September 2026 (30)
Octopus Deploy File Path Manipulation and Potential RCE
1 TTP 1 CVEA vulnerability in Octopus Deploy allows remote attackers to perform unauthorized file manipulation and potentially execute arbitrary code due to improper path validation.
Arbitrary Code Execution in BusyBox via Heap Buffer Overflow
1 TTP 1 CVEA heap-based buffer overflow vulnerability (CVE-2022-30065) in BusyBox allows a local attacker to execute arbitrary code and compromise system integrity.
Multiple Vulnerabilities in GNU C Library
1 TTPMultiple vulnerabilities in the GNU C Library (glibc) allow a local attacker to perform privilege escalation or trigger a denial of service condition on affected Linux-based systems.
Remote Code Execution Vulnerability in Netgate pfSense
1 TTPAn authenticated remote attacker can exploit a vulnerability in Netgate pfSense to bypass security controls and execute arbitrary PHP code and shell commands.
Domain-Restriction Bypass in n8n OpenAI Chat Model Node
3 TTPs 2 CVEsAn unauthenticated credential access vulnerability in n8n allows users to bypass domain restrictions in the OpenAI Chat Model node via the model-search endpoint, leading to unauthorized credential exposure.
Multiple Vulnerabilities in Oracle GraalVM
Oracle GraalVM contains multiple vulnerabilities including CVE-2024-21226, CVE-2024-21227, and CVE-2024-21228, which allow remote unauthenticated attackers to compromise system confidentiality, integrity, and availability.
Multiple Vulnerabilities in Oracle Hyperion
2 CVEsOracle Hyperion is affected by multiple security vulnerabilities (CVE-2024-21054, CVE-2024-21055) that allow remote attackers to compromise system confidentiality, integrity, and availability.
Multiple Vulnerabilities in Aruba EdgeConnect
5 CVEsMultiple vulnerabilities in Aruba EdgeConnect allow for privilege escalation, denial of service, information disclosure, file manipulation, cross-site scripting, security bypass, and arbitrary code execution.
Multiple Vulnerabilities in Apache Airflow Providers
2 TTPsMultiple vulnerabilities in Apache Airflow and its providers (FAB, Keycloak, Kafka, Akeyless) could allow unauthenticated or authenticated attackers to perform remote code execution, privilege escalation, or unauthorized data access.
Vulnerability in F5 NGINX
1 CVEA vulnerability in F5 NGINX, tracked as CVE-2026-90439, allows remote attackers to trigger a denial of service and potentially compromise data integrity.
Multiple Vulnerabilities in Docker Sandboxes
2 CVEsMultiple vulnerabilities, including CVE-2026-77179 and CVE-2026-79994, in Docker Sandboxes versions prior to 0.42.0 could allow remote code execution, data confidentiality breaches, and integrity loss.
Atomic macOS (AMOS) Stealer Activity
1 rule 3 TTPs 4 IOCsAtomic macOS (AMOS) stealer uses deceptive 'toolkit' websites to trick users into executing terminal commands that deploy credential-harvesting malware and persistent Mach-O binaries.
Iranian State-Sponsored Surveillance Malware: Chosen Brick
1 rule 4 TTPsIranian state-sponsored actors are leveraging the 'Chosen Brick' Windows malware to conduct surveillance on global activists and journalists via social engineering and Telegram-based command-and-control.
Command Injection in /api/datastorage/data Endpoint (CVE-2026-27563)
1 rule 1 TTP 1 CVEAn authenticated high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint to execute arbitrary code with root privileges.
Command Injection Vulnerability in IODD Devices (CVE-2026-27561)
1 rule 2 TTPs 1 CVEAn authenticated remote attacker with administrative privileges can execute arbitrary commands with root permissions via a crafted GET request to the /api/iodd/config endpoint.
Command Injection in Attached Devices Endpoint
1 rule 3 TTPs 1 CVEA low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint to achieve arbitrary code execution with root privileges.
Local File Inclusion and RCE in /index.php/ajax/save_iodd_parameters
1 CVEA local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint allows a remote attacker with a valid operator cookie to achieve remote code execution.
Improper Authorization in Device Upload Endpoint (CVE-2026-27552)
1 rule 1 TTP 1 CVEAn improper authorization vulnerability in the /index.php/attached_devices_tab/do_upload endpoint allows low-privileged remote attackers to upload arbitrary files, potentially leading to unauthorized device behavior or denial-of-service.
Command Injection in /index.php/ajax/parameterManage Endpoint
1 rule 1 TTP 1 CVEA low-privileged remote attacker can exploit a command injection vulnerability at the /index.php/ajax/parameterManage endpoint using valid credentials to gain root-level code execution.
Command Injection in Field_Shadow_Password
1 TTP 1 CVECVE-2026-27550 is a command injection vulnerability allowing low-privileged attackers with operator credentials to execute arbitrary commands with root privileges.
PhantomRaven Information Stealer
2 TTPs 8 IOCsA bug bounty hunter is leveraging LLM-generated JavaScript information stealers distributed via malicious npm packages to identify vulnerabilities for bounty submissions.
IDOR Vulnerability in Bookly WordPress Plugin
2 TTPs 1 CVEAn Insecure Direct Object Reference (IDOR) vulnerability in the Bookly WordPress plugin allows unauthenticated attackers to enumerate and exfiltrate private AI booking transcripts via sequential ID incrementation.
Arbitrary File Overwrite in Contest Gallery WordPress Plugin
2 TTPs 1 CVEThe Contest Gallery WordPress plugin is vulnerable to unauthenticated arbitrary file overwrite via the 'baseUrlForFacebook' parameter, allowing authenticated attackers to achieve remote code execution.
Stored XSS in WP-Lister Lite for eBay WordPress Plugin
1 TTP 1 CVEThe WP-Lister Lite for eBay plugin for WordPress contains a Stored Cross-Site Scripting vulnerability in its AJAX Cron Handler allowing unauthenticated script injection.
Authorization Bypass in TrueBooker WordPress Plugin
2 TTPs 1 CVEThe TrueBooker Appointment Booking and Scheduler System plugin for WordPress contains an authorization bypass vulnerability allowing unauthenticated attackers to modify arbitrary user email addresses and facilitate account takeover.
Suspicious Rundll32 Execution Without Command-Line Arguments
2 rules 1 TTP 1 CVEThe execution of rundll32.exe without command-line arguments is detected via endpoint telemetry, a behavior indicative of potential malicious activity such as Cobalt Strike, leading to arbitrary code execution and system compromise.
HTTP Request Smuggling Vulnerability in Tornado
3 TTPs 1 CVETornado versions prior to 6.4.1 are vulnerable to HTTP request smuggling via the improper processing of duplicate 'Transfer-Encoding: chunked' headers when deployed behind a proxy.
HTTP Request Smuggling Vulnerability in http4s Ember
3 TTPs 1 CVEThe http4s Ember HTTP/1.1 parser fails to reject messages containing both 'Transfer-Encoding' and 'Content-Length' headers, enabling CL.TE request smuggling attacks.
Denial of Service via Heap Exhaustion in http4s DigestAuth
1 TTP 1 CVEAn improper eviction logic in the http4s DigestAuth middleware allows unauthenticated remote attackers to cause heap exhaustion and service failure by triggering unbounded growth of the internal nonce map.
Remote Denial of Service in libp2p-quic via Certificate Expiry Race
1 TTP 1 CVEA malicious peer can trigger an application crash in libp2p-quic (< 0.13.1) by initiating a QUIC handshake and delaying the final TLS fragment until the peer certificate expires, causing an unhandled panic.