July 2026 (30)
CVE-2026-16462: SQL Injection Vulnerability in PROCON-WEB SCADA
1 rule 2 TTPs 1 CVECVE-2026-16462 describes a critical SQL Injection vulnerability in Weidmueller Interface's PROCON-WEB SCADA, where a remote unauthenticated attacker can execute arbitrary SQL commands via the 'GetGridData' endpoint due to improper input sanitization, potentially leading to full system compromise.
Netty: Vulnerability Enables Denial of Service
1 TTPA denial of service vulnerability exists in Netty, which an unauthenticated, remote attacker can exploit, allowing the attacker to disrupt the availability of affected systems or services.
Erlang/OTP: Multiple Vulnerabilities
2 TTPsMultiple vulnerabilities in Erlang/OTP allow a remote, anonymous attacker to perform a Denial of Service attack, execute arbitrary code, bypass security measures, and manipulate or disclose data.
Multiple Vulnerabilities in Linux Kernel Allow Local Privilege Escalation and DoS
4 TTPsMultiple vulnerabilities in the Linux Kernel can be exploited by a local attacker to corrupt memory, disclose sensitive information, manipulate data, or cause a denial-of-service condition, often leading to privilege escalation.
Generic SQL Injection Vulnerability in WordPress Web Directory Free Plugin (CVE-2026-14785)
1 rule 2 TTPs 1 CVEThe Web Directory Free plugin for WordPress, in all versions up to and including 1.7.13, is vulnerable to generic SQL Injection through the 'levels' parameter. This flaw, caused by insufficient input escaping and lack of query preparation, enables unauthenticated attackers to append arbitrary SQL queries to existing ones, allowing them to extract sensitive information directly from the database.
Privilege Escalation in Eazy Plugin Manager for WordPress (CVE-2026-14328)
2 rules 1 TTP 1 CVEThe Eazy Plugin Manager - Powerful Plugin Management Solution for WordPress plugin for WordPress (versions up to and including 4.4.1) is vulnerable to privilege escalation (CVE-2026-14328), allowing authenticated attackers with Subscriber-level access to read sensitive WordPress options, compute an authentication key, and obtain Administrator authentication cookies, leading to full site takeover if the plugin's remote connection feature is configured.
WordPress PickPlugins Question Answer Plugin SQL Injection Vulnerability (CVE-2026-10207)
1 rule 2 TTPs 1 CVEAn unauthenticated SQL injection vulnerability, tracked as CVE-2026-10207, exists in the PickPlugins Question Answer plugin for WordPress versions up to and including 1.2.73, allowing attackers to extract sensitive database information due to insufficient input sanitization of the 'id' GET parameter and improper SQL query construction.
CVE-2026-14516 - Bookly WordPress Plugin Time-Based SQL Injection
1 rule 2 TTPs 1 CVEUnauthenticated attackers can exploit a time-based SQL Injection vulnerability (CVE-2026-14516) in the Bookly WordPress plugin, affecting versions up to and including 27.5, via the 'staff_ids' parameter, chaining requests to `bookly_get_form_id` and `bookly_render_time` to extract sensitive database information due to insufficient input escaping and lack of CSRF protection.
CVE-2026-14169: Ads-tec DVG-IRF Series Vulnerability Allows Remote Admin Lockout
1 TTP 1 CVEA low-privileged remote attacker can exploit an incorrect behavior order vulnerability (CVE-2026-14169, CWE-696) in multiple ads-tec Industrial IT DVG-IRF series devices (versions prior to 2.3.0) by sending crafted input, leading to inconsistent account states and password overwrites, resulting in complete administrative unavailability of the device.
CVE-2026-14168: ads-tec Industrial IT DVG-IRF Privilege Escalation
1 TTP 1 CVEA high-severity missing authorization vulnerability, CVE-2026-14168, allows a low-privileged remote attacker to escalate privileges to administrator level by exploiting the insert path of the configuration table in ads-tec Industrial IT DVG-IRF series products, ultimately granting full system access.
CVE-2026-14167: ads-tec Industrial IT DVG-IRF Series Privilege Escalation Vulnerability
1 TTP 1 CVEA low-privileged remote attacker can exploit CVE-2026-14167, an incorrect authorization vulnerability in multiple ads-tec Industrial IT DVG-IRF series products, to perform privileged configuration changes, including permission management, leading to privilege escalation.
TrueBooker WordPress Plugin SQL Injection Vulnerability (CVE-2026-13161)
1 rule 2 TTPs 1 CVEAn unauthenticated attacker can exploit CVE-2026-13161, a generic SQL Injection vulnerability in the TrueBooker - Appointment Booking and Scheduler System plugin for WordPress affecting versions up to and including 1.2.2, by manipulating the 'alldata[truebooker_user]' parameter in POST requests, allowing the extraction of sensitive database information.
WordPress Premium Packages Plugin SQL Injection Vulnerability (CVE-2026-12800)
1 rule 3 TTPs 1 CVEThe Premium Packages - Sell Digital Products Securely plugin for WordPress, in versions up to and including 6.2.0, is vulnerable to SQL Injection via the 'code' parameter of the POST /wp-json/wpdmpp/v1/cart/coupon REST API endpoint, allowing unauthenticated attackers to append additional SQL queries to extract sensitive database information.
Adversarial Indirect Prompt Injection Tools Emerge in Underground Forums
4 TTPsMalicious actors are actively developing and advertising tools for Indirect Prompt Injection (IDPI) on underground forums, leveraging hidden prompts within various mediums like emails, PDFs, calendar invites, and malvertising to manipulate Large Language Models (LLMs) and AI agents, potentially leading to unintended behaviors such as data exfiltration or bypassing content moderation systems.
