IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 623 matching records.
AUTO-POLL // 2026-10-03 05:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 3
NO DATA
--
NO INTEL
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
RESET
2025-01-24 00:00 UTC
Other

Entra ID Allows Users to Update Principal Names

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A configuration change in Entra ID allowed unprivileged users to update their own User Principal Names (UPNs) through interfaces like the Entra admin center and PowerShell. This could lead to impersonation risks. Microsoft quickly fixed the issue after it was reported. The vulnerability affected synchronized hybrid environments as well.

MicrosoftVulnerabilities
P0
2025-01-23 00:00 UTC
Security Journalism

PerfMon! What Is It Good For? | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Explore how Performance Monitor (PerfMon) counters can be used as alternative methods for detecting Kerberos roasting attacks, moving beyond the traditional reliance on Windows Events 4768/4769.

Microsoft
P0
2025-01-17 00:00 UTC
Other

Finding SSRFs in Azure DevOps

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Three SSRF vulnerabilities were discovered in Azure DevOps, allowing access to internal metadata endpoints and potential CRLF injection. The issues affected the endpointproxy and Service Hooks functionality. DNS rebinding could bypass initial fixes. Microsoft awarded $15,000 in bug bounties for the findings.

Cloud SecurityMicrosoft
P0
2025-01-15 00:00 UTC
Other

Issue with Amazon WorkSpaces and AppStream 2.0 Clients

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS identified two vulnerabilities in specific versions of native clients for Amazon WorkSpaces, Amazon AppStream 2.0, and Amazon DCV. These issues could allow man-in-the-middle attacks, potentially giving attackers access to remote sessions. Affected versions include WorkSpaces clients 5.20.0 or earlier, AppStream 2.0 Windows client 1.1.1326 or earlier, and various DCV clients. AWS recommends upgrading to patched versions to address these security concerns.

Cloud SecurityMicrosoft
P0
2024-10-15 12:00 UTC
Government

Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024

NIST Cybersecurity Insights · Shanée Dawkins · indexed 2026-08-15 20:45 UTC

This blog is part of a larger NIST series during the month of October for Cybersecurity Awareness Month , called 'Staff Stories Spotlight.' Throughout the month of October this year, Q&A style blogs will be published featuring some of our unique staff members who have interesting backgrounds, stories to tell, and projects in the world of cybersecurity. This year’s Cybersecurity Awareness Month theme is ‘Secure our World.’ How does this theme resonate with you, as someone working in cybersecurit…

Microsoft
P0
2024-09-04 06:52 UTC
Other

APT Lazarus: Eager Crypto Beavers, Video calls and Games

Group-IB · indexed 2026-09-07 17:30 UTC

Explore the growing threats posed by the Lazarus Group's financially-driven campaign against developers. We will examine their recent Python scripts, including the CivetQ and BeaverTail malware variants, along with their updated versions in Windows and Python releases. Additionally, we will analyze their tactics, techniques, and indicators of compromise.

APT / Nation-StateMalwareMicrosoft
P0
2024-08-19 00:00 UTC
Other

WireServing Up Credentials in Azure Kubernetes Services

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Azure Kubernetes Services allowed attackers to escalate privileges and access cluster credentials. Affected clusters used Azure CNI for network configuration and Azure for network policy. Attackers could exploit this issue to steal data and cause financial and reputational damage. The vulnerability has been fixed by Microsoft after disclosure by Mandiant.

Cloud SecurityMicrosoftVulnerabilities
P0
2024-08-07 00:00 UTC
Other

Privilege Elevation Vulnerability in Entra ID

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Semperis researchers discovered vulnerabilities in Microsoft applications that allowed privilege elevation in Entra ID beyond expected authorization controls. The most severe finding enabled adding users to privileged roles, including Global Administrator, without proper permissions. The issues affected Device Registration Service, Viva Engage, and Microsoft Rights Management Service. Microsoft has since resolved the vulnerabilities.

MicrosoftSecurity ResearchVulnerabilities
P0
2024-07-15 00:00 UTC
Other

Unauthorized Access to AWS Account Findings in Microsoft Defender for Cloud

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Microsoft Defender for Cloud at one point provided customers with a flawed configuration template through their public GitHub repository. This template creates resources in the customer's AWS account so that Microsoft Defender for Cloud can scan it. In the rare cases in which this template was deployed, under certain, limited circumstances, Defender for Cloud's security findings for these AWS accounts could be disclosed to unauthorized third parties.

Cloud SecurityMicrosoft
P0
2024-06-17 00:00 UTC
Other

GCP HMAC Keys do not log creation, deletion or usage

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Cloud Audit Logs do not capture actions mediated through the cloud console private API service (cloudconsole-pa). Consequently, there is no logging of HMAC key creation or deletion linked to user accounts. This absence of logs hampers defenders' ability to alert or monitor the creation of HMAC keys for user accounts, posing a persistence risk, or their deletion, presenting a denial of service risk.

