Skip to content
Threat Feed

September 2026 (30)

medium advisory

Detection of Web Server Access Log Deletion

Adversaries often delete web server access logs to destroy forensic evidence and evade detection after unauthorized activity, a behavior monitorable through file deletion events on common web server log paths.

HTTP Server +1 defense-evasion file-integrity logs cross-platform
1r 1t updated
low advisory

Abuse of OpenSSL Utility for Data Encryption

Adversaries leverage the legitimate OpenSSL command-line utility to encrypt sensitive files for ransomware extortion or to obfuscate data prior to exfiltration.

defense-evasion collection openssl ransomware
1r 2t updated
medium advisory

Suspicious Instance Metadata Service API Requests

Attackers with initial code execution on cloud-hosted virtual machines query the Instance Metadata Service (IMDS) at 169.254.169.254 to harvest sensitive instance details and temporary security credentials for unauthorized cloud control-plane access.

credential-access discovery imds cloud-security linux windows macos
1r 1t 1i updated
medium advisory

Detection of Unauthorized Cloud Instance Metadata Service Access

Attackers exploit cloud instance metadata service (IMDS) endpoints by using command-line tools to exfiltrate temporary security credentials and sensitive configuration data, facilitating unauthorized access to cloud resources.

credential-access cloud discovery imds
1r 2t 2i updated
high advisory

Detection of Multi-Cloud CLI Token and Credential Harvesting

Threat actors harvest cloud and container platform authentication tokens by abusing legitimate CLI utilities to output secrets to standard streams, which can be detected via anomalous multi-provider access patterns.

Google Cloud SDK +6 credential-access cloud-security supply-chain
2t updated
medium advisory

Detection of Forced Authentication via SMB Named Pipes

Adversaries leverage Linux-based systems to coerce Windows hosts into authenticating against attacker-controlled resources via SMB named pipes, facilitating NTLM hash capture and SMB relay attacks.

Active Directory +1 credential-access active-directory smb linux windows coercion
1r 1t updated
medium advisory

Credential Access via Chromium Remote Debugging

Adversaries can exploit Chromium-based browser remote debugging features to extract authentication cookies and hijack active web sessions.

Chrome +1 credential-access information-stealer browser-security
1r 1t
medium advisory

Abuse of Azure WireServer for Credential Access and Discovery

Adversaries with code execution on Azure Virtual Machines abuse the host-only WireServer endpoint at 168.63.129.16 to exfiltrate sensitive configuration data, certificates, and VM settings.

Azure Virtual Machines credential-access discovery cloud azure
1r 2t 1i updated
medium advisory

Detection of Anomalous SOCKS Proxy Traffic via FortiGate Integration

This detection leverages cross-platform correlation between FortiGate network application logs and endpoint telemetry to identify processes acting as SOCKS proxies for potential command and control obfuscation.

FortiGate command-and-control proxy network-security cross-platform
1t updated
high advisory

Sensitive Information Exposure in YS LeadGen WordPress Plugin

The YS LeadGen plugin for WordPress versions 2.1.4 and earlier contains an unauthenticated information exposure vulnerability allowing the retrieval of form submission data.

YS LeadGen web-application sensitive-information-exposure wordpress
1r 1t 1c
high advisory

Arbitrary Shortcode Execution in ProfilePress Plugin

The ProfilePress WordPress plugin is vulnerable to arbitrary shortcode execution in versions up to 4.17.2, allowing authenticated users with subscriber-level access to execute arbitrary shortcodes.

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content wordpress vulnerability rce
2t 1c
high advisory

CVE-2026-4327: Remote Code Execution in The Welcomizer WordPress Plugin

The Welcomizer WordPress plugin contains a remote code execution vulnerability allowing authenticated subscribers to inject arbitrary PHP code via an insufficiently protected AJAX handler.

The Welcomizer wordpress plugin-vulnerability rce
1r 2t 1c
high advisory

Stored XSS in Quill Forms WordPress Plugin

The Quill Forms WordPress plugin (<= 5.7.1) contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious JavaScript via form entry fields.

Quill Forms | Conversational Multi Step Forms, Surveys & quizzes wordpress xss web-application
1t 1c
rumour rumour

HEAVYGRAM Telegram-based Surveillance Backdoor

HEAVYGRAM is a Windows-based surveillance backdoor used by Handala Hack that utilizes the Telegram API for command-and-control communication to facilitate remote information theft and system monitoring.

Handala Hack backdoor surveillance c2 telegram
1t
critical advisory

AnyIO TLS Certificate Spoofing via IDNA 2003 Encoding

AnyIO versions prior to 4.14.2 are vulnerable to TLS certificate spoofing when using IDNA 2003 encoded internationalized domain names, allowing an attacker who redirects traffic to present a domain-validated certificate that the client incorrectly trusts.

AnyIO +1 privilege-escalation vulnerability python linux
1t updated
high advisory

Perses Filesystem Path Traversal Vulnerability

The Perses project, when configured with a filesystem database, fails to validate the project parameter in list requests, enabling unauthorized directory traversal and arbitrary file read access.

