January 2024 (30)
Adobe Connect Deserialization Vulnerability (CVE-2026-27303)
2 rules 2 TTPs 1 CVE 1 IOCAdobe Connect versions 2025.3, 12.10 and earlier are vulnerable to deserialization of untrusted data, potentially leading to arbitrary code execution.
Azure AD Device Registration Policy Changes Detected
2 rules 1 TTPMonitoring changes to the device registration policy can detect potential privilege escalation or defense impairment attempts by malicious actors aiming to weaken security controls related to device management in Azure Active Directory.
Blinko Arbitrary File Read Vulnerability (CVE-2026-23482)
2 rules 1 TTPBlinko versions before 1.8.4 are vulnerable to arbitrary file reading due to a lack of permission checks and path traversal filtering on the temp/ path, potentially allowing attackers to read backup files containing sensitive user data.
blueprintUE Account Takeover Vulnerability (CVE-2026-40588)
2 rules 1 TTP 1 CVEblueprintUE versions prior to 4.2.0 are vulnerable to account takeover due to a missing current password validation on the password change form, allowing attackers with an authenticated session to change the password without knowing the original credential.
D-Link DIR-513 Stack-Based Buffer Overflow Vulnerability
2 rules 1 TTPA stack-based buffer overflow vulnerability (CVE-2026-4555) exists in the formEasySetTimezone function of the /goform/formEasySetTimezone file within the boa component of D-Link DIR-513 1.10, allowing remote attackers to execute arbitrary code.
Detection of Malicious Browser Extension Installation
2 rulesThis rule identifies the installation of potentially malicious browser extensions, which adversaries can leverage for persistence and unauthorized activity by monitoring file creation events in common browser extension directories on Windows systems.
Diesel SQLite Backend UTF-8 Corruption Vulnerability
2 rulesDiesel versions before 2.3.8 are vulnerable to UTF-8 corruption due to the `sqlite3_value_text` function not always returning UTF-8 encoded strings, potentially leading to invalid UTF-8 string processing without validation.
Execution via TSClient Mountpoint
2 rules 2 TTPsThe rule detects execution of processes from the Remote Desktop Protocol (RDP) shared mountpoint tsclient on a target host, indicating a potential lateral movement attempt by executing malicious files from the shared mountpoint.
FlightPHP HTTP Method Override Vulnerability Leads to CSRF and Middleware Bypass
2 rules 1 TTPA vulnerability in FlightPHP core versions before 3.18.1 allows attackers to override HTTP methods via the `X-HTTP-Method-Override` header or `_method` parameter, leading to CSRF escalation, middleware bypass, and cache poisoning.
FreeScout Arbitrary File Write via Crafted ZIP Upload (CVE-2026-41193)
2 rules 1 TTP 1 CVEFreeScout versions prior to 1.8.215 are vulnerable to arbitrary file write via a crafted ZIP archive uploaded by an authenticated administrator due to insufficient file path validation during module installation.
GCP Logging Sink Deletion for Defense Evasion
2 rules 1 TTPDetection of Google Cloud Platform (GCP) Logging sink deletion, a technique used by adversaries to impair defenses and evade detection by preventing log entries from being exported to designated destinations.
Glances Cross-Origin Information Disclosure via Unauthenticated REST API
2 rules 3 TTPs 1 CVEGlances versions before 4.5.4 are vulnerable to cross-origin information disclosure, where a malicious website can retrieve sensitive system information from a running Glances instance due to a permissive CORS policy on the `/api/4/all` endpoint.
i18next-http-middleware Prototype Pollution and Path Traversal Vulnerability
2 rules 2 TTPsVersions of i18next-http-middleware before 3.9.3 are vulnerable to prototype pollution, path traversal, and server-side request forgery (SSRF) due to improper validation of user-controlled language and namespace parameters, potentially leading to denial of service or remote code execution.
Kibana Fleet API Authorization Bypass (CVE-2026-33461)
2 rules 2 TTPs 1 CVEKibana is vulnerable to an authorization bypass (CVE-2026-33461) where users with limited Fleet privileges can access sensitive configuration data, including private keys and authentication tokens, via an internal API endpoint.
Langflow Unauthenticated Image Retrieval Vulnerability (CVE-2026-33484)
2 rules 1 TTPLangflow versions 1.0.0 through 1.8.1 are vulnerable to an unauthenticated image retrieval vulnerability (CVE-2026-33484) that allows attackers to download any user's uploaded images without credentials in multi-tenant deployments by accessing the `/api/v1/files/images/{flow_id}/{file_name}` endpoint.
