CRAFTEDSIGNAL THREAT INTELLIGENCE FEED
Threat intelligence feed for SOC and IR teams
Fresh threat briefs from the CraftedSignal pipeline, with MITRE ATT&CK coverage, CVE references, rule metadata, and IOCs when available. Full rule logic and test data stay inside the platform; this feed shows what is changing now.
Recent activity
1892 briefsLatest briefs
View all →Information Disclosure Vulnerability in multicluster-observability-addon
1 TTP 1 CVEA configuration reference vulnerability in the multicluster-observability-addon allows a managed cluster identity to bypass namespace restrictions and exfiltrate sensitive hub-level secrets.
Active Exploitation of JFrog Artifactory Vulnerabilities
3 TTPs 3 CVEsAttackers are actively exploiting a chain of three critical vulnerabilities (CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329) in JFrog Artifactory to bypass authentication and achieve full administrative control.
Stored XSS in Simple Ajax Chat WordPress Plugin via CVE-2026-81825
2 TTPs 1 CVEThe Simple Ajax Chat plugin for WordPress contains a stored cross-site scripting vulnerability in versions <= 20260811, allowing unauthenticated attackers to inject malicious scripts due to exposed nonces and insufficient input sanitization.
Stored XSS in The Vigilant Security Plugin for WordPress
1 TTP 1 CVEThe Vigilant security plugin for WordPress version 2.10.2 and earlier is vulnerable to Stored Cross-Site Scripting via the User-Agent header, allowing unauthenticated attackers to execute arbitrary scripts in the dashboard.
Arbitrary File Deletion in UsersWP WordPress Plugin
1 rule 1 TTP 1 CVEThe UsersWP plugin for WordPress versions up to 1.2.70 allows authenticated attackers to delete arbitrary files on the web server via a path traversal vulnerability in the upload_file_remove() AJAX handler.
Stored XSS Vulnerability in WP Photo Album Plus Plugin
1 rule 2 TTPs 1 CVEAn unauthenticated stored XSS vulnerability in WP Photo Album Plus versions 9.2.08.003 and earlier allows attackers to inject malicious scripts via the HTTP_X_FORWARDED_FOR header, which is logged without sanitization.
SQL Injection Vulnerability in Unlimited Elements For Elementor
1 rule 1 TTP 1 CVEThe Unlimited Elements For Elementor WordPress plugin contains an unauthenticated SQL injection vulnerability via the addontype parameter, allowing attackers to perform unauthorized database extraction.
SQL Injection in Sticky Chat Widget WordPress Plugin
1 rule 1 TTP 1 CVEThe Sticky Chat Widget plugin for WordPress (<= 1.4.2) is vulnerable to unauthenticated SQL injection via the 'scw_save_form_data' AJAX action, allowing potential exfiltration of sensitive database information.
Unauthenticated Arbitrary File Upload in MIPL Grouped Checkout Fields for WooCommerce
2 TTPs 1 CVEThe MIPL Grouped Checkout Fields plugin for WordPress is vulnerable to unauthenticated arbitrary file uploads via the mipl_wc_upload_file function, potentially resulting in remote code execution.
Path Traversal Vulnerability in AcyMailing WordPress Plugin
1 rule 1 TTP 1 CVEThe AcyMailing WordPress plugin is vulnerable to unauthenticated directory traversal, allowing attackers to read arbitrary files on the server when the Embed images feature is enabled.
Remote Code Execution Vulnerability in SAP Extended Passport Processing
2 TTPsA critical unauthenticated remote code execution vulnerability in the SAP Extended Passport (EPP) kernel component allows attackers to execute arbitrary system commands via RFC or HTTP communication layers.
SQL Injection in Pimcore CustomReportsBundle
1 rule 2 TTPsAn authenticated SQL injection vulnerability in Pimcore's CustomReportsBundle allows users with specific permissions to execute arbitrary database commands by bypassing a weak keyword blacklist.