Skip to content
Threat Feed

January 2024 (30)

medium advisory

Kubernetes Potential Endpoint Permission Enumeration by Anonymous User

An anonymous user attempts to enumerate Kubernetes API endpoints, resulting in a series of failed API requests across multiple endpoints, potentially revealing the cluster's exposed surface.

Kubernetes discovery enumeration cloud
2r 1t
medium advisory

Kubernetes Service Account Token Access Followed by API Request

Detection of interactive access to a Kubernetes service account token or certificate followed by a Kubernetes API request, potentially indicating credential theft and lateral movement within the cluster.

Kubernetes credential-access lateral-movement container
2r 5t
medium advisory

Linux Log Clearing Attempts via Common Utilities

Adversaries attempt to clear Linux system logs using utilities like rm, rmdir, shred, and unlink to conceal malicious activity and evade detection.

defense-evasion log-clearing linux
3r 1t
high advisory

liyupi yu-picture SQL Injection Vulnerability (CVE-2026-7060)

A SQL injection vulnerability (CVE-2026-7060) exists in liyupi yu-picture versions up to a053632c41340152bf75b66b3c543d129123d8ec, allowing a remote attacker to execute arbitrary SQL commands by manipulating the sortField argument in the PageRequest function of PictureServiceImpl.java.

yu-picture sql-injection cve-2026-7060 web-application
2r 1t 1c
critical advisory

llama.cpp Integer Overflow Vulnerability Leading to Potential RCE

A heap-based buffer overflow vulnerability exists in llama.cpp due to an integer overflow in the `ggml_nbytes` function, allowing attackers to potentially achieve Remote Code Execution (RCE) by crafting malicious GGUF files.

llama.cpp integer_overflow rce heap_overflow
2r 1t
high advisory

LSASS Protection Policy Disabled via Registry Modification

Attackers may disable Protected Process Light (PPL) protection for the LSASS process by modifying specific registry keys, allowing for credential dumping and other malicious activities.

Windows credential-access defense-evasion lsass ppl registry
2r 2t
critical advisory

Lupa Sandbox Escape via Incomplete attribute_filter Enforcement

The lupa library's attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr, leading to a sandbox escape and arbitrary code execution.

lupa sandbox-escape rce python
2r 3t
critical advisory

MagicMirror² Unauthenticated SSRF Vulnerability

An unauthenticated Server-Side Request Forgery (SSRF) vulnerability in MagicMirror² allows remote attackers to force the server to perform arbitrary HTTP requests, exfiltrate environment variables, and potentially compromise cloud instances or internal networks.

magicmirror ssrf cve-2026-42281
2r 2t
medium advisory

MSBuild Making Network Connections Indicating Potential Defense Evasion

MsBuild.exe making outbound network connections may indicate adversarial activity as attackers leverage MsBuild to execute code and evade detection.

MSBuild defense-evasion command-and-control
2r 2t
high advisory

NATS Server Panic via Malicious Compression on Leafnode Port

A vulnerability exists in NATS servers configured to accept leafnode connections where a malicious remote NATS server can trigger a server panic by exploiting compression negotiation on the leafnode port.

NATS server nats denial-of-service compression
2r 2t 1i
critical advisory

Network-AI Unauthenticated Access to MCP HTTP Endpoint

Network-AI is vulnerable to missing authentication on the MCP HTTP endpoint, allowing unauthenticated privileged tool calls that could lead to configuration changes and agent manipulation.

Network-AI cwe-306 authentication-bypass
2r 1t 2i
high advisory

Note Mark Stored XSS via Unrestricted Asset Upload

A stored same-origin XSS vulnerability in Note Mark allows an authenticated user to upload malicious HTML, SVG, or XHTML files as note assets, leading to arbitrary code execution in a victim's browser due to missing content type restrictions and resulting in potential access to private notes, books, and authenticated API actions.

Note Mark xss web-application github
2r 2t
high advisory

OAuth2 Proxy Authentication Bypass Vulnerability (CVE-2026-41059)

OAuth2 Proxy versions 7.5.0 through 7.15.1 are vulnerable to an authentication bypass (CVE-2026-41059) due to improper handling of URL fragments in conjunction with `skip_auth_routes` or `skip_auth_regex`, potentially allowing unauthenticated access to protected resources.

OAuth2 Proxy oauth2proxy authentication-bypass cve
2r 2t 1c
low advisory

Okta Group Lifecycle Change Spike Indicating Privilege Escalation

A machine learning job has identified an unusual spike in Okta group lifecycle change events, indicating potential privilege escalation activity, where adversaries may be altering group structures to escalate privileges, maintain persistence, or facilitate lateral movement within an organization’s identity management system.

Okta privileged-access group-lifecycle
2r 4t
high advisory

Okta User Logins from Multiple Cities Within 24 Hours

This analytic identifies instances where the same Okta user logs in from different cities within a 24-hour period, potentially indicating a compromised account and leading to account takeovers and data breaches.

