IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 623 matching records.
AUTO-POLL // 2026-10-03 05:50 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 3
NO DATA
--
NO INTEL
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
RESET
2023-11-16 00:00 UTC
Other

Extracting Managed Identity Credentials from Azure Functions

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Azure Function Apps allowed extraction of Managed Identity credentials from the encrypted startup context of Linux containers. This gave attackers with container access the ability to persist as the Managed Identity, breaking the intended security model. Microsoft has since patched the issue by encrypting the sensitive payload.

Cloud SecurityLinuxMicrosoftVulnerabilities
P0
2023-11-14 00:00 UTC
Other

Azure CLI Leaks Credentials in GitHub Actions Logs

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure CLI commands were found to leak sensitive information, including credentials, through GitHub Actions logs. The vulnerability affects multiple Azure CLI commands and could expose secrets in public and private repositories. Microsoft has issued updates to Azure CLI, Azure Pipelines, and GitHub Actions to address the issue.

Cloud SecurityMicrosoftVulnerabilities
P0
2023-11-08 00:00 UTC
Other

Azure Automation Service Used for Cryptocurrency Mining

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

SafeBreach Labs researchers developed methods to leverage Microsoft Azure's Automation Service for free, undetectable cryptocurrency mining. They found three ways to execute miners: two using their own environment and Azure's resources for free, and one in a victim's environment undetected. The techniques could potentially be used for any task requiring code execution on Azure.

Cloud SecurityMicrosoft
P0
2023-10-06 00:00 UTC
Other

Amazon WorkSpaces Windows client credential logging

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS identified an issue in the Amazon WorkSpaces Windows client which resulted in unintentionally logging connection debugging information to a user's local system. This data could include usernames or passwords if they contain specific characters: \ (backslash) or " (double quotes). If an attacker gained access to an Amazon WorkSpaces user's machine, they could then compromise such credentials from the log.

Cloud SecurityMicrosoft
P0
2023-08-24 00:00 UTC
Other

Power Platform Privilege Escalation in Azure AD

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Secureworks researchers discovered an Azure AD application with an abandoned reply URL related to Microsoft Power Platform. An attacker could leverage this URL to redirect authorization codes, exchange them for access tokens, and call Power Platform API via a middle-tier service to obtain elevated privileges. Microsoft quickly addressed the issue by removing the identified abandoned reply URL from the Azure AD application.

Cloud SecurityMicrosoftSecurity ResearchVulnerabilities
P10
2023-08-04 00:00 UTC
Other

Power Platform Custom Code information disclosure

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Power Platform could lead to unauthorized access to Custom Code functions used for custom connectors, thereby allowing cross-tenant information disclosure of secrets or other sensitive information if these were embedded in a Custom Code function. The issue occurred as a result of insufficient access control to Azure Function hosts, which are launched as part of the creation and operation of custom connectors in Microsoft’s Power Platform. An attacker who determined the hostna…

Cloud SecurityMicrosoftVulnerabilities
P0
2023-06-20 00:00 UTC
Other

nOAuth

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Descope identified a possible misconfiguration in Azure AD which could lead to misuse of the "Log in with Microsoft" authentication method on a web app. If an application relies on email attribute claims for authentication (which is against best practice) and also merges user accounts without proper validation, an attacker could falsify an email claim to gain full control over the target account. Descope and Microsoft Microsoft identified several popular multi-tenant applications with users tha…

Cloud SecurityMicrosoft
P0
2023-06-12 00:00 UTC
Other

Azure App Services takeover via legacy API

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Binary Security found two vulnerabilities in the legacy Azure Resource Manager (ARM) REST API. The first vulnerability allowed an attacker with Reader access to an Azure Function, acting from a Windows host, to get an admin token that could be exchanged for a master key granting access to all operations in Kudu (the Functions deployment service). This would allow them to tamper with the function by deploying malicious code to it. The other vulnerability allowed an attacker with Reader access to…

Cloud SecurityMicrosoftVulnerabilities
P0
2023-03-30 00:00 UTC
Other

Azure on-premises data gateway cross-tenant access

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure on-premises data gateway allows data transfer between an on-prem customer network and several Azure cloud services, and also enables a connected agent installed locally in an on-prem network to perform certain actions remotely. NetSPI discovered a deserialization issue in Microsoft Power Platform connectors that lead to RCE on several Azure backend servers that processed call backs from on-premises data gateways, effectively allowing unauthorized cross-tenant access.

