Skip to content
Threat Feed

January 2024 (30)

critical advisory

Adobe Connect Deserialization Vulnerability (CVE-2026-27303)

Adobe Connect versions 2025.3, 12.10 and earlier are vulnerable to deserialization of untrusted data, potentially leading to arbitrary code execution.

Adobe Connect cve-2026-27303 deserialization adobe-connect code-execution
2r 2t 1c 1i
high advisory

Azure AD Device Registration Policy Changes Detected

Monitoring changes to the device registration policy can detect potential privilege escalation or defense impairment attempts by malicious actors aiming to weaken security controls related to device management in Azure Active Directory.

Azure Active Directory azure device-registration policy-change
2r 1t
high advisory

Blinko Arbitrary File Read Vulnerability (CVE-2026-23482)

Blinko versions before 1.8.4 are vulnerable to arbitrary file reading due to a lack of permission checks and path traversal filtering on the temp/ path, potentially allowing attackers to read backup files containing sensitive user data.

Blinko cve-2026-23482 file-read path-traversal cloud
2r 1t
critical advisory

blueprintUE Account Takeover Vulnerability (CVE-2026-40588)

blueprintUE versions prior to 4.2.0 are vulnerable to account takeover due to a missing current password validation on the password change form, allowing attackers with an authenticated session to change the password without knowing the original credential.

blueprintUE account-takeover CVE-2026-40588 web-application
2r 1t 1c
critical advisory

D-Link DIR-513 Stack-Based Buffer Overflow Vulnerability

A stack-based buffer overflow vulnerability (CVE-2026-4555) exists in the formEasySetTimezone function of the /goform/formEasySetTimezone file within the boa component of D-Link DIR-513 1.10, allowing remote attackers to execute arbitrary code.

D-Link DIR-513 cve stack-overflow d-link network-device
2r 1t
low advisory

Detection of Malicious Browser Extension Installation

This rule identifies the installation of potentially malicious browser extensions, which adversaries can leverage for persistence and unauthorized activity by monitoring file creation events in common browser extension directories on Windows systems.

Elastic Defend +2 persistence browser-extension windows
2r
high advisory

Diesel SQLite Backend UTF-8 Corruption Vulnerability

Diesel versions before 2.3.8 are vulnerable to UTF-8 corruption due to the `sqlite3_value_text` function not always returning UTF-8 encoded strings, potentially leading to invalid UTF-8 string processing without validation.

diesel utf-8 sqlite corruption
2r
high advisory

Execution via TSClient Mountpoint

The rule detects execution of processes from the Remote Desktop Protocol (RDP) shared mountpoint tsclient on a target host, indicating a potential lateral movement attempt by executing malicious files from the shared mountpoint.

Windows lateral-movement rdp
2r 2t
high advisory

FlightPHP HTTP Method Override Vulnerability Leads to CSRF and Middleware Bypass

A vulnerability in FlightPHP core versions before 3.18.1 allows attackers to override HTTP methods via the `X-HTTP-Method-Override` header or `_method` parameter, leading to CSRF escalation, middleware bypass, and cache poisoning.

flightphp/core csrf middleware-bypass cache-poisoning http-method-override
2r 1t
critical advisory

FreeScout Arbitrary File Write via Crafted ZIP Upload (CVE-2026-41193)

FreeScout versions prior to 1.8.215 are vulnerable to arbitrary file write via a crafted ZIP archive uploaded by an authenticated administrator due to insufficient file path validation during module installation.

FreeScout file-write cve-2026-41193 zip-upload
2r 1t 1c
medium advisory

GCP Logging Sink Deletion for Defense Evasion

Detection of Google Cloud Platform (GCP) Logging sink deletion, a technique used by adversaries to impair defenses and evade detection by preventing log entries from being exported to designated destinations.

Google Cloud Platform +1 gcp logging defense-evasion
2r 1t
high advisory

Glances Cross-Origin Information Disclosure via Unauthenticated REST API

Glances versions before 4.5.4 are vulnerable to cross-origin information disclosure, where a malicious website can retrieve sensitive system information from a running Glances instance due to a permissive CORS policy on the `/api/4/all` endpoint.

Glances information-disclosure cors webserver
2r 3t 1c
high advisory

i18next-http-middleware Prototype Pollution and Path Traversal Vulnerability

Versions of i18next-http-middleware before 3.9.3 are vulnerable to prototype pollution, path traversal, and server-side request forgery (SSRF) due to improper validation of user-controlled language and namespace parameters, potentially leading to denial of service or remote code execution.

i18next-http-middleware prototype-pollution path-traversal ssrf denial-of-service i18next
2r 2t
high advisory

Kibana Fleet API Authorization Bypass (CVE-2026-33461)

Kibana is vulnerable to an authorization bypass (CVE-2026-33461) where users with limited Fleet privileges can access sensitive configuration data, including private keys and authentication tokens, via an internal API endpoint.

Kibana authorization-bypass privilege-escalation
2r 2t 1c
medium advisory

Langflow Unauthenticated Image Retrieval Vulnerability (CVE-2026-33484)

Langflow versions 1.0.0 through 1.8.1 are vulnerable to an unauthenticated image retrieval vulnerability (CVE-2026-33484) that allows attackers to download any user's uploaded images without credentials in multi-tenant deployments by accessing the `/api/v1/files/images/{flow_id}/{file_name}` endpoint.

