Skip to content
Threat Feed

January 2024 (30)

critical advisory

AVideo Platform Unauthenticated Live Stream Control via streamerURL Manipulation

AVideo platform versions up to 26.0 are vulnerable to unauthenticated control of live streams due to manipulation of the `streamerURL` parameter in the `control.json.php` endpoint, enabling actions like dropping publishers or starting/stopping recordings.

AVideo Platform avideo authentication-bypass cve-2026-33716
2r 1t
medium threat

Entra ID Unusual ROPC Login Attempt

Detects unusual resource owner password credential (ROPC) login attempts by a user principal in Microsoft Entra ID, potentially indicating account compromise or password spraying.

exploited Microsoft Entra ID azure entra-id ropc initial-access
2r 2t
medium advisory

Okta End-User Reports Suspicious Account Activity

An Okta end-user reports potentially suspicious activity on their account, indicating possible compromise or unauthorized access.

Okta identity suspicious-activity
2r 1t
critical advisory

AVideo SSRF Vulnerability via IPv4-Mapped IPv6 Bypass (CVE-2026-33480)

AVideo versions up to 26.0 are vulnerable to server-side request forgery (SSRF) due to a bypass in the `isSSRFSafeURL()` function, allowing unauthenticated attackers to access internal resources.

AVideo ssrf cve-2026-33480 webserver
2r 1t
high advisory

Laravel Passport Authentication Bypass via Client Credentials Tokens

Laravel Passport before v13.7.1 allows an authentication bypass via client credentials tokens, where a client's identifier can be used to impersonate a user if `Passport::$clientUuids` is set to false or the EnsureClientIsResourceOwner middleware is in use.

Laravel Passport laravel passport oauth2 authentication-bypass
2r 1t
high advisory

M365 OneDrive Malware File Upload

This rule detects files uploaded to OneDrive that are identified as malware by the file scanning engine, potentially leading to lateral movement and further compromise.

OneDrive +1 cloud lateral-movement
2r 2t
high advisory

code-projects Vehicle Showroom Management System 1.0 SQL Injection Vulnerability

A remote SQL injection vulnerability exists in code-projects Vehicle Showroom Management System 1.0 via manipulation of the BRANCH_ID argument in the /util/BookVehicleFunction.php file, potentially allowing unauthorized database access.

Vehicle Showroom Management System cve-2026-6149 sql-injection web-application
2r 1t 1c
low advisory

GCP Pub/Sub Subscription Deletion

Detection of a Google Cloud Platform Pub/Sub subscription deletion, which can be used by adversaries to disrupt communication, evade detection, or impair defenses.

Pub/Sub gcp pubsub defense_evasion cloud
2r 2t
medium advisory

Detect Suspicious Windows Service Installation

This detection identifies the creation of new Windows services with suspicious command values, often used for privilege escalation and persistence by malicious actors.

Windows persistence privilege_escalation service_creation
2r 1t
high advisory

OpenClaw Android App Vulnerable to Arbitrary Code Execution via WebView JavascriptInterface

The openclaw npm package before version 2026.3.22 is vulnerable to arbitrary code execution, where an attacker could inject instructions into the app by invoking the JavascriptInterface bridge from untrusted origins within Android Canvas WebView pages.

OpenClaw Android application android webview rce
2r 1t
low advisory

Azure Automation Runbook Deleted

Detection of Azure Automation runbook deletion, potentially indicating defense evasion or disruption of automated business processes by an adversary removing malicious or critical runbooks.

Azure Automation cloud azure defense-evasion impact
2r 2t
medium advisory

Azure VNet Full Network Packet Capture Enabled

Detection of Azure Network Watcher's Packet Capture feature being enabled, potentially indicating malicious network sniffing for credential access and discovery of sensitive data in unencrypted traffic.

Azure +1 network-sniffing credential-access
3r 2t
medium advisory

GCP Logging Bucket Deletion for Defense Evasion

Detection of a Google Cloud Platform (GCP) logging bucket deletion, which can be used by adversaries to impair defenses and evade detection by removing or modifying cloud logs.

Google Cloud Platform gcp cloud defense_evasion
2r 1t
high advisory

modelscope agentscope Server-Side Request Forgery Vulnerability (CVE-2026-6604)

A server-side request forgery vulnerability (CVE-2026-6604) exists in modelscope agentscope up to version 1.0.18, allowing remote attackers to manipulate the image_url or audio_file_url arguments to perform SSRF attacks via the Cloud Metadata Endpoint component.

agentscope ssrf cve-2026-6604 modelscope
3r 1t
high advisory

Rails Active Storage Vulnerability Allows Arbitrary File Deletion

A vulnerability in Rails Active Storage allows attackers to delete arbitrary files in the storage directory by exploiting glob metacharacters in blob keys passed to `Dir.glob`.

