Skip to content
Threat Feed

January 2024 (30)

medium advisory

Azure AD Successful Single-Factor Authentication

Successful single-factor authentication events against Azure Active Directory are identified using Azure SignInLogs data, which may indicate misconfiguration, policy violation, or potential account takeover leading to data breaches and privilege escalation.

Azure Active Directory azuread single-factor authentication account takeover
2r 2t
high threat

Azure AD Tenant Wide Admin Consent Granted

Detection of admin consent granted to an application within an Azure AD tenant which could lead to data exfiltration and persistence.

Azure AD NOBELIUM Group azure persistence cloud
2r 1t
medium advisory

Azure AD User Added to Administrator Role

An adversary adds a user to an Azure Active Directory administrative role to gain initial access, persist in the environment, escalate privileges, and potentially operate stealthily.

Azure Active Directory attack.initial-access attack.persistence attack.privilege-escalation attack.stealth attack.t1098.003 attack.t1078
2r 4t
medium advisory

Azure AD User Consent Blocked for Risky Application

Azure AD blocked a user's attempt to grant consent to a risky application, indicating potential OAuth abuse and requiring investigation of the user and application involved.

Azure Active Directory azuread oauth consent-phishing cloud
2r 1t
critical advisory

Azure AD User ImmutableId Attribute Modification for Persistence

Attackers modify the ImmutableID attribute of an Azure AD user to establish a federation backdoor, bypassing MFA and enabling persistent access.

Azure Active Directory azuread persistence federation immutabilid
2r 1t
high advisory

Azure Automation Account Creation

Detect the creation of new Azure Automation accounts, which can be used by attackers for persistence, privilege escalation, and malicious runbook execution within Azure environments.

Azure Automation azure automation persistence
2r 1t
high advisory

Azure Automation Runbook Creation for Persistence

This analytic detects the creation of a new Azure Automation Runbook within an Azure tenant using Azure Audit events, which adversaries with privileged access can abuse to maintain persistence, escalate privileges, or execute malicious code, potentially leading to unauthorized actions and compromise of the Azure environment.

Azure Automation azure persistence automation cloud
2r 1t
medium advisory

Azure Compute Restore Point Collection Deleted by Unusual User

The deletion of Azure Restore Point Collections, which contain recovery points for virtual machines, by a user who has not previously performed this activity, indicates a potential attempt to prevent recovery during ransomware attacks or cover tracks during malicious operations.

Azure Compute cloud azure impact
2r 1t
medium advisory

Azure Event Hub Authorization Rule Created or Updated

Creation or modification of Azure Event Hub authorization rules can indicate unauthorized access or privilege escalation by adversaries using cryptographic keys to manage access to event hubs.

Azure Event Hub cloud azure persistence account-manipulation
2r 2t
low advisory

Azure Key Vault Modified by Unusual User

This rule identifies modifications to Azure Key Vaults by unusual users, potentially leading to data breaches or service disruptions through defense evasion or impact operations.

Azure Key Vault azure keyvault configuration-audit impact defense-evasion
2r 2t
medium advisory

Azure Key Vault Unusual Secret Key Usage

Detects unusual secret, key, or certificate retrieval operations from Azure Key Vault by a user principal that has not been seen previously, potentially indicating unauthorized access attempts.

Azure Key Vault azure keyvault credential-access
2r 1t
medium advisory

Azure Kubernetes Services (AKS) Kubernetes Events Deleted

Adversaries may delete Kubernetes events in Azure Kubernetes Services (AKS) to evade detection by removing logs of state changes, container creations, image pulls, and pod scheduling.

Azure Kubernetes Service azure kubernetes defense-evasion
2r 2t
medium advisory

Azure Owner Removed from Application or Service Principal

An adversary may remove an owner from an Azure application or service principal to weaken access controls, persist in the environment, or escalate privileges.

Azure attack.stealth
2r 1t
high advisory

Azure RBAC Built-In Administrator Role Assignment

Detection of a user being assigned a built-in administrator role in Azure RBAC, which can be abused for privilege escalation, lateral movement, or persistence.

Azure rbac privilege-escalation persistence
2r 2t
high advisory

Azure Runbook Webhook Creation Detected

Detection of a new Azure Automation Runbook Webhook creation, potentially leading to unauthorized access and control over Azure resources by enabling unauthenticated URL triggers.

Azure Automation azure runbook webhook persistence
2r 1t
medium advisory

Azure Storage Account Blob Public Access Enabled

Detection of Azure Storage Account Blob public access being enabled, potentially allowing external access to blob containers for data exfiltration, as abused by threat actors modifying storage account settings.

