Intel Free'd: A CYBERSECURITY INTELLIGENCE FEEDby: buf0rd

LATEST

Aggregated cybersecurity reporting, advisories and research. 274 matching records.
AUTO-POLL // 2026-08-19 01:00 UTC
RESET
2026-05-20 16:00 UTC
Vendor Research

Cisco Secure Workload Unauthorized API Access Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the attacker to read sensitive inform…

VulnerabilitiesCVE-2026-20223
P5
2026-05-20 16:00 UTC
Vendor Research

Cisco ThousandEyes Virtual Appliance Authenticated Remote Code Execution Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user. This vulnerability is due to insufficient validation of user-supplied input. An authenticated attacker could exploit this vulnerability by uploading a crafted certificate to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the un…

VulnerabilitiesCVE-2026-20199
P20
2026-05-20 16:00 UTC
Vendor Research

Cisco ThousandEyes Enterprise Agent BrowserBot Command Injection Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on behalf of the BrowserBot synthetics orchestration process. Cisco has addressed this vulnerability in the Cisco ThousandEyes Enterprise Agent, and no customer action is needed. This vulnerability was due to insufficient input validation of command arguments that are supplied by the user. Prior to this vulnerability bein…

VulnerabilitiesCVE-2026-20206
P5
2026-05-19 17:49 UTC
Vendor Research

Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

On April 23, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an update to V1: Emergency Directive (ED) 25-03: Identify and Mitigate Potential Compromise of Cisco Devices related to Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD) products. According to the update, the ArcaneDoor threat actor has developed a previously unknown persistence mechanism that is preserved across upgrading to the fixed releases that wer…

Network SecurityThreat ActorsVulnerabilitiesCVE-2025-20333CVE-2025-20362
P20
2026-05-15 14:00 UTC
Vendor Research

Welcome to BlackFile: Inside a Vishing Extortion Operation

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC

Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass traditional perimeter defenses and multi-factor authentication (MFA), UNC6671 gain…

Data BreachesMicrosoftNetwork SecurityPhishingThreat ActorsThreat IntelligenceVulnerabilities
P0
2026-05-14 16:00 UTC
Vendor Research

Cisco Catalyst SD-WAN Manager Vulnerabilities

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

Multiple vulnerabilities in Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow a remote attacker to gain access to sensitive information, elevate privileges, or gain unauthorized access to the application. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. Cisco strongly recommends that customers upgrade to…

VulnerabilitiesCVE-2026-20209CVE-2026-20210CVE-2026-20224
P5
2026-05-14 15:56 UTC
Vendor Research

Cisco Crosswork Network Controller and Cisco Network Services Orchestrator Advisory

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

Following the initial publication of the Security Advisory about a denial of service (DoS) condition in Cisco Crosswork Network Controller and Cisco Network Services Orchestrator (NSO), additional information has been made available to the Cisco Product Security Incident Response Team (PSIRT). Upon further analysis, the Cisco PSIRT has reclassified this issue as a customer-configurable, resource management issue rather than a security vulnerability. This advisory is available at the following l…

DFIRVulnerabilitiesCVE-2026-20188
P5
2026-05-11 14:00 UTC
Vendor Research

GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC

Executive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. This report, based on insights derived from Mandiant incident response engagements, Gemini, and GTIG’s proactive research, highlights the dual nature of the current threat environment where AI serves as both a so…

AI SecurityAppleAPT / Nation-StateCloud SecurityDFIRMalwareMicrosoftNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities
P60
2026-05-07 13:00 UTC
Vendor Research

How Cloudflare responded to the “Copy Fail” Linux vulnerability

Cloudflare Security · Chris J Arges · indexed 2026-08-15 18:58 UTC

When a critical Linux kernel privilege escalation was publicly disclosed, Cloudflare's security and engineering teams detected, investigated, and mitigated the threat across our global fleet, confirming zero customer impact and no malicious exploitation.

