Skip to content
Threat Feed

January 2024 (30)

high advisory

Google Chrome Use-After-Free Vulnerability in Video Component (CVE-2026-6359)

CVE-2026-6359 is a use-after-free vulnerability in the Video component of Google Chrome on Windows prior to version 147.0.7727.101, allowing a remote attacker who has compromised the renderer process to achieve out-of-bounds memory access via a crafted HTML page.

Google Chrome cve-2026-6359 chrome use-after-free windows
2r 2t 1c 1i
low advisory

Google Workspace Suspended User Account Renewed

Detection of a renewed, previously suspended user account in Google Workspace, potentially indicating unauthorized access or persistence by an adversary.

Google Workspace google_workspace initial_access persistence
2r 3t
high advisory

goshs SimpleHTTPServer SFTP Rename Path Traversal Vulnerability (CVE-2026-40188)

The goshs SimpleHTTPServer, from version 1.0.7 to before 2.0.0-beta.4, is vulnerable to path traversal (CVE-2026-40188) due to insufficient sanitization of the destination path in the SFTP rename command, potentially allowing attackers with low privileges to write files outside the intended root directory.

goshs path-traversal sftp cve-2026-40188
2r 1t 1c
medium advisory

Gotenberg Denial of Service via Context Pool Reuse

Gotenberg versions 8.31.0 and earlier are vulnerable to an unauthenticated denial-of-service attack where a race condition in the webhook middleware causes a panic and process termination when handling concurrent requests.

Gotenberg denial-of-service vulnerability
2r 2t
medium advisory

GPO Modification to Add Startup/Logon Scripts

This rule detects the modification of Group Policy Objects (GPO) to add a startup or logon script to user or computer objects, enabling attackers to achieve privilege escalation and persistence by executing arbitrary commands at scale.

Active Directory +1 group-policy privilege-escalation persistence windows
2r 3t
medium advisory

GPO Scheduled Task Abuse for Privilege Escalation and Lateral Movement

Attackers abuse Group Policy Objects by modifying scheduled task attributes to execute malicious commands across objects controlled by the GPO, potentially leading to privilege escalation and lateral movement.

Active Directory +1 group-policy scheduled-task privilege-escalation lateral-movement
2r 3t
medium advisory

GPO Scheduled Task or Service Creation/Modification

Detection of the creation or modification of new Group Policy based scheduled tasks or services, which can be abused by attackers with domain admin permissions to execute malicious payloads remotely on domain-joined machines, leading to privilege escalation and persistence.

Elastic Defend +2 group-policy privilege-escalation persistence windows
2r 3t
critical advisory

Grav Login Plugin Privilege Escalation Vulnerability

Unauthenticated users can escalate privileges to admin in Grav CMS by manipulating registration data due to missing server-side validation in the Login plugin.

Login Plugin +2 grav privilege-escalation web
2r 1t 1i
medium advisory

Gravity Forms Plugin Unauthenticated Stored XSS Vulnerability

The Gravity Forms plugin for WordPress is vulnerable to unauthenticated stored cross-site scripting (XSS) in versions up to 2.10.0, allowing attackers to inject arbitrary JavaScript code into the product name field within repeater fields, which executes when an administrator views the affected entry.

Gravity Forms plugin <= 2.10.0 xss wordpress gravityforms
2r 1t 1c
low advisory

Group Policy Discovery via GPResult Utility

This rule detects the execution of gpresult.exe with specific arguments to query group policy objects, potentially indicating reconnaissance activity by attackers aiming to understand the Active Directory environment for privilege escalation or lateral movement.

Windows +1 discovery gpresult active-directory
2r 1t
medium advisory

GSuite Email with Known Abuse Web Service Links

This analytic detects emails in Gsuite containing links to known abuse web services such as Pastebin, Telegram, and Discord, commonly used by attackers to deliver malicious payloads leading to malware, phishing, or other harmful activities.

GSuite +1 phishing malware pastebin telegram discord
2r 1t 2i
medium advisory

GSuite Email with Suspicious Attachment

This analytic detects GSuite emails with suspicious file attachments (e.g., .exe, .bat, .js) which may indicate a spear-phishing attack leading to malware deployment and potential system compromise.

GSuite +1 spear-phishing malicious-attachment
2r 1t
medium advisory

GSuite Suspicious File Share with Phishing Filenames

This analytic detects suspicious file sharing activity in Google Workspace where files are shared with names commonly associated with phishing campaigns, such as 'invoice,' 'shipment,' or 'delivery', potentially leading to credential theft or malware infection.

Google Workspace +1 phishing gsuite google_workspace
2r 1t
high advisory

HAPI FHIR Credential Leakage via Improper URL Prefix Matching

HAPI FHIR Core is vulnerable to authentication credential leakage due to improper URL prefix matching on HTTP redirects, allowing attackers to intercept credentials by hosting a domain that is a prefix of a configured FHIR server URL.

