Skip to content
Threat Feed

July 2024 (12)

medium advisory

AWS RDS DB Instance Made Public

An attacker with compromised AWS credentials may modify an Amazon RDS DB instance or cluster to be publicly accessible for persistence, data exfiltration, or to bypass network restrictions.

AWS RDS cloud aws rds persistence defense_evasion
2r 3t
medium advisory

AWS RDS Snapshot Deletion Detected

The deletion of AWS RDS DB snapshots or disabling backups via configuration changes can inhibit recovery, destroy forensic evidence, and prepare for destructive actions by adversaries.

Amazon RDS aws rds snapshot backup datadestruction
3r 2t
high advisory

bitcoinj ScriptExecution P2PKH/P2WPKH Verification Bypass

A vulnerability in bitcoinj's ScriptExecution.correctlySpends() allows attackers to bypass signature verification for P2PKH and P2WPKH spends, potentially leading to unauthorized transaction validation.

bitcoinj-core bitcoin transaction-validation script-execution verification-bypass
2r
medium advisory

AWS RDS DB Instance or Cluster Password Modification

The modification of the master password for an AWS RDS DB instance or cluster can indicate malicious activity used for persistence, privilege escalation, or defense evasion.

RDS cloud aws persistence
2r 3t
medium advisory

DNS Global Query Block List Modified or Disabled

Attackers with DNSAdmin privileges can modify or disable the DNS Global Query Block List (GQBL) in Windows, allowing exploitation of hosts running WPAD with default settings for privilege escalation and lateral movement.

Elastic Defend +4 defense-evasion registry-modification windows
2r 3t
critical advisory

Grafana Vulnerability Allows Remote Code Execution

An authenticated remote attacker can exploit a vulnerability in Grafana to execute arbitrary code, potentially leading to system compromise and data exfiltration.

Grafana code-execution vulnerability
2r 1t
critical advisory

Ivanti VTM Administrator Account Creation via CVE-2024-7593

Unauthenticated remote attackers are exploiting CVE-2024-7593 in Ivanti Virtual Traffic Manager (vTM) to bypass authentication and create new administrator accounts, potentially leading to full system compromise.

Ivanti Virtual Traffic Manager ivanti cve-2024-7593 authentication-bypass account-creation
2r 2t 1c
medium advisory

Microsoft Management Console File Execution from Unusual Path

Adversaries may use Microsoft Management Console (MMC) files from untrusted paths to bypass security controls for initial access and execution on Windows systems.

Microsoft Management Console File +2 execution defense-evasion windows
2r 4t
medium advisory

NTDS Dump via Wbadmin

Attackers with Backup Operator privileges may abuse wbadmin.exe to access the NTDS.dit file, enabling credential dumping and domain compromise.

Microsoft Defender XDR +4 credential-access windows wbadmin ntds.dit
2r 2t
medium advisory

Potential Windows Session Hijacking via CcmExec

Adversaries may exploit Microsoft's System Center Configuration Manager by loading malicious DLLs into SCNotification.exe, a process associated with user notifications, potentially leading to Windows session hijacking.

System Center Configuration Manager defense-evasion dll-hijacking sccm
2r 1t
medium advisory

First Time Python Spawned a Shell on macOS Host

This rule detects the first time a Python process spawns a shell on a given macOS host using the `-c` flag, indicating potential malicious activity stemming from compromised Python environments.

macOS +2 execution python
2r 1t
high advisory

Suspicious Registry Hive Access via RegBack

This rule detects attempts to access registry backup hives (SAM, SECURITY, SYSTEM) via RegBack on Windows systems, which can contain or enable access to credential material.

Endpoint Defense +6 credential-access regback windows
2r 1t

June 2024 (14)

high advisory

VMware Tanzu Spring Framework Vulnerability Allows File Manipulation

An anonymous remote attacker can exploit a vulnerability in VMware Tanzu Spring Framework to manipulate files or disclose information.

Tanzu Spring Framework vmware spring-framework vulnerability
2r 1t
critical advisory

Apache Tomcat Vulnerability Allows Remote Code Execution

An anonymous, remote attacker can exploit an unspecified vulnerability in Apache Tomcat to achieve arbitrary code execution.

Apache Tomcat apache-tomcat rce vulnerability
2r 1t
high advisory

SimpleHelp Missing Authorization Vulnerability Leads to Privilege Escalation

A missing authorization vulnerability in SimpleHelp (CVE-2024-57726) allows low-privileged technicians to create API keys with excessive permissions, potentially escalating privileges to the server admin role.

SimpleHelp privilege-escalation missing-authorization cloud
2r 1t 1c
high advisory

Oracle Fusion Middleware Multiple Vulnerabilities

An unauthenticated or authenticated remote attacker can exploit multiple vulnerabilities in Oracle Fusion Middleware to compromise confidentiality, integrity, and availability.

