Skip to content
Threat Feed

January 2024 (30)

critical advisory

SAIL Library TGA RLE Decoder Heap Overflow Vulnerability

The SAIL library versions before commit 45d48d1f2e8e0d73e80bc1fd5310cb57f4547302 are vulnerable to a heap overflow in the TGA codec's RLE decoder, where the raw-packet path lacks bounds checking, potentially leading to privilege escalation via crafted image files.

SAIL library CVE-2026-40494 sail tga heap-overflow privilege-escalation
2r 1t 1c
critical threat

SAP NetWeaver Visual Composer CVE-2025-31324 Exploitation Attempt

Exploitation attempts targeting CVE-2025-31324, a critical unauthenticated file upload vulnerability in SAP NetWeaver Visual Composer, have been detected using HTTP HEAD and POST requests to sensitive endpoints.

NetWeaver +1 sap-netweaver file-upload webshell cve-2025-31324
2r 1t
medium advisory

Scheduled Task Creation via Group Policy Object

Detects the creation of scheduled tasks within a Group Policy Object (GPO) by monitoring for the creation of the ScheduledTasks.xml file in the SYSVOL share, potentially indicating malicious persistence.

Splunk Enterprise +3 scheduled-task gpo persistence windows
2r 2t
medium advisory

Scheduled Task Creation via Scripting

Detection of scheduled task creation by Windows scripting engines like cscript.exe, wscript.exe, or powershell.exe, used by adversaries to establish persistence on compromised systems.

Elastic Defend +1 persistence scheduled-task windows
3r 3t
high threat

Scheduled Task Disablement via Schtasks.exe

Detection of the use of schtasks.exe to disable scheduled tasks, a common tactic used by adversaries like IcedID to disable security applications and evade detection, potentially leading to persistence and further system compromise.

Splunk Enterprise +2 IcedID persistence defense_evasion windows
2r
medium advisory

Schtasks Run Task On Demand

Detection of on-demand execution of Windows Scheduled Tasks via the schtasks.exe command-line utility, a common technique for persistence and lateral movement.

Splunk Enterprise +2 schtasks scheduled-task persistence execution
2r 1t
critical advisory

Scramble Remote Code Execution via User-Controlled Input

Scramble versions 0.13.2 through 0.13.21 are vulnerable to remote code execution due to the evaluation of user-controlled input in validation rules during documentation generation, potentially allowing attackers to execute arbitrary PHP code.

scramble rce vulnerability php
3r 1t
medium advisory

SeDebugPrivilege Enabled by a Suspicious Process

The rule identifies a process running with a non-SYSTEM account that enables the SeDebugPrivilege privilege, which can be used by adversaries to debug and modify other processes to escalate privileges and bypass access controls.

Windows privilege-escalation token-manipulation
2r 1t
high advisory

Server-Side Request Forgery in mcp-data-vis

A server-side request forgery (SSRF) vulnerability exists in AlejandroArciniegas' mcp-data-vis due to improper handling of HTTP requests, potentially allowing remote attackers to make arbitrary requests through the vulnerable server.

mcp-data-vis ssrf vulnerability
2r 1t 1c
medium advisory

Service Startup Type Modification via WMIC

Adversaries use the Windows Management Instrumentation Command-line (WMIC) utility to modify the startup type of services, setting them to 'Manual' or 'Disabled' to impair defenses or disrupt system operations.

Windows attack.execution attack.t1047 attack.defense-evasion attack.t1562.001
2r 2t
high advisory

Shadow Copy Deletion via VSSAdmin or WMIC

Attackers delete shadow copies using vssadmin.exe or wmic.exe to prevent data recovery, often preceding ransomware deployment or data exfiltration.

Windows shadow-copy anti-forensic ransomware
2r 1t
medium advisory

SharePoint Sensitive Term Discovery via O365 Logs

Adversaries may search for sensitive terms within SharePoint to identify valuable data for exfiltration or further compromise, leaving traces in O365 audit logs.

SharePoint +1 discovery sensitive-data o365
2r 1t
critical advisory

Shipping System CMS 1.0 Authentication Bypass via SQL Injection

Shipping System CMS 1.0 is vulnerable to SQL injection, allowing unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter.

Shipping System CMS sql-injection authentication-bypass web-application
2r 1t
high advisory

Signal K Server WebSocket Login Brute-Force Vulnerability

The Signal K server's WebSocket login endpoint lacks rate limiting, allowing attackers to bypass HTTP rate limiting by opening a WebSocket connection and attempting unlimited password guesses.

signalk-server credential-access brute-force websocket
1r 1t
medium advisory

Signed Proxy Execution via MS Work Folders

Attackers can abuse Windows Work Folders to execute a masqueraded control.exe file from untrusted locations, potentially bypassing application controls for defense evasion and privilege escalation.

