January 2024 (30)
Cline Kanban Server Cross-Origin WebSocket Hijacking Vulnerability
3 rules 4 TTPs 1 IOCThe `kanban` npm package, used by the `cline` CLI, has a cross-origin WebSocket hijacking vulnerability. Due to the lack of Origin header validation, any website can connect to the kanban server via WebSocket and leak sensitive data, hijack running AI agent terminals leading to remote code execution, or kill running agent tasks, resulting in information disclosure, RCE, and denial of service.
Cloud Compute Instance Created With Previously Unseen Image
2 rules 2 TTPsThis analytic detects the creation of cloud compute instances using previously unseen image IDs, potentially indicating unauthorized or suspicious activity like malicious payload deployment or unauthorized access, leading to data breaches or further cloud environment compromise.
Cloud Provisioning Activity From Previously Unseen City
2 rules 1 TTPThe analytic detects cloud provisioning activities originating from previously unseen cities based on source IP geolocation compared to a learned baseline, which may indicate unauthorized access or misuse of cloud resources leading to resource creation, data exfiltration, or further compromise.
Cloud Provisioning Activity From Previously Unseen IP Address
2 rules 1 TTPThis analytic detects cloud provisioning activities originating from previously unseen IP addresses by leveraging cloud infrastructure logs to identify events where resources are created or started, and cross-references these with a baseline of known IP addresses.
Cloud Provisioning Activity From Previously Unseen Region
2 rules 1 TTPThis analytic detects cloud provisioning activities originating from previously unseen regions by identifying resource creation events and cross-referencing them with a baseline of known regions, potentially indicating unauthorized access or misuse of cloud resources.
Cloudflare Tunnel (cloudflared) Abuse for Protocol Tunneling
3 rules 2 TTPs 1 IOCAdversaries are abusing Cloudflare Tunnel (cloudflared) to create outbound tunnels and proxy command and control traffic, or exfiltrate data, evading direct connection blocking by routing traffic through Cloudflare's edge.
Cobalt Strike PowerShell Loader Detection
2 rules 2 TTPsThis brief details a detection for a PowerShell loader pattern commonly used with Cobalt Strike to decompress and execute payloads, often observed in scripted web delivery attacks.
Code Signing Policy Modification Through Registry
2 rules 2 TTPsAttackers modify the Windows Registry to disable code signing enforcement, allowing the execution of unsigned or self-signed malicious code.
Command Execution via ForFiles Utility
2 rules 1 TTPAdversaries may use the Windows forfiles utility to proxy command execution via a trusted parent process, potentially evading detection.
Command Execution via ForFiles Utility for Defense Evasion
2 rules 1 TTPAdversaries are leveraging the Windows `forfiles` utility to proxy command execution, potentially bypassing security controls by using a trusted process, for defense evasion.
Command Obfuscation via Unicode Modifier Letters
2 rules 1 TTPAdversaries evade string-based detections by replacing ASCII characters with visually similar Unicode modifier letters in command lines, leading to execution of malicious commands.
Command Prompt Network Connection Activity
2 rules 2 TTPsDetection of command prompt activity initiating network connections can indicate suspicious or malicious behavior, potentially leading to command and control or data exfiltration.
Component Object Model (COM) Hijacking via Registry Modification
2 rules 4 TTPsAdversaries may establish persistence by executing malicious content triggered by hijacked references to COM objects through Component Object Model (COM) hijacking via registry modification on Windows systems.
Compromised WordPress Plugin 'Accordion and Accordion Slider' Delivers Backdoor
2 rules 2 TTPs 1 CVEA malicious actor injected a backdoor into the WordPress 'Accordion and Accordion Slider' plugin version 1.4.6 after purchasing it, allowing for persistence and spam injection.
Core FTP/SFTP Server 1.2 Buffer Overflow Vulnerability (CVE-2019-25654)
2 rules 1 TTPCore FTP/SFTP Server 1.2 is vulnerable to a buffer overflow, allowing attackers to crash the service by providing an excessively long string in the User domain field.
Craft Commerce Blind SQL Injection via hasVariant/hasProduct Properties
3 rules 1 TTP 1 CVEA blind SQL injection vulnerability exists in Craft Commerce's `ProductQuery::hasVariant` and `VariantQuery::hasProduct` properties, allowing authenticated control panel users to extract arbitrary database contents and potentially escalate privileges.
