January 2024 (30)
ChatGPTNextWeb NextChat SSRF Vulnerability (CVE-2026-7178)
2 rules 1 TTP 1 CVEChatGPTNextWeb NextChat versions up to 2.16.1 are vulnerable to server-side request forgery (SSRF) due to improper input validation in the storeUrl function, allowing remote attackers to potentially access internal resources or conduct other malicious activities.
Chmod Activity Targeting Sensitive Linux Directories
2 rules 1 TTPAttackers may use chmod to modify file permissions within sensitive Linux directories such as /tmp/, /etc/, and /opt/ to maintain persistence, escalate privileges, or disrupt system operations.
CircleCI Security Job Disablement
2 rules 1 TTPAn attacker disables mandatory security jobs within CircleCI pipelines to bypass security checks, potentially leading to data breaches, system downtime, and compromised pipeline integrity.
CircleCI Security Step Disabled
2 rules 1 TTPAn attacker disables security steps within CircleCI to potentially bypass security controls and introduce malicious code into the build pipeline.
Cisco ACI Multi-Site CloudSec Encryption Information Disclosure Vulnerability
2 rules 1 TTP 1 CVEA vulnerability in Cisco ACI Multi-Site CloudSec encryption allows a remote attacker to read or modify intersite encrypted traffic due to a flaw in cipher implementation.
Cisco ASA Logging Disabled via CLI
2 rulesDetection of disabled logging functionality on a Cisco ASA device via CLI commands, indicating potential defense evasion by adversaries.
Cisco ASA Logging Filters Configuration Tampering
2 rules 1 TTPTampering with logging filter configurations on Cisco ASA devices can allow attackers to evade detection by reducing logging levels or disabling specific log categories.
Cisco ASA Logging Message Suppression
2 rules 2 TTPsAdversaries may suppress specific log message IDs on Cisco ASA devices using the 'no logging message' command to selectively disable logging of security-critical events and evade detection.
Cisco ASA Reconnaissance Command Activity
2 rules 3 TTPsThis analytic detects potential reconnaissance on Cisco ASA devices by identifying execution of multiple information-gathering 'show' commands within a short timeframe, indicating potential enumeration by an attacker.
Cisco ASA User Account Lockout Detection
2 rules 2 TTPsDetection of user account lockouts on Cisco ASA devices due to excessive failed authentication attempts, potentially indicating brute-force attacks, password spraying, or credential stuffing.
Cisco Duo Admin Login from Unusual Browser
2 rules 1 TTPDetects Cisco Duo admin logins from browsers other than Chrome, potentially indicating compromised credentials, session hijacking, or unauthorized device usage.
Cisco Duo Admin Login from Unusual Operating System
2 rules 1 TTP 2 IOCsDetection of Cisco Duo admin login attempts originating from operating systems not typically used in the environment, potentially indicating account compromise or unauthorized access.
Cisco Duo Policy Allowing Outdated Java Usage
2 rules 1 TTPA threat actor modifies Cisco Duo policies to permit outdated Java versions, potentially exposing the organization to known vulnerabilities and exploits.
Cisco Duo Policy Allowing Tampered Devices
2 rules 1 TTPA threat actor modifies or creates a Cisco Duo policy to allow tampered or rooted devices to access protected resources, potentially bypassing security controls and enabling unauthorized access.
Cisco Duo Policy Bypass via 2FA Disablement
2 rules 1 TTPAn attacker modifies Cisco Duo policies to allow access without two-factor authentication (2FA), potentially gaining unauthorized access to systems and data.
Cisco Duo Policy Modification to Bypass 2FA for Specific Countries
2 rules 1 TTPA Duo policy is created or updated to allow access without two-factor authentication (2FA) for users in countries other than the default, potentially weakening the organization's security posture and increasing the risk of unauthorized access.
Cisco Duo User 2FA Bypass
2 rules 1 TTPDetection of Cisco Duo user status being changed to 'Bypass' after being 'Active', indicating potential malicious activity to weaken account security.