Active Storage rails active_storage file_deletion vulnerability
2r 1t
high advisory

SiYuan Unauthorized Attribute View Deletion Vulnerability (CVE-2026-40259)

SiYuan versions 3.6.3 and below are vulnerable to unauthorized attribute view deletion via the /api/av/removeUnusedAttributeView endpoint, allowing authenticated users with publish-service RoleReader tokens to delete arbitrary attribute view definitions, leading to database view breakage and workspace rendering issues.

SiYuan attribute-deletion vulnerability webserver
2r 1c
high advisory

suvarchal docker-mcp-server Remote OS Command Injection Vulnerability

A remote OS command injection vulnerability exists in suvarchal docker-mcp-server up to version 0.1.0 allowing for arbitrary command execution via the stop_container, remove_container, or pull_image functions within the src/index.ts file.

docker-mcp-server command-injection docker CVE-2026-5741
2r 1t 1c
medium advisory

Windows Sandbox Abuse with Sensitive Configuration

This rule detects the abuse of Windows Sandbox with sensitive configurations to evade detection, where malware may abuse the sandbox feature to gain write access to the host file system, enable network connections, and automatically execute commands via logon, identifying the start of a new container with these sensitive configurations.

Microsoft Defender XDR +4 defense-evasion windows-sandbox windows
3r 1t
critical advisory

WWBN AVideo Unauthenticated Remote Code Execution via CloneSite Plugin

Unauthenticated attackers can achieve remote code execution in WWBN AVideo versions up to 26.0 by chaining vulnerabilities in the CloneSite plugin related to exposed secrets, database dumps, and OS command injection.

AVideo rce command-injection credential-access
2r 2t
critical advisory

chatboxai chatbox Command Injection Vulnerability (CVE-2026-6130)

A command injection vulnerability (CVE-2026-6130) exists in chatboxai chatbox versions up to 1.20.0, allowing a remote attacker to execute arbitrary OS commands by manipulating the 'args/env' argument in the StdioClientTransport function, potentially leading to complete system compromise.

chatboxai chatbox command-injection vulnerability chatboxai CVE-2026-6130
2r 1t 1c
medium advisory

PhpSpreadsheet XML Reader Denial of Service via Unbounded Row Index

PhpSpreadsheet is vulnerable to a denial-of-service attack by crafting a SpreadsheetML XML file with an excessively large row index, which exhausts server CPU resources due to unbounded iteration.

PhpSpreadsheet denial-of-service xml
2r 1t
high advisory

PowerShell Kerberos Ticket Request via KerberosRequestorSecurityToken

This rule detects PowerShell scripts that request Kerberos service tickets using KerberosRequestorSecurityToken, potentially indicating Kerberoasting attacks for offline password cracking of service accounts.

Elastic Security kerberoasting credential_access windows
2r 1t
high advisory

Renamed Automation Script Interpreter Detection

This rule identifies renamed Automation Script Interpreter processes, often used by malware written in AutoIt/AutoHotKey to evade detection by renaming the executable.

AutoIt +2 defense-evasion execution masquerading windows
2r 2t
medium advisory

Azure Kubernetes Events Deleted

Adversaries may delete events in Azure Kubernetes to evade detection, which this rule detects via the MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/EVENTS.K8S.IO/EVENTS/DELETE operation.

Azure Kubernetes Service azure kubernetes defense-evasion
2r 1t
medium advisory

Unsigned DLL Loaded by Svchost for Persistence and Privilege Escalation

Adversaries may load unsigned DLLs into svchost.exe to establish persistence or escalate privileges, leveraging a shared Windows service to execute malicious code with elevated permissions.

Elastic Defend persistence defense-evasion execution windows dll-injection
2r 4t 5i
low advisory

Uncommon Destination Port Connection by Web Server on Linux

The rule identifies unusual outbound network connections on non-standard ports originating from web server processes on Linux systems, indicative of potential web shell activity or unauthorized communication.

Elastic Defend persistence execution command-and-control web shell linux
2r 4t
medium advisory

AWS EBS Encryption Disabled

Detects when Amazon Elastic Block Store (EBS) encryption by default is disabled in an AWS region, potentially leading to data exposure and weakening data protection against exfiltration or ransomware.

Elastic Block Store aws ebs encryption cloudtrail
2r 2t
high advisory

Scriban TemplateContext Reset Authorization Bypass Vulnerability

Scriban versions before 7.0.0 have an authorization bypass vulnerability due to a stale include cache surviving TemplateContext.Reset(), potentially serving previously authorized content to subsequent renders in applications reusing TemplateContext objects with request-dependent ITemplateLoaders.

Scriban template-injection authorization-bypass
2r 1t
medium advisory

Suspicious Process Execution via Renamed PsExec Executable

The rule identifies suspicious PsExec activity where the psexec service is executed from a renamed executable, possibly to evade detection and enable lateral movement.

PsExec +1 lateral-movement defense-evasion windows
2r 3t
high advisory

Web Shell Activity Detection via Process Monitoring

This brief focuses on detecting malicious activity related to web shells on Windows systems by identifying the execution of command interpreters and scripting engines as child processes of common web server processes, potentially indicating unauthorized command execution and persistent access.

Windows +3 webshell persistence initial-access execution
2r 4t