September 2026 (30)
Detection of Web Server Access Log Deletion
1 rule 1 TTPAdversaries often delete web server access logs to destroy forensic evidence and evade detection after unauthorized activity, a behavior monitorable through file deletion events on common web server log paths.
Abuse of OpenSSL Utility for Data Encryption
1 rule 2 TTPsAdversaries leverage the legitimate OpenSSL command-line utility to encrypt sensitive files for ransomware extortion or to obfuscate data prior to exfiltration.
Suspicious Instance Metadata Service API Requests
1 rule 1 TTP 1 IOCAttackers with initial code execution on cloud-hosted virtual machines query the Instance Metadata Service (IMDS) at 169.254.169.254 to harvest sensitive instance details and temporary security credentials for unauthorized cloud control-plane access.
Detection of Unauthorized Cloud Instance Metadata Service Access
1 rule 2 TTPs 2 IOCsAttackers exploit cloud instance metadata service (IMDS) endpoints by using command-line tools to exfiltrate temporary security credentials and sensitive configuration data, facilitating unauthorized access to cloud resources.
Detection of Multi-Cloud CLI Token and Credential Harvesting
2 TTPsThreat actors harvest cloud and container platform authentication tokens by abusing legitimate CLI utilities to output secrets to standard streams, which can be detected via anomalous multi-provider access patterns.
Detection of Forced Authentication via SMB Named Pipes
1 rule 1 TTPAdversaries leverage Linux-based systems to coerce Windows hosts into authenticating against attacker-controlled resources via SMB named pipes, facilitating NTLM hash capture and SMB relay attacks.
Credential Access via Chromium Remote Debugging
1 rule 1 TTPAdversaries can exploit Chromium-based browser remote debugging features to extract authentication cookies and hijack active web sessions.
Abuse of Azure WireServer for Credential Access and Discovery
1 rule 2 TTPs 1 IOCAdversaries with code execution on Azure Virtual Machines abuse the host-only WireServer endpoint at 168.63.129.16 to exfiltrate sensitive configuration data, certificates, and VM settings.
Detection of Anomalous SOCKS Proxy Traffic via FortiGate Integration
1 TTPThis detection leverages cross-platform correlation between FortiGate network application logs and endpoint telemetry to identify processes acting as SOCKS proxies for potential command and control obfuscation.
Sensitive Information Exposure in YS LeadGen WordPress Plugin
1 rule 1 TTP 1 CVEThe YS LeadGen plugin for WordPress versions 2.1.4 and earlier contains an unauthenticated information exposure vulnerability allowing the retrieval of form submission data.
Arbitrary Shortcode Execution in ProfilePress Plugin
2 TTPs 1 CVEThe ProfilePress WordPress plugin is vulnerable to arbitrary shortcode execution in versions up to 4.17.2, allowing authenticated users with subscriber-level access to execute arbitrary shortcodes.
CVE-2026-4327: Remote Code Execution in The Welcomizer WordPress Plugin
1 rule 2 TTPs 1 CVEThe Welcomizer WordPress plugin contains a remote code execution vulnerability allowing authenticated subscribers to inject arbitrary PHP code via an insufficiently protected AJAX handler.
Stored XSS in Quill Forms WordPress Plugin
1 TTP 1 CVEThe Quill Forms WordPress plugin (<= 5.7.1) contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious JavaScript via form entry fields.
HEAVYGRAM Telegram-based Surveillance Backdoor
1 TTPHEAVYGRAM is a Windows-based surveillance backdoor used by Handala Hack that utilizes the Telegram API for command-and-control communication to facilitate remote information theft and system monitoring.
AnyIO TLS Certificate Spoofing via IDNA 2003 Encoding
1 TTPAnyIO versions prior to 4.14.2 are vulnerable to TLS certificate spoofing when using IDNA 2003 encoded internationalized domain names, allowing an attacker who redirects traffic to present a domain-validated certificate that the client incorrectly trusts.
Perses Filesystem Path Traversal Vulnerability
1 rule 2 TTPs 1 CVEThe Perses project, when configured with a filesystem database, fails to validate the project parameter in list requests, enabling unauthorized directory traversal and arbitrary file read access.