Perses +2 web-vulnerability path-traversal security-misconfiguration authorization-bypass cve-2026-63458
1r 2t 1c updated
high advisory

CVE-2026-92807: Arbitrary Function Invocation in Save as PDF Plugin for WordPress

The Save as PDF Plugin for WordPress up to version 4.6.1 is vulnerable to arbitrary function invocation via the pdf_created_callback shortcode attribute, allowing authenticated Contributor-level users to trigger sensitive data disclosure.

Save as PDF Plugin web-application-vulnerability wordpress cve-2026-92807
1r 1t 1c
high advisory

Remote Code Execution in WP Photo Album Plus Plugin

The WP Photo Album Plus plugin for WordPress contains an RCE vulnerability (CVE-2026-87909) allowing authenticated attackers with subscriber-level access to execute arbitrary commands through improper sanitization of ImageMagick arguments.

WP Photo Album Plus
2t 1c
high advisory

Stored XSS in Asset CleanUp: Page Speed Booster WordPress Plugin

Asset CleanUp: Page Speed Booster versions 1.4.0.5 and earlier are vulnerable to stored cross-site scripting due to insufficient input sanitization of comment content.

Asset CleanUp: Page Speed Booster
1t 1c
critical advisory

Arbitrary Shortcode Execution in Forminator WordPress Plugin

The Forminator plugin for WordPress contains an arbitrary shortcode execution vulnerability (CVE-2026-92229) allowing unauthenticated attackers to execute arbitrary shortcodes by leveraging improper input validation.

Forminator wordpress vulnerability web-application
1t 1c
high advisory

Arbitrary Shortcode Execution in WP Recipe Maker Plugin

The WP Recipe Maker plugin for WordPress (<= 10.8.1) is vulnerable to arbitrary shortcode execution due to recursive do_shortcode calls on user-supplied metadata fields.

WP Recipe Maker web-vulnerability wordpress cve-2026-89274
1t 1c
critical advisory

Unauthenticated Arbitrary File Upload in Gravity Forms

The Gravity Forms WordPress plugin (<= 3.1.0.4) is susceptible to unauthenticated remote code execution due to a validation flaw in the upload_file function allowing hidden file upload fields to bypass extension checks.

Gravity Forms web-application wordpress arbitrary-file-upload rce
1r 2t 1c
high advisory

Remote Code Execution in SiYuan via Malicious Bookmark Labels

SiYuan versions prior to 3.8.4 contain a cross-site scripting vulnerability in bookmark label rendering that enables remote code execution due to insecure Electron configuration.

SiYuan +2 vulnerability rce electron xss web-application-vulnerability sql-injection data-exfiltration web-vulnerability +1
1r 5t 1c updated
medium advisory

Multiple Cross-Site Scripting Vulnerabilities in jQuery

Multiple vulnerabilities in the jQuery library allow remote, anonymous attackers to conduct Cross-Site Scripting (XSS) attacks by injecting malicious scripts into victim browser sessions.

jQuery web-security xss injection
1t
high advisory

Remote Code Execution Vulnerability in Kaspersky Secure Mail Gateway

A critical remote code execution vulnerability, CVE-2023-41056, in Kaspersky Secure Mail Gateway allows unauthenticated attackers to execute arbitrary code on affected appliances.

Secure Mail Gateway vulnerability remote-code-execution network-appliance
2t 1c
medium advisory

Monitoring Unauthorized Amazon EKS Access Entry Modifications

Detection of unauthorized Amazon EKS Access Entry modifications via AWS CloudTrail, which may be used by attackers to achieve persistent access or privilege escalation in Kubernetes clusters.

Elastic Kubernetes Service cloud kubernetes persistence privilege-escalation aws
1r 1t
critical advisory

Unauthenticated SSRF and DoS in OpenShift Console

An unauthenticated vulnerability in the OpenShift console /api/devfile/ endpoints allows remote attackers to perform Server-Side Request Forgery (SSRF) and cause Denial of Service (DoS) via memory exhaustion.

OpenShift vulnerability cloud web-application
1t 1c
critical advisory

Unauthenticated Remote Code Execution in IBM Guardium Data Protection

IBM Guardium Data Protection version 12.2 is vulnerable to a critical deserialization flaw allowing remote, unauthenticated attackers to execute arbitrary code (CVE-2026-81657).

Guardium Data Protection cve rce vulnerability enterprise-security authentication-bypass cve-2026-82967 web-application privilege-escalation +4
4t 1c
high advisory

Multiple Vulnerabilities in Microsoft Edge

Multiple vulnerabilities in Microsoft Edge allow remote attackers to achieve arbitrary code execution and escalate privileges on the host system.

Edge browser vulnerability remote-code-execution
2t 1c updated
high advisory

Insecure Deserialization in Cotonti Comments Plugin

Cotonti version 1.0.0 contains an insecure deserialization vulnerability in the comments plugin allowing authenticated users to trigger object injection and potential remote code execution.

Cotonti web-application deserialization vulnerability
1t 1c