Briefs
August 2026 (30)
Vulnerabilities in MISP cti-transmute
3 IOCsThe MISP project has patched multiple security vulnerabilities in the cti-transmute tool, including arbitrary file/network access and improper authorization controls for user management.
Flowise Unauthenticated RCE via Environment Variable Bypass
6 rules 11 TTPs 2 CVEsFlowise v3.1.2 and earlier are vulnerable to unauthenticated remote code execution because the CVE-2025-8943 patch relies on an incomplete environment variable blocklist, allowing attackers to inject configuration variables that force arbitrary package installation.
Denying the Worm: Detecting SANDWORM_MODE and AI Toolchain Supply Chain Attacks
3 rules 14 TTPs 8 IOCsThe SANDWORM_MODE campaign is a multi-stage npm supply chain worm that targets AI-augmented development workflows by exploiting runtime behaviors of AI coding assistants and CI/CD pipelines, leading to credential theft, supply chain poisoning, and persistence through obfuscated loaders, credential harvesting, and malicious Git hooks.
IBM Langflow OSS Unauthenticated Remote Code Execution via Chained API Endpoints (CVE-2026-9198)
1 rule 3 TTPs 3 CVEs 2 IOCsUnauthenticated attackers can achieve Remote Code Execution (RCE) on default IBM Langflow OSS deployments, versions 1.0.0 through 1.10.0, by chaining access to the `/api/v1/auto_login` endpoint, which mints SUPERUSER tokens, with the `/api/v1/validate/code` endpoint, which executes user-supplied code via `exec()`.
Unrestricted File Upload Vulnerability in ResponsiveFilemanager
1 rule 1 TTP 1 CVEA publicly disclosed, unpatched unrestricted file upload vulnerability in Trippo ResponsiveFilemanager up to version 9.14.0 allows remote attackers to execute arbitrary code.
Improper Access Control in Atlas-Livre Admin Controllers
1 rule 2 TTPs 1 CVEAn unauthenticated access control flaw in Atlas-Livre allows attackers to bypass authentication and execute privileged database operations due to a failure to terminate script execution following HTTP redirects.
Security Updates for cPanel and WP Squared
2 CVEsWebPros has issued a security advisory addressing HTTP request smuggling and database privilege escalation vulnerabilities in cPanel and WP Squared products.
Critical Remote Code Execution in Check Point Security Management
2 TTPs 1 CVECheck Point security management products are vulnerable to remote code execution and security policy bypass via CVE-2026-18574, affecting multiple current and legacy versions.
Command Injection Vulnerability in GL.iNet AX1800 RPC Endpoint
1 TTP 1 CVEAn authenticated remote command injection vulnerability in the RPC component of GL.iNet AX1800 routers (firmware <= 4.8.3) allows attackers to execute arbitrary system commands via the 'remove_rule' function.
Unauthenticated Remote Code Execution in kotaemon
1 rule 2 TTPs 1 CVEAn insecure deserialization vulnerability (CVE-2026-69098) in the kotaemon check_connection endpoint allows unauthenticated attackers to achieve remote code execution by injecting malicious __type__ fields.
Flowise Broken Access Control in /api/v1/files
1 rule 1 TTP 1 CVEA broken access control vulnerability in Flowise versions 3.1.2 and earlier allows authenticated users with low-privileged API keys to list and delete files across different workspaces within the same organization.
Flowise Sandbox Escape to Remote Code Execution
2 TTPs 1 CVEAuthenticated attackers can exploit an insecure JavaScript sandbox configuration in FlowiseAI to execute arbitrary system commands via a chained injection and path traversal payload.
FlowiseAI Flowise CSV Agent Prompt Injection RCE Vulnerability
2 rules 1 TTP 4 CVEsA remote code execution vulnerability exists in FlowiseAI Flowise version 3.0.13 due to insufficient sandboxing when evaluating LLM-generated Python scripts, allowing unauthenticated attackers to inject malicious code via prompts processed by the CSV Agent node, bypassing input validation, to execute arbitrary OS commands.
Qilin Ransomware Claims New Victim in Agriculture and Food Production Sector
2 rules 13 TTPs 156 IOCsThe Qilin ransomware group, active since July 2022 and utilizing Golang, has claimed a new victim, Danone (International Delights) in the US Agriculture and Food Production sector, employing double extortion tactics involving data encryption and threatened data release.