HAPI FHIR Core hapi-fhir credential-leakage redirect CVE-2026-34359
2r 1t 2i
high advisory

Heap/Stack Overflow in rust-openssl with OpenSSL 1.1.x

The rust-openssl crate's `Deriver::derive` and `PkeyCtxRef::derive` functions can cause heap/stack overflows when used with OpenSSL 1.1.x due to insufficient buffer length validation in X25519, X448, DH, and HKDF-extract, affecting rust-openssl versions >= 0.9.27 and < 0.10.78.

openssl buffer-overflow rust cryptography
2r
high advisory

Heimdall Authorization Bypass via Case-Sensitive URL-Encoded Slash Handling

Heimdall versions before 0.17.14 are vulnerable to inconsistent path interpretation due to case-sensitive handling of URL-encoded slashes; when `allow_encoded_slashes` is set to `off` (the default), the lowercase `%2f` is not recognized, potentially leading to authorization bypass if the default rule is overly permissive and the upstream service interprets `%2f` as a path separator.

Heimdall authorization-bypass url-encoding
2r 1t
medium advisory

Hickory DNS NSEC3 Validation Vulnerability Leads to DoS

A vulnerability in Hickory DNS's NSEC3 closest-encloser proof validation allows a remote attacker to cause a denial of service by exhausting memory when processing crafted DNS responses with mismatched SOA records.

hickory-proto +1 denial-of-service dnssec memory-exhaustion
2r 1t
high advisory

Hidden Local Account Creation via Registry Modification

Attackers may create hidden local accounts, appending a dollar sign ($) to the username, to maintain persistence and evade detection by standard enumeration tools by modifying specific registry keys.

Windows persistence defense-evasion
2r 2t
high advisory

Hiding User Account from Sign-In Screen via Registry Modification

An attacker modifies the Windows registry to hide a user account from the login screen, potentially establishing a hidden admin account for persistence and evading detection.

Splunk Enterprise +2 persistence defense-evasion windows
2r
high advisory

High Number of Failed Office 365 Logins from Single Source

The analytic detects multiple failed login attempts in Office365 Azure Active Directory from a single source IP address, potentially indicating brute-force or password spraying attacks.

Office 365 +1 cloud office365 credential-access password-spraying
1r 1t
medium advisory

Host File System Changes via Windows Subsystem for Linux

This rule detects file creation and modification on the host system from the Windows Subsystem for Linux (WSL), potentially indicating defense evasion by adversaries.

Elastic Defend +2 defense-evasion windows wsl
2r 2t
high advisory

HPE Aruba Networking Private 5G Core On-Prem Open Redirect Vulnerability (CVE-2026-23818)

CVE-2026-23818 is an open redirect vulnerability in the HPE Aruba Networking Private 5G Core On-Prem GUI that enables attackers to redirect authenticated users to attacker-controlled login pages to steal credentials.

HPE Aruba Networking Private 5G Core On-Prem aruba open-redirect credential-theft cve-2026-23818 network
2r 1t 1c
high advisory

HTML Help Executable Spawning Child Processes

The execution of hh.exe (HTML Help) spawning a child process indicates the use of a Compiled HTML Help (CHM) file to execute potentially malicious Windows script code.

Microsoft Windows html-help chm lolbas process-creation
2r 1t
medium advisory

i18next-http-middleware HTTP Response Splitting and DoS Vulnerability

i18next-http-middleware versions before 3.9.3 are vulnerable to HTTP response splitting and denial-of-service attacks due to unsanitized Content-Language headers, potentially leading to session fixation, cache poisoning, reflected XSS, or complete service disruption depending on the Node.js version.

i18next-http-middleware crlf-injection http-response-splitting denial-of-service i18next
2r 1t
critical advisory

idachev mcp-javadc OS Command Injection via HTTP Interface (CVE-2026-5802)

A remote command injection vulnerability (CVE-2026-5802) exists in idachev mcp-javadc up to version 1.2.4 via the HTTP Interface by manipulating the jarFilePath argument, allowing unauthenticated attackers to execute arbitrary OS commands.

mcp-javadc command-injection web-application cve-2026-5802
2r 1t 1c
medium advisory

Incoming Execution via WinRM Remote Shell

This rule detects incoming execution via Windows Remote Management (WinRM) remote shell on a target host, which could be an indication of lateral movement by monitoring network traffic on ports 5985 or 5986 and processes initiated by WinRM.

Elastic Defend +1 lateral-movement windows winrm remote-execution
2r 1t
low advisory

Ingress Transfer via Windows BITS

Adversaries may leverage Windows Background Intelligent Transfer Service (BITS) to download executable and archive files to evade defenses and establish command and control.

Background Intelligent Transfer Service +2 bits ingress-transfer command-and-control defense-evasion windows
2r 2t
high advisory

Invoke-Obfuscation Obfuscated IEX Invocation via PowerShell

Attackers use Invoke-Obfuscation, a PowerShell obfuscation framework, to generate obfuscated IEX (Invoke-Expression) commands, evading detection and executing malicious code.

Windows defense-evasion execution powershell obfuscation
2r 2t
medium advisory

IOBit Unlocker Extension DLL Registration via Regsvr32

The IOBit Unlocker Extension DLL is being registered via regsvr32.exe, a Windows utility used to unlock files or folders by terminating locking processes, which could be abused for malicious purposes.

Unlocker Extension +3 iobit unlocker regsvr32 dll windows threat-detection
2r 1t
high advisory

JoeCastrom mcp-chat-studio Server-Side Request Forgery Vulnerability

A server-side request forgery vulnerability exists in JoeCastrom mcp-chat-studio up to version 1.5.0 in the LLM Models API component, allowing remote attackers to manipulate the req.query.base_url argument and potentially conduct further attacks.

mcp-chat-studio cve-2026-7147 ssrf
2r 1t 1c