Skip to content
Threat Feed

May 2024 (27)

medium advisory

Unauthorized Modification of Azure Conditional Access Policy

An unauthorized actor modifies an Azure Conditional Access policy, potentially leading to privilege escalation, credential access, persistence, or defense impairment.

Azure Active Directory azure conditional-access policy-modification attack.privilege-escalation attack.credential-access attack.persistence attack.defense-impairment attack.t1548 +1
2r 2t
high advisory

zyx0814 FilePress SQL Injection Vulnerability (CVE-2026-8133)

A remote SQL injection vulnerability (CVE-2026-8133) exists in zyx0814 FilePress up to version 2.2.0 via the Shares Filelist API by manipulating the argument order, potentially leading to unauthorized data access or modification.

FilePress sql-injection vulnerability web-application
2r 1t 1c
low advisory

Suspicious DNS-Named Record Creation in Active Directory Integrated DNS

Detection of DNS record creation by non-system accounts within Active Directory Integrated DNS (ADIDNS), which attackers can abuse to perform Dynamic Spoofing attacks, potentially targeting services like WPAD for credential access.

Active Directory +1 credential-access windows active-directory
2r 1t
high advisory

OpenStack Keystone LDAP Authentication Bypass Vulnerability (CVE-2026-40683)

OpenStack Keystone before 28.0.1 is vulnerable to an authentication bypass due to improper handling of the user enabled attribute in the LDAP identity backend when the user_enabled_invert configuration option is False, leading to disabled users being treated as enabled.

Keystone openstack ldap authentication-bypass
2r 3t 1c
medium advisory

Suspicious ScreenConnect Client Child Process Activity

This rule identifies suspicious child processes spawned by ScreenConnect client processes, potentially indicating unauthorized access and command execution abusing ScreenConnect remote access software to perform malicious activities such as data exfiltration or establishing persistence.

Elastic Defend +3 command-and-control defense-evasion execution persistence screenconnect
2r 11t 2c
medium advisory

AWS Bedrock Model Invocation Logging Deletion

Detection of AWS Bedrock model invocation logging configuration deletion via the DeleteModelInvocationLogging API in CloudTrail logs, potentially indicating an adversary attempting to evade detection of malicious AI model usage.

Bedrock aws cloudtrail defense-evasion
2r 1t
critical advisory

Cisco Webex Services SSO Impersonation Vulnerability (CVE-2026-20184)

CVE-2026-20184 allows an unauthenticated, remote attacker to impersonate any user in Cisco Webex Services by exploiting improper certificate validation in single sign-on (SSO) integration with Control Hub, potentially granting unauthorized access.

Webex Services cve-2026-20184 webex sso impersonation authentication
2r 1t 1c
high advisory

DirectoryPress WordPress Plugin Vulnerable to SQL Injection (CVE-2026-3489)

The DirectoryPress WordPress plugin before 3.6.26 is vulnerable to unauthenticated SQL Injection via the 'packages' parameter, allowing attackers to extract sensitive database information.

DirectoryPress +1 wordpress sql-injection cve-2026-3489
2r 1t 1c
high advisory

Insyde UEFI Firmware Vulnerabilities Allow Local Privilege Escalation

Multiple vulnerabilities in Insyde UEFI Firmware allow a local attacker to execute arbitrary code with administrator privileges.

UEFI Firmware uefi privilege-escalation firmware
2r 1t
high advisory

Unusual Execution via Microsoft Common Console File

Adversaries may embed a malicious command in an MSC file in order to trick victims into executing malicious commands, leading to initial access and execution of arbitrary code.

Common Console File +6 execution initial-access windows msc
2r 2t
medium advisory

Suspicious Child Processes Spawned by JetBrains TeamCity

Detection of suspicious processes spawned by JetBrains TeamCity indicates potential exploitation of remote code execution vulnerabilities, with attackers using command interpreters and system binaries for malicious purposes.

TeamCity supply-chain initial-access
2r 17t 1c
medium advisory

AWS Route 53 Resolver Query Log Configuration Deleted

Detection of the deletion of an Amazon Route 53 Resolver Query Log Configuration, potentially stopping DNS query and response logging for associated VPCs, which can be used by adversaries to evade detection and suppress forensic evidence.

AWS Route 53 Resolver aws cloudtrail route53 defense_evasion
2r 1t
medium advisory

AWS EC2 EBS Snapshot Shared or Made Public

An AWS Elastic Block Store (EBS) snapshot is shared with another AWS account or made public, potentially leading to data exfiltration and persistence operations.