LinuxVulnerabilities
P10
2026-05-06 16:00 UTC
Vendor Research

Cisco Unity Connection Remote Code Execution and Server-Side Request Forgery Vulnerabilities

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

Multiple vulnerabilities in Cisco Unity Connection could allow a remote attacker to execute arbitrary code on or conduct server-side request forgery (SSRF) attacks through an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/s…

VulnerabilitiesCVE-2026-20034CVE-2026-20035
P20
2026-05-06 16:00 UTC
Vendor Research

Cisco Identity Services Engine Authentication Bypass Vulnerabilities

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to bypass authorization mechanisms or examine error messages to gain access to sensitive information on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https:…

VulnerabilitiesCVE-2026-20193CVE-2026-20195
P15
2026-05-06 16:00 UTC
Vendor Research

Cisco Prime Infrastructure Information Disclosure Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to download arbitrary log files from the server. This vulnerability is due to insufficient authorization checks on the download service API. An attacker could exploit this vulnerability by submitting a crafted URL request to an affected device. A successful exploit could allow the attacker to download sensitive log files that they would otherwise not have authorizat…

VulnerabilitiesCVE-2026-20189
P5
2026-05-06 16:00 UTC
Vendor Research

Cisco Slido Insecure Direct Object Reference Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the REST API of Cisco Slido could have allowed an authenticated, remote attacker to access the social profile data of other users or affect quiz and poll results. Cisco has addressed this vulnerability in Cisco Slido and no customer action is needed. This vulnerability existed because of the presence of an insecure direct object reference. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by sending a crafted request to the vulne…

VulnerabilitiesCVE-2026-20219
P5
2026-05-06 16:00 UTC
Vendor Research

Cisco IoT Field Network Director Vulnerabilities

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

Multiple vulnerabilities in the web-based management interface of Cisco IoT Field Network Director Software could allow an authenticated, remote attacker to access files, execute commands, and cause denial of service (DoS) conditions on managed routers. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is ava…

Network SecurityVulnerabilitiesCVE-2026-20167CVE-2026-20168CVE-2026-20169
P5
2026-05-06 16:00 UTC
Vendor Research

Cisco SG350 and SG350X Series Managed Switches SNMP Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco 350 Series Managed Switches (SG350) and Cisco 350X Series Stackable Managed Switches (SG350X) firmware could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when parsing response data for a specific SNMP request. An attacker could exploit this vulnerability by sending a specific SNMP request to an aff…

DFIRNetwork SecurityVulnerabilitiesCVE-2026-20185
P5
2026-05-06 08:44 UTC
Government

2026-006: Critical Vulnerability in PAN-OS

CERT-EU Security Advisories · indexed 2026-08-15 18:50 UTC

On 6 May 2026, Palo Alto published a security advisory addressing a critical vulnerability affecting PAN-OS. This vulnerability allows an unauthenticated attacker to execute arbitrary code with root privileges. Palo Alto observed limited exploitation of this vulnerability. It is strongly recommended updating affected appliances as soon as patches will be available, and to apply workarounds and mitigation in the meantime.

Network SecurityVulnerabilities
P10
2026-04-30 09:25 UTC
Government

2026-005: High Vulnerability in the Linux Kernel ("Copy Fail")

CERT-EU Security Advisories · indexed 2026-08-15 18:50 UTC

On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed. The vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has been released. As of the date of this advisory, no distribution has shipped a fixed kernel package. The mainline fix was committed on 1 April 2026, but vendor updates are still pending across all major …

Cloud SecurityLinuxVulnerabilitiesCVE-2026-31431
P15
2026-04-16 14:00 UTC
Vendor Research

Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever

Google Threat Intelligence / Mandiant · Francis deSouza · indexed 2026-08-15 18:55 UTC

Introduction Advances in AI model-powered exploitation have demonstrated that general-purpose AI models can excel at vulnerability discovery, even without being purpose-built for the task. Eventually, capabilities such as these will be integrated directly into the development cycle, and code will be more difficult to exploit than ever; however, this transition creates a critical window of risk. As we harden existing software with AI, threat actors will use it to discover and exploit novel vulne…

AI SecurityAPT / Nation-StateCloud SecurityDFIRMicrosoftRansomwareThreat ActorsVulnerabilities
P60
2026-04-10 15:12 UTC
Vendor Research

Bringing Rust to the Pixel Baseband

Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC

Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities. For Pixel 10, Google is advancing its proactive security measures further. Following our previous discussion on "Deploying Rust in Existing…

Mobile SecuritySecurity ResearchVulnerabilitiesCVE-2024-27227
P20
2026-04-02 16:00 UTC
Vendor Research

Google Workspace’s continuous approach to mitigating indirect prompt injections

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Adam Gavish, Google GenAI Security TeamIndirect prompt injection (IPI) is an evolving threat vector targeting users of complex AI applications with multiple data sources, such as Workspace with Gemini. This technique enables the attacker to influence the behavior of an LLM by injecting malicious instructions into the data or tools used by the LLM as it completes the user’s query. This may even be possible without any input directly from the user.IPI is not the kind of technical proble…

AI SecurityMicrosoftSecurity ResearchVulnerabilities
P0
2026-03-31 18:58 UTC
Vendor Research

