Skip to content
Threat Feed

January 2024 (30)

medium threat

Microsoft Exchange Server UM Spawning Suspicious Processes

This rule detects suspicious processes spawned by the Microsoft Exchange Server Unified Messaging (UM) service, potentially indicating exploitation of CVE-2021-26857 and leading to unauthorized process execution and system compromise.

exploited Exchange Server exchange initial-access lateral-movement cve-2021-26857 windows
2r 2t 1c
medium advisory

Signed Proxy Execution via MS Work Folders

Adversaries may misuse Windows Work Folders to execute a masqueraded 'control.exe' file from a non-standard location, bypassing application controls and potentially escalating privileges.

Windows Work Folders defense-evasion masquerading workfolders windows
2r 3t 1i
high advisory

Windows EventLog Autologger Session Disabled via Registry Modification

Adversaries may attempt to disable Windows EventLog autologger sessions via registry modification to evade detection and prevent security monitoring of early boot activities and system events.

Windows attack.defense-evasion attack.t1562.002
2r 1t
low advisory

Account Discovery Command via SYSTEM Account

The rule identifies when the SYSTEM account uses an account discovery utility, potentially indicating discovery activity after privilege escalation, focusing on utilities like whoami.exe and net1.exe executed under the SYSTEM account.

Elastic Defend +5 discovery privilege-escalation windows
3r 3t
medium advisory

Multiple Logon Failure Followed by Logon Success

This rule identifies potential password guessing/brute force activity from a single address, followed by a successful logon, indicating that an attacker may have compromised an account by brute-forcing login attempts across multiple users.

Windows Security Event Logs credential-access brute-force windows
2r 1t
high advisory

Potential Local NTLM Relay via HTTP

Adversaries may coerce local NTLM authentication over HTTP via WebDAV named-pipe paths (Print Spooler, SRVSVC), then relay credentials to elevate privileges.

Microsoft Defender XDR +1 ntlm-relay credential-access windows webdav
2r 1t
high advisory

Ransomware Attempting to Disable Windows Recovery via Bcdedit

This brief details the detection of ransomware actors using bcdedit.exe to modify boot settings, specifically disabling automatic repair mode to hinder system recovery.

Windows ransomware bootkit
2r 1t
high advisory

RegAsm Executed Without Command Line Arguments

The execution of regasm.exe without command-line arguments is often indicative of process injection and potential code execution, which could lead to privilege escalation, persistence, or data compromise.

RegAsm process-injection defense-evasion windows
2r 1t
medium advisory

rust-zserio Unbounded Memory Allocation Vulnerability

The rust-zserio package is vulnerable to unbounded memory allocation when deserializing arrays, strings, or bytes (blob) types, allowing an attacker to cause a denial-of-service by providing a crafted data file with a large size value.

rust-zserio denial-of-service memory-allocation
2r 1t
medium advisory

rustls-webpki Denial-of-Service Vulnerability via Malformed CRL BIT STRING

A denial-of-service vulnerability exists in rustls-webpki versions prior to 0.103.13 and between 0.104.0-alpha.1 and 0.104.0-alpha.7 due to a panic in `bit_string_flags()` when processing a malformed CRL BIT STRING, triggered when CRL checking is enabled and an attacker provides a crafted CRL.

rustls-webpki denial-of-service crl
2r 1t
medium advisory

SUSE Harvester Rancher Integration Vulnerable to MITM and DOS

SUSE Harvester's Rancher integration mechanism is vulnerable to a man-in-the-middle attack due to insecure TLS options, potentially leading to denial of service.

Harvester mitm denial-of-service virtualization
3r 2t
high advisory

Suspicious Access to Chrome Local State File

This analytic detects non-Chrome processes accessing the Chrome Local State file, which can lead to the extraction of the master key used for decrypting saved Chrome passwords.

Chrome credential-access malware redline-stealer windows
2r 1t
high advisory

Suspicious Kernel Module Load from Unusual Location (Linux)

This alert detects the loading of Linux kernel modules from non-standard directories, potentially indicating malicious persistence or rootkit activity.

Kernel kernel-module persistence rootkit linux
2r
high advisory

Suspicious LSASS Access via Malicious Secondary Logon Service

An attacker abuses the Secondary Logon service (seclogon.dll) to gain unauthorized access to the LSASS process, potentially leaking credentials.

Windows credential-access lsass seclogon
3r 1t
high advisory

Suspicious PowerShell Arguments Detected

Detection of suspicious arguments used with PowerShell, potentially indicating malicious activity execution.

PowerShell +1 execution suspicious-arguments windows
2r 1t
critical advisory

Suspicious Raw Disk Access Detected

Detection of processes accessing raw disk volumes outside of normal system paths, often associated with wiper malware and boot sector attacks.

