Skip to content
Threat Feed

January 2024 (30)

high threat

ChatGPTNextWeb NextChat SSRF Vulnerability (CVE-2026-7178)

ChatGPTNextWeb NextChat versions up to 2.16.1 are vulnerable to server-side request forgery (SSRF) due to improper input validation in the storeUrl function, allowing remote attackers to potentially access internal resources or conduct other malicious activities.

exploited NextChat ssrf cve vulnerability web-application
2r 1t 1c
medium advisory

Chmod Activity Targeting Sensitive Linux Directories

Attackers may use chmod to modify file permissions within sensitive Linux directories such as /tmp/, /etc/, and /opt/ to maintain persistence, escalate privileges, or disrupt system operations.

defense-evasion privilege-escalation persistence linux
2r 1t
high advisory

CircleCI Security Job Disablement

An attacker disables mandatory security jobs within CircleCI pipelines to bypass security checks, potentially leading to data breaches, system downtime, and compromised pipeline integrity.

CircleCI devsecops pipeline-security cloud
2r 1t
medium advisory

CircleCI Security Step Disabled

An attacker disables security steps within CircleCI to potentially bypass security controls and introduce malicious code into the build pipeline.

CircleCI ci/cd security-bypass supply-chain
2r 1t
high advisory

Cisco ACI Multi-Site CloudSec Encryption Information Disclosure Vulnerability

A vulnerability in Cisco ACI Multi-Site CloudSec encryption allows a remote attacker to read or modify intersite encrypted traffic due to a flaw in cipher implementation.

Nexus 9000 Series Fabric Switches in ACI mode cve-2023-20185 information-disclosure network
2r 1t 1c
high advisory

Cisco ASA Logging Disabled via CLI

Detection of disabled logging functionality on a Cisco ASA device via CLI commands, indicating potential defense evasion by adversaries.

Adaptive Security Appliance defense-evasion cisco asa
2r
medium advisory

Cisco ASA Logging Filters Configuration Tampering

Tampering with logging filter configurations on Cisco ASA devices can allow attackers to evade detection by reducing logging levels or disabling specific log categories.

ASA +3 cisco logging evasion
2r 1t
medium advisory

Cisco ASA Logging Message Suppression

Adversaries may suppress specific log message IDs on Cisco ASA devices using the 'no logging message' command to selectively disable logging of security-critical events and evade detection.

Cisco ASA cisco-asa logging defense-evasion network
2r 2t
medium advisory

Cisco ASA Reconnaissance Command Activity

This analytic detects potential reconnaissance on Cisco ASA devices by identifying execution of multiple information-gathering 'show' commands within a short timeframe, indicating potential enumeration by an attacker.

Cisco ASA cisco reconnaissance network
2r 3t
medium advisory

Cisco ASA User Account Lockout Detection

Detection of user account lockouts on Cisco ASA devices due to excessive failed authentication attempts, potentially indicating brute-force attacks, password spraying, or credential stuffing.

Cisco ASA authentication brute_force password_spraying cisco_asa
2r 2t
medium advisory

Cisco Duo Admin Login from Unusual Browser

Detects Cisco Duo admin logins from browsers other than Chrome, potentially indicating compromised credentials, session hijacking, or unauthorized device usage.

Cisco Duo cisco-duo credential-access anomaly-detection
2r 1t
high advisory

Cisco Duo Admin Login from Unusual Operating System

Detection of Cisco Duo admin login attempts originating from operating systems not typically used in the environment, potentially indicating account compromise or unauthorized access.

Cisco Duo cisco-duo account-compromise unauthorized-access ttp
2r 1t 2i
high advisory

Cisco Duo Policy Allowing Outdated Java Usage

A threat actor modifies Cisco Duo policies to permit outdated Java versions, potentially exposing the organization to known vulnerabilities and exploits.

Duo cisco-duo policy-modification outdated-software
2r 1t
high advisory

Cisco Duo Policy Allowing Tampered Devices

A threat actor modifies or creates a Cisco Duo policy to allow tampered or rooted devices to access protected resources, potentially bypassing security controls and enabling unauthorized access.

Duo cisco_duo policy_change tampered_devices rooted_devices identity
2r 1t
critical advisory

Cisco Duo Policy Bypass via 2FA Disablement

An attacker modifies Cisco Duo policies to allow access without two-factor authentication (2FA), potentially gaining unauthorized access to systems and data.

Duo cisco-duo 2fa-bypass policy-modification
2r 1t
high advisory

Cisco Duo Policy Modification to Bypass 2FA for Specific Countries

A Duo policy is created or updated to allow access without two-factor authentication (2FA) for users in countries other than the default, potentially weakening the organization's security posture and increasing the risk of unauthorized access.

Duo cisco-duo 2fa-bypass policy-modification
2r 1t
high advisory

Cisco Duo User 2FA Bypass

Detection of Cisco Duo user status being changed to 'Bypass' after being 'Active', indicating potential malicious activity to weaken account security.

