IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 568 matching records.
AUTO-POLL // 2026-10-02 22:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P6
P6
COOL // 45 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-10-02 20:25 UTC
Vendor Research

CVE-2026-104019 - OS command injection in the Studio Space startup script in Amazon SageMaker Distribution

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-02 20:40 UTC

Bulletin ID: 2026-125-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/02/2026 13:00 PM PDT Description: Amazon SageMaker Unified Studio is an AWS service that unifies data, analytics, and AI development. It lets you find and access your organization's data and act on it with integrated, purpose-built tools. We identified CVE-2026-104019, an issue with the startup of SageMaker Spaces in SageMaker Unified Studio. The startup script in a SageMaker Space performs a …

Cloud SecurityVulnerabilitiesCVE-2026-104019
P5
2026-10-02 19:21 UTC
Vendor Research

CVE-2026-103956, CVE-2026-103957, and CVE-2026-103958 - Issues in Loom for AWS

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-02 19:25 UTC

Bulletin ID: 2026-124-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/02/2026 12:00 PM PDT Description: Loom is an AWS Labs open-source AI agent orchestration platform. We have identified and addressed three issues in Loom for AWS, described below. We recommend upgrading to the latest version (1.7.0) and ensuring any forked or derivative code is patched to incorporate the new fixes. - CVE-2026-103956 ‐ Authentication bypass in Loom for AWS (CWE-306, CWE-1188) An…

AI SecurityCloud SecurityVulnerabilitiesCVE-2026-103956CVE-2026-103957CVE-2026-103958
P15
2026-10-02 17:02 UTC
Security Journalism

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 17:45 UTC

Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below - CVE-2026-63688 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an

Cloud SecurityVulnerabilitiesCVE-2026-63688
P5
2026-10-02 16:38 UTC
Vendor Research

CVE-2026-103505 - Mount Option Injection in Amazon EFS CSI Driver

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-02 16:50 UTC

Bulletin ID: 2026-120-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 08:30 AM PDT Description: The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. We identified CVE-2026-103505, where an actor with PersistentVolume creation privileges can inject additional mount options through the mounttargetipmap volumeAttribute. Appending comma-separated values to a value inside that JSO…

Cloud SecurityVulnerabilitiesCVE-2026-103505
P5
2026-10-02 14:30 UTC
Security Journalism

In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats

Security Week · SecurityWeek News · indexed 2026-10-02 14:30 UTC

Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android app flaws. The post In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats appeared first on SecurityWeek.

Cloud SecurityMicrosoftMobile SecurityPhishing
P0
2026-10-01 21:15 UTC
Vendor Research

CVE-2026-104002: Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python)

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-01 21:35 UTC

Bulletin ID: 2026-123-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 14:00 PM PDT Description: Powertools for AWS Lambda (Python) is a developer toolkit that implements serverless best practices and increases developer velocity. We identified CVE-2026-104002, a fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python). This issue might allow actors to read sensitive field values that the application intended to…

Cloud SecurityVulnerabilitiesCVE-2026-104002
P5
2026-10-01 20:50 UTC
Vendor Research

CVE-2026-104020 - Uncontrolled recursion in the Ion reader in Amazon Ion Python

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-01 21:00 UTC

Bulletin ID: 2026-122-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 13:30 PM PDT Description: Amazon Ion Python is an open-source Python implementation of the Amazon Ion data notation. We identified CVE-2026-104020, an issue in the Ion reader in Amazon Ion Python before version 0.15.0 where a crafted, deeply nested Ion value could cause the application to raise an error or crash, resulting in a denial of service. Impacted versions: < 0.15.0 Please refe…

Cloud SecurityVulnerabilitiesCVE-2026-104020
P5
2026-10-01 18:16 UTC
Vendor Research

CVE-2026-97662 - Argument injection in AWS security-agent-mcp-server diff scan

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-01 18:20 UTC

Bulletin ID: 2026-121-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 10:30 AM PDT Description: security-agent-mcp-server is an open-source Model Context Protocol (MCP) server, published by AWS in the awslabs/mcp repository, that AI assistants use to run local security scans (including differential "diff" scans) over source code. We identified CVE-2026-97662, an argument injection issue in the diff scan operation: a crafted reference value supplied to th…

Cloud SecurityVulnerabilitiesCVE-2026-97662
P5
2026-09-30 19:29 UTC
Other

WatchGuard fixes critical Fireware OS flaw allowing remote code execution

Security Affairs · Pierluigi Paganini · indexed 2026-09-30 20:15 UTC

WatchGuard fixes 15 Fireware OS flaws, including a critical RCE bug that could give attackers root access to vulnerable Firebox appliances. WatchGuard has released security updates for Fireware OS that address 15 vulnerabilities, including a critical code injection flaw, tracked as CVE-2026-86131 (CVSS score of 9.2), that could allow an attacker to execute commands with […]

