January 2024 (30)
PraisonAI Cloud Run Environment Variable Injection Vulnerability (CVE-2026-40113)
2 rules 1 TTP 1 CVEPraisonAI versions before 4.5.128 are vulnerable to arbitrary environment variable injection in Google Cloud Run deployments due to insufficient input validation when constructing the `--set-env-vars` argument, potentially leading to privilege escalation.
PromtEngineer localGPT LLM Prompt Handler Injection Vulnerability (CVE-2026-5002)
2 rules 1 TTPA remote code injection vulnerability (CVE-2026-5002) exists in PromtEngineer localGPT versions up to commit 4d41c7d1713b16b216d8e062e51a5dd88b20b054, allowing attackers to execute arbitrary code by manipulating the LLM Prompt Handler component via the _route_using_overviews function in backend/server.py.
Python-Multipart Denial of Service Vulnerability
2 rules 1 TTPA denial-of-service vulnerability exists in python-multipart versions prior to 0.0.27 due to unbounded multipart part header parsing, allowing attackers to exhaust CPU resources by sending requests with many repeated headers or a single oversized header value.
Rack::Session::Cookie Vulnerability Enables Secretless Session Forgery
2 rules 2 TTPs 1 CVERack::Session::Cookie incorrectly handles decryption failures, falling back to a default decoder and allowing attackers to forge session cookies without knowing the secret, potentially leading to authentication bypass or privilege escalation in vulnerable Rack applications.
Rapid7 Velociraptor Improper Input Validation Vulnerability
2 rules 1 TTP 1 CVERapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability allowing authenticated remote attackers to achieve remote code execution on the server.
Registry Modification to Disable .NET ETW Logging
2 rules 1 TTPAttackers may modify the Windows registry to disable ETW logging for the .NET Framework, hindering endpoint detection and response capabilities.
Remcos RAT Activity Detection
3 rules 3 TTPsThis brief outlines detection strategies for Remcos RAT activity, focusing on file and registry artifacts indicative of installation, persistence, and cleanup on compromised Windows systems.
Remote Registry Lateral Movement via RPC Firewall
2 rules 3 TTPsThis brief details detection of lateral movement attempts using remote RPC calls to modify the registry, potentially leading to code execution, detected via RPC Firewall logs.
Rukovoditel CRM Reflected XSS Vulnerability (CVE-2026-31845)
2 rules 1 TTP 1 CVEA reflected XSS vulnerability in Rukovoditel CRM version 3.6.4 and earlier allows unauthenticated attackers to inject malicious JavaScript by reflecting the 'zd_echo' GET parameter, leading to potential session hijacking and account takeover.
RustFS Notification Target Admin API Authorization Bypass
2 rules 3 TTPsA vulnerability in RustFS allows a non-admin user to overwrite a shared admin-defined notification target, leading to event interception and audit evasion due to missing admin-action authorization on notification target admin API endpoints.
S3 Browser Used to Create IAM Login Profiles
2 rules 2 TTPsThe S3 Browser utility is being used to enumerate IAM users lacking login profiles and subsequently create them, potentially for reconnaissance, persistence, and privilege escalation within AWS environments.
Salesforce Marketing Cloud Engagement Argument Injection Vulnerability (CVE-2026-2298)
2 rules 1 TTP 1 IOCCVE-2026-2298 is an argument injection vulnerability in Salesforce Marketing Cloud Engagement that allows Web Services Protocol Manipulation in versions prior to January 30th, 2026.
SAT CFDI 3.3 SQL Injection Vulnerability (CVE-2018-25202)
2 rules 1 TTPSAT CFDI 3.3 is vulnerable to SQL injection via the 'id' parameter in the signIn endpoint, allowing attackers to manipulate database queries, potentially leading to sensitive data extraction or application compromise.
Service Control Executed from Script Interpreters
2 rules 8 TTPsDetection of Service Control (sc.exe) being spawned from script interpreter processes, such as PowerShell or cmd.exe, to create, modify, or start services, which may indicate privilege escalation or persistence attempts by an attacker.
Signal 'Disappearing' Messages Persist in macOS Notification Center
2 rulesmacOS stores Signal message notifications in an unencrypted SQLite database, potentially exposing 'disappearing' messages even after they are deleted from the Signal application.
