Skip to content
Threat Feed

May 2024 (12)

high advisory

AWS Bedrock GuardRails Deletion Attempt

Detection of attempts to delete AWS Bedrock GuardRails, security controls that prevent harmful AI outputs, via the DeleteGuardrail API in AWS CloudTrail logs, potentially indicating an adversary attempting to remove these safeguards after compromising credentials to manipulate model behavior for malicious purposes.

AWS Bedrock aws bedrock guardrails defense-evasion cloud
2r 1t
medium advisory

AWS IAM Roles Anywhere Trust Anchor Created with External CA

The creation of an AWS IAM Roles Anywhere Trust Anchor using an external Certificate Authority (CA) instead of an AWS-managed CA allows adversaries to establish persistent access by using their own CA to sign certificates for authentication.

IAM Roles Anywhere aws iam rolesanywhere persistence
2r 2t
low advisory

AWS Lambda Layer Added to Existing Function

Detection of a Lambda layer being added to an existing AWS Lambda function, potentially indicating malicious activity such as persistence, unauthorized code execution, or data interception by an attacker with the ability to modify function configurations.

AWS Lambda cloud aws lambda execution defense-evasion
2r 2t
low advisory

AWS S3 Bucket Enumeration and Brute Force Attempts

A high number of failed S3 operations (AccessDenied errors) against a single bucket from a single source address within a short timeframe can indicate attempts to enumerate bucket objects, brute-force object keys, or inflate AWS billing.

Amazon S3 cloud aws s3 enumeration brute_force impact discovery collection
2r 4t
medium advisory

AWS S3 Bucket Policy Modified to Share with External Account

An attacker modifies an Amazon S3 bucket policy to grant access to an external AWS account, potentially leading to unauthorized data access and exfiltration.

S3 aws bucket_policy exfiltration
2r 3t
medium advisory

AWS Systems Manager SecureString Parameter Request with Decryption Flag

This rule detects when an AWS resource accesses SecureString parameters within AWS Systems Manager (SSM) with the decryption flag set to true, potentially indicating credential access.

AWS Systems Manager aws credential-access cloud
2r 1t
low advisory

GCP Pub/Sub Subscription Creation

This rule detects the creation of a subscription in Google Cloud Platform (GCP) Pub/Sub, which could indicate unauthorized access to data streams by adversaries attempting to intercept or exfiltrate sensitive information.

Google Cloud Platform Pub/Sub cloud gcp pubsub subscription
2r 2t
high advisory

Okta Admin Console Unusual Behavior Detection

This brief details detection of anomalous activity within the Okta Admin Console, potentially indicating privilege escalation, persistence, defense evasion, or initial access attempts by malicious actors.

Okta Identity Engine okta identity privilege-escalation persistence defense-evasion initial-access
2r 4t
low advisory

Potential Data Exfiltration to Unusual Geographic Region via Machine Learning

A machine learning job has detected potential data exfiltration activity to an unusual geographical region, specifically by region name, indicating exfiltration over command and control channels.

data-exfiltration machine-learning network-traffic
2r 1t
critical advisory

Redis Vulnerabilities Allow Local Code Execution

A local attacker can exploit multiple unspecified vulnerabilities in Redis to achieve arbitrary code execution on the host system.

Redis code-execution local-privilege-escalation
2r 1t
high advisory

OpenClaw Sandbox Media Root Bypass via Unnormalized mediaUrl/fileUrl Parameter Keys

A path traversal vulnerability in OpenClaw allows sandboxed agents to read arbitrary files from other agents' workspaces by exploiting unnormalized `mediaUrl` or `fileUrl` parameter keys, leading to potential exposure of sensitive data like API keys and session information.

OpenClaw path-traversal sandbox-escape
2r 2t
high advisory

Suspicious Execution from INetCache Folder

The rule detects suspicious execution of processes from the INetCache folder, often indicative of malicious payloads delivered via WININET, potentially signaling initial access or command and control activity.

Windows initial-access command-and-control execution inetcache
2r 3t 1c

April 2024 (17)

low advisory

Unusual Remote File Size Indicating Lateral Movement

A machine learning job has detected an unusually high file size shared by a remote host, indicating potential lateral movement as attackers bundle data into a single large file transfer to evade detection when exfiltrating valuable information.

lateral-movement data-exfiltration machine-learning
2r 3t
high advisory

Grafana Privilege Escalation Vulnerability

A remote, authenticated attacker can exploit a vulnerability in Grafana to escalate privileges.

Grafana privilege-escalation web-application
2r 1t
medium advisory

Azure AD Certificate-Based Authentication Enabled

Enabling certificate-based authentication (CBA) in Azure Active Directory can be abused by attackers to establish persistence, escalate privileges, and impair defenses.