Cisco IOS XE DHCP Snooping BOOTP VLAN Leakage DoS (CVE-2026-20084)
2 rules 1 TTPCVE-2026-20084 describes a vulnerability in Cisco IOS XE DHCP snooping where an unauthenticated remote attacker can cause a denial-of-service by forwarding BOOTP packets between VLANs, leading to high CPU utilization on affected Cisco Catalyst 9000 Series Switches.
Cisco IOS XE Wireless Controller CAPWAP Packet Processing Vulnerability (CVE-2026-20086)
2 rules 2 TTPsCVE-2026-20086 describes a vulnerability in Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family, enabling unauthenticated remote attackers to trigger a denial-of-service condition by sending malformed CAPWAP packets that cause the device to reload unexpectedly.
Cisco Secure Endpoint Tampering via SFC Utility
2 rules 1 TTPAn attacker attempts to disable the Immunet Protect service of Cisco Secure Endpoint by leveraging the `sfc.exe` utility with the `-k` parameter, potentially blinding the EDR for further compromise.
Cisco Secure Endpoint Tampering via SFC Utility
2 rulesThe sfc.exe utility is being used with the '-unblock' parameter, a feature within Cisco Secure Endpoint, to remove system blocks imposed by the endpoint protection, potentially indicating an attempt to bypass security measures and execute blocked malicious payloads.
Cisco Secure Endpoint Uninstallation via SFC Utility
2 rulesThe sfc.exe utility is used with the "-u" parameter to uninstall Cisco Secure Endpoint components, potentially disabling endpoint protection and facilitating further exploitation.
CKAN Unauthenticated SQL Injection in datastore_search_sql
2 rules 1 TTPAn unauthenticated SQL injection vulnerability in CKAN's `datastore_search_sql` function allows attackers to access private resources and PostgreSQL system information, affecting versions prior to 2.10.10 and versions 2.11.0 through 2.11.4.
Clearing Windows Console History for Defense Evasion
2 rules 1 TTPAdversaries may clear Windows console history to remove evidence of their activity and evade detection.
Cline Kanban Server Cross-Origin WebSocket Hijacking Vulnerability
3 rules 4 TTPs 1 IOCThe `kanban` npm package, used by the `cline` CLI, has a cross-origin WebSocket hijacking vulnerability. Due to the lack of Origin header validation, any website can connect to the kanban server via WebSocket and leak sensitive data, hijack running AI agent terminals leading to remote code execution, or kill running agent tasks, resulting in information disclosure, RCE, and denial of service.
Cloud Compute Instance Created With Previously Unseen Image
2 rules 2 TTPsThis analytic detects the creation of cloud compute instances using previously unseen image IDs, potentially indicating unauthorized or suspicious activity like malicious payload deployment or unauthorized access, leading to data breaches or further cloud environment compromise.
Cloud Provisioning Activity From Previously Unseen City
2 rules 1 TTPThe analytic detects cloud provisioning activities originating from previously unseen cities based on source IP geolocation compared to a learned baseline, which may indicate unauthorized access or misuse of cloud resources leading to resource creation, data exfiltration, or further compromise.
Cloud Provisioning Activity From Previously Unseen IP Address
2 rules 1 TTPThis analytic detects cloud provisioning activities originating from previously unseen IP addresses by leveraging cloud infrastructure logs to identify events where resources are created or started, and cross-references these with a baseline of known IP addresses.
Cloud Provisioning Activity From Previously Unseen Region
2 rules 1 TTPThis analytic detects cloud provisioning activities originating from previously unseen regions by identifying resource creation events and cross-referencing them with a baseline of known regions, potentially indicating unauthorized access or misuse of cloud resources.
Cloudflare Tunnel (cloudflared) Abuse for Protocol Tunneling
3 rules 2 TTPs 1 IOCAdversaries are abusing Cloudflare Tunnel (cloudflared) to create outbound tunnels and proxy command and control traffic, or exfiltrate data, evading direct connection blocking by routing traffic through Cloudflare's edge.