Cloud SecurityMicrosoftVulnerabilities
P15
2023-03-23 00:00 UTC
Other

Azure Function Apps privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Undocumented APIs used by the Azure Function Apps Portal could have allowed an attacker with existing access to a Reader role on a Function App to escalate their privileges and gain write permissions through arbitrary file reads on Function App containers. For Windows containers, this would only grant an attacker the ability to extract ASP.NET encryption keys (the impact of which remains unclear), but for Linux containers it would have allowed an attacker to read environmental variables contain…

Cloud SecurityLinuxMicrosoftVulnerabilities
P25
2022-12-29 00:00 UTC
Security Journalism

OWASSRF Explained | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress' analysis of a new exploit chain (called OWASSRF) that can lead to critical remote code execution on unpatched Exchange hosts.

MicrosoftVulnerabilities
P15
2022-10-25 00:00 UTC
Other

Azure CLI code injection vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure CLI contained a code injection vulnerability that could be exploited in a scenario where the host runs a command where parameter values have been provided by an external untrusted source - these could be specially crafted in such a way as to exploit the vulnerability, leading to remote code execution on the host. The vulnerability is only applicable when the Azure CLI command is run on a Windows machine and with any version of PowerShell and when the parameter value contains the `&` or `|…

Cloud SecurityMicrosoftVulnerabilities
P15
2022-10-19 00:00 UTC
Other

BlueBleed

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

In September 22', SOCRadar discovered an insecure public Azure blob storage owned by Microsoft (olyympusv2.blob.core.windows[.]net). This blob storage was used for storing emails and other documents from interactions with their customers (such as contracts and purchase orders). In total, the blob storage contained 2.4TB of data with information concerning thousands of Microsoft customers across dozens of countries, dated between 2017 and August 22'. Following disclosure, Microsoft reconfigured …

Cloud SecurityMicrosoft
P0
2022-09-01 00:00 UTC
Other

Synapse Spark LPE

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Azure Synapse Analytics is an analytics service for processing data using various runtimes, among them Apache Spark. Synapse provided users the capability to mount Azure File Shares to their Apache Spark Pools via a script called filesharemount.sh that would execute with elevated privileges. This script would mount the File Share to the /synfs directory. There was a race condition in the script where, if successfully exploited, a user could execute the chown command to change the ownership of a…

Cloud SecurityMicrosoftVulnerabilities
P0
2022-07-12 00:00 UTC
Other

Microsoft Azure Site Recovery DLL hijacking

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

The Microsoft Azure Site Recovery suite contained a DLL hijacking flaw that allowed for privilege escalation from any low privileged user to SYSTEM on hosts where this service was installed. Incorrect permissions on the cxprocessserver service's executable directory allowed new files to be created in it by any user. Since the service ran automatically and with SYSTEM privileges and attempted to load DLLs from the directory, this allowed for a DLL hijacking / planting attack.

Cloud SecurityMicrosoftVulnerabilities
P10
2022-06-28 00:00 UTC
Other

FabricScape (CVE-2022-30137) - Azure Service Fabric privilege escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Service Fabric allows Linux containers to escalate their privileges in order to gain root privileges on the node, and then compromise all of the nodes in the cluster. An attacker would need to have read/write access to the cluster, and the vulnerability could be exploited on containers that are configured to have runtime access, but this is granted by default to every container. Though the bug exists in both the Windows and Linux versions, it is only exploitable on Linux.

Cloud SecurityLinuxMicrosoftVulnerabilitiesCVE-2022-30137
P15
18 19 20 21