Duo cisco-duo 2fa-bypass credential-access
2r 1t
high advisory

Cisco IOS XE DHCP Snooping BOOTP VLAN Leakage DoS (CVE-2026-20084)

CVE-2026-20084 describes a vulnerability in Cisco IOS XE DHCP snooping where an unauthenticated remote attacker can cause a denial-of-service by forwarding BOOTP packets between VLANs, leading to high CPU utilization on affected Cisco Catalyst 9000 Series Switches.

Cisco IOS XE Software +1 cve-2026-20084 dhcp-snooping bootp denial-of-service cisco
2r 1t
high advisory

Cisco IOS XE Wireless Controller CAPWAP Packet Processing Vulnerability (CVE-2026-20086)

CVE-2026-20086 describes a vulnerability in Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family, enabling unauthenticated remote attackers to trigger a denial-of-service condition by sending malformed CAPWAP packets that cause the device to reload unexpectedly.

Cisco IOS XE Wireless Controller Software +1 cve-2026-20086 cisco capwap denial-of-service network
2r 2t
high advisory

Cisco Secure Endpoint Tampering via SFC Utility

An attacker attempts to disable the Immunet Protect service of Cisco Secure Endpoint by leveraging the `sfc.exe` utility with the `-k` parameter, potentially blinding the EDR for further compromise.

Secure Endpoint +1 defense-evasion endpoint cisco
2r 1t
high advisory

Cisco Secure Endpoint Tampering via SFC Utility

The sfc.exe utility is being used with the '-unblock' parameter, a feature within Cisco Secure Endpoint, to remove system blocks imposed by the endpoint protection, potentially indicating an attempt to bypass security measures and execute blocked malicious payloads.

Secure Endpoint +3 defense-evasion endpoint cisco
2r
high advisory

Cisco Secure Endpoint Uninstallation via SFC Utility

The sfc.exe utility is used with the "-u" parameter to uninstall Cisco Secure Endpoint components, potentially disabling endpoint protection and facilitating further exploitation.

Secure Endpoint +3 security-solution-tampering endpoint windows
2r
high advisory

CKAN Unauthenticated SQL Injection in datastore_search_sql

An unauthenticated SQL injection vulnerability in CKAN's `datastore_search_sql` function allows attackers to access private resources and PostgreSQL system information, affecting versions prior to 2.10.10 and versions 2.11.0 through 2.11.4.

ckan sql-injection vulnerability
2r 1t
low advisory

Clearing Windows Console History for Defense Evasion

Adversaries may clear Windows console history to remove evidence of their activity and evade detection.

Windows defense-evasion console-history
2r 1t
critical advisory

Cline Kanban Server Cross-Origin WebSocket Hijacking Vulnerability

The `kanban` npm package, used by the `cline` CLI, has a cross-origin WebSocket hijacking vulnerability. Due to the lack of Origin header validation, any website can connect to the kanban server via WebSocket and leak sensitive data, hijack running AI agent terminals leading to remote code execution, or kill running agent tasks, resulting in information disclosure, RCE, and denial of service.

cline +1 websocket cross-origin rce infoleak dos
3r 4t 1i
high advisory

Cloud Compute Instance Created With Previously Unseen Image

This analytic detects the creation of cloud compute instances using previously unseen image IDs, potentially indicating unauthorized or suspicious activity like malicious payload deployment or unauthorized access, leading to data breaches or further cloud environment compromise.

EC2 cloud aws cloudtrail compute_instance anomaly
2r 2t
medium advisory

Cloud Provisioning Activity From Previously Unseen City

The analytic detects cloud provisioning activities originating from previously unseen cities based on source IP geolocation compared to a learned baseline, which may indicate unauthorized access or misuse of cloud resources leading to resource creation, data exfiltration, or further compromise.

AWS +3 cloud anomaly-detection
2r 1t
medium advisory

Cloud Provisioning Activity From Previously Unseen IP Address

This analytic detects cloud provisioning activities originating from previously unseen IP addresses by leveraging cloud infrastructure logs to identify events where resources are created or started, and cross-references these with a baseline of known IP addresses.

AWS cloud cloudtrail anomaly-detection
2r 1t
medium advisory

Cloud Provisioning Activity From Previously Unseen Region

This analytic detects cloud provisioning activities originating from previously unseen regions by identifying resource creation events and cross-referencing them with a baseline of known regions, potentially indicating unauthorized access or misuse of cloud resources.

AWS cloud provisioning anomaly
2r 1t
medium advisory

Cloudflare Tunnel (cloudflared) Abuse for Protocol Tunneling

Adversaries are abusing Cloudflare Tunnel (cloudflared) to create outbound tunnels and proxy command and control traffic, or exfiltrate data, evading direct connection blocking by routing traffic through Cloudflare's edge.

Cloudflare Tunnel command-and-control protocol-tunneling windows
3r 2t 1i