Skip to content
Threat Feed

January 2024 (30)

high advisory

ESXi Loghost Configuration Tampering

An attacker modifies the ESXi host's syslog configuration to disrupt log forwarding, potentially evading detection and hindering incident response.

ESXi +3 syslog loghost tampering defense-evasion
2r 1t
medium advisory

ESXi VM Discovery via ESXCLI Commands

Adversaries may use ESXCLI commands to discover virtual machines on an ESXi host, potentially indicating reconnaissance for high-value targets, environment mapping, or preparation for data theft or destructive operations.

VMware ESXi esxi vmware discovery
2r
critical advisory

ExactMetrics WordPress Plugin Vulnerability Leads to Remote Code Execution

The ExactMetrics plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation via a REST API endpoint, potentially leading to remote code execution by authenticated attackers.

ExactMetrics – Google Analytics Dashboard for WordPress wordpress plugin rce cve-2026-5464 exactmetrics
2r 4t 1c
medium advisory

Excessive OneDrive File Downloads Detection

Detection of unusual high-volume file downloads from Microsoft OneDrive, potentially indicating data exfiltration by a compromised account or insider threat.

OneDrive data-exfiltration cloud
2r 1t
high advisory

fast-uri Path Traversal Vulnerability via Percent-Encoded Dot Segments

fast-uri versions 3.1.0 and earlier are vulnerable to path traversal due to decoding percent-encoded path separators and dot segments before dot-segment removal, potentially leading to bypasses of path-based policy enforcement.

fast-uri path-traversal defense-evasion javascript
2r 1t 1c
high advisory

FastlyMCP Command Injection Vulnerability (CVE-2026-7220)

A command injection vulnerability (CVE-2026-7220) exists in jackwrichards FastlyMCP allowing remote attackers to execute arbitrary OS commands by manipulating the command argument in the fastly-mcp.mjs file.

FastlyMCP command-injection cve-2026-7220 fastly-mcp
2r 1t 1c
critical advisory

FHIR Validator SSRF via /loadIG Leads to Credential Theft

The FHIR Validator HTTP service is vulnerable to server-side request forgery (SSRF) via the `/loadIG` endpoint, enabling attackers to steal authentication tokens by exploiting a prefix-matching flaw in the credential provider.

FHIR Validator ssrf fhir credential-theft vulnerability
2r 2t 1i
medium advisory

File with Right-to-Left Override Character (RTLO) Created/Executed

This rule detects the creation or execution of files or processes with names containing the Right-to-Left Override (RTLO) character, which can be used to disguise the file extension and trick users into executing malicious files on Windows systems.

Elastic Defend +2 defense-evasion rtlo masquerading windows
2r 2t
high threat

FIN7 DGA Command and Control Behavior Detection

This rule detects command and control activity associated with the FIN7 threat group, which is known to use domain generation algorithms (DGA) to maintain persistence in their target's network by identifying network traffic using TLS or HTTP protocols to domains with a specific pattern.

FIN7 +2 command-and-control dga network_traffic
3r 2t
medium advisory

Firebird Database Server Denial-of-Service Vulnerability (CVE-2026-28212)

An unauthenticated attacker can cause a denial-of-service condition on vulnerable Firebird database servers by sending a specially crafted network packet that triggers a null pointer dereference.

Firebird denial-of-service cve-2026-28212
2r 1t 1c
high advisory

Firewall Rule Manipulation via COM API

A tool enables threat actors to add, remove, or query Windows Firewall rules via the COM API (INetFwPolicy2), bypassing traditional command-line tools and potentially evading detection.

Windows Firewall firewall defense-evasion lateral-movement
2r 1t
medium advisory

First Time Seen AWS Secret Value Accessed in Secrets Manager

This rule detects the first time a specific user identity has programmatically retrieved a secret value from AWS Secrets Manager using the GetSecretValue action, which may indicate a compromised AWS service attempting to access secrets.

AWS Secrets Manager cloud aws credential-access
2r 1t
high advisory

free5GC SMF Unauthenticated State-Mutating Panic-DoS Vulnerability

free5GC's SMF is vulnerable to an unauthenticated denial-of-service attack where a crafted DELETE request to the /upi/v1/upNodesLinks/{ref} endpoint triggers a nil-pointer dereference, causing a panic and mutating the in-memory user-plane topology, impacting the selection of UPFs for legitimate UE sessions.

free5GC SMF free5GC dos vulnerability
2r 2t 2i
high advisory

FuelCMS Vulnerability Report

A vulnerability in FuelCMS has been reported, details available at pentesttools.com/blog/throwing-a-spark-in-fuelcms, potentially allowing attackers to compromise vulnerable systems.

FuelCMS vulnerability cms
2r 2t 1i
low advisory

GCP Firewall Rule Creation for Defense Evasion

An adversary may create a new firewall rule in Google Cloud Platform (GCP) for Virtual Private Cloud (VPC) or App Engine to weaken their target's security controls and allow more permissive ingress or egress traffic flows for their benefit, indicating a defense evasion attempt.

