January 2024 (30)
Acrel EEMS Enterprise Power Operation and Maintenance Cloud Platform SQL Injection Vulnerability
2 rules 1 TTP 1 CVEA SQL injection vulnerability exists in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0 when manipulating the 'fCircuitids' argument in the '/SubstationWEBV2/main/elecMaxMinAvgValue' file, potentially allowing for remote code execution or data exfiltration.
AdFind Active Directory Reconnaissance Activity
3 rules 5 TTPsAdFind.exe, a legitimate Active Directory query tool, is commonly abused by threat actors such as Trickbot, Ryuk, Maze, and FIN6 for post-exploitation Active Directory reconnaissance, enabling enumeration of objects like computers, people, subnets, and domain information.
Admidio SAML Assertion Consumer Service (ACS) URL Validation Bypass
2 rules 2 TTPs 2 IOCsAdmidio's SAML IdP implementation in its SSO module is vulnerable to sending SAML responses to unvalidated Assertion Consumer Service URLs, allowing an attacker to craft a SAML AuthnRequest with an arbitrary AssertionConsumerServiceURL, causing the IdP to send the signed SAML response, containing user identity attributes, to an attacker-controlled URL, enabling impersonation of the victim user on the legitimate SP by replaying the SAML assertion.
APT28 Targeting Roundcube Webmail in Ukraine
2 rules 3 TTPsAPT28 (Fancy Bear) is actively targeting Roundcube webmail platforms to compromise government and defense email accounts, leveraging Roundcube's vulnerabilities and widespread use, primarily targeting Ukrainian entities in an activity tracked as Operation Roundish.
AVideo CDN Plugin Unauthenticated Configuration Modification
2 rules 3 TTPsAVideo is vulnerable to unauthenticated configuration modification in its CDN plugin due to a bypassed key validation check when the default empty key is used, allowing modification of CDN URLs, storage credentials, and the authentication key itself.
AVideo Unauthenticated Access to Payment Log DataTables Endpoints
2 rules 2 TTPs 3 IOCsAVideo is vulnerable to unauthenticated access to multiple `list.json.php` endpoints due to missing authorization checks, allowing attackers to retrieve sensitive payment transaction records, including PayPal billing agreement IDs, Express Checkout tokens, Authorize.Net webhook payloads, and Bitcoin payment records, leading to financial data exposure and potential PII leakage.
AWS Console Login by User from New City
2 rules 1 TTPDetection of AWS console logins by a user from a previously unseen city, potentially indicating compromised credentials or account takeover.
AWS IAM Group Deletion Failure
2 rules 1 TTPDetection of a failed attempt to delete an AWS IAM group, which could indicate an attempt to remove audit trails or disrupt security policies.
AWS Identity API Access from Rare ASN Organizations
2 rules 1 TTPThis rule detects AWS identities with API traffic dominated by cloud-provider source AS organization labels, but also exhibit traffic from other AS organizations, potentially indicating credential reuse or pivoting.
AWS KMS Key User Performing S3 Encryption
2 rules 1 TTPDetection of AWS users employing KMS keys for S3 encryption, potentially indicating suspicious data handling within cloud environments.
AWS SAML Identity Provider Modification
2 rules 1 TTPAn adversary may attempt to modify the AWS SAML Identity Provider configuration to potentially escalate privileges or disrupt federated access.
Azure AD FullAccessAsApp Permission Assignment
2 rules 2 TTPsDetection of 'full_access_as_app' permission assignment to an application in Office 365 Exchange Online, potentially leading to unauthorized access and data exfiltration.
Azure AD Privileged Graph API Permission Assignment
2 rules 1 TTPDetection of high-risk Graph API permission assignments (Application.ReadWrite.All, AppRoleAssignment.ReadWrite.All, and RoleManagement.ReadWrite.Directory) in Azure AD, potentially leading to unauthorized modifications and security breaches.
Chamilo LMS Unrestricted File Upload Leads to Remote Code Execution
2 rules 1 TTP 1 CVEAn unrestricted file upload vulnerability in Chamilo LMS (CVE-2026-32931) allows an authenticated teacher to upload a PHP webshell, leading to remote code execution.
