Skip to content
Threat Feed

January 2024 (30)

low advisory

AWS EventBridge Rule Disabled or Deleted

Detection of Amazon EventBridge rule disabling or deletion events, which can disrupt operational workflows and security monitoring.

EventBridge aws impact defense-evasion
2r 2t
high advisory

AWS GuardDuty IP Set Manipulation for Defense Impairment

An attacker modifies AWS GuardDuty IP sets, potentially whitelisting malicious IPs to disable security alerts and impair defenses.

AWS GuardDuty defense-impairment aws
2r 1t
low advisory

AWS IAM Group Deletion Detected

Detection of AWS IAM group deletion via the DeleteGroup API call, which may indicate an attacker removing audit trails, disrupting operations, or concealing privileged access activity.

IAM aws cloudtrail impact account-access-removal
2r 1t
medium advisory

AWS IAM Key Creation with Encryption Policy but Without MFA

Detection of AWS IAM users creating access keys with encryption policies applied while failing to use multi-factor authentication, potentially indicating compromised accounts or malicious privilege escalation.

Identity and Access Management aws iam access_key encryption mfa
2r 2t
medium advisory

AWS IAM Operations via Compromised CloudShell

Compromised AWS console sessions can lead to attackers performing sensitive IAM operations via CloudShell to establish persistence or escalate privileges.

AWS CloudShell +2 cloudshell aws iam persistence privilege-escalation
2r 4t
medium advisory

AWS IAM SAML Provider Creation for Persistence

Detects the creation of a new SAML Identity Provider (IdP) in AWS IAM, potentially indicating an adversary establishing persistent, federated access to AWS accounts by forging SAML assertions from an IdP they control.

IAM aws saml persistence cloud
3r 3t
high advisory

AWS Management Console Brute Force of Root User Identity

Detection of a high number of failed login attempts to the AWS Management Console targeting the root user, which can indicate a brute-force attack to gain complete access to the AWS account.

AWS Management Console aws brute-force credential-access
2r 1t
medium advisory

AWS Management Console Root Login Detected

Detection of a successful AWS Management Console login by the Root user, which is an original identity with unrestricted privileges, indicates a potential security breach requiring immediate investigation.

AWS Management Console +2 cloud aws initial-access
2r 2t
high advisory

AWS Network Access Control List Created with All Open Ports

The analytic detects the creation of AWS Network Access Control Lists (ACLs) with all ports open to a specified CIDR by monitoring `CreateNetworkAclEntry` or `ReplaceNetworkAclEntry` actions with rules allowing all traffic, potentially leading to unauthorized network access.

Splunk Enterprise +3 cloud aws network-acl misconfiguration
2r
medium advisory

AWS Network Access Control List Deletion Detected

Detection of AWS Network Access Control List (ACL) deletion using AWS CloudTrail logs, which can remove critical access restrictions, potentially allowing unauthorized access to cloud instances and leading to data exfiltration or further compromise.

Splunk Enterprise +3 cloud aws network
2r 1t
high advisory

AWS Route 53 Domain Transferred to Another Account

An AWS Route 53 domain was transferred to another AWS account, potentially leading to unauthorized control over DNS records and traffic redirection for malicious purposes, such as phishing or establishing persistence.

Route 53 aws route53 domain-transfer persistence resource-development
2r 2t
medium advisory

AWS Route 53 Private Hosted Zone Associated With Unauthorized VPC

An adversary with sufficient permissions may associate unauthorized VPCs to intercept, observe, or reroute internal traffic, establish persistence, or expand their visibility within an AWS environment by associating a Route 53 private hosted zone with a new Virtual Private Cloud (VPC).

Route 53 cloud aws route53 persistence
2r 3t
high threat

AWS S3 Bucket Lifecycle Rule for Rapid Log Deletion

An attacker modifies an AWS S3 bucket lifecycle policy to rapidly expire CloudTrail logs, hindering incident response and forensic analysis.

exploited CloudTrail +4 aws defense_evasion s3
2r 1t
medium advisory

AWS S3 Bucket Policy Added to Allow Public Access

An AWS S3 bucket policy was modified to grant public access using a wildcard (Principal:"*") statement, potentially allowing data exfiltration or malicious content hosting.

Amazon S3 aws s3 exfiltration cloud
2r 2t
medium advisory

AWS S3 Data Exfiltration via Uncommon Client Applications

This rule detects AWS API activity originating from uncommon desktop client applications based on the user agent string, specifically S3 Browser and Cyberduck, which provide bulk upload/download capabilities and have been observed in use by threat actors for data exfiltration, warranting validation against authorized data transfer workflows.

Amazon S3 aws s3 exfiltration cloudtrail
3r 2t
low advisory

AWS SNS Topic Created by Rare User

An AWS SNS topic was created by a user who does not typically perform this action, potentially indicating resource development for data exfiltration or other malicious activities.

