Skip to content
Threat Feed

January 2024 (30)

high advisory

LiquidJS Template Engine Root Restriction Bypass via Symlink Exploitation

A vulnerability in LiquidJS allows attackers to bypass template root restrictions by using symlinks within allowed directories to render arbitrary files outside the intended scope, potentially leading to sensitive information disclosure.

LiquidJS Template Engine liquidjs symlink template-injection root-restriction-bypass
2r 2t
critical advisory

macOS Privilege Escalation via Feedback Assistant Race Condition (CVE-2019-8565)

A race condition vulnerability (CVE-2019-8565) exists in macOS where a privileged XPC service, com.apple.appleseed.fbahelperd, improperly validates XPC messages based on process ID, allowing an unprivileged process to escalate privileges to root.

macOS +1 privilege-escalation xpc race-condition
2r 1t 1c
high advisory

MONAI Library Vulnerable to Arbitrary Code Execution via Pickle Deserialization

The MONAI library is vulnerable to arbitrary code execution due to insecure deserialization of pickle files via the `algo_from_pickle` function, allowing attackers to execute arbitrary code by providing a malicious pickle file.

MONAI pickle rce insecure-deserialization python
2r 1t
medium advisory

Newly Observed Fortigate Alert

This brief covers a newly observed Fortigate alert rule added to the Elastic detection rules repository, potentially indicating emerging threat activity targeting Fortigate devices.

Fortigate intrusion-detection network-security
2r 7t
high advisory

NGINX ngx_http_dav_module Buffer Overflow Vulnerability (CVE-2026-27654)

A buffer overflow vulnerability (CVE-2026-27654) exists in the ngx_http_dav_module of NGINX Open Source and NGINX Plus, potentially allowing attackers to terminate the NGINX worker process or modify files outside the document root by exploiting specific configurations with MOVE or COPY methods.

NGINX Open Source +1 nginx dav buffer-overflow cve-2026-27654 denial-of-service
2r 1t
critical advisory

OAuth2 Proxy Authentication Bypass via X-Forwarded-Uri Header Spoofing

OAuth2 Proxy is vulnerable to an authentication bypass when configured with `--reverse-proxy` and `--skip_auth_routes` or `--skip_auth_regex`; by spoofing the `X-Forwarded-Uri` header, an attacker can bypass authentication and access protected routes without a valid session.

OAuth2 Proxy oauth2-proxy authentication-bypass reverse-proxy header-spoofing
2r 1t
medium advisory

Okta Initial Access via Proxy

Detection of a first-time user session started via a proxy, potentially indicating unauthorized initial access.

Okta initial-access proxy
2r 1t
medium advisory

Okta Policy Rule Modification or Deletion

An Okta policy rule was modified or deleted, potentially weakening security controls.

Okta identity policy attack.impact
2r 1t
critical advisory

OpenBao Reflected XSS Vulnerability in OIDC Authentication Error Message

OpenBao installations with OIDC/JWT authentication enabled and roles with `callback_mode=direct` are vulnerable to reflected XSS via the `error_description` parameter, allowing attackers to steal Web UI tokens; patched in v2.5.2.

OpenBao xss reflected-xss web-application
2r 1t
critical advisory

OpenHarness Command Injection Vulnerability (CVE-2026-40502)

OpenHarness versions prior to commit dd1d235 are vulnerable to command injection, allowing remote gateway users with chat access to execute administrative commands and alter system permissions.

OpenHarness command-injection vulnerability
2r 1t 1c
high advisory

PandasAI Code Injection Vulnerability (CVE-2026-4998)

A code injection vulnerability (CVE-2026-4998) exists in Sinaptik AI PandasAI versions up to 3.0.0, enabling remote attackers to execute arbitrary code via the CodeExecutor.execute function within the Chat Message Handler component.

PandasAI code-injection cve-2026-4998
2r 1t
medium advisory

Potential Evasion via Filter Manager

Adversaries may abuse the Filter Manager Control Program (fltMC.exe) to unload filter drivers, evading defenses like EDR and antivirus.

Windows defense-evasion filter-manager
2r 1t
medium advisory

Potential LSASS Memory Dump Activity

This brief covers the potential for credential access via LSASS memory dumping, a technique used to steal credentials from memory, though specific details are absent from the provided source.

Windows credential-access lsass memory-dump
2r 1t
high advisory

Potential Privilege Escalation via unshare Followed by Root Process

The rule detects a sequence of events indicating a potential privilege escalation attempt on Linux systems where a non-root user performs namespace activity using unshare, followed by the execution of a root process shortly after.

Auditd Manager +1 privilege-escalation linux auditd
2r 1t
high advisory

pretalx Stored Cross-Site Scripting Vulnerability in Organizer Search

A stored cross-site scripting (XSS) vulnerability exists in the pretalx backend organizer search, allowing attackers to inject malicious JavaScript into user-controlled fields that executes in an organizer's browser, potentially leading to data modification or exfiltration.

pretalx xss stored-xss
2r 1t
medium advisory

Prismatic WordPress Plugin Stored XSS Vulnerability

The Prismatic plugin for WordPress versions 3.7.3 and earlier is vulnerable to stored cross-site scripting (XSS) via the 'prismatic_encoded' pseudo-shortcode, allowing unauthenticated attackers to inject arbitrary web scripts into pages.

