Skip to content
Threat Feed

January 2024 (30)

critical advisory

Cline Kanban Server Cross-Origin WebSocket Hijacking Vulnerability

The `kanban` npm package, used by the `cline` CLI, has a cross-origin WebSocket hijacking vulnerability. Due to the lack of Origin header validation, any website can connect to the kanban server via WebSocket and leak sensitive data, hijack running AI agent terminals leading to remote code execution, or kill running agent tasks, resulting in information disclosure, RCE, and denial of service.

cline +1 websocket cross-origin rce infoleak dos
3r 4t 1i
high advisory

Cloud Compute Instance Created With Previously Unseen Image

This analytic detects the creation of cloud compute instances using previously unseen image IDs, potentially indicating unauthorized or suspicious activity like malicious payload deployment or unauthorized access, leading to data breaches or further cloud environment compromise.

EC2 cloud aws cloudtrail compute_instance anomaly
2r 2t
medium advisory

Cloud Provisioning Activity From Previously Unseen City

The analytic detects cloud provisioning activities originating from previously unseen cities based on source IP geolocation compared to a learned baseline, which may indicate unauthorized access or misuse of cloud resources leading to resource creation, data exfiltration, or further compromise.

AWS +3 cloud anomaly-detection
2r 1t
medium advisory

Cloud Provisioning Activity From Previously Unseen IP Address

This analytic detects cloud provisioning activities originating from previously unseen IP addresses by leveraging cloud infrastructure logs to identify events where resources are created or started, and cross-references these with a baseline of known IP addresses.

AWS cloud cloudtrail anomaly-detection
2r 1t
medium advisory

Cloud Provisioning Activity From Previously Unseen Region

This analytic detects cloud provisioning activities originating from previously unseen regions by identifying resource creation events and cross-referencing them with a baseline of known regions, potentially indicating unauthorized access or misuse of cloud resources.

AWS cloud provisioning anomaly
2r 1t
medium advisory

Cloudflare Tunnel (cloudflared) Abuse for Protocol Tunneling

Adversaries are abusing Cloudflare Tunnel (cloudflared) to create outbound tunnels and proxy command and control traffic, or exfiltrate data, evading direct connection blocking by routing traffic through Cloudflare's edge.

Cloudflare Tunnel command-and-control protocol-tunneling windows
3r 2t 1i
high advisory

Cobalt Strike PowerShell Loader Detection

This brief details a detection for a PowerShell loader pattern commonly used with Cobalt Strike to decompress and execute payloads, often observed in scripted web delivery attacks.

Splunk Enterprise +2 cobaltstrike powershell malware windows
2r 2t
medium advisory

Code Signing Policy Modification Through Registry

Attackers modify the Windows Registry to disable code signing enforcement, allowing the execution of unsigned or self-signed malicious code.

Windows defense-evasion registry-modification code-signing
2r 2t
medium advisory

Command Execution via ForFiles Utility

Adversaries may use the Windows forfiles utility to proxy command execution via a trusted parent process, potentially evading detection.

Microsoft Defender XDR +2 defense-evasion indirect-execution windows
2r 1t
medium advisory

Command Execution via ForFiles Utility for Defense Evasion

Adversaries are leveraging the Windows `forfiles` utility to proxy command execution, potentially bypassing security controls by using a trusted process, for defense evasion.

Windows defense-evasion indirect-command-execution
2r 1t
high advisory

Command Obfuscation via Unicode Modifier Letters

Adversaries evade string-based detections by replacing ASCII characters with visually similar Unicode modifier letters in command lines, leading to execution of malicious commands.

Windows +1 command-obfuscation defense-evasion
2r 1t
medium advisory

Command Prompt Network Connection Activity

Detection of command prompt activity initiating network connections can indicate suspicious or malicious behavior, potentially leading to command and control or data exfiltration.

Microsoft Windows command-prompt network-connection execution
2r 2t
low advisory

Component Object Model (COM) Hijacking via Registry Modification

Adversaries may establish persistence by executing malicious content triggered by hijacked references to COM objects through Component Object Model (COM) hijacking via registry modification on Windows systems.

Elastic Defend +9 persistence com-hijacking windows registry defense-evasion privilege-escalation
2r 4t
critical advisory

Compromised WordPress Plugin 'Accordion and Accordion Slider' Delivers Backdoor

A malicious actor injected a backdoor into the WordPress 'Accordion and Accordion Slider' plugin version 1.4.6 after purchasing it, allowing for persistence and spam injection.

Accordion and Accordion Slider wordpress backdoor plugin spam cve-2026-6443
2r 2t 1c
high advisory

Core FTP/SFTP Server 1.2 Buffer Overflow Vulnerability (CVE-2019-25654)

Core FTP/SFTP Server 1.2 is vulnerable to a buffer overflow, allowing attackers to crash the service by providing an excessively long string in the User domain field.

