Skip to content
Threat Feed

May 2026 (30)

high advisory

Spring AI MCP Security Unvalidated URL Fetching (SSRF)

The mcp-security framework fails to implement SSRF mitigations outlined in the Model Context Protocol, processing untrusted URLs for OAuth-related discovery and metadata without verification, affecting installations with Dynamic Client Registration (DCR) enabled and exposing them to potential Server-Side Request Forgery (SSRF) attacks, tracked as CVE-2026-45609.

mcp-client-security ssrf spring-ai oauth cve-2026-45609
2r 1t
high advisory

Graphite graph database engine Insecure Deserialization Vulnerability

Graphite versions before 0.2 are vulnerable to insecure deserialization due to the use of Python's `pickle` module for database storage, allowing attackers to craft malicious database files that execute arbitrary code when loaded.

graphitedb insecure-deserialization code-execution
1r 1t
medium advisory

form-data-objectizer Prototype Pollution Vulnerability (CVE-2026-46510)

The form-data-objectizer npm package version 1.0.0 is vulnerable to prototype pollution (CVE-2026-46510) via crafted form keys, allowing an attacker to modify Object.prototype and potentially cause denial-of-service, bypass security checks, or inject unintended values.

form-data-objectizer prototype-pollution javascript node.js
2r 1t
high advisory

APM CLI Symlink Vulnerability Leads to File Content Disclosure (CVE-2026-45539)

A vulnerability in the `apm-cli` tool allows a malicious APM package to include symlinks that, when installed, can lead to file-content disclosure, by dereferencing symlinks under `.apm/prompts/` and `.apm/agents/` during `apm install`, and copying host-local file contents into the project tree.

apm symlink file-disclosure apm-cli dependency-confusion
2r 1t 1c
medium advisory

GnuTLS DTLS Packet Reordering Vulnerability (CVE-2026-42009)

A remote attacker could exploit a flaw in GnuTLS's DTLS packet reordering logic (CVE-2026-42009) to cause unstable packet ordering or undefined behavior, resulting in a denial of service.

GnuTLS dtls dos cve-2026-42009
2r 1t 1c
medium advisory

AWS EKS Control Plane Logging Disabled

This rule detects successful Amazon EKS UpdateClusterConfig requests that disable control plane logging, potentially indicating defense evasion via compromised AWS credentials or unauthorized administrative access that reduces visibility into cluster activity.

EKS cloud kubernetes aws defense_evasion
2r 1t
medium advisory

Avro Map Decoder Vulnerable to Denial-of-Service via Unbounded Memory Allocation

The Avro map decoder accepted attacker-controlled block-element counts, leading to unbounded map growth and potential denial-of-service via memory exhaustion; upgrading to v2.33.0 requires explicit configuration of MaxMapAllocSize to mitigate the vulnerability.

avro +1 denial-of-service memory-exhaustion data-serialization
2r 1t
high advisory

Suspicious SUID Binary Execution for Privilege Escalation on Linux

This detection rule identifies suspicious executions of SUID binaries that may be used for privilege escalation on Linux systems, focusing on scenarios where the real user and parent user are not root, combined with minimal argument counts and suspicious parent contexts.

privilege-escalation suid linux
2r 2t
high advisory

Potential Privilege Escalation via SUID/SGID on Linux

This rule detects potential privilege escalation under the root effective user when the real user and parent user are not root, indicative of the execution of binaries with SUID or SGID bits set, often exploited by adversaries to gain elevated access on Linux systems.

Elastic Endpoint Security privilege-escalation suid sgid linux
3r 2t
high advisory

Zoom-themed Phishing Campaign Delivering ConnectWise ScreenConnect

A phishing campaign impersonates Zoom to trick users into downloading and installing ConnectWise ScreenConnect, a legitimate remote monitoring and management tool, allowing attackers to gain persistent remote access, harvest credentials, and deploy secondary malware such as ransomware.

Zoom +2 phishing remote_access social_engineering screenconnect
2r 5t 4i
medium advisory

macOS Finder Sync Plugin Persistence via Pluginkit

This rule detects suspicious Finder Sync plugin registrations on macOS, where adversaries abuse the pluginkit process to establish persistence by repeatedly executing malicious payloads.

OneDrive +5 persistence macos pluginkit finder sync plugin
2r 1t
high threat

Q1 2026 Malware Trends: Ransomware and Miners

Kaspersky's Q1 2026 report highlights trends in malware targeting Windows, macOS, and IoT devices, including the exploitation of CVE-2026-20131 in Cisco Secure FMC firewalls and the rise of new ransomware variants and mining activities.

exploited Secure FMC ransomware miner vulnerability
2r 2t 1c
medium advisory

Q1 2026 Mobile Threat Landscape: SparkCat and Triada Updates

The Q1 2026 mobile threat landscape saw a decrease in overall attack volume driven by reduced adware and RiskTool detections, while the number of unique users targeted remained stable, with new SparkCat variants on app stores and increased banking Trojan and Triada backdoor activity.

Google Play +2 mobile malware trojan cryptostealer sparkcat triada android ios
2r 1t
high advisory

Multiple Vulnerabilities in Microsoft Edge Allow for Remote Code Execution and Security Policy Bypass

Multiple vulnerabilities in Microsoft Edge prior to version 148.0.3967.70 allow a remote attacker to execute arbitrary code and bypass security policies.

