Skip to content
Threat Feed

January 2024 (30)

high advisory

PraisonAI Cloud Run Environment Variable Injection Vulnerability (CVE-2026-40113)

PraisonAI versions before 4.5.128 are vulnerable to arbitrary environment variable injection in Google Cloud Run deployments due to insufficient input validation when constructing the `--set-env-vars` argument, potentially leading to privilege escalation.

PraisonAI cve-2026-40113 cloud environment variable injection privilege escalation
2r 1t 1c
high advisory

PromtEngineer localGPT LLM Prompt Handler Injection Vulnerability (CVE-2026-5002)

A remote code injection vulnerability (CVE-2026-5002) exists in PromtEngineer localGPT versions up to commit 4d41c7d1713b16b216d8e062e51a5dd88b20b054, allowing attackers to execute arbitrary code by manipulating the LLM Prompt Handler component via the _route_using_overviews function in backend/server.py.

localGPT injection llm cve-2026-5002 webserver
2r 1t
medium advisory

Python-Multipart Denial of Service Vulnerability

A denial-of-service vulnerability exists in python-multipart versions prior to 0.0.27 due to unbounded multipart part header parsing, allowing attackers to exhaust CPU resources by sending requests with many repeated headers or a single oversized header value.

python-multipart denial-of-service web-application
2r 1t
critical advisory

Rack::Session::Cookie Vulnerability Enables Secretless Session Forgery

Rack::Session::Cookie incorrectly handles decryption failures, falling back to a default decoder and allowing attackers to forge session cookies without knowing the secret, potentially leading to authentication bypass or privilege escalation in vulnerable Rack applications.

rack-session rack session cookie deserialization vulnerability privilege-escalation
2r 2t 1c
critical advisory

Rapid7 Velociraptor Improper Input Validation Vulnerability

Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability allowing authenticated remote attackers to achieve remote code execution on the server.

Velociraptor rce input-validation linux
2r 1t 1c
high advisory

Registry Modification to Disable .NET ETW Logging

Attackers may modify the Windows registry to disable ETW logging for the .NET Framework, hindering endpoint detection and response capabilities.

Splunk Enterprise +2 defense-evasion registry-modification etw
2r 1t
high advisory

Remcos RAT Activity Detection

This brief outlines detection strategies for Remcos RAT activity, focusing on file and registry artifacts indicative of installation, persistence, and cleanup on compromised Windows systems.

Windows remcos rat malware
3r 3t
high advisory

Remote Registry Lateral Movement via RPC Firewall

This brief details detection of lateral movement attempts using remote RPC calls to modify the registry, potentially leading to code execution, detected via RPC Firewall logs.

lateral-movement defense-impairment persistence rpc
2r 3t
high advisory

Rukovoditel CRM Reflected XSS Vulnerability (CVE-2026-31845)

A reflected XSS vulnerability in Rukovoditel CRM version 3.6.4 and earlier allows unauthenticated attackers to inject malicious JavaScript by reflecting the 'zd_echo' GET parameter, leading to potential session hijacking and account takeover.

Rukovoditel CRM rukovoditel xss cve-2026-31845 web-application
2r 1t 1c
high advisory

RustFS Notification Target Admin API Authorization Bypass

A vulnerability in RustFS allows a non-admin user to overwrite a shared admin-defined notification target, leading to event interception and audit evasion due to missing admin-action authorization on notification target admin API endpoints.

rustfs authorization-bypass ssrf event-interception
2r 3t
high advisory

S3 Browser Used to Create IAM Login Profiles

The S3 Browser utility is being used to enumerate IAM users lacking login profiles and subsequently create them, potentially for reconnaissance, persistence, and privilege escalation within AWS environments.

AWS IAM aws cloud iam s3browser privilege-escalation persistence
2r 2t
critical advisory

Salesforce Marketing Cloud Engagement Argument Injection Vulnerability (CVE-2026-2298)

CVE-2026-2298 is an argument injection vulnerability in Salesforce Marketing Cloud Engagement that allows Web Services Protocol Manipulation in versions prior to January 30th, 2026.

Marketing Cloud Engagement argument-injection web-services salesforce
2r 1t 1i
high advisory

SAT CFDI 3.3 SQL Injection Vulnerability (CVE-2018-25202)

SAT CFDI 3.3 is vulnerable to SQL injection via the 'id' parameter in the signIn endpoint, allowing attackers to manipulate database queries, potentially leading to sensitive data extraction or application compromise.

CFDI cve-2018-25202 sql-injection web-application
2r 1t
low advisory

Service Control Executed from Script Interpreters

Detection of Service Control (sc.exe) being spawned from script interpreter processes, such as PowerShell or cmd.exe, to create, modify, or start services, which may indicate privilege escalation or persistence attempts by an attacker.

Elastic Defend +2 privilege-escalation defense-evasion execution windows service-creation
2r 8t
medium advisory

Signal 'Disappearing' Messages Persist in macOS Notification Center

macOS stores Signal message notifications in an unencrypted SQLite database, potentially exposing 'disappearing' messages even after they are deleted from the Signal application.