Cloud SecurityVulnerabilitiesCVE-2026-86131
P20
2026-09-30 15:09 UTC
Vendor Research

Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)

Rapid7 · Rapid7 · indexed 2026-09-30 15:25 UTC

OverviewOn September 30, 2026, Cisco published a security advisory for CVE-2026-76504, a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The vulnerability has a CVSSv3.1 score of 9.8 and results from improper handling of URL encoding (CWE-177). An unauthenticated, remote attacker can send a crafted HTTP request that bypasses an authentication rule for a specific API endpoint, gaining access to the API with the privileges of the admin user.According to C…

Cloud SecurityVulnerabilitiesCVE-2026-20127CVE-2026-20182CVE-2026-76504
P90
2026-09-30 14:00 UTC
Vendor Research

Vulnerability Discovery and Exploitation Trends in the AI Era

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-30 14:45 UTC

Written by: Robin Grunewald, Supriya Mazumdar, Kelli Vanderlee Introduction Google Threat Intelligence Group (GTIG) examines vulnerability disclosure and exploitation statistics to evaluate the impact of artificial intelligence (AI) on the vulnerability threat landscape. We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered. Key findings: Vulnerability discl…

AI SecurityCloud SecurityLinuxMicrosoftNetwork SecurityThreat ActorsThreat IntelligenceVulnerabilities
P60
2026-09-30 12:16 UTC
Security Journalism

Chrome, Firefox Updates Patch Over 100 Vulnerabilities

Security Week · Ionut Arghire · indexed 2026-09-30 12:30 UTC

Some of the flaws could allow remote attackers to execute arbitrary code or escape the browser sandbox. The post Chrome, Firefox Updates Patch Over 100 Vulnerabilities appeared first on SecurityWeek.

Cloud Security
P0
2026-09-29 15:17 UTC
Vendor Research

CVE-2026-100308 - GluonTS arbitrary command execution during model deserialization

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-29 15:35 UTC

Bulletin ID: 2026-119-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/29/2026 08:00 AM PDT Description: GluonTS is an open source library for deep learning based time series models. We identified CVE-2026-100308 that allows arbitrary command execution upon deserialization of untrusted model artifacts. Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary opera…

Cloud SecurityVulnerabilitiesCVE-2026-100308
P5
2026-09-29 10:00 UTC
Vendor Research

OperTraitors: How Kubernetes Operators Betray Your Security Posture

Palo Alto Networks Unit 42 · Lior Yakim · indexed 2026-09-29 10:20 UTC

We introduce OperTraitor, a tool to audit privileges of Kubernetes operators, identify excessive RBAC risks, and secure non-human identities. The post OperTraitors: How Kubernetes Operators Betray Your Security Posture appeared first on Unit 42.

Cloud Security
P0
2026-09-28 17:05 UTC
Vendor Research

AWS European Sovereign Cloud: Demonstrating an independent operation

AWS Security Blog · Stéphane Israël · indexed 2026-09-28 17:40 UTC

On Saturday, October 24, 2026, we will conduct an exercise demonstrating that the AWS European Sovereign Cloud can operate without depending on any infrastructure outside of the European Union (EU). For several hours, the AWS European Sovereign Cloud will operate without a connection to the AWS Global Network backbone. The backbone is the private network […]

Cloud Security
P0
2026-09-28 10:46 UTC
Other

Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities

Security Affairs · Pierluigi Paganini · indexed 2026-09-28 11:00 UTC

Microsoft details Storm-3168, the JADEPUFFER-linked actor that used stolen service principals to delete Azure storage in minutes and harvest keys. Microsoft just published the first detailed look at what JADEPUFFER does inside Azure. Sysdig first spotted the group’s activity in July 2026 and called it the first documented agentic ransomware operation. Microsoft tracks the same […]

Cloud SecurityMicrosoftRansomware
P15
2026-09-28 09:08 UTC
Security Journalism

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 10:25 UTC

The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours. "The destructive operations

Cloud SecurityMicrosoftThreat Actors
P0
2026-09-28 08:55 UTC
Other

U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-28 09:40 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-88771 (CVSS score: 9.5) is a remote code execution vulnerability caused by improper input validation that could allow an unauthenticated remote […]

Cloud SecurityVulnerabilitiesCVE-2026-88771
P50
2026-09-28 07:21 UTC
Security Journalism

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 10:25 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerabilities are listed below - CVE-2026-88771 (CVSS score: 9.5) - An improper input validation vulnerability that could allow an unauthenticated attacker to

Cloud SecurityVulnerabilitiesCVE-2026-88771
P35
1 2 3