Edge microsoft-edge rce security-bypass
2r 1t 4c
high advisory

Kubernetes API Request Impersonating Privileged Identity

Detects Kubernetes API requests where a user is impersonating a privileged cluster identity such as system:kube-controller-manager, system:admin, system:anonymous, or a member of the system:masters group, potentially leading to privilege escalation and unauthorized access.

Kubernetes privilege-escalation defense-evasion
2r 2t
medium advisory

Kubernetes Static Pod Manifest File Access

This rule detects Linux process executions that access Kubernetes static pod manifest files, potentially indicating malicious tampering for persistence or privilege escalation.

kubernetes persistence privilege_escalation linux
2r 2t
high advisory

Multiple Vulnerabilities in Joplin Allow for DoS, Information Disclosure, and Arbitrary File Overwrite

Multiple vulnerabilities in Joplin allow an attacker to perform a denial of service attack, disclose sensitive information, or overwrite arbitrary files, potentially leading to arbitrary code execution.

Joplin vulnerability dos information-disclosure file-overwrite
2r 1t
medium advisory

Entra ID Register Device with Unusual User Agent (Azure AD Join)

Detects suspicious Microsoft Entra ID audit events for device registration where details indicate an Azure AD join and the user agent is not a standard registration client, potentially indicating scripted registration, third-party tooling, or malicious device registration for persistence or token abuse.

Entra ID azure entra_id persistence
2r 1t
critical threat

Multiple Vulnerabilities in Webmin Allow Remote Code Execution

Multiple vulnerabilities in Webmin allow an attacker to bypass security measures and execute arbitrary code with administrator privileges, leading to potential system compromise.

Webmin rce privilege-escalation execution
2r 3t
high advisory

Budibase Security Bypass Vulnerability

An authenticated remote attacker can exploit a vulnerability in Budibase to bypass security measures and manipulate data.

Budibase security-bypass data-manipulation
2r 1t
high advisory

Google Workspace Device Registration After OAuth from Suspicious ASN

Detects a sequence of events in Google Workspace where OAuth authorization from a suspicious ASN is immediately followed by device registration, potentially indicating attacker-controlled device enrollment after user authorization of a sensitive client, possibly related to Tycoon2FA.

Google Workspace cloud google-workspace persistence initial-access tycoon2fa
2r 2t
high threat

Entra ID OAuth Device Code Phishing via AiTM

Detects successful Microsoft Entra ID sign-ins using the OAuth device code authentication protocol with the Microsoft Authentication Broker client requesting first-party Office API resources, indicative of adversary-in-the-middle (AiTM) phishing attacks such as Tycoon 2FA.

Entra ID +3 Tycoon2FA cloud identity azure entra_id phishing
2r 3t
medium advisory

Entra ID Microsoft Authentication Broker Sign-In to Unusual Resource

Detects successful Microsoft Entra ID sign-ins where the client application is the Microsoft Authentication Broker (MAB) and the requested resource identifier is outside a short list of commonly observed first-party targets, potentially indicating abuse to obtain tokens for unexpected APIs or enterprise applications.

Entra ID cloud identity azure entra_id microsoft_entra_id sign_in_logs threat_detection initial_access
2r 2t
high advisory

GIMP Vulnerability Allows Remote Code Execution

A remote, anonymous attacker can exploit a vulnerability in GIMP to execute arbitrary program code.

GIMP code-execution vulnerability
2r 1t
high advisory

GIMP Multiple Vulnerabilities Allow Remote Code Execution

A remote, anonymous attacker can exploit multiple unspecified vulnerabilities in GIMP to execute arbitrary program code, potentially leading to complete system compromise.

GIMP rce code-execution
2r 1t
critical advisory

Multiple Vulnerabilities in NGINX Open Source and NGINX Plus

Multiple vulnerabilities in NGINX Open Source and NGINX Plus allow a remote, anonymous attacker to bypass security measures, execute arbitrary code, manipulate data, disclose confidential information, or cause a denial-of-service condition.

nginx open source +1 nginx vulnerability webserver
2r 8t
medium advisory

Curl or Wget Execution from Container Context

Detects execution of curl or wget from processes running inside OCI/runc-backed containers, potentially indicating ingress tool transfer or data exfiltration after a container breakout.

command-and-control execution container linux
2r 1t
medium advisory

Kubernetes Multi-Resource Discovery

Detects potential reconnaissance activity in Kubernetes environments where adversaries or automated scripts attempt to map the environment by rapidly querying multiple API resource kinds, indicative of initial setup before actions like privilege escalation or data exfiltration.

kubernetes discovery
2r 1t
high advisory

Kubernetes Secrets List Across Cluster or Sensitive Namespaces

Detects list operations on Kubernetes Secrets from a non-loopback client when the request URI targets cluster-wide secrets or list operations under kube-system or default namespaces, indicating potential credential access or discovery attempts.

kubernetes credential-access discovery cloud
2r 2t
medium advisory

Kubernetes Secret Access by Node or Pod Service Account

This rule detects Kubernetes audit events where node or pod service accounts are accessing secrets via `get` or `list` operations, which may indicate credential access attempts by attackers sweeping Secret objects for sensitive information.

kubernetes credential-access cloud
2r 1t