August 2026 (30)
Unauthenticated Remote Code Execution in Pix for WooCommerce
1 rule 2 TTPs 1 CVEA critical vulnerability (CVE-2026-3891) in the Pix for WooCommerce WordPress plugin allows unauthenticated attackers to upload and execute arbitrary PHP files via vulnerable AJAX handlers.
Critical Prototype Pollution Vulnerability in Apollo Federation
1 TTP 1 CVE 1 IOCCVE-2026-32621 is a critical prototype pollution vulnerability in Apollo Federation that allows unauthenticated attackers to manipulate application objects via malicious GraphQL queries.
Blind SQL Injection in Krayin CRM leads DataGrid
1 rule 1 TTP 1 CVEKrayin CRM versions prior to 2.2.4 contain a blind SQL injection vulnerability in the leads DataGrid, allowing authenticated attackers to exfiltrate database contents via the rotten_lead[in] query parameter.
Arbitrary Code Execution in Ghidra Swift Demangler
1 TTP 1 CVEAn arbitrary code execution vulnerability in the Ghidra Swift demangler analyzer allows attackers to execute arbitrary binaries by manipulating the Swift tool directory path within a project file.
Remote Stack-Based Buffer Overflow in Wavlink Networking Devices
1 TTP 1 CVE 1 IOCMultiple Wavlink networking devices are vulnerable to a remote stack-based buffer overflow in the lighttpd component due to insecure use of strcpy in the upload.cgi script via the HTTP_COOKIE header.
Privilege Escalation in Razer RzUpdateService
1 TTP 1 CVEA local privilege escalation vulnerability in Razer RzUpdateService version 1.10.14.0 allows local attackers to manipulate the Named Pipe Handler to gain unauthorized privileges.
Local Privilege Escalation in CheckMAL AppCheck Pro via Kernel Driver
1 TTP 1 CVEA local privilege escalation vulnerability in the AppCheckD.sys driver of CheckMAL AppCheck Pro version 3.1.43.10 allows attackers to perform uncontrolled search path manipulation.
Krayin CRM Installer Authentication Bypass Vulnerability
1 rule 1 TTP 1 CVEKrayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware, allowing unauthenticated remote attackers to overwrite the administrator account via crafted HTTP POST requests.
Cross-Site Scripting Vulnerability in Angular Server-Side Rendering
1 TTP 1 CVEA Cross-Site Scripting (XSS) vulnerability in @angular/platform-server (CVE-2026-69149) allows script injection via improper serialization of fallback raw-content elements during server-side rendering.
Multiple Vulnerabilities in PaperCut NG/MF
2 CVEsMultiple vulnerabilities, including CVE-2026-8793 and CVE-2026-8794, affect PaperCut NG/MF versions prior to 26.0.3, potentially allowing for data confidentiality breaches and security policy bypass.
Detection of Unusual File Creation by Web Server Processes on Linux
1 rule 4 TTPsThis brief details a behavioral detection strategy for identifying potential web shell deployment and persistence mechanisms by monitoring anomalous file creation activities originating from common web server processes on Linux.
Detection of Destructive NFS File Operations
2 TTPsDetection logic identifies ransomware-like activity on NFS shares by flagging high-frequency bursts of successful WRITE, REMOVE, and RENAME operations from a single client within a one-minute window.
Detection of SSH Reverse Port Forwarding on Windows
1 rule 3 TTPsAdversaries are abusing native Windows OpenSSH and Plink binaries to establish unauthorized reverse SSH tunnels, bypassing inbound connectivity controls for C2 and lateral movement.
Detection of Suspicious Base64 Decoding Activity on Linux
2 TTPsThis detection brief monitors Linux hosts for the use of standard system utilities and scripting interpreters to decode Base64 data, a common technique employed by adversaries to obfuscate malicious payloads and command-and-control traffic.
OS Command Injection in Telenia Software TVox
1 rule 3 TTPs 1 CVETelenia Software TVox contains an OS command injection vulnerability in action_audio.php that allows authenticated attackers to execute arbitrary system commands as the apache user.
