Skip to content
Threat Feed

January 2024 (30)

high advisory

OpenClaw Inconsistent Host Exec Environment Override Sanitization

OpenClaw versions before 2026.3.22 have an inconsistent host execution environment override sanitization, allowing blocked or malformed override keys to bypass sanitization, which could lead to unauthorized access or code execution.

OpenClaw sanitization vulnerability
2r 1t
high advisory

OpenClaw Remote Filesystem Bridge Sandbox Escape Vulnerability (CVE-2026-41296)

OpenClaw before 2026.3.31 is vulnerable to a time-of-check-time-of-use (TOCTOU) race condition in the remote filesystem bridge readFile function, allowing attackers to bypass sandbox restrictions and read arbitrary files.

OpenClaw cve-2026-41296 sandbox-escape toctou
2r 2t 1c
high advisory

OpenClaw Sandbox Browser CDP Relay Vulnerability Exposing DevTools Protocol

OpenClaw versions prior to 2026.4.10 are vulnerable to a configuration issue where the sandbox browser CDP relay could bind too broadly, exposing Chrome DevTools Protocol access outside the intended local/sandbox source range, potentially allowing unauthorized access to browser DevTools.

openclaw cdp devtools sandbox exposure
2r 2t
high advisory

OpenClaw Symlink Race Condition Allows Sandbox Escape

A time-of-check/time-of-use (TOCTOU) race condition in OpenClaw versions 2026.4.21 and earlier allows a symlink swap to redirect filesystem writes outside the intended sandbox mount root, potentially leading to arbitrary file modification.

openclaw sandbox-escape symlink race-condition npm
1r 1t
high advisory

OpenClaw Synology Chat Reply Delivery Vulnerability

A vulnerability exists in OpenClaw versions prior to 2026.3.22 where Synology Chat reply delivery can be rebound to a mutable username match instead of the stable numeric user_id, potentially leading to information disclosure or privilege escalation.

OpenClaw +1 synology-chat vulnerability
2r
high advisory

OpenHands Command Injection Vulnerability in Git Diff Handler

A command injection vulnerability exists in OpenHands' `get_git_diff()` method, allowing authenticated attackers to execute arbitrary commands in the agent sandbox via the `/api/conversations/{conversation_id}/git/diff` endpoint by exploiting the unsanitized `path` parameter.

OpenHands command-injection web-application
2r 1t
high advisory

OpenRemote Improper Access Control Leads to Privilege Escalation

OpenRemote is vulnerable to privilege escalation, allowing an attacker with write:admin privileges in one Keycloak realm to gain administrator access to the master realm by manipulating Keycloak realm roles due to missing authorization checks in the updateUserRealmRoles function.

openremote-manager privilege-escalation access-control openremote
2r 1t
high advisory

Oracle Life Sciences Empirica Signal CVE-2026-21997 Vulnerability

CVE-2026-21997 allows a low-privileged attacker with network access via HTTP to compromise Oracle Life Sciences Empirica Signal versions 9.2.1-9.2.3, leading to unauthorized data access and modification with potential impact on other products.

Oracle Life Sciences Empirica Signal CVE-2026-21997 oracle empirica-signal vulnerability network
2r 1t 1c
critical advisory

ORY Oathkeeper Authorization Bypass via Path Traversal (CVE-2026-33494)

ORY Oathkeeper versions prior to 26.2.0 are vulnerable to an authorization bypass (CVE-2026-33494) via HTTP path traversal, enabling attackers to access protected resources by crafting URLs with path traversal sequences.

Oathkeeper CVE-2026-33494 ORY Oathkeeper path traversal authorization bypass
2r 1t
critical advisory

Pardus OS My Computer OS Command Injection Vulnerability (CVE-2026-6849)

CVE-2026-6849 is an OS Command Injection vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus OS My Computer versions <=0.7.5 before 0.8.0, allowing an attacker to execute arbitrary OS commands due to improper neutralization of special elements.

Pardus OS My Computer cve-2026-6849 os command injection pardus os
1r 1t 1c
high advisory

Parse Server PostgreSQL Adapter SQL Injection Vulnerability

A SQL injection vulnerability in Parse Server's PostgreSQL adapter allows an attacker with master key access to execute arbitrary SQL statements via crafted field names in aggregate `$group` or `distinct` operations, leading to privilege escalation.

Parse Server sql-injection privilege-escalation parse-server
2r 1t
high advisory

phpMyFAQ Stored XSS Vulnerability in Comment Rendering

A stored XSS vulnerability in phpMyFAQ version 4.1.1 allows an authenticated user to inject JavaScript code into comments, leading to session cookie theft and potential admin account takeover when other users view the affected FAQ or News page.

phpMyFAQ 4.1.1 xss phpmyfaq stored-xss
2r 2t 1i
critical advisory

phpVMS Unauthenticated Access to Legacy Import Feature

A critical vulnerability exists in phpVMS 7.x versions up to 7.0.5, allowing unauthenticated access to a legacy import feature, enabling a remote attacker to trigger internal processes that can modify or delete application data, potentially leading to data loss and service disruption.

phpVMS authorization-bypass data-loss
2r 1t
high advisory

PicoTronica e-Clinic Healthcare System ECHS 5.7 Hardcoded Credentials Vulnerability

PicoTronica e-Clinic Healthcare System ECHS 5.7 is vulnerable to remote hardcoded credential exploitation due to manipulation of the ADMIN_KEY argument in /cdemos/echs/priv/echs.js, potentially leading to unauthorized access.

e-Clinic Healthcare System ECHS 5.7 cve-2026-8032 hardcoded-credentials web-application
2r 1t 1c
high advisory

PingID MFA Bombing Attack

Adversaries attempt to bypass multi-factor authentication by flooding users with push notifications, hoping they will eventually accept a fraudulent request, potentially leading to unauthorized access.