ChurchCRM SQL Injection Vulnerability in PropertyTypeEditor.php
2 rules 1 TTP 1 CVEA critical SQL injection vulnerability (CVE-2026-39323) in ChurchCRM versions prior to 7.1.0 allows authenticated users with 'Manage Properties' permission to execute arbitrary SQL commands via unsanitized POST parameters in PropertyTypeEditor.php, leading to potential data exfiltration, modification, or deletion.
code16/sharp Package Vulnerable to Path Traversal via Unsanitized File Extension
2 rules 1 TTPThe code16/sharp package is vulnerable to path traversal due to improper sanitization of file extensions, allowing authenticated attackers to manipulate file paths to write files outside the intended temporary directory or overwrite critical files.
Connect-CMS Code Study Plugin Arbitrary Code Execution
2 rules 1 TTPAn authenticated user of the Connect-CMS Code Study Plugin can execute arbitrary code due to a vulnerability (CVE-2026-32276) in versions 1.x before 1.41.1 and 2.x before 2.41.1, potentially leading to code execution on the server or information disclosure.
Discussion of EDR Killers on Reddit
2 rules 2 TTPsA Reddit post on r/blueteamsec references an ESET WeLiveSecurity article discussing EDR killer techniques that extend beyond driver manipulation.
DSGVO Google Web Fonts GDPR WordPress Plugin Arbitrary File Upload Vulnerability (CVE-2026-3535)
2 rules 2 TTPs 1 CVEThe DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to unauthenticated arbitrary file upload due to missing file type validation, allowing attackers to upload PHP webshells and achieve remote code execution.
Enhancing Detection Capabilities Through PowerShell Script Logging
2 rules 6 TTPsThis brief highlights the importance of PowerShell and script logging to improve threat detection capabilities within an organization's environment, focusing on increased visibility into malicious activities.
Entra ID External Guest User Invitation
2 rules 2 TTPsDetection of external guest user invitations in Entra ID, which can be abused for unauthorized access and persistence by creating overlooked accounts.
Firebird Server Denial-of-Service via Out-of-Order Authentication Segments
2 rules 1 TTP 1 CVEAn unauthenticated attacker can crash Firebird database servers prior to versions 5.0.4, 4.0.7 and 3.0.14 by sending out-of-order CNCT_specific_data segments during the authentication process, leading to a denial-of-service condition.
Firefox 0-day Drops OSX.Mokes.B Backdoor on macOS
2 rules 5 TTPs 1 IOCA Firefox 0-day exploit was used to target Mac users, dropping a second backdoor identified as a new variant of the cross-platform Mokes malware (OSX.Mokes.B) with screen capture, audio capture, and document exfiltration capabilities.
GCP Storage Bucket Deletion for Impact
2 rules 1 TTPAn adversary may delete a Google Cloud Platform (GCP) storage bucket to disrupt business operations, detected via GCP audit logs.
gix and gitoxide Submodule Path Traversal Vulnerability
2 rules 1 TTPA path traversal vulnerability exists in gix and gitoxide where unvalidated submodule names from `.gitmodules` can be used to escape the `.git/modules` directory, potentially leading to repository confusion by redirecting submodule state inspection and open operations to attacker-controlled paths.
Kubernetes Cluster Enumeration via Audit Logs
3 rules 2 TTPsAttackers attempt to enumerate and discover sensitive information within a Kubernetes cluster by leveraging common shells, utilities, and specialized tools, as reflected in audit logs.
Potential HTTP Downgrade Attack Detected
2 rules 1 TTPThe new_terms rule detects potential HTTP downgrade attacks by identifying HTTP traffic using a different HTTP version than typically used, potentially exposing systems to vulnerabilities in older protocols.
Potential Remote Install via MsiExec
2 rules 1 TTPThis rule detects attempts to install a file from a remote server using MsiExec, which adversaries may abuse to deliver malware, by identifying msiexec.exe processes running with arguments indicative of remote installations and executed from suspicious parent processes.
SharePoint Malware Upload for Lateral Movement
2 rules 2 TTPsAttackers can upload malware to SharePoint, leveraging the platform's file-sharing capabilities to propagate threats laterally within an organization and compromise additional systems.
Woocommerce Custom Product Addons Pro Plugin RCE Vulnerability (CVE-2026-4001)
2 rules 1 TTPThe Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution (RCE) due to insufficient sanitization of user-submitted field values, allowing unauthenticated attackers to execute arbitrary code via crafted WCPA text fields.