Windows raw-disk-access wiper boot-sector
2r 1t
medium advisory

Suspicious WMI Image Load from MS Office

Adversaries may exploit Windows Management Instrumentation (WMI) to execute code stealthily, bypassing traditional security measures by loading `wmiutils.dll` from Microsoft Office applications, potentially indicating malicious execution.

WINWORD.EXE +4 wmi image load office execution
2r 1t
high advisory

thin-vec Double Free / Use-After-Free Vulnerability

A double free/use-after-free vulnerability exists in the `thin_vec` crate before version 0.2.16, specifically in the `IntoIter::drop` and `ThinVec::clear` implementations, which can be triggered via a panic during element deallocation, leading to memory corruption and potential arbitrary code execution.

thin-vec use-after-free double-free memory-corruption rust
2r
high threat

TinyCC Masquerading as Svchost for Shellcode Execution

Attackers rename TinyCC (tcc.exe) to svchost.exe and use it to compile and execute C source files containing shellcode, using the `-nostdlib` and `-run` flags, as observed in the Lotus Blossom Chrysalis backdoor campaign, indicating potential evasion and malicious code execution.

Tiny C Compiler Lotus Blossom tinycc shellcode svchost lotus-blossom chrysalis t1059.003 t1027
2r 2t
high advisory

Tutor LMS WordPress Plugin Insecure Direct Object Reference (CVE-2026-3360)

The Tutor LMS plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR), allowing unauthenticated attackers to overwrite billing profiles of users with incomplete orders.

Tutor LMS wordpress plugin idor cve-2026-3360 tutor-lms
2r 2t 1c
critical advisory

Unauthenticated Remote Takeover of Nginx-UI via MCP Endpoint

Nginx-UI is vulnerable to unauthenticated remote takeover due to a missing authentication check on the `/mcp_message` endpoint, allowing attackers to invoke MCP tools without authentication, leading to arbitrary nginx configuration modification, traffic interception, service disruption, configuration exfiltration, and credential harvesting; the default empty IP whitelist allows access from any network attacker.

Nginx-UI nginx unauthenticated remote-takeover CVE-2026-33032
2r 5t 1i
high advisory

Untrusted Driver Loaded by Windows Kernel

An untrusted driver loaded by the Windows kernel may indicate an attempt to bypass code signing policies and execute unsigned or self-signed kernel code, potentially leading to defense evasion.

Windows Kernel +1 defense-evasion driver-load kernel
3r 1t 4i
medium advisory

Unusual Persistence via Services Registry Modification

Adversaries may modify the Windows services registry keys directly to stealthily persist through abnormal service creation or modification of an existing service, bypassing standard APIs, detected by monitoring registry changes related to service DLLs and image paths.

Windows persistence registry services
2r 3t
low advisory

Wallpaper Modification Detection

Detection of unauthorized or suspicious wallpaper modifications on endpoints can indicate malicious activity or policy violations.

Windows endpoint wallpaper modification registry policy violation
3r 1t
low advisory

Web Server Discovery or Fuzzing Activity Detection

This rule detects potential web server discovery or fuzzing activity by identifying a high volume of HTTP GET requests resulting in 404 or 403 status codes from a single source IP address within a short timeframe, indicating attackers discovering hidden resources for targeted attacks.

Nginx +4 web-server fuzzing reconnaissance web
2r 2t
low advisory

Web Server Remote File Inclusion Activity Detected

This rule detects potential Remote File Inclusion (RFI) activity on web servers by identifying HTTP GET requests that attempt to access sensitive remote files through directory traversal techniques or known file paths to read sensitive files, gain system information, or further compromise the server.

Nginx +4 remote-file-inclusion web-server discovery
2r 1t
high advisory

Windows Defender Real-Time Behavior Monitoring Disabled via Registry Modification

Attackers modify Windows Registry keys to disable Windows Defender real-time behavior monitoring, a tactic used by malware to evade detection and persist on compromised systems.

Windows Defender windows defense-evasion registry endpoint
2r 1t
high advisory

Windows Suspicious Process Execution from Unusual File Paths

Adversaries may execute malicious processes from unusual file paths (e.g., within Windows, Users, or Recycle Bin directories) to evade defenses and potentially compromise systems.

Windows suspicious-process defense-evasion persistence
3r 2t
high advisory

WMI Permanent Event Subscription Abuse for Persistence

Attackers use WMI permanent event subscriptions to execute malicious scripts or binaries for persistence by creating event consumers other than the default NTEventLogEventConsumer.

Windows persistence wmi
2r 1t
high advisory

WordPress Drag and Drop Multiple File Upload Plugin Path Traversal Vulnerability

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin is vulnerable to path traversal, allowing unauthenticated attackers to read arbitrary files within the 'wp-content' directory readable by the web server process.

Drag and Drop Multiple File Upload for Contact Form 7 wordpress path-traversal arbitrary-file-read plugin-vulnerability
2r 1t 1c