CVE-2026-69096: OS Command Injection in OpenWrt luci-app-dockerman
2 TTPs 1 CVEAn authenticated OS command injection vulnerability in the docker_rpc.uc backend of luci-app-dockerman allows attackers with read-only ACLs to execute arbitrary commands as root via the /ubus RPC endpoint.
Authentication Bypass Vulnerability in Admidio Forum Module
1 rule 1 TTP 1 CVEAdmidio versions prior to 5.0.11 contain an authentication bypass vulnerability in the forum module, allowing unauthenticated remote attackers to access sensitive forum content.
Path Traversal Vulnerability in Grav CMS ImageMedium Class
1 rule 1 TTP 1 CVEGrav CMS 2.0.10 is vulnerable to path traversal in the ImageMedium::watermark() method, allowing unauthenticated attackers to disclose arbitrary image files by traversing outside the media sandbox.
Arbitrary Static Method Execution in Grav CMS
2 TTPs 1 CVEGrav CMS versions 2.0.7 through 2.0.10 allow authenticated users with page-editing permissions to trigger arbitrary public static method calls via malicious blueprint directives, leading to unauthorized file read and write operations.
SQL Injection in SiYuan fullTextSearchAssetContent Endpoint
3 rules 2 TTPs 1 CVESiYuan versions before 3.7.3 contain a critical SQL injection vulnerability in the fullTextSearchAssetContent endpoint, allowing unauthenticated attackers to execute arbitrary SQL commands on the backend asset-content database.
Authentication Bypass Vulnerability in SiYuan Publish Mode
2 TTPs 1 CVESiYuan versions before 3.7.3 contain an authentication bypass vulnerability allowing unauthenticated attackers to retrieve content from password-protected documents.
Deserialization Vulnerability in eta-otp-lock
1 TTP 1 CVEAn insecure deserialization vulnerability in TUBITAK BILGEM eta-otp-lock (CVE-2026-18642) allows unauthenticated attackers to perform object injection, potentially leading to remote code execution.
Remote Code Execution and Arbitrary File Read in Ruby on Rails Active Storage
1 CVE 1 IOCA vulnerability (CVE-2026-66066) in Ruby on Rails Active Storage allows unauthenticated attackers to achieve arbitrary file read and remote code execution during the variant processing phase.
Critical Pre-Authentication RCE in Gitea and Forgejo
1 rule 3 TTPsCVE-2026-60004 is a critical pre-authentication RCE vulnerability in Gitea and Forgejo platforms caused by an unsafe bare clone design in the diffpatch API endpoint, enabling arbitrary command execution via injected Git hooks.
Linux Kernel posix-cpu-timers Use-After-Free Vulnerability
1 TTP 1 CVE 1 IOCA use-after-free vulnerability in the Linux kernel posix-cpu-timers subsystem, identified as CVE-2026-64560, allows attackers to trigger kernel memory corruption via a race condition during non-leader thread exec() calls.
Authorization Bypass Vulnerability in Menulux Mobile App
1 TTP 1 CVECVE-2026-2346 is a critical authorization bypass vulnerability (CWE-639) in the Menulux Mobile App allowing unauthenticated attackers to manipulate user-controlled keys and compromise software integrity.
Apache HttpComponents Denial of Service Vulnerability
1 TTPA vulnerability in Apache HttpComponents allows a remote, unauthenticated attacker to trigger a Denial of Service condition on targeted applications.
Denial of Service Vulnerability in Red Hat Multicluster Engine for Kubernetes
1 TTPA vulnerability in Red Hat Multicluster Engine for Kubernetes allows an unauthenticated remote attacker to trigger a denial of service condition by exploiting a software flaw.
Multiple Vulnerabilities in Red Hat Ansible Automation Platform
2 TTPsMultiple vulnerabilities in Red Hat Ansible Automation Platform allow a remote, unauthenticated attacker to achieve remote code execution or manipulate information displayed by the platform.
Multiple Vulnerabilities in cPanel/WHM
2 TTPsMultiple vulnerabilities in cPanel/WHM allow remote attackers to manipulate files and escalate privileges, potentially leading to arbitrary code execution with administrative rights.