Skip to content
Threat Feed

January 2024 (30)

high advisory

Decidim API Unauthorized Access via CVE-2026-40870

CVE-2026-40870 allows unauthenticated access to commentable resources in Decidim platforms prior to versions 0.30.5 and 0.31.1 due to missing permission checks on the publicly accessible `/api` endpoint, potentially exposing sensitive data.

Decidim cve-2026-40870 api unauthorized-access
2r 1t 1c
low advisory

Detection of New GitHub Actions Secrets Creation

This analytic detects the creation of new GitHub Actions secrets at the organization, environment, codespaces, or repository level, potentially indicating malicious persistence or privilege escalation.

GitHub Actions github persistence privilege-escalation initial-access
3r 3t
medium advisory

Detection of Unauthorized GitHub Actions Runner Registration

The configuration of a GitHub Actions self-hosted runner using the Runner.Listener binary can indicate malicious activity aimed at establishing remote code execution via malicious GitHub workflows.

GitHub Actions Runner github-actions supply-chain remote-code-execution
3r 3t
medium advisory

DiceBear SVG Size Capping Bypass Leads to Denial of Service

A denial-of-service vulnerability exists in DiceBear versions prior to 9.4.2 due to a bypassable regex in the `ensureSize()` function, allowing attackers to craft SVGs that cause out-of-memory crashes during rendering on Node.js.

DiceBear +1 dos svg vulnerability
2r 1t
critical advisory

DigitalOcean Droplet Agent Command Injection Vulnerability (CVE-2026-24516)

CVE-2026-24516 is a command injection vulnerability in DigitalOcean Droplet Agent through 1.3.2, allowing attackers to execute arbitrary OS commands with root privileges by manipulating metadata responses due to insufficient input validation in the troubleshooting actioner component.

DigitalOcean Droplet Agent command-injection vulnerability cloud
2r 3t 1i
high advisory

Entra ID Concurrent Sign-in with Suspicious Properties

This rule identifies concurrent Azure sign-in events for the same user from multiple sources, where at least one authentication event exhibits suspicious properties associated with DeviceCode and OAuth phishing, potentially indicating refresh token theft.

Azure Entra ID +2 azure entra-id credential-access phishing
2r 4t
high advisory

Entra ID Privilege Escalation to User Access Administrator

A user has elevated their access to User Access Administrator for their Azure Resources, potentially leading to privilege escalation and unauthorized access; this activity is flagged only if the user hasn't performed it in the last 14 days.

Microsoft Azure +1 azure entra_id privilege_escalation
2r 2t
low advisory

Entra ID Service Principal Creation for Persistence

An adversary may create a new service principal in Microsoft Entra ID to establish persistence and potentially impersonate legitimate services or applications, blending in with normal activity.

Microsoft Entra ID +1 azure entra_id service_principal persistence
2r 1t
medium advisory

Expired or Revoked Driver Loaded

An expired or revoked driver being loaded on a Windows system may indicate an attempt to gain code execution in kernel mode or abuse revoked certificates for malicious purposes, potentially leading to privilege escalation or defense evasion.

Elastic Defend privilege-escalation defense-evasion windows
2r 3t
medium advisory

Fortigate SSL VPN Login Followed by SIEM Alert

Detection of initial access via Fortigate SSL VPN login, followed by a SIEM alert, indicating potential malicious activity post-VPN access.

Fortigate SSL VPN fortigate sslvpn initial-access siem
2r
high advisory

Freeciv21 Stack Overflow Vulnerability (CVE-2026-33250)

Freeciv21 versions prior to 3.1.1 are vulnerable to a stack overflow when processing specially-crafted packets, allowing a remote attacker to crash public servers or a malicious server to crash a player's game.

Freeciv21 stack-overflow denial-of-service cve-2026-33250 linux
2r 1t
low advisory

GCP Logging Sink Modification for Exfiltration or Defense Evasion

Modification of a Google Cloud Platform (GCP) Logging sink is detected, potentially indicating an adversary's attempt to exfiltrate logs to an unauthorized destination or impair defenses by disabling or modifying cloud logs.

Google Cloud Platform gcp cloud exfiltration defense_evasion
2r 2t
high advisory

gix-fs Symlink Prefix-Reuse Worktree Escape

A vulnerability in rust's gix-fs library (<= 0.21.0) allows a malicious actor to construct a tree that, when checked out with gitoxide, permits writing an attacker-controlled symlink into any existing directory the user has write access to, potentially leading to code execution.

gix-fs symlink worktree-escape gitoxide code-execution
3r 2t
high advisory

gmaps-mcp Unauthenticated HTTP Transport Allows Unlimited Google Maps API Calls

The gmaps-mcp package allows unauthenticated access to Google Maps API calls when deployed with a blank MCP_API_KEY, potentially leading to significant financial costs for the operator; it also permits path injection attacks.

Places API +1 googlemaps unauthenticated-access api-abuse injection
2r 1i
high advisory

Grav File Cache Insecure Deserialization Vulnerability

Grav versions 1.7.44 through 1.7.49.5 are vulnerable to insecure deserialization in the File Cache component, where the `unserialize` function with `allowed_classes => true` can lead to arbitrary code execution if an attacker tampers with cache files.

grav insecure-deserialization code-execution web-application
2r 2t
critical advisory

JetEngine WordPress Plugin SQL Injection Vulnerability (CVE-2026-4352)

The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endpoint, allowing unauthenticated attackers to extract sensitive database information.

