Skip to content
Threat Feed

January 2024 (30)

high advisory

@fastify/middie Middleware Bypass Vulnerability via Duplicate Slashes

`@fastify/middie` versions 9.3.1 and earlier are vulnerable to middleware bypass via URLs with duplicate leading slashes due to improper handling of the deprecated `ignoreDuplicateSlashes` option, potentially allowing unauthorized access to protected resources.

Fastify +1 middie middleware-bypass vulnerability defense-evasion
2r 1t 1c
high advisory

Amelia Booking WordPress Plugin Insecure Direct Object Reference Vulnerability

The Amelia Booking plugin for WordPress versions 9.1.2 and earlier is vulnerable to Insecure Direct Object References (IDOR), allowing authenticated attackers with customer-level permissions or higher to change user passwords and potentially compromise administrator accounts.

Amelia Booking plugin wordpress plugin idor privilege-escalation CVE-2026-2931
2r 1t
medium advisory

AWS IAM AdministratorAccess Policy Attached to User

An adversary with compromised AWS credentials may attempt to escalate privileges or persist access by attaching the AdministratorAccess AWS managed policy to an existing IAM user via the AttachUserPolicy API, granting full access to all AWS services and resources.

AWS IAM aws iam privilege-escalation persistence
2r 2t
low advisory

GCP Pub/Sub Topic Deletion for Defense Evasion

Detection of Google Cloud Platform Pub/Sub topic deletions can indicate an attempt to disrupt message flow and potentially evade defenses by impairing logging or event-driven automation.

GCP Pub/Sub gcp pubsub defense-evasion cloud
2r 2t
medium advisory

Local Account TokenFilter Policy Modification for Defense Evasion

Modification of the LocalAccountTokenFilterPolicy registry key to enable high-integrity tokens for local administrator accounts is detected, potentially allowing attackers to bypass User Account Control (UAC) and facilitate lateral movement.

Windows defense-evasion lateral-movement registry-modification
2r 3t
low advisory

Netsh Helper DLL Persistence via Registry Modification

Attackers may establish persistence by adding a malicious DLL as a Netsh Helper, which executes whenever the Netsh utility is run, often abusing this mechanism to execute malicious payloads.

Windows persistence registry netsh
2r 3t
low advisory

Potential Exploitation of an Unquoted Service Path Vulnerability

This rule detects potential exploitation of unquoted service path vulnerabilities, where adversaries may escalate privileges by placing a malicious executable in a higher-level directory within the path of an unquoted service executable.

Microsoft Defender XDR +4 privilege-escalation unquoted-service-path windows
2r 1t
high advisory

Suspicious Startup Shell Folder Modification

This rule detects suspicious modifications to the startup shell folder registry keys, potentially indicating an attempt to establish persistence by pointing to malicious executables and bypassing traditional defenses.

Windows persistence defense-evasion registry-modification
2r 2t
low advisory

AWS S3 Data Exfiltration via Uncommon Clients

Detection of AWS API activity from rare S3 client applications (S3 Browser, Cyberduck), potentially indicating unauthorized data exfiltration by threat actors.

S3 aws exfiltration cloudtrail
2r 1t
high advisory

AWS Password Spraying Attack via Multiple Failed Console Logins

A single source IP attempts to authenticate to the AWS Console against multiple unique user accounts within a short timeframe, indicating a potential password spraying attack.

AWS Console aws password-spraying credential-access
2r 2t
medium advisory

CircleCI Security Step Disabled Detection

Detection of disabling security steps in CircleCI, potentially indicating an attempt to bypass security controls during the CI/CD process.

CircleCI ci/cd devops security-bypass
2r 1t
critical advisory

Ghidra Improper Annotation Processing Leads to RCE (CVE-2026-4946)

Ghidra versions before 12.0.3 improperly process annotation directives from automatically extracted binary data, leading to arbitrary command execution when an analyst interacts with the user interface by clicking on a crafted element.

Ghidra CVE-2026-4946 rce
3r 1t
critical advisory

Incus Path Traversal Vulnerability (CVE-2026-33945)

A path traversal vulnerability in Incus versions prior to 6.23.0 (CVE-2026-33945) allows an attacker to write arbitrary files as root, leading to privilege escalation and denial of service by crafting a malicious systemd credential path.

Incus path-traversal privilege-escalation denial-of-service CVE-2026-33945 linux
2r 1t
medium advisory

Kerberos Pre-authentication Disabled for User Account

Detection of Kerberos pre-authentication being disabled for a user account, potentially leading to AS-REP roasting and offline password cracking by attackers with GenericWrite or GenericAll rights over the account.

Active Directory kerberos credential-access as-rep-roasting active-directory windows
3r 4t
high advisory

LORIS Reflected Cross-Site Scripting Vulnerability (CVE-2026-35169)

A reflected cross-site scripting vulnerability (CVE-2026-35169) exists in the LORIS help_editor module due to insufficient sanitization of user-supplied variables, potentially leading to arbitrary markdown file downloads or script execution if a user clicks a crafted link.

