Skip to content
Threat Feed

May 2026 (30)

high advisory

Lateral Movement via Remote Startup Folder Modification

Adversaries may achieve lateral movement by creating malicious files in remote Windows startup folders via RDP or SMB, leading to code execution upon system reboot or user logon.

m365_defender +4 lateral-movement persistence windows
2r 3t
high advisory

Potential SharpRDP Behavior

This rule detects potential SharpRDP behavior, a tool used for authenticated command execution against a remote target via Remote Desktop Protocol (RDP) for lateral movement by identifying incoming RDP connections followed by RunMRU registry value modifications and subsequent process execution.

Elastic Defend +1 lateral-movement execution windows sharprdp
2r 3t
high advisory

Execution via TSClient Mountpoint

The rule detects execution of processes from the Remote Desktop Protocol (RDP) shared mountpoint tsclient on Windows hosts, which may indicate a lateral movement attempt.

Microsoft Defender XDR +1 lateral-movement execution rdp tsclient windows
2r 2t
high advisory

Potential Remote Desktop Shadowing Activity

This brief detects potential remote desktop shadowing activity by identifying modifications to the RDP Shadow registry or the execution of processes indicative of an active RDP shadowing session, which adversaries may abuse to spy on or control other users' RDP sessions.

Windows NT +4 rdp shadowing lateral-movement windows
3r 1t
high advisory

Incoming DCOM Lateral Movement with MMC

Detection of Distributed Component Object Model (DCOM) abuse to execute commands remotely via the MMC20 Application COM object, potentially indicating lateral movement.

Elastic Defend +1 lateral-movement dcom windows
2r 1t
high advisory

Incoming DCOM Lateral Movement via MSHTA

Detection of Distributed Component Object Model (DCOM) abuse to execute commands from a remote host via the HTA Application COM Object, potentially indicating lateral movement.

Windows lateral-movement dcom mshta
2r 1t
high advisory

Suspicious Kerberos Authentication Ticket Request

This rule detects suspicious Kerberos authentication ticket requests by correlating network connections to the standard Kerberos port (88) from a source machine with a Kerberos authentication ticket request from the target domain controller, which could indicate lateral movement or credential access attempts within a Windows domain.

Elastic Defend +4 lateral-movement threat-detection windows
2r 2t
critical advisory

OpenClaude Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` Input

A sandbox bypass vulnerability exists due to the `dangerouslyDisableSandbox` parameter being exposed as part of the BashTool input schema, allowing an untrusted LLM to bypass the sandbox for any command and achieve host-level code execution due to the default `allowUnsandboxedCommands: true` setting.

sandbox-bypass llm code-execution
3r 1t
high advisory

Third-Party Compromise Leading to Stealthy Intrusions via Trusted IT Management Tools

A threat actor compromised a third-party IT services provider and abused legitimate IT management tools like HPE Operations Agent to conduct a stealthy campaign focusing on long-term access, credential theft, and persistent footholds within a target environment.

Microsoft Defender +2 third-party-compromise trusted-relationship lateral-movement credential-access
2r 4t
high threat

Suspicious Processes Spawned by Microsoft Exchange Worker Process

Detects suspicious processes spawned by the Microsoft Exchange Server worker process (w3wp.exe), potentially indicating exploitation or web shell activity.

exploited Exchange Server initial-access webshell exchange-server windows
2r 2t
high threat

Suspicious SolarWinds Web Help Desk Java Module Load or Child Process

Detects suspicious behavior related to SolarWinds Web Help Desk, specifically the loading of untrusted native modules (DLLs) or the spawning of suspicious child processes (cmd, PowerShell, rundll32) by the Java process, potentially indicating exploitation of deserialization vulnerabilities CVE-2025-40536 and CVE-2025-40551.

Web Help Desk solarwinds webhelpdesk deserialization cve-2025-40536 cve-2025-40551 remote code execution initial access
2r 1t 2c
high advisory

Volume Shadow Copy Deletion via WMIC

The rule detects the use of wmic.exe for shadow copy deletion on Windows endpoints, a common tactic used in ransomware or other destructive attacks to inhibit system recovery.

Windows Management Instrumentation +3 impact windows threat-detection
3r 2t
high advisory

Volume Shadow Copy Deletion via PowerShell

Detects the use of PowerShell to delete volume shadow copies, a tactic commonly employed by ransomware and other destructive attacks to hinder data recovery efforts.

Windows impact powershell volume shadow copy ransomware
2r 1t
high advisory

Potential Ransomware Note File Dropped via SMB

The rule identifies the creation of files resembling ransomware notes via SMB, potentially indicating a remote ransomware attack on Windows systems.

Elastic Defend ransomware smb impact windows
2r 4t
high advisory

Suspicious File Renamed via SMB

Detection of a suspicious file rename operation following an incoming SMB connection, potentially indicating a remote ransomware attack via the SMB protocol, targeting Windows hosts.

Elastic Defend ransomware smb file-rename windows
2r 4t
high advisory

Potential System Tampering via File Modification

Detection of attempts to delete or modify critical Windows boot files indicating a potential destructive attack to prevent system startup.

Elastic Defend +2 impact destructive-attack windows
2r 1t
medium advisory

Ivanti Addresses Multiple Vulnerabilities in Various Products

Ivanti released security advisories on May 12, 2026, to address vulnerabilities in Xtraction, Endpoint Manager (EPM), Virtual Traffic Manager (vTM), and Secure Access Client (Windows), urging users to apply necessary updates to mitigate potential risks from CVE-2026-8043, CVE-2026-8051, CVE-2026-7431, and CVE-2026-7432.