Signal macos notification privacy credential-access
2r
high advisory

SmarterTools SmarterMail Local File Inclusion Vulnerability (CVE-2026-7807)

SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint (CVE-2026-7807) that allows authenticated users to read arbitrary .json files, potentially leading to credential compromise.

SmarterMail lfi file-inclusion credential-access
2r 1t 1c
medium advisory

SMB Registry Hive Exfiltration

Detection of medium-sized registry hive files being created or modified on Server Message Block (SMB) shares, potentially indicating exfiltration of Security Account Manager (SAM) data for credential extraction.

Elastic Defend credential-access lateral-movement exfiltration windows
2r 3t
critical advisory

SourceCodester Pharmacy Sales and Inventory System SQL Injection Vulnerability

CVE-2026-6187 is a remote SQL injection vulnerability in SourceCodester Pharmacy Sales and Inventory System 1.0 via the ID parameter in /ajax.php?action=chk_prod_availability, allowing unauthenticated attackers to execute arbitrary SQL queries.

Pharmacy Sales and Inventory System sqli vulnerability web-application
2r 1t 1c
high advisory

SP1 V6 Recursion Circuit Row-Count Binding Gap Vulnerability

A soundness vulnerability in the SP1 V6 recursive shard verifier allows a malicious prover to construct a recursive proof from a shard proof that the native verifier would reject due to inconsistent trace shapes, potentially leading to data forgery and circuit misrepresentation.

SP1 +3 soundness-vulnerability recursive-proof data-forgery
2r 1t
low advisory

Spike in Remote File Transfers via Lateral Movement

A machine learning job detects an abnormal volume of remote file transfers, potentially indicating lateral movement by attackers attempting to blend in with normal network egress activity.

lateral-movement machine-learning
2r 2t
high advisory

Spring Boot Actuator Misconfiguration Leads to Potential SharePoint Exfiltration via Stolen Credentials

A threat actor can exploit a misconfigured Spring Boot Actuator to steal credentials and potentially exfiltrate data from SharePoint after bypassing MFA.

Spring Boot +1 spring-boot actuator sharepoint credential-theft data-exfiltration
2r 4t 1i
medium advisory

Suspicious .NET Code Compilation via Unusual Parent Processes

Adversaries may use unusual parent processes to execute .NET compilers for compiling malicious code after delivery, evading security mechanisms, and this activity is detected by monitoring compiler executions initiated by scripting engines or system utilities.

Microsoft Defender XDR +3 defense-evasion compile-after-delivery windows
2r 3t
low advisory

Suspicious Access to LDAP Attributes

The rule detects suspicious access to LDAP attributes in Active Directory by identifying read access to a high number of Active Directory object attributes, which can help adversaries find vulnerabilities, elevate privileges, or collect sensitive information.

Active Directory active_directory ldap discovery windows
2r 3t
medium advisory

Suspicious AWS ECR Container Upload Outside Business Hours

An AWS Elastic Container Registry (ECR) container image upload occurring outside of normal business hours can indicate suspicious or malicious activity, such as an attacker attempting to deploy compromised containers.

AWS Elastic Container Registry cloud aws ecr container
2r 1t
medium advisory

Suspicious Command Execution via SolarWinds Process

This brief covers the detection of suspicious command execution, specifically Cmd.exe or PowerShell.exe, as child processes of legitimate SolarWinds executables, indicative of potential supply chain compromise and unauthorized command execution on Windows systems.

SolarWinds Orion supply-chain solarwinds command-execution powershell cmd
2r 3t
low advisory

Suspicious Command Prompt Network Connection

This alert identifies suspicious network connections initiated by the command prompt (cmd.exe) when executed with arguments indicative of script execution, remote resource access, or originating from Microsoft Office applications, which is a common tactic for downloading payloads or establishing command and control.

Elastic Defend +7 command-prompt network-connection windows execution command-and-control
2r 4t
medium advisory

Suspicious Enumeration Commands Spawned via WMIPrvSE

This rule identifies suspicious activity where enumeration commands are spawned via the Windows Management Instrumentation Provider Service (WMIPrvSE) to gather system and network information.

Windows enumeration wmi reconnaissance
2r 13t
high advisory

Suspicious Executable or Script Creation in Uncommon Paths

Detection of executables or scripts being created in unusual directories on Windows systems, which can be indicative of malware installation or persistence attempts.

Windows file-creation persistence
3r 1t
high advisory

Suspicious Execution Patterns with NodeJS Interpreter

This rule detects suspicious execution patterns using the NodeJS interpreter, focusing on process paths and arguments, indicating potential abuse of command and scripting interpreters and obfuscation techniques to evade defenses.

NodeJS execution javascript windows
3r 2t
medium advisory

Suspicious Explorer Child Process via DCOM

Adversaries abuse the trusted status of explorer.exe to launch malicious scripts or executables, often using DCOM to start processes like PowerShell or cmd.exe, achieving initial access, defense evasion, and execution.

Microsoft Defender XDR +2 initial-access defense-evasion execution explorer.exe dcom
2r 9t