LSASS Credential Dumping via Windows Error Reporting (WER) Abuse
2 rules 2 TTPsAttackers can enable full user-mode dumps system-wide via registry modification to facilitate LSASS credential dumping, allowing extraction of credentials from process memory without deploying malware.
LSASS Memory Dump Creation Detection
2 rules 1 TTPThis rule detects the creation of LSASS memory dumps, which may indicate a credential access attempt via tools like Task Manager, SQL Dumper, Dumpert, and AndrewSpecial.
Marimo Pre-Auth RCE via Terminal WebSocket Authentication Bypass
1 rule 1 TTPMarimo versions 0.20.4 and earlier contain a pre-authentication remote code execution vulnerability in the `/terminal/ws` WebSocket endpoint, allowing unauthenticated attackers to execute arbitrary system commands, resulting in a full interactive root shell.
MindsDB Unrestricted File Upload Vulnerability (CVE-2026-7711)
2 rules 1 TTP 1 CVECVE-2026-7711 allows for remote, unrestricted file uploads in MindsDB up to version 26.01 due to insufficient validation in the `exec` function of `proc_wrapper.py`, potentially leading to code execution or data exfiltration.
Movary Privilege Escalation via User Management Endpoint Access (CVE-2026-40350)
2 rules 1 TTP 1 CVEMovary versions prior to 0.71.1 are vulnerable to a privilege escalation, allowing authenticated non-admin users to access user management endpoints and create new administrator accounts due to missing middleware and flawed authorization checks.
Nerdbank.MessagePack DateTime Decoding Stack Overflow Vulnerability
2 rules 1 TTPA malicious MessagePack payload can trigger a StackOverflowException in Nerdbank.MessagePack due to an uncontrolled stack allocation when decoding DateTime values with oversized timestamp extension lengths, leading to process termination.
OpenClaw Gateway Agent Session Reset Vulnerability
2 rulesOpenClaw versions prior to 2026.3.23 expose an administrative session reset vulnerability via the Gateway agent RPC, allowing attackers with `operator.write` privileges to reset sessions that should require `operator.admin`.
Orbit Agent Local Privilege Escalation via Tcl Command Injection
2 rules 1 TTPThe Orbit agent is vulnerable to local privilege escalation due to Tcl command injection, where a crafted password containing '}' can inject arbitrary Tcl commands and allow an unprivileged local user to execute commands as root.
Potential Kerberos Coercion via DNS-Based SPN Spoofing
2 rules 1 TTPAdversaries may abuse MicrosoftDNS records containing a base64-encoded blob to coerce victim systems into authenticating to attacker-controlled hosts while requesting Kerberos tickets for legitimate services, detected via directory-service access events.
PowerShell Kerberos Ticket Dumping via LSA Authentication Package Access
2 rules 1 TTPDetection of PowerShell scripts attempting to dump Kerberos tickets from memory by accessing LSA authentication packages, potentially leading to credential access and lateral movement.
Qualcomm Memory Corruption Vulnerability in Performance Counter Deselect Operation (CVE-2026-24082)
2 rules 1 TTP 1 CVECVE-2026-24082 is a use-after-free vulnerability in Qualcomm products that occurs when copying data from a freed source during a performance counter deselect operation, potentially leading to memory corruption and arbitrary code execution.
EKG Gadu 1.9 Local Buffer Overflow Vulnerability (CVE-2016-20047)
2 rules 2 TTPsEKG Gadu 1.9~pre+r2855-3+b1 is vulnerable to a local buffer overflow (CVE-2016-20047) in username handling, allowing attackers to execute arbitrary code by providing an oversized username string.
Google Workspace Suspicious Login Activity
3 rules 1 TTPDetect Google Workspace login activity that Google has classified as suspicious, potentially indicating initial access, privilege escalation, defense evasion, or persistence attempts.
Persistence via BITS Job Notify Cmdline
2 rules 1 TTPAdversaries can achieve persistence by abusing the Background Intelligent Transfer Service (BITS) SetNotifyCmdLine method to execute a program after a job finishes, leading to arbitrary code execution and system compromise.
Unusual Network Connection via RunDLL32
2 rules 2 TTPsThe rule detects unusual outbound network connections made by rundll32.exe, specifically when executed with minimal arguments, which may indicate command and control activity or defense evasion tactics on Windows systems.