Credential Manager Access By Uncommon Applications
1 rule 1 TTPA SigmaHQ detection rule identifies suspicious processes accessing Windows credential manager and vault files, potentially indicating credential theft by tools like Mimikatz, enabling lateral movement and data exfiltration.
System File Execution Location Anomaly
1 rule 4 TTPsThis brief describes the detection of Windows system binaries executing from uncommon locations, a defense evasion and stealth technique employed by various threat actors including Lazarus Group and Sidewinder APT, indicating potential malicious activity on an endpoint.
Msiexec Quiet Installation for Proxy Execution
1 rule 1 TTPAdversaries leverage the Windows Installer utility msiexec.exe to proxy the quiet execution of malicious payloads, bypassing traditional security controls by masquerading as legitimate installation processes.
Suspicious WSMAN Provider Image Loads
1 rule 2 TTPsA detection engineering rule targets suspicious loading of Windows Management (WSMAN) provider DLLs by unusual processes, indicating potential local or remote execution and lateral movement through Windows Remote Management (WinRM) by threat actors.
PowerShell Core DLL Loaded By Non PowerShell Process
1 rule 1 TTPThis threat brief details a detection for the suspicious loading of PowerShell Core DLLs by non-PowerShell processes, a technique often employed by attackers to execute PowerShell code stealthily and evade security monitoring.
Uncommon Process Loading RstrtMgr.DLL for Malicious Purposes
1 rule 2 TTPsAttackers, including ransomware families like Conti and Cactus, and wipers such as BiBi, abuse the legitimate Windows `RstrtMgr.dll` (Restart Manager) by loading it into uncommon processes to terminate applications, including security software and those holding locks on files, facilitating data encryption or destruction.
PSScriptPolicyTest Creation By Uncommon Process
1 rule 1 TTPThis brief describes a detection opportunity for the stealthy creation of the 'PSScriptPolicyTest' PowerShell script by processes other than standard PowerShell executables or legitimate Windows components, a behavior potentially indicative of advanced adversaries attempting to bypass PowerShell logging and security policies.
Suspicious System Process Names in Unusual File Locations
1 rule 1 TTPThis brief detects an attacker's attempt to evade detection and maintain persistence by creating executable files with names identical to legitimate Windows system processes in non-standard directories, a tactic associated with stealth and defense evasion.
Suspicious Access to Windows DPAPI Master Keys by Uncommon Applications
1 rule 1 TTPAdversaries can access Windows Data Protection API (DPAPI) master keys using uncommon applications like Mimikatz to decrypt user credentials and sensitive data, indicating credential theft activities.
CVE-2026-12741: Unauthenticated SQL Injection in WP Fast Total Search WordPress Plugin
1 rule 2 TTPs 1 CVEAn SQL injection vulnerability (CVE-2026-12741) exists in the WP Fast Total Search - The Power of Indexed Search plugin for WordPress, affecting all versions up to and including 1.80.280. The flaw, located in the 'form_data[s]' parameter, is due to insufficient input escaping and poor SQL query preparation, allowing unauthenticated attackers to inject malicious SQL queries and extract sensitive information from the underlying database.
Authentication Bypass in WordPress SMS Alert Plugin Leads to Account Takeover (CVE-2026-15014)
1 rule 2 TTPs 1 CVEAn authentication bypass vulnerability (CVE-2026-15014) in the 'SMS Alert - SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery' WordPress plugin allows unauthenticated attackers to achieve account takeover by exploiting a flaw in the `processRegistration()` function's OTP verification, enabling authentication as any existing WordPress user with a known phone number.
Mirage Kitten Targets Middle East and Africa with New Malware
4 rules 13 TTPs 3 IOCsMirage Kitten, an advanced persistent threat (APT) group, is deploying new Windows backdoor (NightLedger) and WebSocket tunnelers (ArcBridge, BridgeHead) via spear-phishing campaigns to conduct cyber-espionage and data exfiltration against aerospace, aviation, defense, and telecommunications sectors in the Middle East and Europe.
CVE-2026-50107: NGINX Gateway Fabric Configuration Injection Vulnerability
2 rules 1 TTP 5 CVEs 2 IOCsAn injection vulnerability, CVE-2026-50107, exists in the NGINX configuration generator component of NGINX Gateway Fabric when configured with NGINX Plus or NGINX Open Source as the data plane, allowing authenticated attackers with CRD modification permissions to inject arbitrary NGINX configuration directives via unsanitized user-supplied string values in the access log format setting, leading to control plane compromise and potential defense evasion or system impact.
Arbitrary File Deletion Vulnerability in WordPress Better Messages Plugin
1 rule 2 TTPs 1 CVEA path traversal vulnerability, CVE-2026-16585, in the Better Messages - Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress allows authenticated administrators to delete arbitrary files on the server by bypassing file path validation, potentially leading to remote code execution.
The Demi WordPress Plugin Vulnerable to Arbitrary Directory Deletion (CVE-2026-14490)
2 TTPs 1 CVEUnauthenticated attackers can exploit CVE-2026-14490 in The Demi - One Click Demo Import, WP Backup & Site Migration WordPress plugin (versions up to and including 0.0.7) to achieve arbitrary directory deletion by retrieving a publicly exposed HMAC signing key and forging valid requests to a vulnerable AJAX handler.
Svchost LOLBAS Execution Process Spawn
1 rule 2 TTPsThis brief details the detection of `svchost.exe` spawning Living Off The Land Binaries and Scripts (LOLBAS) processes, indicating potential malicious code execution, privilege escalation, or persistence attempts by adversaries within a Windows environment.