Simple Notification Service cloud aws sns resource-development impact
2r 2t
medium threat

AWS SSM Inventory Reconnaissance by Rare User

Detection of a rare user or role accessing AWS Systems Manager (SSM) inventory APIs or running the AWS-GatherSoftwareInventory job, potentially indicating reconnaissance activity by threat actors seeking information about managed EC2 instances.

AWS Systems Manager +1 Scattered Spider (LUCR-3) aws ssm inventory reconnaissance cloudtrail
2r 3t
high advisory

Axios HTTP Adapter Prototype Pollution Vulnerability

A prototype pollution vulnerability in the Axios HTTP adapter allows an attacker to inject arbitrary HTTP headers into outgoing requests by polluting the Object prototype with specific properties, leading to potential authentication bypass and privilege escalation.

axios +1 prototype-pollution header-injection cve-2026-42035 authentication-bypass privilege-escalation
2r 4t 1c
high advisory

Azure AD Brute Force Attack Detected via High Failed Authentication Count

Detection of a potential brute-force attack against an Azure AD account, identified by a high number of failed authentication attempts within a short time frame, potentially leading to unauthorized access and data breaches.

Azure Active Directory azuread brute-force credential-access cloud
2r 1t
high threat

Azure AD Service Principal Owner Added

Detection of a new owner being added to an Azure AD Service Principal, potentially indicating persistence or privilege escalation by an attacker exploiting the lack of multi-factor authentication on service principals.

Azure Active Directory NOBELIUM Group azure cloud persistence privilege-escalation
2r 1t
high advisory

Azure AD Service Principal Privilege Escalation

An Azure Active Directory (Azure AD) Service Principal elevates its own privileges by adding itself to a new application role assignment, potentially leading to unauthorized access and control within the Azure environment.

Azure AD azure azure-ad service-principal privilege-escalation
2r 1t
low advisory

Azure Alert Suppression Rule Created or Modified

Detection of Azure alert suppression rule creation or modification events, which can be used by attackers to disable security alerts and evade detection.

Azure +1 defense-evasion cloud
2r 1t
low advisory

Azure Automation Webhook Created for Persistence

Adversaries may create Azure Automation webhooks to trigger malicious runbooks for persistence in cloud environments.

Azure Automation azure persistence cloud
2r 2t
medium advisory

Azure Blob Storage Container Access Level Modified

The rule identifies modifications to Azure Blob Storage container access levels, which, if unauthorized, may lead to data exposure and exfiltration.

Azure Blob Storage cloud azure asset-visibility discovery
2r 3t
medium advisory

Azure Domain Federation Settings Modified

An attacker may modify Azure domain federation settings to establish persistence, escalate privileges, or gain unauthorized access to resources.

Azure Active Directory azure federation privilege-escalation persistence initial-access
2r 2t
medium advisory

Azure Kubernetes Services (AKS) Kubernetes Pod Deletion

The deletion of Azure Kubernetes Pods can indicate malicious activity aimed at disrupting the environment's normal behavior.

Azure Kubernetes Services azure kubernetes impact cloud
2r 2t
high advisory

Azure PIM - Role Assignment Outside of Privileged Identity Management

Detection of privilege role assignments outside of Azure Privileged Identity Management (PIM) can indicate potential attacker activity related to initial access, stealth, persistence, or privilege escalation within the Azure environment.

Azure Active Directory azure pim role-assignment attack.initial-access attack.stealth attack.t1078 attack.persistence attack.privilege-escalation
2r 4t
high advisory

basic-ftp CRLF Injection Vulnerability Allows Arbitrary FTP Command Execution

The basic-ftp npm package (<= 5.2.1) is vulnerable to CRLF injection, enabling attackers to inject arbitrary FTP commands via crafted credentials or MKD commands, leading to file manipulation, server command execution, and potential session hijacking.

basic-ftp crlf-injection ftp command-injection nodejs
2r 3t
high advisory

basic-ftp Denial-of-Service Vulnerability via Unbounded Memory Consumption

The basic-ftp npm package version 5.2.2 and earlier is vulnerable to a denial-of-service attack. A malicious FTP server can send an extremely large or never-ending directory listing in response to the Client.list() command, causing the client to consume excessive memory until the process becomes unstable or crashes due to unbounded memory growth in the StringWriter class.

basic-ftp denial-of-service ftp memory-exhaustion npm
2r 1t
high advisory

BidingCC BuildingAI SSRF Vulnerability (CVE-2026-7065)

A server-side request forgery (SSRF) vulnerability exists in BidingCC BuildingAI up to version 26.0.1, allowing remote attackers to manipulate the `url` argument in the `uploadRemoteFile` function of `file-storage.service.ts` to conduct SSRF attacks.

BuildingAI ssrf cve-2026-7065 web-application
2r 1t 1c