VRP 2025 Year in Review

Google Security Blog · Dirk Göhmann · indexed 2026-08-15 18:55 UTC

2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉! Originally started in 2010, our vulnerabi…

Vulnerabilities
P0
2026-03-31 16:55 UTC
Vendor Research

VRP 2025 Year in Review

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Dirk Göhmann, Tony Mendez, and the Vulnerability Rewards Program Team2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉! Originally started in 2010, our vulnerability reward program (VRP) has seen constant additions and expansions over the past decade and a half, clearly indicating the value the programs under this umbrella contribute to the safety and security of Google and its users, but also highlighting…

Mobile SecuritySecurity ResearchVulnerabilities
P0
2026-03-25 07:51 UTC
Government

2026-004: Critical Vulnerability in SharePoint Exploited

CERT-EU Security Advisories · indexed 2026-08-15 18:50 UTC

On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthenticated attacker. This vulnerability was added in the CISA's Known Exploited Vulnerabilities (KEV) catalogue on 18 March 2026. Additionally, three further RCE flaws affecting Microsoft SharePoint were ad…

Cloud SecurityMicrosoftVulnerabilities
P55
2026-02-26 18:38 UTC
Government

2026-002: Multiple Vulnerabilities in Cisco Products

CERT-EU Security Advisories · indexed 2026-08-15 18:50 UTC

On 25 February 2026, Cisco released security advisories addressing multiple high and critical severity vulnerabilities in Cisco Catalyst SD-WAN controllers and Cisco SD-WAN Manager. If exploited, these vulnerabilities could allow attackers to gain administrative access to compromised systems. It is recommended to capture forensic evidence, hunt for indicators of compromise, and apply updates as soon as possible. One of the vulnerabilities, CVE-2026-20127, is exploited in the wild since 2023.

VulnerabilitiesCVE-2026-20127
P25
2026-01-30 09:09 UTC
Government

2026-001: Critical vulnerabilities in Ivanti EPMM

CERT-EU Security Advisories · indexed 2026-08-15 18:50 UTC

On 29 January 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their EPMM products. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device. One of these vulnerabilities have been exploited in a limited number of cases.

Cloud SecurityVulnerabilities
P15
2025-12-18 09:08 UTC
Government

2025-042: Critical Vulnerability in Cisco Secure Email and Web Manager

CERT-EU Security Advisories · indexed 2026-08-15 18:50 UTC

On December 17, 2025, Cisco released a security advisory for a critical vulnerability affecting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager products. It is recommended to follow Cisco's recommendations to check whether vulnerable appliances have been compromised, and to remediate the issue. There is no patch available for this vulnerability yet.

Vulnerabilities
P10
2025-11-13 16:59 UTC
Vendor Research

Rust in Android: move fast and fix things

Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC

Posted by Jeff Vander Stoep, Android Last year, we wrote about why a memory safety strategy that focuses on vulnerability prevention in new code quickly yields durable and compounding gains. This year we look at how this approach isn’t just fixing things, but helping us move faster. The 2025 data continues to validate the approach, with memory safety vulnerabilities falling below 20% of total vulnerabilities for the first time. Updated data for 2025. This data covers first-party and third-party…

LinuxMobile SecurityVulnerabilities
P25
2025-09-15 17:01 UTC
Vendor Research

Supporting Rowhammer research to protect the DRAM ecosystem

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Daniel MoghimiRowhammer is a complex class of vulnerabilities across the industry. It is a hardware vulnerability in DRAM where repeatedly accessing a row of memory can cause bit flips in adjacent rows, leading to data corruption. This can be exploited by attackers to gain unauthorized access to data, escalate privileges, or cause denial of service. Hardware vendors have deployed various mitigations, such as ECC and Target Row Refresh (TRR) for DDR5 memory, to mitigate Rowhammer and e…

Security ResearchVulnerabilities
P10
2025-08-12 16:00 UTC
Vendor Research

Android’s pKVM Becomes First Globally Certified Software to Achieve Prestigious SESIP Level 5 Security Certification

Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC

Posted by Dave Kleidermacher, VP Engineering, Android Security & Privacy Today marks a watershed moment and new benchmark for open-source security and the future of consumer electronics. Google is proud to announce that protected KVM (pKVM), the hypervisor that powers the Android Virtualization Framework, has officially achieved SESIP Level 5 certification. This makes pKVM the first software security system designed for large-scale deployment in consumer electronics to meet this assurance bar. …

LinuxMobile SecurityVulnerabilities
P0
78910