Skip to content
Threat Feed

January 2024 (30)

medium advisory

BITS Transfer Job With Uncommon or Suspicious Remote TLD

Adversaries abuse Background Intelligent Transfer Service (BITS) to download malicious payloads from unusual top-level domains, bypassing traditional security measures and establishing persistence on compromised systems.

Windows attack.defense-evasion attack.persistence attack.t1197
2r 2t
medium advisory

Brizy WordPress Plugin Unauthenticated Stored XSS Vulnerability

The Brizy – Page Builder plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting (XSS) in versions up to and including 2.8.11, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the form Leads page due to missing nonce verification and improper handling of file upload fields.

Brizy – Page Builder plugin <= 2.8.11 wordpress xss unauthenticated
2r 1t 1c
high advisory

Budibase XSS Leads to Account Takeover via JWT Theft

The `budibase:auth` cookie in Budibase is set without the `httpOnly` flag, enabling attackers with XSS to steal JWTs and gain persistent access to user accounts.

Budibase xss account takeover jwt cookie
2r 1t
high advisory

Canias ERP Authentication Bypass Vulnerability (CVE-2026-8216)

CVE-2026-8216 is a remote improper authentication vulnerability in the iasServerRemoteInterface.doAction function of the Java RMI Session Management component of Industrial Application Software IAS Canias ERP 8.03.

Canias ERP 8.03 cve authentication-bypass erp
2r 1t 1c
high advisory

cbor2 Denial of Service via Uncontrolled Recursion

The cbor2 library is vulnerable to a Denial of Service (DoS) attack due to uncontrolled recursion when decoding deeply nested CBOR structures, allowing a remote attacker to crash worker processes with crafted CBOR payloads.

cbor2 denial-of-service recursion-error python
2r 1t
high advisory

choieastsea simple-openstack-mcp OS Command Injection Vulnerability (CVE-2026-7066)

The choieastsea simple-openstack-mcp application is vulnerable to OS command injection via the exec_openstack function in server.py, allowing remote attackers to execute arbitrary commands.

simple-openstack-mcp command-injection vulnerability openstack
3r 1t 1c
high threat

Chrome Credential Theft via Password Store Copying

The Braodo stealer and other malware copy Chrome's Local State and Login Data files to temporary directories to steal encrypted user credentials.

Chrome Braodo Stealer credential-access malware windows
2r 1t
high advisory

CI4MS .env File Injection Vulnerability (CVE-2026-39394)

CI4MS versions prior to 0.31.4.0 are vulnerable to .env file injection via the Install::index() controller due to insufficient input validation and bypassed CSRF protection, allowing attackers to inject arbitrary configuration directives.

CI4MS codeigniter env-injection cve-2026-39394
2r 1t 1c
critical advisory

CI4MS Theme Upload Zip Slip Vulnerability

A critical vulnerability exists in ci4ms Theme::upload, where improper validation of ZIP archive entry names allows authenticated users with theme creation permissions to write files to arbitrary locations, leading to remote code execution.

ci4-cms-erp/ci4ms zip-slip rce codeigniter vulnerability
2r 2t
medium advisory

CircleCI Security Job Disablement Detection

Detection of activity related to disabling security jobs within CircleCI, potentially indicating an attempt to bypass security controls in a CI/CD pipeline.

CircleCI ci/cd supply-chain
2r 1t
high advisory

Cisco ASA AAA Policy Tampering

Unauthorized modifications to Cisco ASA AAA policies via CLI or ASDM can weaken authentication mechanisms, potentially enabling brute-force attacks, privilege escalation, and persistent access by malicious actors.

Cisco Adaptive Security Appliance cisco-asa aaa-policy privilege-escalation persistence
2r 3t
high advisory

Cisco ASA Logging Disabled via CLI

Detection of adversaries or malicious insiders disabling logging on a Cisco ASA device via CLI commands, hindering detection and hiding malicious activity.

Cisco ASA cisco_asa logging defense_evasion network
2r 1t
high advisory

Cisco ASA Packet Capture Activity

Detection of packet capture commands on Cisco ASA devices indicates potential network sniffing for credential theft, sensitive data interception, or network traffic analysis by adversaries.

Cisco ASA cisco_asa network_sniffing credential_access
2r 2t
medium advisory

Cisco Duo Policy Allowing Outdated Flash Usage

A Cisco Duo administrator may create or update a policy to allow the use of outdated Flash components, potentially increasing the attack surface by allowing exploitation of Flash vulnerabilities.

Cisco Duo +1 cisco_duo policy_change outdated_software
2r 1t
medium advisory

Cisco Duo Policy Change to Allow Devices Without Screen Lock

A Splunk detection analytic identifies when a Duo policy is created or updated to allow devices without a screen lock, potentially weakening device security controls and increasing the risk of unauthorized access and data breaches.

Duo cisco-duo screen-lock policy-change
2r 1t
high advisory

Cisco IKEv2 Memory Leak Vulnerability (CVE-2026-20012)

CVE-2026-20012 is a vulnerability in the IKEv2 feature of multiple Cisco products that allows an unauthenticated remote attacker to cause a denial of service by sending crafted IKEv2 packets leading to memory exhaustion.

