CRAFTEDSIGNAL THREAT INTELLIGENCE FEED
Threat intelligence feed for SOC and IR teams
Fresh threat briefs from the CraftedSignal pipeline, with MITRE ATT&CK coverage, CVE references, rule metadata, and IOCs when available. Full rule logic and test data stay inside the platform; this feed shows what is changing now.
Recent activity
1712 briefsLatest briefs
View all →Vulnerabilities in MISP cti-transmute
3 IOCsThe MISP project has patched multiple security vulnerabilities in the cti-transmute tool, including arbitrary file/network access and improper authorization controls for user management.
Unrestricted File Upload Vulnerability in ResponsiveFilemanager
1 rule 1 TTP 1 CVEA publicly disclosed, unpatched unrestricted file upload vulnerability in Trippo ResponsiveFilemanager up to version 9.14.0 allows remote attackers to execute arbitrary code.
Improper Access Control in Atlas-Livre Admin Controllers
1 rule 2 TTPs 1 CVEAn unauthenticated access control flaw in Atlas-Livre allows attackers to bypass authentication and execute privileged database operations due to a failure to terminate script execution following HTTP redirects.
Security Updates for cPanel and WP Squared
2 CVEsWebPros has issued a security advisory addressing HTTP request smuggling and database privilege escalation vulnerabilities in cPanel and WP Squared products.
Command Injection Vulnerability in GL.iNet AX1800 RPC Endpoint
1 TTP 1 CVEAn authenticated remote command injection vulnerability in the RPC component of GL.iNet AX1800 routers (firmware <= 4.8.3) allows attackers to execute arbitrary system commands via the 'remove_rule' function.
Unauthenticated Remote Code Execution in kotaemon
1 rule 2 TTPs 1 CVEAn insecure deserialization vulnerability (CVE-2026-69098) in the kotaemon check_connection endpoint allows unauthenticated attackers to achieve remote code execution by injecting malicious __type__ fields.
Flowise Broken Access Control in /api/v1/files
1 rule 1 TTP 1 CVEA broken access control vulnerability in Flowise versions 3.1.2 and earlier allows authenticated users with low-privileged API keys to list and delete files across different workspaces within the same organization.
Flowise Unauthenticated RCE via Environment Variable Bypass
6 rules 11 TTPs 2 CVEsFlowise v3.1.2 and earlier are vulnerable to unauthenticated remote code execution because the CVE-2025-8943 patch relies on an incomplete environment variable blocklist, allowing attackers to inject configuration variables that force arbitrary package installation.
Flowise Sandbox Escape to Remote Code Execution
2 TTPs 1 CVEAuthenticated attackers can exploit an insecure JavaScript sandbox configuration in FlowiseAI to execute arbitrary system commands via a chained injection and path traversal payload.
Hard-Coded Cryptographic Key in Acrisure KARR BT and DR-100
1 TTPA hard-coded cryptographic key vulnerability (CVE-2026-18411) in Acrisure KARR BT and DR-100 automotive anti-theft systems allows nearby attackers to issue unauthorized commands to vehicles.
Integrity Vulnerability in Thermo Fisher Genetic Analyzer Software
Thermo Fisher Applied Biosystems Genetic Analyzer software lacks integrity checks for output data files, enabling local users to modify DNA analysis results (CVE-2026-17583).
Unauthenticated Remote Code Execution in Perspective 5.0.0
3 TTPs 3 CVEsPerspective version 5.0.0 is vulnerable to unauthenticated remote code execution via unsafe Python eval() calls within the PolarsVirtualServer backend triggered by crafted protobuf messages.