Intel Free'd: A CYBERSECURITY INTELLIGENCE FEEDby: buf0rd

LATEST

Aggregated cybersecurity reporting, advisories and research. 168 matching records.
AUTO-POLL // 2026-08-18 20:55 UTC
RESET
2026-08-18 19:44 UTC
Vendor Research

CVE-2026-75935 and CVE-2026-75936 - Issue with Amazon ion-java - Memory-amplification denial of service

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-18 20:10 UTC

Bulletin ID: 2026-083-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/18/2026 12:30 PM PDT Description: ion-java is a Java library that implements the Amazon Ion data format specification. We identified CVE-2026-75935, memory-amplification denial of service via declared-length preallocation, and CVE-2026-75936, memory-amplification denial of service via highly compressed data expansion. Affected versions: < 1.12.0 Please refer to the article below for the most u…

Cloud SecurityVulnerabilitiesCVE-2026-75935CVE-2026-75936
P5
2026-08-18 18:26 UTC
Vendor Research

CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-18 18:30 UTC

Bulletin ID: 2026-082-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/18/2026 10:00 AM PDT Description: OpenSearch Dashboards is the open-source visualization and management UI for OpenSearch, and ships as part of Amazon OpenSearch Service. We identified CVE-2026-75897, an improper input validation in the capabilities route handler in OpenSearch Dashboards. The handler does not bound the size of the request payload, which might allow remote attackers to cause a …

Cloud SecurityVulnerabilitiesCVE-2026-75897
P5
2026-08-18 17:47 UTC
Security Journalism

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-18 18:35 UTC

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced

Cloud SecurityMicrosoft
P0
2026-08-18 17:04 UTC
Vendor Research

Security Hub Extended adds Supply Chain Security as its tenth category

AWS Security Blog · Michael Fuller · indexed 2026-08-18 17:30 UTC

Since February, we’ve grown AWS Security Hub Extended from 14 curated partners across 9 categories to 23 partners across 10. At Black Hat this month, 14 of those partners were at the Amazon Web Services (AWS) booth demoing live. Four of those partners delivered theater talks and ten were featured on SecurityLive streaming. We hosted […]

Cloud Security
P0
2026-08-18 14:00 UTC
Vendor Research

Staying Ahead of Adversarial AI Through Agentic Source Code Review

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-18 15:55 UTC

Written by: Alex Tselevich, Michael Maturi Introduction Adversarial misuse of AI has increased the risk of data theft and extortion events, because when proprietary source code is exposed, defenders must scramble to identify and patch vulnerabilities while attackers deploy machine-speed AI tools against them. By structuring the analysis process, enforcing skeptical validation steps, and injecting domain-specific human expertise directly into the pipeline, we’ve achieved a leap in efficacy. Comb…

AI SecurityCloud SecurityDFIRMicrosoftThreat IntelligenceVulnerabilitiesCVE-2026-13242CVE-2026-55803
P20
2026-08-18 12:49 UTC
Vendor Research

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

Rapid7 · Rapid7 Labs · indexed 2026-08-18 15:35 UTC

You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive program…

APT / Nation-StateCloud SecurityCybercrimeDFIRICS / OTMicrosoftPhishingRansomwareVulnerabilities
P15
2026-08-17 17:22 UTC
Vendor Research

Updates to your AWS Sign-In experience

AWS Security Blog · Vaibhav Chowla · indexed 2026-08-17 17:40 UTC

Amazon Web Services (AWS) is gradually introducing updates to the AWS Sign-In and sign-up experience to a limited number of customers. We’re sharing these changes so you will know what to expect as we gradually make the updated experience available to more customers. These updates include new options for creating and accessing AWS accounts. To […]

Cloud Security
P0
2026-08-17 15:15 UTC
Vendor Research

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

Tenable Blog · Clément Notin · indexed 2026-08-17 15:35 UTC

Learn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose Storm-0501 TTPs, backed by precision-engineered threat detection alerts.Key takeawaysStorm-0501 demonstrates that cloud-first ransomware groups have shifted from simple endpoint encryption to the total hijacking of cloud tenants.Storm-0501 systematically neutra…

AppleCloud SecurityCybercrimeDFIRMalwareMicrosoftRansomwareThreat ActorsThreat Intelligence
P15
2026-08-17 09:29 UTC
Security Journalism

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. "While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including