Amazon EC2 +1 cloud aws exfiltration
2r 1t
medium advisory

Google Workspace Object Copied from External Drive Followed by OAuth Consent

Detects a sequence of events where a user copies a Google Workspace object (spreadsheet, form, document, or script) from an external drive and subsequently grants OAuth permissions to a custom application, potentially indicating a phishing attack leveraging container-bound scripts.

Google Workspace +5 google-workspace oauth phishing initial-access persistence
1r 3t
high advisory

Windows Parent Process PID Spoofing Detection

Adversaries use parent process PID spoofing to evade detection by creating processes with mismatched parent-child relationships, hindering process monitoring and potentially elevating privileges on Windows systems.

Elastic Defend defense-evasion process-injection windows
3r 1t
critical advisory

Electerm Path Traversal Vulnerability Leads to Arbitrary Code Execution

Electerm versions prior to 3.7.16 are vulnerable to path traversal, leading to arbitrary code execution through unsanitized widget identifiers.

electerm path-traversal code-execution
2r 2t 1c
high advisory

Open WebUI Cross-Instance Cache Poisoning Vulnerability

Open WebUI versions up to 0.8.12 are vulnerable to cross-instance cache poisoning when multiple instances share a Redis backend, allowing an attacker with admin access on one instance to overwrite cache values used by other instances, leading to data exfiltration and prompt injection attacks.

open-webui +1 cache-poisoning redis vulnerability
2r 2t
high advisory

Azure Compute Restore Point Collections Mass Deletion

A single user deleting multiple Azure Restore Point Collections in a short time period can indicate a ransomware attack or destructive operation, preventing victim recovery by inhibiting system recovery.

Azure cloud ransomware impact
2r 1t
medium advisory

Azure AD Root Certificate Authority Added for Passwordless Authentication

An attacker may add a new root certificate authority to an Azure AD tenant to support certificate-based authentication for persistence, privilege escalation, or defense evasion.

Azure Active Directory attack.credential-access attack.persistence attack.privilege-escalation attack.defense-impairment attack.t1556
2r 4t
high advisory

OpenCanary SSH Connection Attempt

An SSH connection attempt to an OpenCanary node indicates a potential adversary probing for vulnerable services or attempting unauthorized access within a network.

OpenCanary honeypot ssh reconnaissance
2r 1t
medium advisory

Suspicious JetBrains TeamCity Child Process Activity

Detection of suspicious processes spawned by JetBrains TeamCity indicates potential exploitation of remote code execution vulnerabilities.

TeamCity jetbrains rce supply-chain
2r 17t 1c
low advisory

AWS IAM Roles Anywhere Profile Creation

Detection of AWS IAM Roles Anywhere profile creation, potentially indicating an adversary establishing persistence or escalating privileges through rogue trust anchors to gain long-term external access.

IAM Roles Anywhere aws iam rolesanywhere persistence privilege-escalation
2r 2t
high advisory

phpseclib Library Vulnerable to Prime Number Generation Weakness

The phpseclib library has a vulnerability affecting prime number generation and primality testing, impacting versions >= 0.1.1 and < 1.0.23, >= 2.0.0 and < 2.0.47, and >= 3.0.0 and < 3.0.36, potentially leading to insecure cryptographic operations.

phpseclib/phpseclib cryptography vulnerability phpseclib prime_number
2r 1t
medium advisory

OpenSSL Vulnerability Allows Denial of Service and Information Disclosure

A remote, authenticated attacker can exploit a vulnerability in OpenSSL to perform a denial-of-service attack and disclose information.

OpenSSL denial-of-service information-disclosure
2r 2t
high advisory

Windows HTTP.sys Local Privilege Escalation Vulnerability (CVE-2026-21250)

A local privilege escalation vulnerability exists in Windows 11 24H2, Windows 11 25H2, and Windows Server 2022 23H2 due to improper handling of untrusted pointers in HTTP.sys via strcat truncation.

Windows 11 +1 local-privilege-escalation windows cve-2026-21250 http.sys
2r 1t 1c
medium advisory

phpseclib OID Amplification DoS Vulnerability

A vulnerability exists in phpseclib when loading untrusted ASN1 files, potentially leading to an OID amplification denial-of-service (DoS) in the ASN1::decodeOID() function.

phpseclib +2 denial-of-service asn1
2r 1t
high advisory

Argo Workflows ConfigMap Sync Service Missing Authorization Vulnerability

The Sync Service's ConfigMap-backed provider in Argo Workflows performs zero authorization checks on all CRUD operations, allowing any authenticated user to create, read, update, and delete Kubernetes ConfigMaps containing synchronization limits, potentially leading to denial of service, workflow disruption, information disclosure, or arbitrary ConfigMap manipulation in Argo Workflows versions v4.0.0 to v4.0.4.

argo-workflows/v4 argo-workflows kubernetes configmap authorization vulnerability
2r 1t