IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,785 matching records.
AUTO-POLL // 2026-10-11 23:05 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 11

ACTIVE EXPLOITATION
P5
P5
COOL // 6 ARTICLES
SAT
Oct 10

RANSOMWARE
P1
P1
COOL // 11 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
RESET
2025-03-10 00:00 UTC
Other

Azure API Connections Expose Backend Secrets

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure API Connections were found to allow any reader on a subscription to access backend resources through a proxy endpoint, potentially exposing secrets from Key Vaults, databases, and third-party services. This vulnerability affects various Azure services and external APIs, enabling privilege escalation and unauthorized access to sensitive information.

Cloud SecurityVulnerabilities
P10
2025-03-10 00:00 UTC
Security Journalism

Untold Tales from Tactical Response | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Explore the inner workings of real-world cyberattacks and gain insight into the challenges faced by Huntress threat analysts. Discover the critical role of investigative techniques and their importance in uncovering and addressing these threats.

P0
2025-03-06 00:00 UTC
Security Journalism

How Huntress Achieved a Blazing Fast MTTR

Huntress · indexed 2026-09-07 17:30 UTC

The Huntress SOC has an average response time of 8 minutes. That means we can investigate threats, send incident reports, and resolve alerts in record time, shutting down attackers before they have a chance to act.

P0
2025-03-04 00:00 UTC
Other

Issue with AWS Temporary Elevated Access Management

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in AWS Temporary Elevated Access Management (TEAM) allows users to modify valid requests and spoof approvals due to improper input validation. This affects versions prior to 1.2.2 of TEAM for AWS IAM Identity Center. AWS has released a fix in version 1.2.2 and recommends customers upgrade to the latest release.

Cloud SecurityVulnerabilities
P0
2025-03-04 00:00 UTC
Security Journalism

Cybersecurity Threats in Healthcare [2025 Report] | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

These are the top cybersecurity threats in healthcare, according to Huntress’s 2025 survey of IT pros. Read the full report and learn how to avoid them.

P0
2025-03-03 15:55 UTC
Security Journalism

Hunt for RedCurl | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress discovered RedCurl activity across several organizations in Canada going back to 2023. Learn more about how this APT operates and how they aim to remain undetected while exfiltrating sensitive data.

APT / Nation-State
P0
2025-03-03 15:25 UTC
Other

Tool Release: Webcap

Black Lantern Security · TheTechromancer · indexed 2026-09-07 17:30 UTC

An ultra-lightweight web screenshot tool with advanced features.

P0
2025-02-27 00:00 UTC
Security Journalism

How Effective Is Your SAT Program? | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Discover how modernized security awareness training can transform your workforce into a cybersecurity-first culture. Learn Huntress' key strategies.

P0
2025-02-26 12:00 UTC
Government

Celebrating 1 Year of CSF 2.0

NIST Cybersecurity Insights · Stephen Quinn · indexed 2026-08-15 20:45 UTC

It has been one year since the release of the NIST Cybersecurity Framework (CSF) 2.0 ! To make improving your security posture even easier, in this blog we are: Sharing new CSF 2.0 resources; Taking a retrospective look at some resources and applications you may have missed; and Highlighting ways you can stay involved in our work, helping us help you implement better cybersecurity. NIST’s subject matter experts have worked over the last year to continue expanding the CSF 2.0 implementation reso…

P0
2025-02-26 00:00 UTC
Other

Silent Reaper (Azure LogicApp Secrets Control Plane Exfiltration)

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure iPaaS services, such as Logic Apps, separate the Control Plane (management) from the Data Plane (execution), but a flaw in this model enabled undetectable data harvesting. An attacker with Azure Reader access to workflow run history can silently extract sensitive data from executions, including secrets and API responses. This is possible because execution details are exposed via the Control Plane, bypassing Data Plane access controls. The root cause of this issue is the unintended exposur…

Cloud Security
P0
2025-02-26 00:00 UTC
Other

Vault Recon (Azure KeyVault Secrets Metadata Control Plane Exfiltration)

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Key Vault enforces a separation between the Control Plane (management) and Data Plane (secrets access). However, a flaw in this isolation allows unauthorized users to enumerate secrets and keys within a vault. By having Reader access or lesser privileges on a Key Vault, an attacker could leverage Azure Resource Explorer to access metadata about stored secrets. This is due to unintended exposure through the Control Plane, which should not provide insight into Data Plane resources. The root…

Cloud Security
P0
2025-02-26 00:00 UTC
Other

AWS EKS Logged ServiceAccount Tokens in Plaintext

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS EKS was logging ServiceAccount tokens in plaintext, including those used for AssumeRoleWithWebIdentity and connecting to the Kubernetes API server. This issue affected clusters between March 2020 and May 2021, potentially exposing sensitive credentials in CloudWatch logs.

Cloud Security
P0
2025-02-19 00:00 UTC
Other

Abusing AWS Serverless Image Handler Configuration Weakness

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS solution 'Dynamic Image Transformation for Amazon CloudFront', prior to version 6.2.6, contains a configuration weakness. The Lambda role doesn't constrain bucket access, and the environment variable can be set to a wildcard, allowing access to any bucket. This could potentially lead to unintended access to sensitive images across multiple buckets in the AWS account.

Cloud Security
P0
2025-02-11 00:00 UTC
Security Journalism

2025 Cybersecurity Threat Report | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress’ 2025 Cyber Threat Report is here! Explore the year's biggest threats—RATs, phishing, ransomware—and how evolving tactics demand smarter defense.

PhishingRansomware
P15
2025-02-10 00:00 UTC
Security Journalism

6 Months of Researching OAuth Application Attacks | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

There’s never just one termite. Huntress has spent the last 6 months researching and cracking down on malicious OAuth applications. Read about what we’ve found in this blog!

P0
2025-02-06 00:00 UTC
Security Journalism

Device Code Phishing: OAuth 2.0 Attacks in Google & Azure

Huntress · indexed 2026-09-07 17:30 UTC

All OAuth 2.0 implementations are equal. Some are just more equal than others. This blog covers device code phishing and compares OAuth implementations between Google and Azure. Does OAuth implementation impact the efficacy of hacker tradecraft? Find out here!

Cloud SecurityPhishing
P0
2025-01-30 00:00 UTC
Security Journalism

Why Every Business Needs Endpoint Protection | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Your endpoints are prime targets for cyberattacks. Learn why protecting them is vital and how endpoint security can shield your business from becoming an easy mark.

P0
2025-01-28 06:43 UTC
Other

Cat’s out of the bag: Lynx Ransomware-as-a-Service

Group-IB · indexed 2026-09-07 17:30 UTC

In this blog, we observed how the Lynx Ransomware-as-a-Service (RaaS) group operates, detailing the workflow of their affiliates within the panel, their cross-platform ransomware arsenal, customizable encryption modes, and advanced technical capabilities.

Ransomware
P15
127 128 129 130 131