Windows Work Folders +3 defense-evasion masquerading windows
2r 3t
high advisory

Simple IT Discussion Forum 1.0 SQL Injection Vulnerability (CVE-2026-5672)

A remote SQL injection vulnerability exists in code-projects Simple IT Discussion Forum 1.0 via manipulation of the cat_id parameter in the /edit-category.php file.

Simple IT Discussion Forum sql-injection web-application vulnerability
2r 1t 1c
medium advisory

SolarWinds Process Disabling Services via Registry Modification

A SolarWinds binary is modifying the start type of a service to be disabled via registry modification, potentially to disable or impair security services.

Microsoft Defender XDR +1 solarwinds defense-evasion registry-modification supply-chain
2r 3t
high advisory

SourceCodester Food Ordering System SQL Injection Vulnerability (CVE-2026-4839)

CVE-2026-4839 is a SQL injection vulnerability in the SourceCodester Food Ordering System 1.0, affecting the /purchase.php file and allowing remote attackers to manipulate the 'custom' argument to inject malicious SQL code.

Food Ordering System sql-injection web-application cve-2026-4839
2r 1t
high advisory

SourceCodester Patients Waiting Area Queue Management System Improper Authorization Vulnerability

A remote, unauthenticated attacker can bypass authorization in SourceCodester Patients Waiting Area Queue Management System 1.0 by manipulating the ValidateToken function in the Patient Check-In Module.

SourceCodester Patients Waiting Area Queue Management System improper-authorization web-application php
2r 1t 6i
medium advisory

Spike in AWS Security Hub Alerts for EC2 Instance

Detects a sudden increase in security alerts generated by AWS Security Hub related to a specific EC2 instance, potentially indicating active compromise or misconfiguration.

EC2 cloud aws securityhub alert-spike
2r 6t
critical advisory

Splunk OpenTelemetry Java Agent RMI Deserialization Vulnerability

A remote code execution vulnerability exists in splunk-otel-javaagent versions prior to 2.26.1 due to unsafe deserialization in RMI instrumentation, potentially allowing attackers with network access to execute arbitrary code on affected systems.

Splunk OpenTelemetry Java Agent rmi deserialization rce javaagent
2r 1t
low advisory

Startup or Run Key Registry Modification

Attackers modify registry run keys or startup keys to achieve persistence by referencing a program that executes when a user logs in or the system boots.

Elastic Defend +6 persistence registry runkey
3r 2t
medium advisory

Successful AWS IAM Group Deletion Detection

Successful deletion of an AWS IAM group, while not inherently malicious, can indicate insider threat activity, account compromise, or attempts to remove audit trails, and should be monitored.

IAM aws cloud deletion
2r 1t
high threat

SUNBURST Command and Control Activity Detected

This rule detects post-exploitation command and control activity related to the SUNBURST backdoor, which targets SolarWind's Orion software, mimicking the Orion Improvement Program (OIP) protocol for covert communication.

SolarWinds Orion Platform APT29 +5 solarwinds sunburst supply-chain command-and-control
2r 2t
high advisory

Suspicious Access to Chrome Extension Directories

Non-Chrome processes accessing Chrome extension directories can indicate credential theft or data exfiltration attempts by malware such as RedLine Stealer.

Chrome credential-theft malware windows
2r 1t
medium advisory

Suspicious Access to Windows Product Key Registry

Detection of processes attempting to access the Windows registry to recover product keys, potentially indicating malware activity, unauthorized security bypass, or data exfiltration.

Windows registry product-key malware
2r 1t
high advisory

Suspicious Alternate Data Stream (ADS) File Creation

The rule identifies the suspicious creation of Alternate Data Streams (ADS) on targeted files using a script or command interpreter, a technique used by adversaries to hide malicious files and evade detection.

Windows +2 defense-evasion alternate-data-stream
2r 1t
high advisory

Suspicious AppLocker XML Policy Import via PowerShell

Detection of PowerShell commands used to import AppLocker XML policies, potentially indicating an attempt to bypass security controls, as observed with Azorult malware.

Splunk Enterprise +2 applocker defense-evasion powershell
2r
medium advisory

Suspicious AWS EC2 Key Pair Creation from Non-Cloud AS

An AWS EC2 CreateKeyPair event triggered by a new principal originating from a network autonomous system (AS) organization not associated with major cloud providers, indicating potential unauthorized access or persistence activity.

Amazon EC2 aws ec2 keypair persistence credential_access lateral_movement
2r 3t
medium advisory

Suspicious AWS STS GetSessionToken Usage

The AWS STS GetSessionToken API is being misused to create temporary tokens for lateral movement and privilege escalation within AWS environments by potentially compromised IAM users.

AWS CloudTrail aws cloud lateral-movement privilege-escalation sts GetSessionToken
2r 2t