January 2024 (30)
LiquidJS Template Engine Root Restriction Bypass via Symlink Exploitation
2 rules 2 TTPsA vulnerability in LiquidJS allows attackers to bypass template root restrictions by using symlinks within allowed directories to render arbitrary files outside the intended scope, potentially leading to sensitive information disclosure.
macOS Privilege Escalation via Feedback Assistant Race Condition (CVE-2019-8565)
2 rules 1 TTP 1 CVEA race condition vulnerability (CVE-2019-8565) exists in macOS where a privileged XPC service, com.apple.appleseed.fbahelperd, improperly validates XPC messages based on process ID, allowing an unprivileged process to escalate privileges to root.
MONAI Library Vulnerable to Arbitrary Code Execution via Pickle Deserialization
2 rules 1 TTPThe MONAI library is vulnerable to arbitrary code execution due to insecure deserialization of pickle files via the `algo_from_pickle` function, allowing attackers to execute arbitrary code by providing a malicious pickle file.
Newly Observed Fortigate Alert
2 rules 7 TTPsThis brief covers a newly observed Fortigate alert rule added to the Elastic detection rules repository, potentially indicating emerging threat activity targeting Fortigate devices.
NGINX ngx_http_dav_module Buffer Overflow Vulnerability (CVE-2026-27654)
2 rules 1 TTPA buffer overflow vulnerability (CVE-2026-27654) exists in the ngx_http_dav_module of NGINX Open Source and NGINX Plus, potentially allowing attackers to terminate the NGINX worker process or modify files outside the document root by exploiting specific configurations with MOVE or COPY methods.
OAuth2 Proxy Authentication Bypass via X-Forwarded-Uri Header Spoofing
2 rules 1 TTPOAuth2 Proxy is vulnerable to an authentication bypass when configured with `--reverse-proxy` and `--skip_auth_routes` or `--skip_auth_regex`; by spoofing the `X-Forwarded-Uri` header, an attacker can bypass authentication and access protected routes without a valid session.
Okta Initial Access via Proxy
2 rules 1 TTPDetection of a first-time user session started via a proxy, potentially indicating unauthorized initial access.
Okta Policy Rule Modification or Deletion
2 rules 1 TTPAn Okta policy rule was modified or deleted, potentially weakening security controls.
OpenBao Reflected XSS Vulnerability in OIDC Authentication Error Message
2 rules 1 TTPOpenBao installations with OIDC/JWT authentication enabled and roles with `callback_mode=direct` are vulnerable to reflected XSS via the `error_description` parameter, allowing attackers to steal Web UI tokens; patched in v2.5.2.
OpenHarness Command Injection Vulnerability (CVE-2026-40502)
2 rules 1 TTP 1 CVEOpenHarness versions prior to commit dd1d235 are vulnerable to command injection, allowing remote gateway users with chat access to execute administrative commands and alter system permissions.
PandasAI Code Injection Vulnerability (CVE-2026-4998)
2 rules 1 TTPA code injection vulnerability (CVE-2026-4998) exists in Sinaptik AI PandasAI versions up to 3.0.0, enabling remote attackers to execute arbitrary code via the CodeExecutor.execute function within the Chat Message Handler component.
Potential Evasion via Filter Manager
2 rules 1 TTPAdversaries may abuse the Filter Manager Control Program (fltMC.exe) to unload filter drivers, evading defenses like EDR and antivirus.
Potential LSASS Memory Dump Activity
2 rules 1 TTPThis brief covers the potential for credential access via LSASS memory dumping, a technique used to steal credentials from memory, though specific details are absent from the provided source.
Potential Privilege Escalation via unshare Followed by Root Process
2 rules 1 TTPThe rule detects a sequence of events indicating a potential privilege escalation attempt on Linux systems where a non-root user performs namespace activity using unshare, followed by the execution of a root process shortly after.
pretalx Stored Cross-Site Scripting Vulnerability in Organizer Search
2 rules 1 TTPA stored cross-site scripting (XSS) vulnerability exists in the pretalx backend organizer search, allowing attackers to inject malicious JavaScript into user-controlled fields that executes in an organizer's browser, potentially leading to data modification or exfiltration.