Cloud SecurityLinuxMalwareSecurity Research
P0
2026-08-17 07:58 UTC
Other

McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen

Security Affairs · Pierluigi Paganini · indexed 2026-08-17 08:40 UTC

A seller claims 1.7M McDonald’s employee records were stolen from Azure. An 8,000-row sample appears genuine, but its age and full size remain unconfirmed. A seller on a data-trading forum posted an 8,000-row sample this week claiming it came from McDonald’s own Azure tenant, part of a supposed 1.7 million-record employee directory obtained using stolen […]

Cloud Security
P0
2026-08-15 01:36 UTC
Vendor Research

The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure

Tenable Blog · Research Special Operations · indexed 2026-08-15 18:55 UTC

Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality.Key TakeawaysTaiwan's Ministry of Digital Affairs confirmed a near-autonomous AI cyber attack in July 2026 in which autonomous agents mapped 21 connected government systems, compromised 85 accounts,…

AI SecurityAPT / Nation-StateCloud SecurityNetwork SecurityThreat ActorsVulnerabilitiesCVE-2025-3248
P30
2026-08-13 21:23 UTC
Vendor Research

AWS Certificate Manager will discontinue email validation to prove domain validation for certificates

AWS Security Blog · Adam Aboudi · indexed 2026-08-15 18:55 UTC

Today, we’re announcing that AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027. If you use email validation for your ACM public certificates, you need to migrate to DNS validation before that date. This change aligns with the Certification Authority/Browser (CA/B) Forum’s industry-wide deprecation of email-based domain validation and […]

Cloud Security
P0
2026-08-13 17:46 UTC
Vendor Research

CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-081-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/13/2026 10:30 AM PDT Description: OpenSearch SQL plugin is a plugin that enables SQL and PPL query capabilities on OpenSearch clusters, including direct query integration with external data sources via Apache Spark. An issue exists where the Flint extension query handler validates SQL queries without sufficient restrictions, allowing a user with async query access to bypass the SQL grammar den…

Cloud SecurityVulnerabilitiesCVE-2026-18428
P5
2026-08-13 17:43 UTC
Vendor Research

CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-079-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/12/2026 11:45 AM PDT Description: OpenSearch is a community-driven, open-source search and analytics suite. We identified CVE-2026-18952, a missing input validation issue in the threat intelligence feed parser of the OpenSearch Security Analytics plugin. This issue may allow an authenticated user with the security_analytics_full_access role to perform server-side request forgery (SSRF) and rea…

Cloud SecurityThreat IntelligenceVulnerabilitiesCVE-2026-18952
P5
2026-08-12 22:16 UTC
Vendor Research

How AWS IAM role manager rethinks the starting point for IAM roles

AWS Security Blog · Zach Jiang · indexed 2026-08-15 18:55 UTC

When you build a new application or capability on Amazon Web Services (AWS), you want to focus on what you’re building. Getting a service running almost always begins with AWS Identity and Access Management (IAM). Many AWS services that act on your behalf need an IAM role, an identity the service assumes to access your […]

Cloud Security
P0
2026-08-12 19:52 UTC
Vendor Research

CVE-2026-19642 & CVE-2026-19643 - Memory-safety issues in the Base64 decoder in the AWS SDK for C++

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-080-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/12/2026 12:30 PM PDT Description: The AWS SDK for C++ is an open-source library that provides C++ developers with APIs for AWS services. Its core library includes a Base64 codec used by the generated service clients for a variety of features.We identified the following CVEs: - CVE-2026-19642 - Out-of-bounds write in the Base64 decoder in the AWS SDK for C++ - CVE-2026-19643 - Out-of-bounds rea…

Cloud SecurityVulnerabilitiesCVE-2026-19642CVE-2026-19643
P20
2026-08-12 18:46 UTC
Vendor Research

CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-078-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/12/2026 11:30 AM PDT Description: OpenSearch is a community-driven, open-source search and analytics suite. We identified CVE-2026-19311, a missing authorization issue in the Execute Monitor API of the OpenSearch Alerting plugin. This issue may allow an authenticated user with the alerting_full_access role to read, modify, or delete arbitrary index data via a crafted inline monitor request wit…

Cloud SecurityVulnerabilitiesCVE-2026-19311
P5
2026-08-12 11:13 UTC
Security Journalism

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below - CVE-2026-48362 (CVSS score: 10.0) - An operating system command injection vulnerability in ColdFusion that could

