Skip to content
Threat Feed

January 2024 (30)

medium advisory

Linux Auditd Daemon (Re)Initialization Detection

Detection of Linux audit daemon (auditd) re-initialization events, which can indicate attempts to re-enable audit logging after evasion or restarts with modified rule sets.

Splunk Enterprise +4 linux auditd anomaly
3r 1t
high advisory

Linux BPF Program Tampering for Defense Evasion

Attackers can manipulate or tamper with Berkeley Packet Filter (BPF) programs on Linux systems to evade detection or analysis by security tools that rely on BPF for monitoring and security enforcement.

Linux Kernel defense-evasion bpf linux kernel
2r 1t
high advisory

Linux Credential Access via Sensitive File Monitoring

This rule detects potential credential access attempts on Linux systems by monitoring access to sensitive files commonly containing credentials or configuration information.

Linux credential_access file_monitoring
2r 1t
critical advisory

Livemesh Addons for Elementor Plugin LFI Vulnerability (CVE-2026-1620)

The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion (LFI) due to insufficient sanitization of the template name parameter, allowing authenticated attackers to include and execute arbitrary files on the server.

Livemesh Addons for Elementor wordpress lfi cve-2026-1620 elementor
2r 1t 1c
high advisory

livewire-markdown-editor Arbitrary File Upload Vulnerability

The livewire-markdown-editor versions before v1.3 contain an arbitrary file upload vulnerability in the MarkdownEditor::updatedAttachments() Livewire handler, allowing authenticated users to upload any file type, potentially leading to stored XSS, phishing, malware distribution, and markdown injection.

mckenziearts/livewire-markdown-editor +3 arbitrary-file-upload stored-xss vulnerability
2r 1t
high advisory

LMDeploy Vision-Language Module SSRF Vulnerability

A server-side request forgery (SSRF) vulnerability exists in LMDeploy's vision-language module, allowing attackers to access cloud metadata services and internal networks by exploiting the lack of URL validation in the `load_image()` function.

LMDeploy ssrf vulnerability
2r 1t 1c 4i
high advisory

locize Client SDK Cross-Origin DOM XSS and Handler Hijack Vulnerability

The locize client SDK versions prior to 4.0.21 are vulnerable to cross-origin DOM XSS and handler hijack due to missing origin validation in the InContext Editor, allowing attackers to inject malicious code and exfiltrate data via crafted postMessage events.

locize client SDK xss dom-xss postMessage locize javascript
2r 1t
medium advisory

LSASS Memory Dump Creation Detection

This rule identifies the creation of LSASS memory dump files, often indicative of credential access attempts using tools like Task Manager, SQLDumper, Dumpert, or AndrewSpecial, by monitoring for specific filenames and excluding legitimate dump locations.

Elastic Defend +4 credential_access lsass memory_dump windows
2r 1t
medium advisory

LSASS Shtinkering Detection via Full User-Mode Dump Configuration

Detection of the enabling of full user-mode dumps system-wide, a setting change leveraged in LSASS Shtinkering attacks to dump LSASS process memory and steal credentials.

Windows credential-access lsass registry
2r 2t
medium advisory

Mac File Opener Adware Persists via Document Handler Registration

The 'Mac File Opener' adware achieves persistence by registering itself as a document handler for numerous file types, leveraging the Launch Services Daemon (lsd) to automatically parse the application's Info.plist and register the handlers.

macOS adware persistence
2r 1t
medium advisory

macOS DNS Request for IP Lookup Service via Unsigned Binary

An unsigned or untrusted binary on macOS is performing DNS requests for IP lookup services to determine the system's external IP address, which is commonly used by malware for reconnaissance before establishing C2 connections.

macOS discovery dns reconnaissance unsigned_binary
2r 1t 42i
high advisory

mailcow: dockerized Second-Order SQL Injection Vulnerability (CVE-2026-40871)

A second-order SQL injection vulnerability (CVE-2026-40871) exists in mailcow: dockerized versions prior to 2026-03b due to improper validation of the quarantine_category field in the /api/v1/add/mailbox endpoint, leading to potential exfiltration of sensitive data.

mailcow: dockerized sql-injection mailcow cve-2026-40871 webserver
2r 1t 1c
high advisory

Malicious MSC File Creation in Mock Trusted Directory

The creation of MSC files within a 'C:\Windows \System32' directory can be exploited to execute malicious files due to path parsing vulnerabilities in Windows, potentially leading to privilege escalation, persistence, and defense evasion.

Splunk Enterprise +2 defense-evasion privilege-escalation persistence windows
2r 3t
critical advisory

MantisBT Authentication Bypass via SOAP API on MySQL

MantisBT instances running on MySQL are vulnerable to an authentication bypass in the SOAP API due to improper type checking on the password parameter, allowing attackers with a valid username to log in without the actual password.

MantisBT authentication-bypass soap-api
3r 1t
medium advisory

Masquerading Business Application Installers

Attackers masquerade malicious executables as legitimate business application installers to trick users into downloading and executing malware, leveraging defense evasion and initial access techniques.