Azure Active Directory azure certificate-based-authentication persistence privilege-escalation
2r 1t
medium advisory

Bitbucket Global Secret Scanning Rule Deletion

An adversary with administrative privileges may delete global secret scanning rules in Bitbucket to impair defenses and exfiltrate sensitive data without detection.

Bitbucket attack.defense-impairment attack.t1685
2r 1t
low advisory

AWS S3 Bucket Expiration Lifecycle Configuration Added for Defense Evasion

An adversary may add an expiration lifecycle configuration to an Amazon S3 bucket to automatically delete logs, forensic evidence, or sensitive objects, detected via the PutBucketLifecycle or PutBucketLifecycleConfiguration APIs with Expiration parameters.

Amazon S3 cloud aws s3 defense_evasion indicator_removal
2r 3t
low advisory

Bitbucket Project Secret Scanning Allowlist Added

An adversary may impair defenses by adding a secret scanning allowlist rule for Bitbucket projects, potentially allowing secrets to be committed and exposed.

Bitbucket attack.defense-impairment attack.t1685
2r
medium advisory

Bitbucket Repository Exempted from Secret Scanning

An attacker may attempt to disable or bypass secret scanning on a Bitbucket repository to avoid detection of committed secrets, potentially leading to credential compromise and subsequent unauthorized access.

Bitbucket Server attack.defense-impairment attack.t1685 bitbucket
2r 1t
critical advisory

ConnectWise ScreenConnect Path Traversal Vulnerability (CVE-2024-1708)

CVE-2024-1708 is a path traversal vulnerability in ConnectWise ScreenConnect that could allow an attacker to execute remote code or directly impact confidential data and critical systems.

ScreenConnect path-traversal remote-code-execution cve-2024-1708 connectwise
2r 1t 1c
critical advisory

Dell Wyse Management Suite Unauthenticated Remote Code Execution

An unauthenticated remote code execution (RCE) vulnerability exists in Dell Wyse Management Suite, allowing attackers to execute arbitrary code without authentication.

Wyse Management Suite dell wyse rce unauthenticated
2r 4t
high advisory

Detection of System Control Panel Item Load from Uncommon Locations

This brief focuses on detecting the loading of system control panel items (.cpl) from unusual locations, potentially indicating DLL sideloading or other exploitation techniques by threat actors to achieve defense evasion, persistence, and privilege escalation on Windows systems.

Windows defense-evasion persistence privilege-escalation dll-sideloading
2r 3t
low advisory

GitHub Push Protection Bypass Detection

Detection of a GitHub user bypassing push protection, potentially leading to the exposure of secrets.

Github defense-impairment t1685
2r
critical threat

JetBrains TeamCity Relative Path Traversal Vulnerability (CVE-2024-27199)

A relative path traversal vulnerability in JetBrains TeamCity (CVE-2024-27199) could allow limited administrative actions and has been linked to ransomware attacks.

exploited TeamCity cve-2024-27199 path-traversal ransomware jetbrains
2r 1t 1c
info advisory

Microsoft Sentinel Unified RBAC and Row-Level Access Support

Microsoft announced unified role-based access control (RBAC) with row-level access in Microsoft Sentinel, enhancing security management and access control.

Microsoft Sentinel microsoft-sentinel rbac access-control
2r 1i
medium advisory

Potential Abuse of AWS Console GetSigninToken

Adversaries may abuse the AWS GetSigninToken API to create temporary federated credentials for obfuscating compromised AWS access keys and pivoting to console sessions without MFA, potentially leading to lateral movement within the AWS environment.

AWS CloudTrail aws cloud lateral-movement credential-access
2r 2t
medium advisory

AWS SSM Session Started to EC2 Instance for Lateral Movement

An AWS user or role establishing a session via SSM to an EC2 instance may indicate lateral movement, and this rule detects the first occurrence of such an event.

AWS Systems Manager +1 aws lateral-movement ssm
2r 1t
high advisory

WSO2 Products Vulnerable to XML External Entity (XXE) Injection via CVE-2024-2374

CVE-2024-2374 describes an XML External Entity (XXE) vulnerability in multiple WSO2 products, where improperly configured XML parsers allow attackers to inject malicious XML payloads to include external resources, leading to confidential file access, limited HTTP resource access, and denial-of-service attacks.

WSO2 xxe cve-2024-2374 xml vulnerability attack cloud network
2r 2t
medium advisory

AWS EC2 User Data Retrieval for EC2 Instance

Detection of the AWS EC2 DescribeInstanceAttribute API call to retrieve the userData attribute, potentially exposing sensitive information like credentials or configuration details.

EC2 +1 aws cloudtrail userdata discovery credential-access
2r 2t