challenges. But this blog offers exactly what you need to build a strategy that empowers you to manage and mitigate threats—cutting through the noise of an otherwise demanding role.

P0
2025-04-11 00:00 UTC
Government

Activités de post-exploitation dans Fortinet FortiGate (11 avril 2025)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Fortinet a publié le 10 avril 2025 un billet de blogue [1] indiquant l'utilisation d'une technique de post-exploitation qui permet une atteinte à la confidentialité des données de l'ensemble du système des équipements Fortigate affectés. Cette technique repose sur l'utilisation d'un lien...

Network Security
P0
2025-04-10 05:00 UTC
Security Journalism

Ransomware Initial Access Brokers Exposed

Huntress · indexed 2026-09-07 17:30 UTC

Discover how a seemingly simple brute force attack led to the uncovering of a suspected ransomware-as-a-service operation. This ecosystem appears to be leveraged by initial access brokers, driving an illicit and complex network of cybercrime.

CybercrimeRansomware
P15
2025-04-09 05:00 UTC
Security Journalism

How EDR and ITDR Elevate Your Security

Huntress · indexed 2026-09-07 17:30 UTC

Threat actors are now exploiting both endpoints and identities in the latest cyberattacks. Learn about the rise of identity-based threats and why a combined EDR and ITDR approach is crucial for your cybersecurity.

Threat Actors
P0
2025-04-09 00:00 UTC
Other

Path Traversal in AWS SSM Agent Plugin ID Validation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A path traversal vulnerability in AWS SSM Agent's ValidatePluginId function allows attackers to create directories and execute scripts in unintended locations on the filesystem. This could lead to privilege escalation or other malicious activities, as files may be written to or executed from sensitive areas of the system with root privileges.

Cloud SecurityVulnerabilities
P10
2025-04-03 00:00 UTC
Government

[MàJ] Vulnérabilité dans les produits Ivanti (03 avril 2025)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

**\[Mise à jour du 11 avril 2025\]** Le CERT-FR a connaissance d'une preuve de concept publique permettant de provoquer une exécution de code arbitraire à distance. **[Mise à jour du 04 avril 2025]** Le CERT-FR a connaissance d'une preuve de concept publique permettant de provoquer un arrêt du...

P0
2025-04-02 06:02 UTC
Other

The beginning of the end: the story of Hunters International

Group-IB · indexed 2026-09-07 17:30 UTC

Learn about technical details on the ransomware and Storage Software tool, how the criminals use the affiliate panel as well as information on the Hunters International ransomware group from its emergence to the end of the operation.

Ransomware
P15
2025-04-02 05:00 UTC
Security Journalism

The Unwanted Guest

Huntress · indexed 2026-09-07 17:30 UTC

Threat actors are enabling the built-in Windows Guest account to maintain persistence. Learn how they gain access and how to detect this activity.

MicrosoftThreat Actors
P0
2025-04-01 05:00 UTC
Security Journalism

Scalable EDR Advanced Agent Analytics with ClickHouse

Huntress · indexed 2026-09-07 17:30 UTC

Learn how and why Huntress uses ClickHouse for scalable EDR agent analytics, ensuring availability and stability for millions of endpoints while maintaining cost efficiency.

P0
2025-04-01 00:00 UTC
Other

ImageRunner: Privilege Escalation Vulnerability in GCP Cloud Run

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An attacker with `run.services.update` and `iam.serviceAccounts.actAs` permissions but without explicit registry access could deploy new revisions of Cloud Run services that pulled private container images stored in the same GCP project. This was possible because Cloud Run uses a service agent with the necessary registry read permissions to retrieve these images, regardless of the caller’s access level. By updating a service revision and injecting malicious commands into the container's argumen…

Vulnerabilities
P10
2025-03-31 05:00 UTC
Security Journalism

Why cybersecurity matters for your business.

Huntress · indexed 2026-09-07 17:30 UTC

Doing nothing now can cost your business more than money. Learn why proactive cybersecurity steps keep your business resilient and save costs in the long term.

P0
2025-03-28 05:00 UTC
Security Journalism

Securing Endpoints from Common Vulnerabilities

Huntress · indexed 2026-09-07 17:30 UTC

Learn how to lock down common endpoint vulnerabilities like weak passwords and unpatched software to secure your systems against threats like phishing and malware.

MalwarePhishing
P0
2025-03-26 09:03 UTC
Other

Unmasking the Classiscam in Central Asia

Group-IB · indexed 2026-09-07 17:30 UTC

Scams like Classiscam automate fake websites to steal financial data, exploiting digitalization’s rise in developing countries, making fraud both effective and hard to detect. In this blog, we dissect the inner working of the scam and its prevalence in Central Asia.

CybercrimeMicrosoft
P0
2025-03-26 00:00 UTC
Other

CodeQLEAKED - CodeQL Supply Chain Attack via Exposed Secret

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A publicly exposed GitHub token in CodeQL workflow artifacts could allow attackers to execute malicious code in repositories using CodeQL, potentially leading to source code exfiltration, secrets compromise, and supply chain attacks. The vulnerability stemmed from a debug artifact containing environment variables, which could be downloaded and exploited within a 1-2 second window.

Vulnerabilities
P0
2025-03-25 00:00 UTC
Other

Entra ID Bug Creates Immutable Users

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A bug in Entra ID restricted management administrative units allowed creating immutable users that couldn't be modified or disabled, even by Global Administrators. This could enable an attacker to protect a compromised account from containment. The issue was caused by a timing vulnerability when removing users from restricted AUs and required specific steps to remediate affected accounts.

MicrosoftVulnerabilities
P0
2025-03-21 00:00 UTC
Other

AWS CDK CLI Issue with Custom Credential Plugins

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS identified a security issue in the AWS CDK CLI versions 2.172.0-2.178.1 where temporary credentials from custom credential plugins could be printed to console output. This potentially exposes sensitive information to users with access to the console. The issue affects plugins that include an expiration property when returning temporary credentials.

Cloud Security
P0
2025-03-20 09:09 UTC
Other

The Cybercriminal with Four Faces: Revealing Group-IB’s Investigation into ALTDOS, DESORDEN, GHOSTR and 0mid16B

Group-IB · indexed 2026-09-07 17:30 UTC

Following the arrest of the cybercriminal behind the aliases ALTDOS, DESORDEN, GHOSTR, and 0mid16B, Group-IB provides a deep dive into his activities, uncovering striking similarities and unmasking the cybercriminal that breached more than 90 instances of data leaks worldwide over the span of four years in operation.

Data BreachesDFIR
P0
126 127 128 129 130