Prismatic plugin +1 wordpress xss plugin prismatic
2r 1t 1c
medium advisory

Program Files Directory Masquerading

Adversaries may masquerade malicious executables within directories mimicking the legitimate Windows Program Files directory to evade defenses and execute untrusted code.

Elastic Defend +2 defense-evasion masquerading windows
2r 1t
critical advisory

ProSolution WP Client Plugin Arbitrary File Upload Vulnerability (CVE-2026-2942)

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation, allowing unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution.

ProSolution WP Client wordpress plugin file-upload rce
2r 1t 1c
high advisory

rust-openssl AES Key Wrap Out-of-Bounds Write Vulnerability

The rust-openssl package is vulnerable to an out-of-bounds write due to an incorrect bounds assertion in the `aes::unwrap_key()` function, potentially leading to arbitrary code execution if attacker-controlled buffer sizes are permitted.

openssl aes keywrap oob-write memory-corruption
2r
medium advisory

Scheduled Task Created or Deleted via Command Line

Detection of scheduled task creation or deletion via command-line, often used for persistence and privilege escalation by threat actors.

Windows persistence privilege_escalation scheduled_task
2r 2t
high advisory

Scriban `object.to_json` Uncontrolled Recursion DoS

The Scriban library is vulnerable to a denial-of-service attack where a specially crafted template with a self-referencing object passed to the `object.to_json` function causes unbounded recursion, leading to a `StackOverflowException` that terminates the .NET process.

Scriban denial-of-service .net
2r 1t
high threat

ShinyHunters Targeting Experience Cloud

The ShinyHunters group is conducting a campaign targeting Adobe Experience Cloud, potentially leading to data breaches and unauthorized access to customer data.

Adobe Experience Cloud ShinyHunters data breach
2r 4t 1i
high advisory

Suspicious File Creation via Print Spooler Service

The Print Spooler service is being abused to create suspicious files, potentially leading to privilege escalation.

Windows printspooler privilege-escalation file-creation
2r 1t
high advisory

Suspicious Managed Code Hosting Process

This rule detects suspicious managed code hosting processes on Windows systems, potentially indicating code injection or defense evasion tactics by monitoring file events associated with processes commonly used to host managed code, such as wscript.exe, cscript.exe, and mshta.exe.

M365 Defender +3 defense-evasion windows managed code lolbin
2r 1t
medium advisory

Suspicious Registry Modifications by Scripting Engines

The use of scripting engines like WScript and CScript to modify the Windows registry can indicate an attempt to bypass standard tools and evade defenses, potentially for persistence or other malicious activities.

Windows defense-evasion persistence execution registry-modification
2r 3t
high advisory

Tandoor Recipes Host Header Injection Vulnerability (CVE-2026-33149)

Tandoor Recipes versions up to 2.5.3 use a wildcard for ALLOWED_HOSTS, making Django accept any HTTP Host header without validation, which allows an attacker to manipulate server-generated absolute URLs and potentially compromise user accounts through invite link poisoning.

Tandoor Recipes host-header-injection cve-2026-33149 web-application
2r 1t
critical advisory

Thymeleaf Server-Side Template Injection Vulnerability

Thymeleaf versions up to 3.1.3.RELEASE are vulnerable to server-side template injection (SSTI) due to improper neutralization of specific syntax patterns, allowing attackers to execute unauthorized expressions when unvalidated user input is passed directly to the template engine.

Thymeleaf +2 ssti cve-2026-40478 server-side template injection expression injection
2r 1t
critical advisory

Tiandy Easy7 Integrated Management Platform OS Command Injection Vulnerability

A remote OS command injection vulnerability exists in Tiandy Easy7 Integrated Management Platform up to version 7.17.0, allowing attackers to execute arbitrary commands by manipulating the 'File' argument in the '/Easy7/apps/WebService/ImportSystemConfiguration.jsp' file, potentially leading to full system compromise.

Easy7 Integrated Management Platform cve-2026-4585 command-injection tiandy
2r 1t
medium advisory

VaultCmd Usage for Listing Windows Credentials

Adversaries may use vaultcmd.exe to list credentials stored in the Windows Credential Manager to gain unauthorized access to saved usernames and passwords, potentially in preparation for lateral movement.

Microsoft Defender XDR +1 credential-access windows vaultcmd
2r 2t
medium advisory

Web Server Local File Inclusion Activity Detected

Detection of potential Local File Inclusion (LFI) activity on web servers through HTTP GET requests attempting to access sensitive local files via directory traversal or known file paths, potentially leading to information disclosure and system compromise.

Nginx +4 web-server lfi file-inclusion discovery credential-access initial-access
3r 4t