CVE-2026-92807: Arbitrary Function Invocation in Save as PDF Plugin for WordPress
1 rule 1 TTP 1 CVEThe Save as PDF Plugin for WordPress up to version 4.6.1 is vulnerable to arbitrary function invocation via the pdf_created_callback shortcode attribute, allowing authenticated Contributor-level users to trigger sensitive data disclosure.
Remote Code Execution in WP Photo Album Plus Plugin
2 TTPs 1 CVEThe WP Photo Album Plus plugin for WordPress contains an RCE vulnerability (CVE-2026-87909) allowing authenticated attackers with subscriber-level access to execute arbitrary commands through improper sanitization of ImageMagick arguments.
Stored XSS in Asset CleanUp: Page Speed Booster WordPress Plugin
1 TTP 1 CVEAsset CleanUp: Page Speed Booster versions 1.4.0.5 and earlier are vulnerable to stored cross-site scripting due to insufficient input sanitization of comment content.
Arbitrary Shortcode Execution in Forminator WordPress Plugin
1 TTP 1 CVEThe Forminator plugin for WordPress contains an arbitrary shortcode execution vulnerability (CVE-2026-92229) allowing unauthenticated attackers to execute arbitrary shortcodes by leveraging improper input validation.
Arbitrary Shortcode Execution in WP Recipe Maker Plugin
1 TTP 1 CVEThe WP Recipe Maker plugin for WordPress (<= 10.8.1) is vulnerable to arbitrary shortcode execution due to recursive do_shortcode calls on user-supplied metadata fields.
Unauthenticated Arbitrary File Upload in Gravity Forms
1 rule 2 TTPs 1 CVEThe Gravity Forms WordPress plugin (<= 3.1.0.4) is susceptible to unauthenticated remote code execution due to a validation flaw in the upload_file function allowing hidden file upload fields to bypass extension checks.
Remote Code Execution in SiYuan via Malicious Bookmark Labels
1 rule 5 TTPs 1 CVESiYuan versions prior to 3.8.4 contain a cross-site scripting vulnerability in bookmark label rendering that enables remote code execution due to insecure Electron configuration.
Multiple Cross-Site Scripting Vulnerabilities in jQuery
1 TTPMultiple vulnerabilities in the jQuery library allow remote, anonymous attackers to conduct Cross-Site Scripting (XSS) attacks by injecting malicious scripts into victim browser sessions.
Remote Code Execution Vulnerability in Kaspersky Secure Mail Gateway
2 TTPs 1 CVEA critical remote code execution vulnerability, CVE-2023-41056, in Kaspersky Secure Mail Gateway allows unauthenticated attackers to execute arbitrary code on affected appliances.
Monitoring Unauthorized Amazon EKS Access Entry Modifications
1 rule 1 TTPDetection of unauthorized Amazon EKS Access Entry modifications via AWS CloudTrail, which may be used by attackers to achieve persistent access or privilege escalation in Kubernetes clusters.
Unauthenticated SSRF and DoS in OpenShift Console
1 TTP 1 CVEAn unauthenticated vulnerability in the OpenShift console /api/devfile/ endpoints allows remote attackers to perform Server-Side Request Forgery (SSRF) and cause Denial of Service (DoS) via memory exhaustion.
Unauthenticated Remote Code Execution in IBM Guardium Data Protection
4 TTPs 1 CVEIBM Guardium Data Protection version 12.2 is vulnerable to a critical deserialization flaw allowing remote, unauthenticated attackers to execute arbitrary code (CVE-2026-81657).
Multiple Vulnerabilities in Microsoft Edge
2 TTPs 1 CVEMultiple vulnerabilities in Microsoft Edge allow remote attackers to achieve arbitrary code execution and escalate privileges on the host system.
Insecure Deserialization in Cotonti Comments Plugin
1 TTP 1 CVECotonti version 1.0.0 contains an insecure deserialization vulnerability in the comments plugin allowing authenticated users to trigger object injection and potential remote code execution.