Okta account-takeover identity
2r 2t
medium advisory

Ollama Abnormal Network Connectivity Detected

This detection identifies unusual network patterns and connection problems within Ollama, encompassing unauthorized API access attempts beyond localhost and warning-level network errors like DNS lookup failures, TCP connection issues, or host resolution problems, which can signal network-based attacks, unauthorized access, or infrastructure reconnaissance.

Ollama network-connectivity anomaly
2r 1t
high advisory

OpenClaw MCP Loopback Token Spoofing Vulnerability

A vulnerability in OpenClaw versions 2026.4.21 and earlier allows a non-owner loopback client to spoof the owner context by manipulating request headers, potentially gaining unauthorized access to owner-gated operations.

openclaw vulnerability npm token spoofing
2r 1t
critical advisory

OpenMage LTS Weak API Session ID Vulnerability Leads to Session Hijacking

OpenMage LTS version 20.16.0 and earlier has a critical vulnerability in the XML-RPC/SOAP API session ID generation, which uses a predictable MD5 hash of time-derived inputs, allowing attackers to brute-force and hijack active API sessions for data exfiltration, order fraud, and supply chain manipulation.

magento-lts session hijacking API vulnerability brute-force attack
2r 1t 1i
critical advisory

OpenRemote IoT Platform Expression Injection Vulnerability

The OpenRemote IoT platform is vulnerable to expression injection, allowing remote code execution due to an unsandboxed Nashorn JavaScript engine and an inactive Groovy sandbox, leading to full server compromise.

OpenRemote IoT Platform openremote expression-injection remote-code-execution iot
2r 1t
critical advisory

OpenTelemetry RMI Instrumentation Unsafe Deserialization RCE

A remote code execution vulnerability exists in OpenTelemetry Java agent versions prior to 2.26.1 due to unsafe deserialization in the RMI instrumentation, potentially allowing attackers with network access to execute arbitrary code on vulnerable systems.

OpenTelemetry Java agent rce opentelemetry deserialization
2r 1t
high advisory

Oxia Bearer Token Exposure in Debug Logs

Oxia exposes the full bearer token, including JWT header, payload, and signature, in debug log messages when OIDC authentication fails, allowing attackers with log access to replay the tokens.

Oxia jwt token leakage credential access
2r 1t
high advisory

Oxia Server Crash via Session Heartbeat Race Condition

A race condition in Oxia's session heartbeat handling allows a remote client to trigger a denial-of-service by sending rapid KeepAlive requests during session expiration or closure, leading to a server crash.

Oxia denial-of-service race-condition
2r 1t
medium advisory

Pachno 1.0.6 Stored Cross-Site Scripting Vulnerability

Pachno 1.0.6 is vulnerable to stored cross-site scripting (XSS), allowing attackers to inject malicious HTML or scripts into POST parameters, which are then stored and executed in user browser sessions due to improper sanitization.

Pachno xss web-application
2r 1t 1c
critical advisory

Paperclip Unauthenticated Remote Code Execution via Import Authorization Bypass

An unauthenticated attacker can achieve remote code execution on Paperclip instances by exploiting multiple vulnerabilities, including open signup, self-approval of CLI authentication challenges, and missing authorization checks in the company import endpoint, leading to arbitrary command execution as the server's OS user.

Paperclip +2 rce authentication-bypass code-execution
2r 4t 1i
medium advisory

Persistence via Scheduled Job Creation

This detection rule identifies attempts to establish persistence on Windows systems by creating scheduled jobs in the Windows Tasks directory, excluding known legitimate jobs.

Microsoft Defender XDR +5 persistence windows
2r 1t
critical advisory

phpMyFAQ Unauthenticated SQL Injection via User-Agent Header

Unauthenticated SQL injection vulnerability exists in phpMyFAQ <= 4.1.1 due to improper handling of the User-Agent header in BuiltinCaptcha, allowing attackers to inject malicious SQL payloads and potentially gain complete control of the datastore.

phpMyFAQ sql-injection unauthenticated web-application
2r 1t
medium advisory

Potential Application Shimming via Sdbinst

This brief covers the abuse of application shimming in Windows via `sdbinst.exe` to achieve persistence and privilege escalation by executing arbitrary code within legitimate processes.

Windows persistence privilege-escalation application-shimming
3r 2t
high advisory

Potential Credential Discovery via Recursive Grep

Adversaries may use recursive grep commands on Linux or macOS to discover credentials, secrets, keys, or tokens within files, indicating potential credential access and data exfiltration attempts.

macOS +1 credential-access discovery linux
2r 2t
medium advisory

Potential Reverse Shell via Java on Linux

The execution of a Linux shell process from a Java JAR application following an incoming network connection may indicate reverse shell activity.

Elastic Defend reverse-shell java linux execution
2r 2t
critical advisory

PraisonAI Browser Server Unauthenticated Session Hijacking Vulnerability

PraisonAI Browser Server is vulnerable to unauthenticated WebSocket client hijacking due to exposing the browser bridge on 0.0.0.0 by default and accepting WebSocket clients that omit the Origin header, allowing unauthorized remote use of a connected browser automation session.

PraisonAI Browser Server praisonai websocket session-hijacking vulnerability
2r 1t