Fusion Middleware vulnerability oracle
2r 1t
critical advisory

SimpleHelp Path Traversal Vulnerability (CVE-2024-57728)

CVE-2024-57728 is a path traversal vulnerability in SimpleHelp that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file, potentially leading to arbitrary code execution.

SimpleHelp cve-2024-57728 path-traversal zip-slip
2r 3t 1c
high advisory

Otter Blocks Plugin Purchase Verification Bypass Vulnerability (CVE-2026-2892)

CVE-2026-2892 is a purchase verification bypass vulnerability in the Otter Blocks plugin for WordPress, affecting versions up to 3.1.4, that allows unauthenticated attackers to access restricted content by forging a cookie used for purchase validation.

Otter Blocks plugin wordpress plugin purchase-bypass CVE-2026-2892 defense-evasion
3r 1t 1c
high advisory

Docker Privilege Escalation Vulnerability

A remote, authenticated attacker can exploit a vulnerability in Docker to escalate privileges on a Linux host.

Docker privilege-escalation linux
2r 1t
high advisory

Phoenix Contact FL MGUARD Multiple Vulnerabilities

A remote attacker can exploit multiple vulnerabilities in Phoenix Contact FL MGUARD to escalate privileges, disclose sensitive information, or cause a denial-of-service condition.

FL MGUARD phoenix-contact vulnerability privilege-escalation information-disclosure denial-of-service
2r 3t
high advisory

Red Hat Enterprise Linux File Manipulation Vulnerability

An authenticated remote attacker can exploit a vulnerability in Red Hat Enterprise Linux (CPython) to manipulate files.

Red Hat Enterprise Linux rhel file-manipulation linux
2r 2t
medium advisory

Roundcube Vulnerabilities Leading to Cross-Site Scripting and Information Disclosure

Multiple vulnerabilities in Roundcube allow an attacker to perform a cross-site scripting attack and disclose confidential information.

Roundcube xss vulnerability
2r 1t 3c
high advisory

Juniper Junos OS SRX Series ICMPv6 Denial-of-Service Vulnerability (CVE-2026-33790)

A specific, malformed ICMPv6 packet sent to a Juniper Networks Junos OS SRX Series device can trigger a crash and restart of the srxpfe process, leading to a sustained Denial of Service.

Junos OS +1 dos icmpv6 junos srx nat64
2r 1t 1c
critical threat

Samsung MagicINFO 9 Server Path Traversal Vulnerability (CVE-2024-7399)

A path traversal vulnerability in Samsung MagicINFO 9 Server could allow an attacker to write arbitrary files with system privileges, potentially leading to code execution or system compromise.

exploited MagicINFO 9 Server path-traversal cve-2024-7399 samsung
2r 1t 1c
medium advisory

AWS IAM AdministratorAccess Policy Attached to Role

An adversary with compromised AWS credentials may escalate privileges or persist in the environment by attaching the AdministratorAccess AWS managed policy to an existing IAM role.

AWS IAM cloud aws iam privilege-escalation persistence
2r 2t
high advisory

NetScaler ADC and Gateway Vulnerabilities Lead to Session Mixup

A race condition vulnerability in NetScaler ADC and Gateway (CVE-2026-3055 and CVE-2026-4368) could lead to user session mixup, potentially allowing unauthorized access to sensitive information.

NetScaler ADC +1 netscaler citrix session-hijacking vulnerability
2r 1t

May 2024 (4)

medium advisory

Unauthorized Modification of Azure Conditional Access Policy

An unauthorized actor modifies an Azure Conditional Access policy, potentially leading to privilege escalation, credential access, persistence, or defense impairment.

Azure Active Directory azure conditional-access policy-modification attack.privilege-escalation attack.credential-access attack.persistence attack.defense-impairment attack.t1548 +1
2r 2t
high advisory

zyx0814 FilePress SQL Injection Vulnerability (CVE-2026-8133)

A remote SQL injection vulnerability (CVE-2026-8133) exists in zyx0814 FilePress up to version 2.2.0 via the Shares Filelist API by manipulating the argument order, potentially leading to unauthorized data access or modification.

FilePress sql-injection vulnerability web-application
2r 1t 1c
low advisory

Suspicious DNS-Named Record Creation in Active Directory Integrated DNS

Detection of DNS record creation by non-system accounts within Active Directory Integrated DNS (ADIDNS), which attackers can abuse to perform Dynamic Spoofing attacks, potentially targeting services like WPAD for credential access.

Active Directory +1 credential-access windows active-directory
2r 1t
high advisory

OpenStack Keystone LDAP Authentication Bypass Vulnerability (CVE-2026-40683)

OpenStack Keystone before 28.0.1 is vulnerable to an authentication bypass due to improper handling of the user enabled attribute in the LDAP identity backend when the user_enabled_invert configuration option is False, leading to disabled users being treated as enabled.

Keystone openstack ldap authentication-bypass
2r 3t 1c