Azure Storage Account azure storage data_exfiltration cloud_security
2r 1t
high advisory

Azure Subscription Permission Elevation via Activity Logs

An attacker elevates their Azure subscription permissions to manage all subscriptions, potentially leading to unauthorized access and control over the environment.

Azure privilege-escalation persistence initial-access stealth
2r 1t
low advisory

Azure VNet Firewall Policy Deletion for Defense Evasion

An adversary may delete a firewall policy in Azure in an attempt to evade defenses, which can be detected by monitoring Azure activity logs for successful deletion operations of firewall policies.

Azure Firewall azure cloud defense-evasion
2r 1t
high advisory

BCDEdit Failure Recovery Modification

Detection of modifications to Windows error recovery boot configurations using bcdedit.exe, a technique commonly used by ransomware to disable system restoration options.

Windows bcdedit boot-configuration ransomware
2r 1t
high advisory

Beghelli Sicuro24 SicuroWeb AngularJS Sandbox Escape via Template Injection

Beghelli Sicuro24 SicuroWeb is vulnerable to arbitrary JavaScript execution due to embedding an end-of-life AngularJS 1.5.2 component with known sandbox escape primitives combined with template injection, enabling attackers to compromise operator browser sessions via MITM attacks.

Sicuro24 SicuroWeb +1 cve-2026-41468 angularjs template-injection mitm
2r 1t 1c
critical advisory

Betheme WordPress Theme Arbitrary File Upload Vulnerability

The Betheme theme for WordPress is vulnerable to arbitrary file upload, allowing authenticated attackers with author-level privileges or higher to upload arbitrary files, including PHP, leading to remote code execution.

Betheme theme arbitrary-file-upload rce wordpress betheme
2r 1t 1c
medium advisory

BITS Job Notify Command Persistence

Adversaries can abuse the Background Intelligent Transfer Service (BITS) SetNotifyCmdLine method to execute arbitrary commands for persistence by configuring a BITS job to execute a program after a transfer completes or enters a specific state.

Windows persistence bits
2r 1t
medium advisory

blueprintUE Password Reset Token Vulnerability (CVE-2026-40585)

blueprintUE versions before 4.2.0 generate password reset tokens that remain valid indefinitely due to the absence of a timestamp validation, allowing attackers to potentially gain unauthorized access via token reuse.

blueprintUE cve-2026-40585 password-reset
2r 1t 1c
critical advisory

Budibase Authentication Bypass via Unanchored Regex

Budibase versions 3.35.3 and earlier are vulnerable to an authentication bypass due to unanchored regular expressions in the public endpoint matcher, allowing unauthenticated attackers to access protected endpoints by manipulating the query string.

Budibase authentication-bypass web-application
2r 1t 2i
medium advisory

Certreq HTTP POST Abuse for File Transfer

Adversaries may abuse the Windows Certreq utility to download files or upload data to a remote URL by making an HTTP POST request, potentially for command and control, defense evasion, or exfiltration.

Windows lolbin certreq command-and-control defense-evasion exfiltration
2r 4t
critical advisory

CF Image Hosting Script 1.6.5 Unauthenticated Database Download and Remote Image Deletion

CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download the application database, extract delete IDs, and delete all pictures via the `d` parameter.

CF Image Hosting Script cve-2019-25709 image-hosting unauthorized-access
2r 2t 1c
medium advisory

changedetection.io Arbitrary Local File Read via Crafted Backup Restore

changedetection.io is vulnerable to arbitrary local file read due to insufficient validation of snapshot paths restored from backup files, allowing attackers to read sensitive files by crafting a malicious backup archive containing a manipulated `history.txt` file.

changedetection.io arbitrary-file-read vulnerability
2r 1t
critical advisory

changedetection.io Authentication Bypass via Flask Decorator Misordering

changedetection.io is vulnerable to authentication bypass due to incorrect decorator ordering in Flask routes, allowing unauthenticated access to backup functionalities and potentially leading to data exfiltration of sensitive information.

changedetection.io authentication-bypass data-exfiltration flask
2r 4t 1i
critical advisory

charm.land/wish SCP Path Traversal Vulnerability

The charm.land/wish/v2 and github.com/charmbracelet/wish libraries are vulnerable to path traversal attacks via the SCP protocol, allowing malicious clients to read or write arbitrary files, create directories outside the configured root, and enumerate files, potentially leading to remote code execution or data exfiltration.

Wish path-traversal scp charmbracelet
2r 1t
medium advisory

ChatGPTNextWeb NextChat Improper Authorization Vulnerability (CVE-2026-7644)

CVE-2026-7644 is an improper authorization vulnerability in the addMcpServer function of ChatGPTNextWeb NextChat version 2.16.1 and earlier, allowing for potential remote exploitation following public disclosure of the exploit.

NextChat authorization cve-2026-7644 web-application
1r 1t 1c