SmarterTools SmarterMail Local File Inclusion Vulnerability (CVE-2026-7807)
2 rules 1 TTP 1 CVESmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint (CVE-2026-7807) that allows authenticated users to read arbitrary .json files, potentially leading to credential compromise.
SMB Registry Hive Exfiltration
2 rules 3 TTPsDetection of medium-sized registry hive files being created or modified on Server Message Block (SMB) shares, potentially indicating exfiltration of Security Account Manager (SAM) data for credential extraction.
SourceCodester Pharmacy Sales and Inventory System SQL Injection Vulnerability
2 rules 1 TTP 1 CVECVE-2026-6187 is a remote SQL injection vulnerability in SourceCodester Pharmacy Sales and Inventory System 1.0 via the ID parameter in /ajax.php?action=chk_prod_availability, allowing unauthenticated attackers to execute arbitrary SQL queries.
SP1 V6 Recursion Circuit Row-Count Binding Gap Vulnerability
2 rules 1 TTPA soundness vulnerability in the SP1 V6 recursive shard verifier allows a malicious prover to construct a recursive proof from a shard proof that the native verifier would reject due to inconsistent trace shapes, potentially leading to data forgery and circuit misrepresentation.
Spike in Remote File Transfers via Lateral Movement
2 rules 2 TTPsA machine learning job detects an abnormal volume of remote file transfers, potentially indicating lateral movement by attackers attempting to blend in with normal network egress activity.
Spring Boot Actuator Misconfiguration Leads to Potential SharePoint Exfiltration via Stolen Credentials
2 rules 4 TTPs 1 IOCA threat actor can exploit a misconfigured Spring Boot Actuator to steal credentials and potentially exfiltrate data from SharePoint after bypassing MFA.
Suspicious .NET Code Compilation via Unusual Parent Processes
2 rules 3 TTPsAdversaries may use unusual parent processes to execute .NET compilers for compiling malicious code after delivery, evading security mechanisms, and this activity is detected by monitoring compiler executions initiated by scripting engines or system utilities.
Suspicious Access to LDAP Attributes
2 rules 3 TTPsThe rule detects suspicious access to LDAP attributes in Active Directory by identifying read access to a high number of Active Directory object attributes, which can help adversaries find vulnerabilities, elevate privileges, or collect sensitive information.
Suspicious AWS ECR Container Upload Outside Business Hours
2 rules 1 TTPAn AWS Elastic Container Registry (ECR) container image upload occurring outside of normal business hours can indicate suspicious or malicious activity, such as an attacker attempting to deploy compromised containers.
Suspicious Command Execution via SolarWinds Process
2 rules 3 TTPsThis brief covers the detection of suspicious command execution, specifically Cmd.exe or PowerShell.exe, as child processes of legitimate SolarWinds executables, indicative of potential supply chain compromise and unauthorized command execution on Windows systems.
Suspicious Command Prompt Network Connection
2 rules 4 TTPsThis alert identifies suspicious network connections initiated by the command prompt (cmd.exe) when executed with arguments indicative of script execution, remote resource access, or originating from Microsoft Office applications, which is a common tactic for downloading payloads or establishing command and control.
Suspicious Enumeration Commands Spawned via WMIPrvSE
2 rules 13 TTPsThis rule identifies suspicious activity where enumeration commands are spawned via the Windows Management Instrumentation Provider Service (WMIPrvSE) to gather system and network information.
Suspicious Executable or Script Creation in Uncommon Paths
3 rules 1 TTPDetection of executables or scripts being created in unusual directories on Windows systems, which can be indicative of malware installation or persistence attempts.
Suspicious Execution Patterns with NodeJS Interpreter
3 rules 2 TTPsThis rule detects suspicious execution patterns using the NodeJS interpreter, focusing on process paths and arguments, indicating potential abuse of command and scripting interpreters and obfuscation techniques to evade defenses.
Suspicious Explorer Child Process via DCOM
2 rules 9 TTPsAdversaries abuse the trusted status of explorer.exe to launch malicious scripts or executables, often using DCOM to start processes like PowerShell or cmd.exe, achieving initial access, defense evasion, and execution.