JetEngine plugin sqli wordpress jetengine cve-2026-4352 web-application
2r 1t 1c
critical advisory

Jupiter X Core WordPress Plugin Vulnerability Leads to Remote Code Execution

The Jupiter X Core plugin for WordPress is vulnerable to remote code execution and stored cross-site scripting due to missing authorization and insufficient file type validation in versions up to 4.14.1, allowing authenticated attackers with subscriber-level access to upload malicious files.

Jupiter X Core +1 wordpress plugin rce xss file-upload
2r 1t
high advisory

KadNap Botnet Targeting Asus Routers

The KadNap botnet is delivering malicious payloads targeting Asus routers, indicated by specific SHA256 hashes of MIPS and ARM binaries.

Routers botnet router kadnap
2r 1t 2i
medium advisory

Keitaro Tracker Abused in AI-Driven Investment Scams

The Keitaro Tracker advertising platform is being exploited by malicious actors to facilitate AI-driven investment scams.

Keitaro Tracker keitaro tds traffic-direction investment-scam ai
2r 2t 1i
high advisory

Kentico Xperience Path Traversal Vulnerability (CVE-2025-2749)

Kentico Xperience contains a path traversal vulnerability (CVE-2025-2749) that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations, potentially leading to remote code execution or data compromise.

Kentico Xperience path traversal cve-2025-2749 kentico
2r 1t 1c
high advisory

Matrimony Website Script M-Plus SQL Injection Vulnerabilities

Matrimony Website Script M-Plus is vulnerable to unauthenticated SQL injection via POST parameters, enabling attackers to extract sensitive data or execute arbitrary SQL commands.

Matrimony Website Script M-Plus sql-injection vulnerability web-application
2r 1t
critical advisory

MikroORM SQL Injection Vulnerability

MikroORM versions 6.6.9 and 7.0.5 are vulnerable to SQL injection when specially crafted objects are interpreted as raw SQL query fragments, potentially allowing attackers to execute arbitrary SQL commands.

MikroORM sqli sql-injection cve-2026-34220
2r 1t
high advisory

Mozilla Firefox Audio/Video Boundary Condition Vulnerability (CVE-2026-4714)

CVE-2026-4714 is a high-severity vulnerability affecting Firefox, Firefox ESR, and Thunderbird due to incorrect boundary conditions in the Audio/Video component, potentially leading to denial-of-service.

Firefox +2 cve-2026-4714 thunderbird denial-of-service
2r 3t
high advisory

n8n-MCP Server-Side Request Forgery Vulnerability (CVE-2026-39974)

A server-side request forgery (SSRF) vulnerability in n8n-MCP prior to version 2.47.4 allows authenticated attackers to send HTTP requests to arbitrary URLs, potentially accessing sensitive information.

n8n-MCP Server ssrf n8n-mcp cve-2026-39974 cloud
2r 1t 1c
low advisory

Netsh Helper DLL Persistence

Attackers may abuse the Netsh Helper DLL functionality by adding malicious DLLs to execute payloads every time the netsh utility is executed via administrators or scheduled tasks, achieving persistence.

Microsoft Defender XDR +3 persistence windows netsh registry
2r 2t
high advisory

OpenClaw Sandboxed Agent Exec Routing Escape

A vulnerability in the openclaw npm package (versions >= 2026.4.5 and < 2026.4.10) allows a sandboxed agent to bypass intended sandbox execution paths by requesting `host: "node"`, potentially leading to code execution on a remote node.

openclaw npm sandbox-escape
2r 1t
high advisory

Oxia TLS Certificate Chain Validation Failure

Oxia's `trustedCertPool()` function fails to parse multi-certificate PEM bundles, leading to certificate chain validation failure and rejection of legitimate clients in mTLS deployments.

Oxia tls mtls certificate-validation vulnerability
2r 1t
high advisory

Parse Server /users/me Endpoint Exposes MFA Secrets

Parse Server versions before 8.6.61 and versions 9.0.0 to 9.6.0-alpha.55 expose sensitive MFA credentials via the `/users/me` endpoint, allowing authenticated users to extract TOTP secrets and recovery codes.

Parse Server parse-server credential-access mfa-bypass
2r 1t
critical advisory

PhpSpreadsheet SSRF and RCE Vulnerability via IOFactory::load

PhpSpreadsheet is vulnerable to Server-Side Request Forgery (SSRF) and Remote Code Execution (RCE) due to improper validation of filenames in the IOFactory::load function, exploitable via PHP wrappers like `phar://` and `ftp://`.

PhpSpreadsheet ssrf rce php deserialization
2r 2t
high advisory

Postiz File Upload Vulnerability Leads to Stored XSS (CVE-2026-40487)

An authenticated file upload validation bypass in Postiz prior to version 2.21.6 allows attackers to upload arbitrary HTML, SVG, or other executable file types by spoofing the `Content-Type` header, resulting in stored XSS and potential account takeover.

Postiz xss file-upload vulnerability cve-2026-40487
2r 5t 1c