Cisco IOS Software +3 cve-2026-20012 denial-of-service cisco ikev2
2r 2t
high advisory

Cisco IOS XE Software TLS Memory Exhaustion Vulnerability (CVE-2026-20004)

CVE-2026-20004 is a vulnerability in the TLS library of Cisco IOS XE Software that allows an unauthenticated, adjacent attacker to exhaust device memory, leading to denial of service.

Cisco IOS XE Software cisco ios xe tls denial of service memory exhaustion
2r 1t
medium advisory

Cloud API Calls From Previously Unseen User Roles

This analytic identifies anomalous cloud API calls executed by user roles that have not previously performed those commands, potentially indicating malicious activity or unauthorized actions leading to unauthorized access or data breaches.

Amazon Web Services cloud aws anomaly assumedrole
2r 2t
critical advisory

CodeChecker Authentication Bypass Vulnerability

An authentication bypass vulnerability exists in CodeChecker for certain API calls, allowing unauthenticated users to execute function calls with arbitrary arguments, potentially granting superuser permissions to an attacker.

codechecker authentication-bypass privilege-escalation web-application
2r 1t 1c
low advisory

Component Object Model (COM) Hijacking via Registry Modification

This rule detects Component Object Model (COM) hijacking via registry modification, where adversaries establish persistence by executing malicious content triggered by hijacked references to COM objects.

Windows persistence defense-evasion privilege-escalation com-hijacking
2r 4t
high advisory

Connect CMS Improper Authorization Vulnerability

An improper authorization vulnerability in Connect CMS allows authenticated users to modify arbitrary user profile information, potentially leading to account takeover and unauthorized data modification on affected versions 1.x <= 1.41.0 and 2.x <= 2.41.0.

Connect CMS connect-cms authorization account-takeover web-application
2r 1t
critical advisory

Convict NPM Package Prototype Pollution Vulnerability

The `convict` npm package is vulnerable to prototype pollution via the `load()`, `loadFile()`, and schema initialization functions, allowing attackers to overwrite properties on `Object.prototype` by supplying malicious input, potentially leading to unexpected behavior, authentication bypass, or remote code execution, affecting versions 6.2.4 and earlier.

convict prototype-pollution npm
2r
high advisory

Craft CMS Authenticated Remote Code Execution via Malicious Attached Behavior

Craft CMS versions before 4.17.12 and 5.9.18 are vulnerable to authenticated remote code execution via malicious behavior injection in the field layout hydration path.

cms +1 craft-cms rce vulnerability
2r 2t
high advisory

Creation or Modification of Domain Backup DPAPI Private Keys

Detection of creation or modification of Domain Backup private keys, which adversaries may extract from a Domain Controller (DC) to decrypt domain user master key files.

Elastic Defend +2 credential-access dpapi domain-controller
3r 1t
medium advisory

CVE-2017-3735 Vulnerability Targeting Microsoft Products

CVE-2017-3735 is a vulnerability impacting Microsoft products, potentially allowing unauthorized access or code execution.

vulnerability microsoft cve-2017-3735
2r 1t 1c
high advisory

CVE-2018-0735 ECDSA Signature Generation Timing Attack

CVE-2018-0735 is a timing attack vulnerability in ECDSA signature generation affecting Microsoft products, potentially allowing attackers to recover private keys.

ecdsa timing-attack cryptography
2r 1t 1c
high advisory

CVE-2026-27923 Use-After-Free in Desktop Window Manager

A use-after-free vulnerability, CVE-2026-27923, in the Desktop Window Manager allows an authorized attacker with local access to escalate privileges.

Windows use-after-free privilege-escalation
2r 1t 1c 1i
critical advisory

CVE-2026-34275 - Oracle Advanced Inbound Telephony Unauthenticated Remote Code Execution

CVE-2026-34275 allows an unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Inbound Telephony versions 12.2.3-12.2.15, potentially leading to a complete takeover of the application.

Oracle Advanced Inbound Telephony +1 oracle e-business-suite ait cve-2026-34275 rce
2r 1t 1c
high advisory

CVE-2026-4722 - Mozilla Firefox and Thunderbird Privilege Escalation

CVE-2026-4722 is a privilege escalation vulnerability in the IPC component of Mozilla Firefox and Thunderbird versions less than 149, potentially allowing an attacker to gain elevated privileges on a compromised system.

Firefox +1 cve-2026-4722 privilege-escalation mozilla thunderbird
2r 1t 1i
high advisory

CVE-2026-6315 Use-After-Free Vulnerability in Google Chrome on Android

A use-after-free vulnerability in Google Chrome on Android prior to version 147.0.7727.101 (CVE-2026-6315) allows remote attackers to execute arbitrary code by convincing a user to interact with a crafted HTML page through specific UI gestures.

Chrome use-after-free android cve-2026-6315 remote-code-execution
2r 2t 1c