Craft Commerce SQL Injection Leading to Remote Code Execution
2 rules 2 TTPs 1 CVEA SQL injection vulnerability in the Craft Commerce TotalRevenue widget can lead to remote code execution through a chain of vulnerabilities including unsanitized widget settings in SQL expressions, enabled PDO Multi-Statement Queries, unrestricted unserialize(), and a FileCookieJar gadget chain, allowing attackers to write a PHP webshell to the server's webroot and achieve arbitrary command execution as the PHP process user.
Creation or Modification of Domain Backup DPAPI Private Keys
2 rules 3 TTPsThis rule detects the creation or modification of Domain Backup private keys on Windows systems, which adversaries may extract from a Domain Controller (DC) to decrypt domain user master key files and gain credential access.
Credential Guard Bypass Techniques and Detection Strategies
3 rules 4 TTPs 1 IOCOffensive techniques such as patching, Pass-the-Challenge, downgrade attacks, and SSP negotiation can bypass Credential Guard, requiring robust detection strategies.
CVE-2019-1547 ECDSA Remote Timing Attack Vulnerability
2 rulesCVE-2019-1547 is a security vulnerability that could allow a remote timing attack.
CVE-2026-26180 Windows Kernel Heap Overflow for Privilege Escalation
2 rules 1 TTP 1 CVE 1 IOCCVE-2026-26180 is a heap-based buffer overflow vulnerability in the Windows Kernel that allows an authenticated local attacker to elevate privileges.
CVE-2026-28390 NULL Dereference in CMS KeyTransportRecipientInfo Processing
2 rules 1 CVECVE-2026-28390 is a vulnerability related to a possible NULL pointer dereference when processing CMS KeyTransportRecipientInfo, potentially leading to a denial-of-service condition.
CVE-2026-32074 Double Free in Windows Projected File System
2 rules 1 TTP 1 CVECVE-2026-32074 is a double free vulnerability in the Windows Projected File System that allows a local attacker to elevate privileges.
CVE-2026-32083 Windows SSDP Service Race Condition Privilege Escalation
1 rule 1 TTP 1 CVECVE-2026-32083 is a race condition vulnerability in the Windows SSDP Service that allows an authorized local attacker to elevate privileges.
CVE-2026-32086 Function Discovery Service Race Condition Privilege Escalation
2 rules 1 TTP 1 CVECVE-2026-32086 is a race condition vulnerability in the Function Discovery Service (fdwsd.dll) that allows an authorized local attacker to elevate privileges on a Windows system.
CVE-2026-32089 Use-After-Free in Windows Speech Brokered API for Privilege Escalation
2 rules 1 TTP 1 CVECVE-2026-32089 is a use-after-free vulnerability in the Windows Speech Brokered API that allows a local attacker to elevate privileges on a vulnerable system.
CVE-2026-32093 Function Discovery Service Race Condition Privilege Escalation
2 rules 1 TTP 1 CVEA race condition vulnerability in the Function Discovery Service (fdwsd.dll), tracked as CVE-2026-32093, allows a locally authorized attacker to escalate privileges on a vulnerable Windows system.
CVE-2026-7337 Type Confusion Vulnerability in Chromium V8 Engine
2 rules 1 TTP 1 CVECVE-2026-7337 is a type confusion vulnerability in the V8 JavaScript engine that affects Google Chrome and Microsoft Edge (Chromium-based).
D-Link DI-8100 Remote Buffer Overflow Vulnerability (CVE-2026-7853)
2 rules 1 TTP 1 CVED-Link DI-8100 version 16.07.26A1 is vulnerable to a remote buffer overflow in the `sprintf` function within the `/auto_reboot.asp` file's HTTP handler component due to improper handling of the `enable/time` argument, potentially leading to arbitrary code execution.
Decidim Amendment Acceptance Vulnerability
2 rules 1 TTPAn authentication bypass vulnerability in Decidim allows any registered user to accept or reject amendments, potentially granting them co-author status on affected proposals; versions 0.19.0 through 0.30.5 and 0.31.0.rc1 through 0.31.1 are affected.