Google Cloud Platform +2 gcp firewall defense_evasion
2r 1t
medium advisory

GCP Firewall Rule Deletion for Defense Evasion

The deletion of firewall rules in Google Cloud Platform (GCP) for Virtual Private Cloud (VPC) or App Engine is detected, potentially weakening security controls and enabling unauthorized access or data exfiltration by adversaries.

Google Cloud Platform +2 cloud defense-evasion gcp
2r 1t
low advisory

GCP IAM Service Account Key Deletion

Detection of Identity and Access Management (IAM) service account key deletion in Google Cloud Platform (GCP), potentially indicating malicious activity such as disrupting services or covering tracks after unauthorized access.

Google Cloud Platform cloud gcp iam persistence impact
2r 2t
high advisory

GCP Multi-Factor Authentication Disabled

Detection of disabled multi-factor authentication (MFA) for a Google Cloud Platform (GCP) user, potentially leading to unauthorized access and data exfiltration.

Google Cloud Platform +1 cloud gcp mfa persistence defense-evasion
2r 2t
high advisory

GCP Password Spraying Detection

A single source IP is failing to authenticate into Google Workspace with multiple valid users, potentially indicating a Password Spraying attack.

Google Workspace gcp password-spraying cloud
2r 2t
low advisory

GCP Service Account Creation for Persistence

Successful creation of a new service account in Google Cloud Platform (GCP) can indicate malicious persistence, as adversaries may create these accounts to evade detection by avoiding standard user accounts.

Google Cloud Platform cloud gcp persistence iam
2r 1t
high advisory

geekgod382 filesystem-mcp-server Path Traversal Vulnerability (CVE-2026-7400)

A path traversal vulnerability exists in geekgod382 filesystem-mcp-server version 1.0.0 allowing remote attackers to access unauthorized files due to insufficient path validation in the is_path_allowed function.

filesystem-mcp-server path-traversal web-application cve-2026-7400
2r 1t 1c
high advisory

GeekyBot WordPress Plugin Vulnerable to SQL Injection

The GeekyBot WordPress plugin is vulnerable to SQL Injection, allowing unauthenticated attackers to extract sensitive information from the database by manipulating the 'attributekey' parameter.

The GeekyBot - Generate AI Content Without Prompt, Chatbot and Lead Generation plugin <= 1.2.0 sqli wordpress plugin cve-2026-3456
2r 1t 1c
high advisory

Gigabyte Control Center Insecure Deserialization Privilege Escalation (CVE-2026-4416)

A local, authenticated attacker can exploit an insecure deserialization vulnerability in the Gigabyte Control Center's Performance Library component by sending a malicious serialized payload to the EasyTune Engine service, leading to privilege escalation.

Control Center insecure-deserialization privilege-escalation windows
2r 1t
high advisory

GitHub Enterprise 2FA Requirement Disabled

Detection of two-factor authentication (2FA) being disabled in GitHub Enterprise, potentially weakening account security and facilitating unauthorized access by threat actors.

GitHub Enterprise github 2fa defense-evasion initial-access
2r 2t
high advisory

GitHub Enterprise Dependabot Disablement

An attacker disables Dependabot in a GitHub repository to prevent automatic vulnerability detection, potentially leading to exploitation of unpatched dependencies and supply chain compromise.

GitHub Enterprise github dependabot supply-chain defense-evasion
3r 2t
high advisory

GitHub Organization Repository Deletion

Anomalous deletion of a GitHub organization repository can indicate malicious activity aimed at destroying source code, intellectual property, or evidence of compromise, potentially stemming from account compromise, insider threats, or business disruption attempts.

GitHub Organizations github repository deletion impact
1r 2t
low advisory

GitHub Secret Scanning Disabled

Detection of disabled GitHub Secret Scanning on a repository, indicating potential defense evasion by attackers seeking to introduce and exploit hardcoded secrets.

GitHub cloud defense-evasion
2r 1t
high advisory

GitPilot-MCP Command Injection Vulnerability (CVE-2026-6980)

A command injection vulnerability (CVE-2026-6980) in Divyanshu-hash GitPilot-MCP up to version 9ed9f153ba4158a2ad230ee4871b25130da29ffd allows remote attackers to execute arbitrary commands by manipulating the 'command' argument in the repo_path function of main.py, and public exploit code is available.

GitPilot-MCP command-injection web-application cve
2r 1t 1c
high advisory

GitPython config_writer().set_value() Newline Injection RCE

A newline injection vulnerability in GitPython's `config_writer().set_value()` function enables remote code execution by manipulating the `core.hooksPath` Git configuration.

GitPython newline injection remote code execution config poisoning
2r 1t
high advisory

Glances Command Injection Vulnerability via Dynamic Configuration

Glances versions 4.5.2 and earlier are vulnerable to command injection via dynamic configuration values, allowing arbitrary command execution with the privileges of the Glances process if an attacker can modify or influence configuration files, potentially leading to privilege escalation.

Glances command-injection privilege-escalation cve-2026-33641
2r 2t