Skip to content
Threat Feed

January 2024 (30)

high advisory

Acrel EEMS Enterprise Power Operation and Maintenance Cloud Platform SQL Injection Vulnerability

A SQL injection vulnerability exists in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0 when manipulating the 'fCircuitids' argument in the '/SubstationWEBV2/main/elecMaxMinAvgValue' file, potentially allowing for remote code execution or data exfiltration.

EEMS Enterprise Power Operation and Maintenance Cloud Platform sql-injection web-application vulnerability
2r 1t 1c
low threat

AdFind Active Directory Reconnaissance Activity

AdFind.exe, a legitimate Active Directory query tool, is commonly abused by threat actors such as Trickbot, Ryuk, Maze, and FIN6 for post-exploitation Active Directory reconnaissance, enabling enumeration of objects like computers, people, subnets, and domain information.

Active Directory Trickbot +3 adfind active-directory reconnaissance discovery windows
3r 5t
medium advisory

Admidio SAML Assertion Consumer Service (ACS) URL Validation Bypass

Admidio's SAML IdP implementation in its SSO module is vulnerable to sending SAML responses to unvalidated Assertion Consumer Service URLs, allowing an attacker to craft a SAML AuthnRequest with an arbitrary AssertionConsumerServiceURL, causing the IdP to send the signed SAML response, containing user identity attributes, to an attacker-controlled URL, enabling impersonation of the victim user on the legitimate SP by replaying the SAML assertion.

admidio saml sso acs-bypass cve-2026-41670
2r 2t 2i
high threat

APT28 Targeting Roundcube Webmail in Ukraine

APT28 (Fancy Bear) is actively targeting Roundcube webmail platforms to compromise government and defense email accounts, leveraging Roundcube's vulnerabilities and widespread use, primarily targeting Ukrainian entities in an activity tracked as Operation Roundish.

Roundcube Webmail APT28 +6 roundcube webmail ukraine exploitation
2r 3t
high advisory

AVideo CDN Plugin Unauthenticated Configuration Modification

AVideo is vulnerable to unauthenticated configuration modification in its CDN plugin due to a bypassed key validation check when the default empty key is used, allowing modification of CDN URLs, storage credentials, and the authentication key itself.

AVideo cdn configuration-modification vulnerability
2r 3t
high advisory

AVideo Unauthenticated Access to Payment Log DataTables Endpoints

AVideo is vulnerable to unauthenticated access to multiple `list.json.php` endpoints due to missing authorization checks, allowing attackers to retrieve sensitive payment transaction records, including PayPal billing agreement IDs, Express Checkout tokens, Authorize.Net webhook payloads, and Bitcoin payment records, leading to financial data exposure and potential PII leakage.

AVideo authentication-bypass payment-data-leak
2r 2t 3i
medium advisory

AWS Console Login by User from New City

Detection of AWS console logins by a user from a previously unseen city, potentially indicating compromised credentials or account takeover.

AWS Management Console aws cloud account-takeover credential-compromise
2r 1t
medium advisory

AWS IAM Group Deletion Failure

Detection of a failed attempt to delete an AWS IAM group, which could indicate an attempt to remove audit trails or disrupt security policies.

AWS Identity and Access Management aws iam cloud deletion
2r 1t
high advisory

AWS Identity API Access from Rare ASN Organizations

This rule detects AWS identities with API traffic dominated by cloud-provider source AS organization labels, but also exhibit traffic from other AS organizations, potentially indicating credential reuse or pivoting.

aws cloudtrail initial-access credential-access
2r 1t
medium advisory

AWS KMS Key User Performing S3 Encryption

Detection of AWS users employing KMS keys for S3 encryption, potentially indicating suspicious data handling within cloud environments.

AWS Identity and Access Management +2 aws kms s3 cloud encryption
2r 1t
medium advisory

AWS SAML Identity Provider Modification

An adversary may attempt to modify the AWS SAML Identity Provider configuration to potentially escalate privileges or disrupt federated access.

AWS Identity and Access Management aws saml identity-provider privilege-escalation
2r 1t
high threat

Azure AD FullAccessAsApp Permission Assignment

Detection of 'full_access_as_app' permission assignment to an application in Office 365 Exchange Online, potentially leading to unauthorized access and data exfiltration.

Office 365 Exchange Online +1 NOBELIUM Group azure azuread office365 persistence nobelium
2r 2t
critical threat

Azure AD Privileged Graph API Permission Assignment

Detection of high-risk Graph API permission assignments (Application.ReadWrite.All, AppRoleAssignment.ReadWrite.All, and RoleManagement.ReadWrite.Directory) in Azure AD, potentially leading to unauthorized modifications and security breaches.

Azure Active Directory NOBELIUM Group azuread cloud graphapi privilegeescalation persistence
2r 1t
critical advisory

Chamilo LMS Unrestricted File Upload Leads to Remote Code Execution

An unrestricted file upload vulnerability in Chamilo LMS (CVE-2026-32931) allows an authenticated teacher to upload a PHP webshell, leading to remote code execution.

