CRAFTEDSIGNAL THREAT INTELLIGENCE FEED
Threat intelligence feed for SOC and IR teams
Fresh threat briefs from the CraftedSignal pipeline, with MITRE ATT&CK coverage, CVE references, rule metadata, and IOCs when available. Full rule logic and test data stay inside the platform; this feed shows what is changing now.
Recent activity
1997 briefsLatest briefs
View all →AWS GuardDuty Publishing Destination Deletion
1 rule 1 TTPAdversaries with administrative access to AWS GuardDuty may delete publishing destinations to break security finding exports, effectively blinding SOC monitoring without triggering detector-disabling alerts.
AWS CloudTrail Defense Evasion via DeleteTrail API
1 rule 1 TTPThe deletion of AWS CloudTrail trails via the DeleteTrail API is a high-risk indicator of defense evasion or sabotage used to eliminate audit visibility.
Detection of Assets with Elevated Vulnerability Exposure via Wiz
1 TTPThis brief describes a detection capability designed to identify cloud assets exhibiting poor security posture by correlating high volumes of vulnerabilities, exploitable findings, and critical-severity bugs reported by the Wiz Cloud Security Platform.
Credential Access via Chromium Remote Debugging
1 rule 1 TTPAdversaries can exploit Chromium-based browser remote debugging features to extract authentication cookies and hijack active web sessions.
Sensitive Information Exposure in YS LeadGen WordPress Plugin
1 rule 1 TTP 1 CVEThe YS LeadGen plugin for WordPress versions 2.1.4 and earlier contains an unauthenticated information exposure vulnerability allowing the retrieval of form submission data.
Arbitrary Shortcode Execution in ProfilePress Plugin
2 TTPs 1 CVEThe ProfilePress WordPress plugin is vulnerable to arbitrary shortcode execution in versions up to 4.17.2, allowing authenticated users with subscriber-level access to execute arbitrary shortcodes.
CVE-2026-4327: Remote Code Execution in The Welcomizer WordPress Plugin
1 rule 2 TTPs 1 CVEThe Welcomizer WordPress plugin contains a remote code execution vulnerability allowing authenticated subscribers to inject arbitrary PHP code via an insufficiently protected AJAX handler.
Stored XSS in Quill Forms WordPress Plugin
1 TTP 1 CVEThe Quill Forms WordPress plugin (<= 5.7.1) contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious JavaScript via form entry fields.
CVE-2026-92807: Arbitrary Function Invocation in Save as PDF Plugin for WordPress
1 rule 1 TTP 1 CVEThe Save as PDF Plugin for WordPress up to version 4.6.1 is vulnerable to arbitrary function invocation via the pdf_created_callback shortcode attribute, allowing authenticated Contributor-level users to trigger sensitive data disclosure.
Remote Code Execution in WP Photo Album Plus Plugin
2 TTPs 1 CVEThe WP Photo Album Plus plugin for WordPress contains an RCE vulnerability (CVE-2026-87909) allowing authenticated attackers with subscriber-level access to execute arbitrary commands through improper sanitization of ImageMagick arguments.
Stored XSS in Asset CleanUp: Page Speed Booster WordPress Plugin
1 TTP 1 CVEAsset CleanUp: Page Speed Booster versions 1.4.0.5 and earlier are vulnerable to stored cross-site scripting due to insufficient input sanitization of comment content.
Arbitrary Shortcode Execution in Forminator WordPress Plugin
1 TTP 1 CVEThe Forminator plugin for WordPress contains an arbitrary shortcode execution vulnerability (CVE-2026-92229) allowing unauthenticated attackers to execute arbitrary shortcodes by leveraging improper input validation.