July 2026 (30)
Authorization Bypass in Red Hat Quay
1 TTP 1 CVEAn incorrect authorization vulnerability in Red Hat Quay allows read-only superusers to view and impersonate robot account tokens, potentially leading to unauthorized repository access.
Logging Operator Configuration Injection Leading to RCE
1 TTPThe Logging operator is vulnerable to remote code execution due to improper input sanitization in Fluentd configuration rendering, allowing authenticated users to inject arbitrary configuration blocks via CRDs.
Zitadel User API Verification Code Disclosure Vulnerability
1 TTP 1 CVEAn improper permission check in Zitadel's user API allows authenticated users to retrieve verification codes for arbitrary contact information, facilitating unauthorized verification of email addresses and phone numbers.
Critical Unauthenticated RCE in JetBrains TeamCity
2 TTPs 1 CVEA critical insecure deserialization vulnerability (CVE-2026-63077) in JetBrains TeamCity allows unauthenticated remote attackers to execute arbitrary system commands via the agent polling protocol.
Proot-Distro Container Isolation Bypass via Crafted Restore Archive
1 TTPThe proot-distro package fails to validate container boundaries during the restoration of archive files, allowing attackers to perform cross-container file disclosure and injection.
Arbitrary Host File Write via Symlink Escape in proot-distro
2 TTPs 1 IOCThe proot-distro utility contains a symlink traversal vulnerability (CVE-2026-54574) that allows malicious tar archives to overwrite arbitrary files on the host filesystem during the installation or reset process.
Easy!Appointments Excessive Data Exposure and Appointment Takeover
1 rule 1 TTP 1 CVEAn excessive data exposure vulnerability in Easy!Appointments version 1.5.2 allows authenticated attackers to retrieve sensitive appointment hashes and hijack other providers' appointments.
Pre-Authentication Remote Code Execution in Xlight FTP Server
1 TTP 2 CVEsXlight FTP Server versions prior to 3.9.5 contain a pre-authentication stack buffer overflow vulnerability triggered by malformed SSH packets, potentially leading to remote code execution.
Unauthenticated API Access in AMMOS Instrument Toolkit DSN Interface
1 TTP 1 CVEThe AMMOS Instrument Toolkit (AIT) DSN Interface prior to version 2.2.2 contains a missing authentication vulnerability in the Space Link Extension interface manager, allowing unauthenticated attackers to invoke sensitive API routes.
Authentication Bypass in AMMOS Instrument Toolkit GUI
1 TTP 1 CVEThe AMMOS Instrument Toolkit (AIT) GUI before version 2.5.1 allows unauthenticated attackers to bypass credential checks to establish sessions and issue arbitrary spacecraft commands.
Heap-Based Buffer Overflow in Autodesk AutoCAD
1 TTP 1 CVEA heap-based buffer overflow vulnerability in Autodesk AutoCAD, AutoCAD LT, and DWG TrueView allows attackers to execute arbitrary code via maliciously crafted DXF files.
AgentCore CLI Code Injection Vulnerability
1 TTP 1 CVEThe AgentCore CLI is vulnerable to arbitrary code execution due to improper escaping of metadata when importing Amazon Bedrock agents, allowing attackers to inject malicious Python code into generated files.
Prebid Server SSRF Vulnerability in Bidder Adapters
2 TTPsPrebid Server contains a Server-Side Request Forgery vulnerability (CVE-2026-54735) allowing unauthenticated attackers to force the server to perform arbitrary outbound HTTP requests.
Req Library Unbounded Archive/Compression Extraction Denial-of-Service
1 TTP 1 CVEThe Elixir library 'Req' (versions >= 0.1.0, < 0.6.1) is susceptible to a denial-of-service vulnerability (CVE-2026-49755) caused by unbounded archive and compression extraction, which an attacker can leverage by providing a malicious HTTP response with a crafted 'content-type' or 'content-encoding' header, leading to memory exhaustion and application crashes.
veraPDF Validation XXE via Rich Text
3 TTPsAn XML External Entity (XXE) injection vulnerability (CVE-2026-54078, CWE-611) in the veraPDF-validation library's `validation-model` module allows a remote attacker to read arbitrary files from the server's file system and perform Server-Side Request Forgery by submitting a crafted PDF containing a malicious rich-text entry, which is then parsed by an insecure `DocumentBuilderFactory`.
veraPDF Validation Module XML External Entity Injection Vulnerability (CVE-2026-54079)
4 TTPsA critical XML External Entity Injection (XXE) vulnerability, CVE-2026-54079, in veraPDF's validation-model module allows a remote attacker to read arbitrary files on the server file system or perform Server-Side Request Forgery (SSRF) by submitting a crafted PDF containing a malicious XFA stream, due to insecure XML parsing defaults.