Xtraction +3 ivanti vulnerability patch cve
2r 4c
high advisory

Dalfox Server Mode Unauthenticated Arbitrary File Read

Dalfox server mode is vulnerable to an unauthenticated arbitrary file read with out-of-band exfiltration via the `custom-payload-file` parameter, allowing attackers to read sensitive files on the host.

dalfox/v2 unauthenticated-access file-read ghsa
2r 3t
high advisory

Dalfox Server Mode Unauthenticated Arbitrary File Create/Append Vulnerability

Dalfox in REST API server mode is vulnerable to CVE-2026-45089, an unauthenticated arbitrary file create/append vulnerability, due to the `output`, `output-all`, and `debug` options being deserialized directly from the attacker's request body, allowing a network caller to create or append to any file writable by the dalfox process.

dalfox <= 2.12.0 xss file-write unauthenticated CVE-2026-45089
2r 3t
medium advisory

Dalfox Unauthenticated Remote DoS via Closed-Channel Write in ParameterAnalysis

Dalfox is vulnerable to an unauthenticated remote denial-of-service (DoS) vulnerability (CVE-2026-45090) due to a closed channel write in the `ParameterAnalysis` function, triggered by a crafted POST request that crashes the Dalfox server process.

dalfox dos vulnerability
2r 1t
critical advisory

Dalfox Server Mode Vulnerable to Unauthenticated Remote Code Execution via `found-action`

Dalfox in REST API server mode is vulnerable to unauthenticated remote code execution (CVE-2026-45087) because the server binds to 0.0.0.0:6664 by default without requiring an API key and deserializes attacker-supplied JSON in `POST /scan` without stripping the `FoundAction` and `FoundActionShell` fields, allowing arbitrary command execution.

dalfox/v2 rce dalfox cve-2026-45087
2r 1t
critical advisory

sealed-env Enterprise Mode TOTP Secret Leak in Unseal Tokens (CVE-2026-45091)

sealed-env versions 0.1.0-alpha.1 through 0.1.0-alpha.3 embedded the operator's literal TOTP secret in the JWS payload of every minted unseal token, allowing an attacker with a leaked token and the master key to mint new unseal tokens indefinitely.

sealed-env +1 credential-access cve-2026-45091
2r 1t 1c
high advisory

protobuf.js Code Injection via Crafted Bytes Field Defaults (CVE-2026-44293)

protobuf.js is vulnerable to code injection (CVE-2026-44293); by crafting a protobuf descriptor with a non-string default value for a `bytes` field, an attacker can inject arbitrary Javascript code into the generated `toObject` conversion function if default values are enabled, requiring the application to load an attacker-controlled schema and convert a message of the affected type with defaults enabled.

protobufjs code-injection CVE-2026-44293 javascript
2r 1t
high advisory

protobuf.js Denial-of-Service Vulnerability via Unbounded Recursion (CVE-2026-44289)

protobuf.js is vulnerable to a denial-of-service (DoS) attack (CVE-2026-44289) due to unbounded recursion while decoding nested protobuf data, potentially leading to stack exhaustion and process crashes when processing crafted protobuf binary payloads.

protobufjs +1 denial of service CVE-2026-44289
2r 1t
high advisory

protobuf.js Prototype Pollution Leads to Code Generation Gadget

protobufjs versions 7.5.5 and earlier, as well as versions 8.0.0 through 8.0.1, are vulnerable to arbitrary JavaScript execution if Object.prototype has been polluted, allowing attackers to influence generated encode/decode functions.

protobufjs +1 prototype-pollution code-generation javascript
2r
high advisory

protobuf.js CLI pbts Command Injection Vulnerability

The protobuf.js CLI tool `pbts` is vulnerable to OS command injection via crafted filenames or paths with shell metacharacters, potentially leading to arbitrary command execution with the privileges of the `pbts` process when invoked on attacker-influenced file paths; CVE-2026-42290.

protobufjs-cli +1 command-injection protobufjs cli execution
2r 1t
medium advisory

Schneider Electric Security Advisory AV26-449 Addressing Multiple Vulnerabilities

Schneider Electric published advisories on May 12, 2026, addressing vulnerabilities in multiple products including Ecostruxure Machine Expert HVAC, Easergy MiCOM C264, Easergy C5, Easergy MiCOM P30, Easergy MiCOM P40, EcoStruxure Power Automation System, iPMFLS, PowerLogic, Saitel DP, EasyLogic T150, EasyLogic T150 Remote Terminal Unit and Controller, Saitel DP Remote Terminal Unit and Controller, EcoStruxure Panel Server PAS400, PAS600, PAS600V2, PAS800, PAS800V2 and Easergy MiCOM Px40 Series related to clear text storage, insufficient entropy, improper path restrictions and insecure defaults.

Ecostruxure Machine Expert HVAC +17 vulnerability scada ics ot
2r
medium advisory

Siemens Security Advisory Addressing Multiple Product Vulnerabilities

Siemens released a security advisory on May 12, 2026, addressing vulnerabilities in a range of products including RUGGEDCOM, SCALANCE, Solid Edge, and SIMATIC, prompting users to apply necessary updates.

RUGGEDCOM ROX II family +20 siemens security-advisory industrial-control-systems
2r
medium advisory

Multiple Vulnerabilities in Microsoft Azure

Multiple vulnerabilities exist in Microsoft Azure, specifically affecting azl3 kernel and azl3 krb5, potentially leading to an unspecified security issue.

Azure +2 vulnerability
2r 3c
high advisory

Multiple Vulnerabilities in Microsoft Edge Allow for Privilege Escalation, Data Breach, and Security Policy Bypass

Multiple vulnerabilities in Microsoft Edge and Microsoft Edge for Android can allow an attacker to perform privilege escalation, cause a data breach, and bypass security policies.

Edge +1 vulnerability privilege-escalation data-breach security-policy-bypass
2r 1t 1c