LORIS xss cve-2026-35169
2r 1t 1c
medium advisory

Remote File Download via Script Interpreter

Attackers are using Windows script interpreters (cscript.exe or wscript.exe) to download executable files from remote locations to deliver second-stage payloads or download tools.

Windows Script Host command-and-control execution windows script_interpreter
2r 3t
high advisory

Suspicious PowerShell Execution via Windows Script Host

Adversaries may execute PowerShell commands through the Windows Script Host (wscript.exe or cscript.exe) using suspicious arguments, potentially bypassing traditional PowerShell execution policies and detection mechanisms.

Windows powershell wscript cscript execution scripting
2r 1t
critical advisory

vm2 NodeVM Nesting Bypass Allows Arbitrary Command Execution

A vulnerability in vm2's NodeVM, when nesting is enabled, allows sandbox code to bypass require restrictions, enabling arbitrary OS command execution on the host.

vm2 sandbox-escape code-execution
2r 2t
medium advisory

Windows Registry Classes Autorun Keys Modification for Persistence

Adversaries modify Windows Registry Classes keys to establish persistence by executing malicious code when specific file types are opened or actions are performed, potentially leading to privilege escalation and persistent access.

Windows attack.privilege-escalation attack.persistence attack.t1547.001
3r 1t
medium advisory

Detection of Obfuscated IP Address Usage in Download Commands

This brief details the use of obfuscated IP addresses within download commands, often employed to evade detection by hiding the true destination of malicious downloads.

Windows discovery evasion obfuscation
2r 2t
high advisory

AMSI Enable Registry Key Modification for Defense Evasion

Adversaries modify the AmsiEnable registry key to 0 to disable Windows Script AMSI scanning, bypassing AMSI protections for Windows Script Host or JScript execution.

Microsoft Defender XDR +4 defense-evasion amsi registry windows
2r 1t
medium advisory

Suspicious Zoom Child Process Activity

The spawning of command interpreters (cmd.exe, powershell.exe, pwsh.exe) as child processes of Zoom.exe is indicative of potential exploitation or malicious masquerading, allowing attackers to execute arbitrary commands within the context of the Zoom application.

Zoom masquerading process-injection defense-evasion
2r 5t
critical advisory

ToTok iOS Application Used for Government Surveillance

The ToTok iOS application, developed by Breej Holding Ltd., was identified as a spying tool used by the government of the United Arab Emirates (UAE) to track users' conversations, movements, and relationships by collecting sensitive user data and transmitting it to servers using self-signed certificates.

ToTok +1 spyware ios surveillance
2r 2t 2i
medium advisory

M365 Copilot Impersonation Jailbreak Attempt Detection

This detection identifies M365 Copilot impersonation and roleplay jailbreak attempts by analyzing exported eDiscovery prompt logs, searching for users manipulating the AI into adopting alternate personas or bypassing safety controls via roleplay keywords, categorizing specific impersonation types to identify persona injection attacks.

Microsoft 365 Copilot copilot jailbreak ai persona-injection
2r 1t
high advisory

OpenClaw Unbounded Memory Allocation Vulnerability

The openclaw npm package prior to version 2026.3.22 is vulnerable to unbounded memory allocation due to missing size limits when reading remote media HTTP error bodies, potentially leading to denial-of-service.

openclaw memory-allocation denial-of-service npm
2r 1t
high advisory

Potential Disabling of Windows Defender Antivirus via Registry Modification

An attacker might attempt to disable Windows Defender Antivirus by modifying specific registry keys, potentially leading to a system vulnerable to malware and other threats.

Windows Defender Antivirus windowsdefender registry antivirus disable malware
2r 1t
high advisory

Pre-Ransomware Active Directory Discovery Burst

Attackers perform a burst of Active Directory discovery commands on a Windows host to gather information prior to ransomware deployment.

Windows +1 active-directory discovery ransomware
3r 3t
high advisory

Scriban Template Engine LoopLimit Bypass Vulnerability

Scriban's LoopLimit can be bypassed by crafted template expressions, allowing attackers to perform resource exhaustion through CPU or memory amplification, leading to denial of service.

Scriban Template Engine scriban dos template-injection
2r 1t
high advisory

Tandoor Recipes Authentication Bypass Vulnerability (CVE-2026-35045)

Tandoor Recipes before version 2.6.4 allows authenticated users within a space to modify any recipe in that space, including private ones, via the PUT /api/recipe/batch_update/ endpoint, bypassing object-level authorization checks and enabling unauthorized access and data tampering.

Tandoor Recipes authentication-bypass web-application tandoor-recipes
2r 1t 1c
high advisory

Vite Arbitrary File Read Vulnerability via WebSocket

Vite versions 6.0.0 to 8.0.4 are vulnerable to arbitrary file read, allowing attackers to bypass access controls and retrieve the contents of arbitrary files on the server via the WebSocket path when the dev server is exposed to the network.

Vite file-read vulnerability websocket
2r 1t