Elastic Defend +22 masquerading defense-evasion initial-access malware windows
2r 4t
high advisory

mcp-ssh-tool Path Traversal and Timing Attack Vulnerabilities

mcp-ssh-tool versions 2.1.0 and earlier have a policy bypass in transfer path handling and expose a timing side channel in bearer-token comparison for HTTP deployments, addressed in version 2.1.1.

mcp-ssh-tool path-traversal timing-attack
2r
high advisory

Microsoft APM CLI Path Traversal Vulnerability

Microsoft APM CLI version 0.8.11 and earlier are vulnerable to path traversal, allowing a malicious plugin to copy arbitrary readable host files during installation by manipulating paths in the plugin.json file.

apm-cli path-traversal supply-chain
2r 1t
medium advisory

Microsoft Defender ATP Alert Aggregation and Correlation

This analytic aggregates and summarizes alerts from Microsoft Defender ATP, enriching them with MITRE ATT&CK context and risk scoring for improved correlation and risk-based alerting.

Microsoft Defender ATP endpoint alert-correlation risk-based-alerting
2r
medium advisory

Microsoft Devtunnels Image Load Detection

This detection identifies potential misuse of Microsoft Devtunnels within Visual Studio by detecting image load events, indicating that an attacker could expose a compromised system or service to the internet for covert communication and data exfiltration.

Visual Studio +3 devtunnels reverse-proxy command-and-control data-exfiltration windows
2r 2t
high advisory

Microsoft Diagnostics Troubleshooting Wizard (MSDT) Proxy Execution Abuse

The Microsoft Diagnostics Troubleshooting Wizard (MSDT) can be abused to proxy malicious command or binary execution via malicious process arguments, potentially leading to defense evasion and arbitrary code execution.

Microsoft Diagnostics Troubleshooting Wizard +1 defense-evasion proxy-execution msdt
2r 3t 1c
low advisory

Microsoft Graph API Request User Impersonation by Unusual Client

Detection of the first-time use of a Microsoft Graph API request by a specific client application ID, user principal object ID, and tenant ID, potentially indicating unauthorized access via phishing, token theft, or OAuth abuse.

Microsoft Graph API +1 cloud azure graphapi initial_access
2r 2t
medium advisory

Microsoft IIS Service Account Password Dump via AppCmd

An attacker with IIS web server access via a web shell can extract service account passwords by requesting full configuration output or targeting credential-related fields using the AppCmd tool.

IIS credential-access appcmd windows
2r 2t
medium advisory

Microsoft Outlook VBA Template Persistence

Attackers establish persistence by installing a malicious VBA template in Microsoft Outlook, triggering scripts upon application startup by modifying the VBAProject.OTM file.

Outlook persistence vba windows
2r 1t
critical advisory

Microsoft SharePoint Server Elevation of Privilege via CVE-2023-29357

Exploitation attempts against Microsoft SharePoint Server vulnerability CVE-2023-29357, involving specific API calls and HTTP methods, can lead to privilege escalation and unauthorized access to sensitive data within the SharePoint environment.

SharePoint Server sharepoint elevation_of_privilege cve-2023-29357
2r 1t
high advisory

MLOps_MCP Path Traversal Vulnerability (CVE-2026-7213)

A path traversal vulnerability exists in ef10007 MLOps_MCP version 1.0.0, allowing a remote attacker to manipulate the 'filename/destination' argument in the 'save_file Tool' component's 'fastmcp_server.py' file.

MLOps_MCP 1.0.0 path-traversal web-application cve-2026-7213
2r 1t 1c
medium advisory

Mod_gnutls Certificate Chain Overflow Vulnerability (CVE-2026-33307)

Mod_gnutls versions prior to 0.12.3 and 0.13.0 are vulnerable to a certificate chain overflow when verifying client certificates, potentially leading to a segfault or stack corruption.

Mod_gnutls apache tls certificate-overflow cve-2026-33307 denial-of-service
2r 3t
high advisory

Modification of WDigest Security Provider

The rule detects attempts to modify the WDigest security provider in the registry to force the user's password to be stored in clear text in memory, which could lead to credential dumping.

Windows +2 credential-access registry-modification
2r 1t
high advisory

Modoboa <= 2.7.0 OS Command Injection Vulnerability

Modoboa versions 2.7.0 and earlier are vulnerable to OS command injection, allowing a Reseller or SuperAdmin to execute arbitrary OS commands on the server by injecting shell metacharacters into a domain name due to unsanitized input in the `exec_cmd()` function.

Modoboa command-injection code-execution
2r 1t
medium advisory

Mounting of Hidden or WebDav Remote Shares via Net Utility

Adversaries may leverage the `net.exe` utility to mount WebDav or hidden remote shares, potentially indicating lateral movement, data exfiltration preparation, or initial access via discovery of accessible shares.

Elastic Defend +2 lateral-movement data-exfiltration windows
2r 4t
critical advisory

MPP Multiple Payment Bypass and Griefing Vulnerabilities

Multiple vulnerabilities were discovered in mpp versions prior to 0.8.0 that allowed for payment bypass and griefing, including performing free charge and session requests, replaying existing charge requests, piggybacking and griefing existing session channels, manipulating fee payers, and replaying stripe charge requests.

mpp payment-bypass griefing rust
2r