Langflow unauthenticated-access image-retrieval vulnerability
2r 1t
medium advisory

LSASS Credential Dumping via Windows Error Reporting (WER) Abuse

Attackers can enable full user-mode dumps system-wide via registry modification to facilitate LSASS credential dumping, allowing extraction of credentials from process memory without deploying malware.

Elastic Defend +2 credential-access windows lsass wepw
2r 2t
high advisory

LSASS Memory Dump Creation Detection

This rule detects the creation of LSASS memory dumps, which may indicate a credential access attempt via tools like Task Manager, SQL Dumper, Dumpert, and AndrewSpecial.

Windows credential-access lsass memory-dump
2r 1t
critical advisory

Marimo Pre-Auth RCE via Terminal WebSocket Authentication Bypass

Marimo versions 0.20.4 and earlier contain a pre-authentication remote code execution vulnerability in the `/terminal/ws` WebSocket endpoint, allowing unauthenticated attackers to execute arbitrary system commands, resulting in a full interactive root shell.

Marimo rce websocket
1r 1t
critical advisory

MindsDB Unrestricted File Upload Vulnerability (CVE-2026-7711)

CVE-2026-7711 allows for remote, unrestricted file uploads in MindsDB up to version 26.01 due to insufficient validation in the `exec` function of `proc_wrapper.py`, potentially leading to code execution or data exfiltration.

MindsDB cve vulnerability file-upload
2r 1t 1c
high advisory

Movary Privilege Escalation via User Management Endpoint Access (CVE-2026-40350)

Movary versions prior to 0.71.1 are vulnerable to a privilege escalation, allowing authenticated non-admin users to access user management endpoints and create new administrator accounts due to missing middleware and flawed authorization checks.

Movary cve-2026-40350 privilege-escalation web-application
2r 1t 1c
high advisory

Nerdbank.MessagePack DateTime Decoding Stack Overflow Vulnerability

A malicious MessagePack payload can trigger a StackOverflowException in Nerdbank.MessagePack due to an uncontrolled stack allocation when decoding DateTime values with oversized timestamp extension lengths, leading to process termination.

Nerdbank.MessagePack denial-of-service stack-overflow messagepack
2r 1t
high advisory

OpenClaw Gateway Agent Session Reset Vulnerability

OpenClaw versions prior to 2026.3.23 expose an administrative session reset vulnerability via the Gateway agent RPC, allowing attackers with `operator.write` privileges to reset sessions that should require `operator.admin`.

OpenClaw session-reset privilege-escalation
2r
critical advisory

Orbit Agent Local Privilege Escalation via Tcl Command Injection

The Orbit agent is vulnerable to local privilege escalation due to Tcl command injection, where a crafted password containing '}' can inject arbitrary Tcl commands and allow an unprivileged local user to execute commands as root.

Orbit agent privilege-escalation tcl-injection macos
2r 1t
high advisory

Potential Kerberos Coercion via DNS-Based SPN Spoofing

Adversaries may abuse MicrosoftDNS records containing a base64-encoded blob to coerce victim systems into authenticating to attacker-controlled hosts while requesting Kerberos tickets for legitimate services, detected via directory-service access events.

Active Directory kerberos coercion dns spn spoofing credential-access
2r 1t
high advisory

PowerShell Kerberos Ticket Dumping via LSA Authentication Package Access

Detection of PowerShell scripts attempting to dump Kerberos tickets from memory by accessing LSA authentication packages, potentially leading to credential access and lateral movement.

PowerShell credential-access kerberos windows
2r 1t
high advisory

Qualcomm Memory Corruption Vulnerability in Performance Counter Deselect Operation (CVE-2026-24082)

CVE-2026-24082 is a use-after-free vulnerability in Qualcomm products that occurs when copying data from a freed source during a performance counter deselect operation, potentially leading to memory corruption and arbitrary code execution.

cve-2026-24082 use-after-free memory corruption qualcomm
2r 1t 1c
high advisory

EKG Gadu 1.9 Local Buffer Overflow Vulnerability (CVE-2016-20047)

EKG Gadu 1.9~pre+r2855-3+b1 is vulnerable to a local buffer overflow (CVE-2016-20047) in username handling, allowing attackers to execute arbitrary code by providing an oversized username string.

EKG Gadu buffer-overflow local-privilege-escalation cve-2016-20047
2r 2t
medium advisory

Google Workspace Suspicious Login Activity

Detect Google Workspace login activity that Google has classified as suspicious, potentially indicating initial access, privilege escalation, defense evasion, or persistence attempts.

Google Workspace initial-access privilege-escalation defense-evasion persistence gworkspace
3r 1t
medium advisory

Persistence via BITS Job Notify Cmdline

Adversaries can achieve persistence by abusing the Background Intelligent Transfer Service (BITS) SetNotifyCmdLine method to execute a program after a job finishes, leading to arbitrary code execution and system compromise.

Defender XDR +2 persistence bits windows
2r 1t
medium advisory

Unusual Network Connection via RunDLL32

The rule detects unusual outbound network connections made by rundll32.exe, specifically when executed with minimal arguments, which may indicate command and control activity or defense evasion tactics on Windows systems.

Elastic Defend +1 defense-evasion command-and-control windows
2r 2t