PingID mfa credential-access defense-evasion
1r 3t
high advisory

PocketMine-MP LogDoS via Malformed Login Packet

Attackers can cause a denial-of-service on PocketMine-MP servers by sending a crafted Minecraft LoginPacket containing large or complex structures in the clientData JWT body, leading to excessive logging and potential server crashes.

PocketMine-MP minecraft logdos denial-of-service
2r 1t
medium advisory

Potential Credential Access via DCSync

This rule identifies when a User Account starts the Active Directory Replication Process, potentially indicating a DCSync attack, which allows attackers to steal credential information compromising the entire domain.

Azure AD Connect credential-access privilege-escalation windows active-directory
2r 3t
high advisory

Potential Credential Access via MSBuild Loading Credential Management DLLs

The detection rule identifies a potential credential access attempt via the trusted developer utility MSBuild by detecting instances where it loads DLLs associated with Windows credential management, specifically vaultcli.dll or SAMLib.DLL, which is often used for credential dumping.

MSBuild +2 credential-access defense-evasion windows
2r 1t
high advisory

Potential Credential Access via Renamed COM+ Services DLL

Detection of renamed COMSVCS.DLL being loaded by rundll32.exe, potentially used to dump LSASS memory for credential access while evading command-line detection.

Windows credential-access defense-evasion
2r 3t 1i
high threat

Potential CVE-2025-33053 Exploitation via Internet Explorer Diagnostics

Exploitation of CVE-2025-33053 via a malicious URL file can lead to the spawning of suspicious child processes from the Internet Explorer Diagnostics Utility (iediagcmd.exe), enabling initial access, defense evasion, and execution of arbitrary commands.

exploited Internet Explorer cve-2025-33053 initial-access defense-evasion execution windows
2r 5t 1c
medium advisory

Potential Data Exfiltration Through Curl

This rule detects potential data exfiltration attempts on Linux systems using the curl command-line tool to upload files to external servers, potentially indicating unauthorized data transfer.

curl +1 data-exfiltration linux
2r 1t
critical advisory

Potential Invoke-Mimikatz PowerShell Script

This rule detects the use of Invoke-Mimikatz or Mimikatz commands within PowerShell scripts to dump credentials, extract password stores, export certificates, or use alternate authentication material, indicating potential in-memory credential access.

winlogbeat-* credential-access mimikatz powershell
2r 1t
medium advisory

Potential Kubeletctl Execution on Linux Hosts

This rule detects the execution of kubeletctl, a command-line tool used to interact with the Kubelet API, on Linux hosts, potentially leading to discovery and lateral movement within Kubernetes environments.

Kubernetes kubeletctl container linux
2r 3t
low advisory

Potential Secure File Deletion via SDelete Utility

This rule detects file name patterns generated by the use of Sysinternals SDelete utility, which attackers may abuse to delete forensic indicators and hinder recovery efforts after ransomware or data theft.

SDelete defense-evasion impact windows
2r 2t
high advisory

PowerShell Keylogging Script Detection

This brief documents a high-severity threat involving PowerShell scripts used for keylogging on Windows systems to capture credentials and sensitive user input.

Windows +1 keylogger powershell collection
2r 1t
medium advisory

PowerShell Script Block Logging Disabled via Registry Modification

Attackers may disable PowerShell Script Block Logging by modifying the registry to evade detection and conceal their activities on the host, detected by monitoring changes to the `EnableScriptBlockLogging` registry value.

PowerShell +1 defense-evasion windows
2r 2t
high advisory

PowerShell Used to Disable Windows Defender Security Monitoring

This analytic identifies attempts to disable Windows Defender real-time behavior monitoring via PowerShell commands using `Set-MpPreference`, commonly used by malware to evade detection and potentially leading to data exfiltration or system compromise.

Windows Defender defense-evasion powershell windows-defender
2r 1t
high advisory

PowerShell Windows Defender Exclusion Commands

Attackers use PowerShell commands with `Add-MpPreference` or `Set-MpPreference` to create Windows Defender exclusions, allowing malware to execute undetected.

Windows Defender powershell windows-defender exclusion defense-evasion
2r 1t
high advisory

PraisonAI Agents SSRF Vulnerability in Web Crawl Tool

The praisonaiagents library is vulnerable to Server-Side Request Forgery (SSRF) due to missing URL validation in the `web_crawl` tool's httpx fallback, potentially allowing attackers to access internal services or cloud metadata endpoints.

PraisonAI Agents ssrf praisonai ai-agent cloud
2r 1t 2i
high advisory

PraisonAI Arbitrary Code Execution Vulnerability (CVE-2026-40156)

PraisonAI versions before 4.5.128 are vulnerable to arbitrary code execution due to the automatic loading and execution of a 'tools.py' file from the current working directory without proper validation or user consent, potentially allowing attackers to execute malicious code by placing a rogue file in a PraisonAI execution directory.

PraisonAI cve-2026-40156 code-execution
2r 1t 1c