Hard-Coded Cryptographic Key in Acrisure KARR BT and DR-100
1 TTPA hard-coded cryptographic key vulnerability (CVE-2026-18411) in Acrisure KARR BT and DR-100 automotive anti-theft systems allows nearby attackers to issue unauthorized commands to vehicles.
Integrity Vulnerability in Thermo Fisher Genetic Analyzer Software
Thermo Fisher Applied Biosystems Genetic Analyzer software lacks integrity checks for output data files, enabling local users to modify DNA analysis results (CVE-2026-17583).
Unauthenticated Remote Code Execution in Perspective 5.0.0
3 TTPs 3 CVEsPerspective version 5.0.0 is vulnerable to unauthenticated remote code execution via unsafe Python eval() calls within the PolarsVirtualServer backend triggered by crafted protobuf messages.
Missing Authorization Vulnerability in HAVELSAN Liman MYS
1 CVEA missing authorization vulnerability (CVE-2026-18650) in HAVELSAN Liman MYS versions 2.2.3 through 2.3.0 allows authenticated users to escalate privileges.
Authorization Bypass in HAVELSAN Liman MYS
1 TTP 1 CVEA missing authorization vulnerability in HAVELSAN Liman MYS (versions 2.2.3 through 2.3.0) allows low-privileged users to access restricted system functions.
Authentication Bypass in Puwell IP Camera Firmware
2 TTPs 2 CVEs 1 IOCPuwell IP Camera firmware versions 2.x through 4.x contain an authentication bypass vulnerability (CVE-2026-61514) allowing unauthenticated attackers to control device functions via TCP port 23456.
Microsoft Security Updates - August 2026
5 CVEsRoundup of five Microsoft security advisories affecting Microsoft Office Excel and Microsoft Edge, with CVSS scores from 7.4 to 8.8.
Critical Vulnerabilities in HUMANIST Digital Human Resources
1 rule 3 TTPs 4 CVEsMultiple critical vulnerabilities in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources version 26.0 allow unauthorized access, web shell upload, session hijacking, and remote code execution. Upgrade to version 26.1 immediately.
Remote Command Injection in GL.iNet GL-MT3000
1 rule 3 TTPs 2 CVEs 2 IOCsMultiple unauthenticated remote command injection vulnerabilities in the GL.iNet GL-MT3000 router allow arbitrary code execution via the /cgi-bin/glc component. Public exploit code is available; patch firmware immediately.
Stack-based Buffer Overflow in Autodesk FBX SDK
1 TTP 2 CVEsA stack-based buffer overflow vulnerability (CVE-2026-10709) in the Autodesk FBX SDK allows arbitrary code execution via maliciously crafted FBX files.
QuickFox Supply Chain Attack and FDMTP Implant Deployment
1 TTPThreat actors compromised QuickFox software supply chain to distribute trojanized Windows installers, resulting in the installation of a custom FDMTP implant for persistent access.
N-able N-central Authentication Bypass Exploitation
3 TTPs 2 CVEs 6 IOCsThreat actors are actively exploiting a patch bypass vulnerability (CVE-2026-18577) in N-able N-central to gain administrative control and establish persistent remote access via Cloudflare tunnels.
Unauthenticated Arbitrary File Write in Apache Kyuubi REST API
1 rule 2 TTPsAn unauthenticated path-traversal vulnerability in the Apache Kyuubi REST API (CVE-2026-52680) allows remote attackers to write arbitrary files to the filesystem, leading to remote code execution.
Multiple Vulnerabilities in PHP Language
3 CVEs 1 IOCMultiple vulnerabilities, including CVE-2026-17543, CVE-2026-17544, CVE-2026-7260, and CVE-2026-9672, have been identified in PHP, potentially enabling SQL injection and denial-of-service attacks.
Remote Code Execution in ArcadeDB via Script Triggers
1 TTP 1 CVE 1 IOCAn authenticated remote code execution vulnerability (CVE-2026-67340) in ArcadeDB engine versions before 26.7.2 allows attackers to escape script sandboxing and execute arbitrary OS commands.
Unauthenticated Remote Code Execution in Realtyna Organic IDX and WPL Real Estate WordPress Plugins
1 rule 1 CVE 1 IOCThe Realtyna Organic IDX and WPL Real Estate plugins contain an arbitrary file upload vulnerability (CVE-2026-14483) allowing unauthenticated remote code execution via static, default API credentials.