Prismatic WordPress Plugin Stored XSS Vulnerability
2 rules 1 TTP 1 CVEThe Prismatic plugin for WordPress versions 3.7.3 and earlier is vulnerable to stored cross-site scripting (XSS) via the 'prismatic_encoded' pseudo-shortcode, allowing unauthenticated attackers to inject arbitrary web scripts into pages.
Program Files Directory Masquerading
2 rules 1 TTPAdversaries may masquerade malicious executables within directories mimicking the legitimate Windows Program Files directory to evade defenses and execute untrusted code.
ProSolution WP Client Plugin Arbitrary File Upload Vulnerability (CVE-2026-2942)
2 rules 1 TTP 1 CVEThe ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation, allowing unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution.
rust-openssl AES Key Wrap Out-of-Bounds Write Vulnerability
2 rulesThe rust-openssl package is vulnerable to an out-of-bounds write due to an incorrect bounds assertion in the `aes::unwrap_key()` function, potentially leading to arbitrary code execution if attacker-controlled buffer sizes are permitted.
Scheduled Task Created or Deleted via Command Line
2 rules 2 TTPsDetection of scheduled task creation or deletion via command-line, often used for persistence and privilege escalation by threat actors.
Scriban `object.to_json` Uncontrolled Recursion DoS
2 rules 1 TTPThe Scriban library is vulnerable to a denial-of-service attack where a specially crafted template with a self-referencing object passed to the `object.to_json` function causes unbounded recursion, leading to a `StackOverflowException` that terminates the .NET process.
ShinyHunters Targeting Experience Cloud
2 rules 4 TTPs 1 IOCThe ShinyHunters group is conducting a campaign targeting Adobe Experience Cloud, potentially leading to data breaches and unauthorized access to customer data.
Suspicious File Creation via Print Spooler Service
2 rules 1 TTPThe Print Spooler service is being abused to create suspicious files, potentially leading to privilege escalation.
Suspicious Managed Code Hosting Process
2 rules 1 TTPThis rule detects suspicious managed code hosting processes on Windows systems, potentially indicating code injection or defense evasion tactics by monitoring file events associated with processes commonly used to host managed code, such as wscript.exe, cscript.exe, and mshta.exe.
Suspicious Registry Modifications by Scripting Engines
2 rules 3 TTPsThe use of scripting engines like WScript and CScript to modify the Windows registry can indicate an attempt to bypass standard tools and evade defenses, potentially for persistence or other malicious activities.
Tandoor Recipes Host Header Injection Vulnerability (CVE-2026-33149)
2 rules 1 TTPTandoor Recipes versions up to 2.5.3 use a wildcard for ALLOWED_HOSTS, making Django accept any HTTP Host header without validation, which allows an attacker to manipulate server-generated absolute URLs and potentially compromise user accounts through invite link poisoning.
Thymeleaf Server-Side Template Injection Vulnerability
2 rules 1 TTPThymeleaf versions up to 3.1.3.RELEASE are vulnerable to server-side template injection (SSTI) due to improper neutralization of specific syntax patterns, allowing attackers to execute unauthorized expressions when unvalidated user input is passed directly to the template engine.
Tiandy Easy7 Integrated Management Platform OS Command Injection Vulnerability
2 rules 1 TTPA remote OS command injection vulnerability exists in Tiandy Easy7 Integrated Management Platform up to version 7.17.0, allowing attackers to execute arbitrary commands by manipulating the 'File' argument in the '/Easy7/apps/WebService/ImportSystemConfiguration.jsp' file, potentially leading to full system compromise.
VaultCmd Usage for Listing Windows Credentials
2 rules 2 TTPsAdversaries may use vaultcmd.exe to list credentials stored in the Windows Credential Manager to gain unauthorized access to saved usernames and passwords, potentially in preparation for lateral movement.
Web Server Local File Inclusion Activity Detected
3 rules 4 TTPsDetection of potential Local File Inclusion (LFI) activity on web servers through HTTP GET requests attempting to access sensitive local files via directory traversal or known file paths, potentially leading to information disclosure and system compromise.