Microsoft
P0
2024-06-11 00:00 UTC
Other

Issue with Amazon EC2 VM Import Export Service

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS addressed an issue with the Amazon EC2 VM Import Export Service where importing Windows VMs with custom Sysprep answer files resulted in an unprotected backup copy being created, potentially exposing sensitive data. The issue affected imports made before April 12, 2024, and could impact instances launched from affected AMIs.

Cloud SecurityMicrosoft
P0
2024-06-03 00:00 UTC
Other

Abusing Service Tags to Bypass Azure Firewall Rules

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Tenable Research discovered a vulnerability in Azure allowing attackers to bypass firewall rules based on Service Tags by forging requests from trusted services. It affects over 10 Azure services and enables access to internal/private Azure resources. Microsoft updated documentation to clarify Service Tags' security limitations.

Cloud SecurityMicrosoftNetwork SecurityVulnerabilities
P0
2024-05-16 00:00 UTC
Other

Internal Azure Container Registry writable via exposed secret

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A Microsoft employee accidentally published credentials via a git commit to a public repository. These credentials granted privileged access to an internal Azure Container Registry (ACR) used by Azure, which reportedly held container images utilized by multiple Azure projects, including Azure IoT Edge, Akri, and Apollo. The privileged access could have allowed an attacker to download private images as well as upload new images and (most importantly) overwrite existing ones. In theory, an attack…

Cloud SecurityMicrosoft
P0
2024-05-07 00:00 UTC
Other

Lethal Injection

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Multiple vulnerabilities were uncovered in Azure Health Bot service, Microsoft's health chatbot platform. These could have potentially exposed sensitive user data and granted attackers extensive control, allowing unrestricted code execution as root on the bot backend, unrestricted access to authentication secrets & integration auth providers, unrestricted memory read in the bot backend, exposing sensitive secrets, allowing cross-tenant data access and unrestricted deletion of other tenants' pub…

Cloud SecurityMicrosoft
P0
2024-04-29 00:00 UTC
Other

GraphNinja

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Microsoft Graph allowed attackers to conduct password-spray attacks without detection. The issue involved switching the 'common' authentication endpoint with that of an unrelated tenant, thereby avoiding the appearance of logon attempts in the victim's logs. This technique could allow attackers to validate user credentials through verbose error messages, but actual successful logons using these credentials would still be recorded in the victims' logs (regardless of endpoint).

MicrosoftNetwork SecurityVulnerabilities
P0
2024-04-26 00:00 UTC
Other

Azure tenant takeover via Microsoft application

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Microsoft Dynamics 365 Supply Chain Visibility allowed arbitrary takeover of Azure tenants via a malicious reply URL. Clicking a link could grant an attacker directory read access or full tenant control if clicked by a Global Admin, without requiring user consent.

Cloud SecurityMicrosoftVulnerabilities
P0
2024-03-07 00:00 UTC
Security Journalism

Time Travelers Busted: How to Detect Impossible Travel | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Impossible Travel is one of the earliest indicators of user compromise, and it works against any user-centric event that can be tied back to a location. Huntress goes in-depth on this problem, explaining how it works, revealing challenges surrounding it, and offering real-world examples occurring within Microsoft 365.

Microsoft
P0
2024-02-08 00:00 UTC
Security Journalism

Attacking MSSQL Servers | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

In addition to social engineering attacks, threat actors target organizations' attack surface, looking for exposed services and applications to gain access into an infrastructure. Microsoft SQL database servers have long been a target for attackers.

MicrosoftThreat Actors
P0
2024-01-01 00:00 UTC
Other

Microsoft Healthcare Chatbot Vulnerabilities

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Multiple vulnerabilities in Microsoft's Azure Health Bot service were discovered, allowing access to sensitive infrastructure and confidential medical data. Issues included sandbox escapes, unrestricted code execution, access to authentication secrets, cross-tenant data exposure, and unauthorized deletion of resources. Microsoft quickly patched the vulnerabilities and restructured the service architecture for improved security.

Cloud SecurityMicrosoft
P0
2023-12-19 00:00 UTC
Other

AWS IAM Identity Center Expiry

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS IAM Identity Center exchanges third-party OIDC tokens for Identity Center-issued tokens. Identity Center relies on the jti claim in the third-party tokens to prevent replay attacks. Identity Center maintained a cache of previously-seen jti values for a fixed period (24 hours) and didn’t enforce that the third-party tokens had expiry claims. This meant that a token with a jti claim and without an exp claim could be replayed after >24 hours had passed.

Cloud SecurityMicrosoft
P0
2023-12-12 00:00 UTC
Other

Control plane bypass in Azure OpenAI

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A way to manage Azure OpenAI deployments via the Data Plane was discovered, bypassing key security controls. This allows creation/modification/deletion of deployments without the usual protections of Resource Manager Locks, Azure Policy, and Entra ID authentication.

Cloud SecurityMicrosoft
P0
17 18 19 20 21