Chamilo LMS chamilo rce file-upload
2r 1t 1c
critical advisory

ChurchCRM SQL Injection Vulnerability in PropertyTypeEditor.php

A critical SQL injection vulnerability (CVE-2026-39323) in ChurchCRM versions prior to 7.1.0 allows authenticated users with 'Manage Properties' permission to execute arbitrary SQL commands via unsanitized POST parameters in PropertyTypeEditor.php, leading to potential data exfiltration, modification, or deletion.

ChurchCRM sql-injection web-application
2r 1t 1c
high advisory

code16/sharp Package Vulnerable to Path Traversal via Unsanitized File Extension

The code16/sharp package is vulnerable to path traversal due to improper sanitization of file extensions, allowing authenticated attackers to manipulate file paths to write files outside the intended temporary directory or overwrite critical files.

sharp path-traversal web-application php code16/sharp
2r 1t
high advisory

Connect-CMS Code Study Plugin Arbitrary Code Execution

An authenticated user of the Connect-CMS Code Study Plugin can execute arbitrary code due to a vulnerability (CVE-2026-32276) in versions 1.x before 1.41.1 and 2.x before 2.41.1, potentially leading to code execution on the server or information disclosure.

Connect-CMS code-execution vulnerability
2r 1t
medium advisory

Discussion of EDR Killers on Reddit

A Reddit post on r/blueteamsec references an ESET WeLiveSecurity article discussing EDR killer techniques that extend beyond driver manipulation.

Endpoint Detection and Response edr-evasion defense-evasion red-team
2r 2t
critical advisory

DSGVO Google Web Fonts GDPR WordPress Plugin Arbitrary File Upload Vulnerability (CVE-2026-3535)

The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to unauthenticated arbitrary file upload due to missing file type validation, allowing attackers to upload PHP webshells and achieve remote code execution.

DSGVO Google Web Fonts GDPR plugin wordpress plugin file-upload rce CVE-2026-3535
2r 2t 1c
medium advisory

Enhancing Detection Capabilities Through PowerShell Script Logging

This brief highlights the importance of PowerShell and script logging to improve threat detection capabilities within an organization's environment, focusing on increased visibility into malicious activities.

PowerShell script-logging threat-detection
2r 6t
low advisory

Entra ID External Guest User Invitation

Detection of external guest user invitations in Entra ID, which can be abused for unauthorized access and persistence by creating overlooked accounts.

Entra ID +1 cloud azure initial-access persistence
2r 2t
high advisory

Firebird Server Denial-of-Service via Out-of-Order Authentication Segments

An unauthenticated attacker can crash Firebird database servers prior to versions 5.0.4, 4.0.7 and 3.0.14 by sending out-of-order CNCT_specific_data segments during the authentication process, leading to a denial-of-service condition.

Firebird cve dos
2r 1t 1c
high threat

Firefox 0-day Drops OSX.Mokes.B Backdoor on macOS

A Firefox 0-day exploit was used to target Mac users, dropping a second backdoor identified as a new variant of the cross-platform Mokes malware (OSX.Mokes.B) with screen capture, audio capture, and document exfiltration capabilities.

exploited Firefox +2 malware backdoor osx.mokes macos
2r 5t 1i
medium advisory

GCP Storage Bucket Deletion for Impact

An adversary may delete a Google Cloud Platform (GCP) storage bucket to disrupt business operations, detected via GCP audit logs.

Google Cloud Platform +1 cloud gcp impact
2r 1t
high advisory

gix and gitoxide Submodule Path Traversal Vulnerability

A path traversal vulnerability exists in gix and gitoxide where unvalidated submodule names from `.gitmodules` can be used to escape the `.git/modules` directory, potentially leading to repository confusion by redirecting submodule state inspection and open operations to attacker-controlled paths.

gix +1 path-traversal git repository-confusion supply-chain
2r 1t
medium advisory

Kubernetes Cluster Enumeration via Audit Logs

Attackers attempt to enumerate and discover sensitive information within a Kubernetes cluster by leveraging common shells, utilities, and specialized tools, as reflected in audit logs.

Kubernetes enumeration cloud
3r 2t
low advisory

Potential HTTP Downgrade Attack Detected

The new_terms rule detects potential HTTP downgrade attacks by identifying HTTP traffic using a different HTTP version than typically used, potentially exposing systems to vulnerabilities in older protocols.

Nginx +3 defense-evasion http-downgrade web-server
2r 1t
high advisory

Potential Remote Install via MsiExec

This rule detects attempts to install a file from a remote server using MsiExec, which adversaries may abuse to deliver malware, by identifying msiexec.exe processes running with arguments indicative of remote installations and executed from suspicious parent processes.

Microsoft Defender XDR +3 defense-evasion windows msiexec remote-install
2r 1t
high advisory

SharePoint Malware Upload for Lateral Movement

Attackers can upload malware to SharePoint, leveraging the platform's file-sharing capabilities to propagate threats laterally within an organization and compromise additional systems.

SharePoint +1 lateral-movement malware o365
2r 2t
critical advisory

Woocommerce Custom Product Addons Pro Plugin RCE Vulnerability (CVE-2026-4001)

The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution (RCE) due to insufficient sanitization of user-submitted field values, allowing unauthenticated attackers to execute arbitrary code via crafted WCPA text fields.

Custom Product Addons Pro plugin wordpress woocommerce rce code-injection cve-2026-4001
2r 1t