CVE-2026-42897 Microsoft Exchange Server Cross-Site Scripting Vulnerability
2 rules 2 TTPs 1 CVE 7 IOCsCVE-2026-42897 is a cross-site scripting (XSS) vulnerability in Microsoft Exchange Server that allows an attacker to perform spoofing attacks by injecting malicious scripts into web pages.
Swagger-typescript-api Vulnerable to Authorization Token Exfiltration via Spec $ref
1 rule 5 TTPsThe `swagger-typescript-api` tool is vulnerable to authorization token exfiltration. When a developer provides an `--authorizationToken` to fetch an OpenAPI specification, the tool attaches this token to all subsequent HTTP requests made while resolving external `$ref` URLs within the spec. Critically, it lacks same-origin checks, allowing a malicious OpenAPI spec containing a `$ref` to an attacker-controlled URL to cause the authorization token (e.g., GitHub PAT, OAuth bearer) to be sent verbatim to the attacker. This credential disclosure provides an attacker with the same scope of access as the stolen token, affecting development environments, CI/CD pipelines, and multi-tenant SaaS platforms.
Denial of Service Vulnerability in cJSON Library (CVE-2026-67215)
1 TTP 1 CVECVE-2026-67215 describes a denial-of-service vulnerability in cJSON through version 1.7.19, where an attacker can trigger uncontrolled recursion and stack exhaustion by supplying a crafted RFC 6902 JSON Patch to cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(), leading to process crash.
Apache Tomcat Denial of Service Vulnerability (CVE-2026-66299)
1 TTP 1 CVE 4 IOCsA critical vulnerability, CVE-2026-66299, has been discovered in Apache Tomcat versions 9.0.x prior to 9.0.121, 10.1.x prior to 10.1.58, and 11.0.x prior to 11.0.25, allowing a remote attacker to cause a denial of service (DoS).
Multiple Vulnerabilities in Xen Hypervisor
7 CVEs 31 IOCsMultiple vulnerabilities have been discovered in Xen, allowing an attacker to achieve privilege escalation, remote denial of service, and compromise data confidentiality across all unpatched Xen versions, necessitating immediate patching.
Detection of Container Tunneling and Port Forwarding Tools
1 rule 2 TTPsElastic has released a detection rule for its Defend for Containers integration, identifying the use of tunneling and port forwarding tools within Linux containers, indicating potential threat actor activity such as command-and-control, data exfiltration, or lateral movement.
Public Exploit for Linux Kernel Use-After-Free Vulnerability CVE-2026-43499
1 TTP 2 CVEs 6 IOCsA public exploit has been published for CVE-2026-43499, a Use-After-Free vulnerability in the Linux Kernel, demonstrated to achieve KASLR bypass and potential privilege escalation on Android 15 devices running Linux Kernel 5.15.149, significantly elevating risk for unpatched systems.
DebugFS Execution Detected via Defend for Containers
1 rule 2 TTPsAttackers can leverage the Linux `debugfs` utility within privileged containers to access and manipulate host file systems (e.g., /dev/sd*), enabling privilege escalation and container escape to the underlying host machine.
Suspicious Echo or Printf Execution Detected via Defend for Containers
1 rule 9 TTPsA detection rule for Elastic Defend for Containers identifies threat actors leveraging `echo` or `printf` commands within Linux containers to write data to sensitive files for persistence, decode obfuscated payloads, or establish command and control (C2) communication, impacting system integrity and potentially leading to privilege escalation.
SSH Authorized Key File Activity Detected in Containers
1 rule 4 TTPsAdversaries may modify the Secure Shell (SSH) authorized_keys file inside Linux containers to maintain persistence, achieve lateral movement, or escalate privileges by adding their own public keys, with this activity detected by Elastic Defend for Containers.
Sensitive File Compression Detected in Linux Containers for Credential Access
3 rules 8 TTPs 1 IOCElastic Defend for Containers detects the use of compression utilities like tar or zip within Linux containers to collect sensitive files such as SSH keys, AWS credentials, or system configurations, indicating potential credential access and data collection attempts by adversaries.
Suspicious Interactive Interpreter Execution in Containers
1 rule 6 TTPsThis brief describes the detection of suspicious inline command execution by scripting interpreters (Perl, PHP, Lua, Python, Ruby) within Linux containers, indicating potential malicious code execution, data exfiltration, or command-and-control by an attacker without dropping files, requiring decoding payloads and investigation of container integrity.
Netcat Listener or File Transfer Detected in Containers
1 rule 3 TTPsThis threat brief details the detection of malicious Netcat usage within Linux containers, indicating potential backdoor establishment, persistence, command and control, or data exfiltration by adversaries.
Potential Kubeletctl Execution Detected in Containers
1 rule 3 TTPsDetection engineers should be aware of the execution of `kubeletctl` within Linux containers, a tool attackers can leverage for discovery and lateral movement by interacting directly with the Kubelet API, potentially leading to unauthorized access and resource hijacking within a Kubernetes cluster.