Core FTP/SFTP Server buffer overflow denial of service cve-2019-25654 core ftp sftp windows
2r 1t
high advisory

Craft Commerce Blind SQL Injection via hasVariant/hasProduct Properties

A blind SQL injection vulnerability exists in Craft Commerce's `ProductQuery::hasVariant` and `VariantQuery::hasProduct` properties, allowing authenticated control panel users to extract arbitrary database contents and potentially escalate privileges.

Craft Commerce sqli craft-commerce web-application
3r 1t 1c
critical advisory

Craft Commerce SQL Injection Leading to Remote Code Execution

A SQL injection vulnerability in the Craft Commerce TotalRevenue widget can lead to remote code execution through a chain of vulnerabilities including unsanitized widget settings in SQL expressions, enabled PDO Multi-Statement Queries, unrestricted unserialize(), and a FileCookieJar gadget chain, allowing attackers to write a PHP webshell to the server's webroot and achieve arbitrary command execution as the PHP process user.

Craft Commerce craft-commerce sql-injection rce webshell
2r 2t 1c
high advisory

Creation or Modification of Domain Backup DPAPI Private Keys

This rule detects the creation or modification of Domain Backup private keys on Windows systems, which adversaries may extract from a Domain Controller (DC) to decrypt domain user master key files and gain credential access.

Windows +1 credential-access dpapi
2r 3t
high advisory

Credential Guard Bypass Techniques and Detection Strategies

Offensive techniques such as patching, Pass-the-Challenge, downgrade attacks, and SSP negotiation can bypass Credential Guard, requiring robust detection strategies.

Windows credential-guard bypass security authentication
3r 4t 1i
medium advisory

CVE-2019-1547 ECDSA Remote Timing Attack Vulnerability

CVE-2019-1547 is a security vulnerability that could allow a remote timing attack.

cve-2019-1547 timing-attack ecdsa
2r
high advisory

CVE-2026-26180 Windows Kernel Heap Overflow for Privilege Escalation

CVE-2026-26180 is a heap-based buffer overflow vulnerability in the Windows Kernel that allows an authenticated local attacker to elevate privileges.

Windows privilege-escalation cve-2026-26180
2r 1t 1c 1i
medium advisory

CVE-2026-28390 NULL Dereference in CMS KeyTransportRecipientInfo Processing

CVE-2026-28390 is a vulnerability related to a possible NULL pointer dereference when processing CMS KeyTransportRecipientInfo, potentially leading to a denial-of-service condition.

vulnerability denial-of-service
2r 1c
high advisory

CVE-2026-32074 Double Free in Windows Projected File System

CVE-2026-32074 is a double free vulnerability in the Windows Projected File System that allows a local attacker to elevate privileges.

Windows privilege-escalation cve-2026-32074
2r 1t 1c
high threat

CVE-2026-32083 Windows SSDP Service Race Condition Privilege Escalation

CVE-2026-32083 is a race condition vulnerability in the Windows SSDP Service that allows an authorized local attacker to elevate privileges.

exploited Windows privilege-escalation cve-2026-32083
1r 1t 1c
high advisory

CVE-2026-32086 Function Discovery Service Race Condition Privilege Escalation

CVE-2026-32086 is a race condition vulnerability in the Function Discovery Service (fdwsd.dll) that allows an authorized local attacker to elevate privileges on a Windows system.

Windows cve-2026-32086 privilege-escalation race-condition
2r 1t 1c
high advisory

CVE-2026-32089 Use-After-Free in Windows Speech Brokered API for Privilege Escalation

CVE-2026-32089 is a use-after-free vulnerability in the Windows Speech Brokered API that allows a local attacker to elevate privileges on a vulnerable system.

Windows cve-2026-32089 privilege-escalation
2r 1t 1c
high advisory

CVE-2026-32093 Function Discovery Service Race Condition Privilege Escalation

A race condition vulnerability in the Function Discovery Service (fdwsd.dll), tracked as CVE-2026-32093, allows a locally authorized attacker to escalate privileges on a vulnerable Windows system.

Windows privilege-escalation race-condition
2r 1t 1c
high advisory

CVE-2026-7337 Type Confusion Vulnerability in Chromium V8 Engine

CVE-2026-7337 is a type confusion vulnerability in the V8 JavaScript engine that affects Google Chrome and Microsoft Edge (Chromium-based).

Chrome +1 type confusion v8 engine chromium cve-2026-7337
2r 1t 1c
critical advisory

D-Link DI-8100 Remote Buffer Overflow Vulnerability (CVE-2026-7853)

D-Link DI-8100 version 16.07.26A1 is vulnerable to a remote buffer overflow in the `sprintf` function within the `/auto_reboot.asp` file's HTTP handler component due to improper handling of the `enable/time` argument, potentially leading to arbitrary code execution.

DI-8100 buffer overflow remote code execution d-link cve-2026-7853
2r 1t 1c
high advisory

Decidim Amendment Acceptance Vulnerability

An authentication bypass vulnerability in Decidim allows any registered user to accept or reject amendments, potentially granting them co-author status on affected proposals; versions 0.19.0 through 0.30.5 and 0.31.0.rc1 through 0.31.1 are affected.

Decidim-core decidim authentication-bypass privilege-escalation web-application
2r 1t