Cloud SecurityVulnerabilitiesCVE-2026-48362
P15
2026-08-12 08:04 UTC
Security Journalism

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more

Cloud SecurityThreat Intelligence
P0
2026-08-11 21:50 UTC
Vendor Research

Landing Zone Accelerator Independent Assessment Report for C5:2020 now available on AWS Artifact

AWS Security Blog · Kevin Donohue · indexed 2026-08-15 18:55 UTC

Organizations operating in Germany and across Europe increasingly need to demonstrate cloud security compliance under the Cloud Computing Compliance Criteria Catalogue (C5:2020), published by Germany’s Federal Office for Information Security (BSI). Last year, we introduced Landing Zone Accelerator on AWS support for digital sovereignty and today we’re announcing the availability of a new independent assessment […]

Cloud Security
P0
2026-08-11 21:10 UTC
Vendor Research

Patch Tuesday - August 2026

Rapid7 · Adam Barnett · indexed 2026-08-15 18:55 UTC

Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday, including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for one of the vulnerabilities published today, as well as public disclosure for two others, although the …

Cloud SecurityLinuxMicrosoftSecurity ResearchVulnerabilitiesCVE-2026-50656CVE-2026-55040CVE-2026-62832CVE-2026-63520CVE-2026-6726CVE-2026-6727CVE-2026-68820CVE-2026-72971
P95
2026-08-11 20:10 UTC
Security Journalism

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first. The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only

Cloud SecurityLinuxMicrosoftVulnerabilitiesCVE-2026-68820
P30
2026-08-11 19:08 UTC
Security Journalism

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter's. The flaw sat in the annotation tool, the feature that lets participants draw and type on a shared screen, and it asked nothing of the victim beyond being in the meeting. No click, no download, no prompt, and nothing on screen to show it

Cloud Security
P0
2026-08-11 18:53 UTC
Vendor Research

Summer 2026 SOC 1 report is now available with 185 services in scope

AWS Security Blog · Baj Bajwa · indexed 2026-08-15 18:55 UTC

Amazon Web Services (AWS) is pleased to announce that the Summer 2026 System and Organization Controls (SOC) 1 report is now available. The reports cover 185 services over the 12-month period from July 1, 2025–June 30, 2026, giving customers a full year of assurance. These reports demonstrate our continuous commitment to adhering to the heightened […]

Cloud Security
P0
2026-08-11 18:04 UTC
Vendor Research

Microsoft's August 2026 Patch Tuesday addresses 398 CVEs (CVE-2026-68820)

Tenable Blog · Research Special Operations · indexed 2026-08-15 18:55 UTC

42Critical355Important1Moderate0LowMicrosoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild.Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated as important and one rated as moderate. Our counts omitted two CVEs assigned by MITRE; CVE-2026-6726 and CVE-2026-6727.This month’s update includes patches for:.NET.NET Core.NET FrameworkAMD ZenActive Directory Certificate Servi…

Cloud SecurityLinuxMicrosoftMobile SecurityNetwork SecurityVulnerabilitiesCVE-2022-21919CVE-2022-26904CVE-2024-38193CVE-2025-21418CVE-2025-32709CVE-2026-61348CVE-2026-62714CVE-2026-62715CVE-2026-62716CVE-2026-62718CVE-2026-62720CVE-2026-62742CVE-2026-62745CVE-2026-62761CVE-2026-62776CVE-2026-62803CVE-2026-62807CVE-2026-62812CVE-2026-62814CVE-2026-6726CVE-2026-6727CVE-2026-68820CVE-2026-70307
P65
2026-08-11 16:12 UTC
Vendor Research

AWS successfully completed its 2025-26 NHS DSPT assessment

AWS Security Blog · Tariro Dongo · indexed 2026-08-15 18:55 UTC

Amazon Web Services (AWS) is pleased to announce its successful completion of the 2025-26 NHS Data Security and Protection Toolkit (NHS DSPT) assessment audit and achieving a status of Standards Exceeded. The NHS DSPT is an assessment that allows organizations to measure their performance against the National Data Guardian’s 10 data security standards. All organizations […]

Cloud Security
P0
2026-08-11 09:16 UTC
Security Journalism

Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. "Gunra is another variant in the ongoing trend of

AppleCloud SecurityNetwork SecurityRansomware
P15
123