Skip to content
Threat Feed

January 2024 (30)

medium advisory

Abnormal Cloud Security Group API Call Activity

Detection of an abnormally high number of cloud security group API calls which can indicate malicious activity such as reconnaissance, privilege escalation, or lateral movement within a cloud environment.

Amazon Web Services +2 cloud security-group api-abuse
2r 2t
medium advisory

Abuse of Predefined BIOCs in Palo Alto Cortex XDR

Attackers may decrypt and abuse predefined Behavioral Indicators of Compromise (BIOCs) in Palo Alto Cortex XDR to evade detection or manipulate the system.

Cortex XDR cortex-xdr bioc evasion
2r 1t
low threat

AdFind Tool Used for Active Directory Reconnaissance

The execution of AdFind.exe, an Active Directory query tool, is often used by threat actors for post-exploitation Active Directory reconnaissance, as observed in campaigns involving Trickbot, Ryuk, Maze, and FIN6.

Elastic Defend FIN6 adfind active-directory reconnaissance windows
2r 5t
high advisory

Adobe InDesign Out-of-Bounds Read Vulnerability (CVE-2026-27284)

Adobe InDesign Desktop versions 20.5.2, 21.2 and earlier are vulnerable to an out-of-bounds read (CVE-2026-27284) when parsing a crafted file, potentially leading to code execution if a user opens a malicious file.

InDesign Desktop cve-2026-27284 adobe-indesign out-of-bounds-read code-execution
2r 1t 1c
medium advisory

Algovate xhs-mcp Server-Side Request Forgery Vulnerability

A server-side request forgery (SSRF) vulnerability exists in Algovate xhs-mcp 0.8.11 within the xhs_publish_content function, allowing a remote attacker to manipulate the media_paths argument and potentially access internal resources.

xhs-mcp 0.8.11 SSRF algovate xhs-mcp
2r 1t 1c
medium advisory

Android-ImageMagick7 Memory Leak Vulnerability (CVE-2026-33856)

A missing release of memory after effective lifetime vulnerability exists in MolotovCherry Android-ImageMagick7 before version 7.1.2-11, potentially leading to denial of service.

Android-ImageMagick7 cve-2026-33856 memory leak denial of service android
2r 1t
high advisory

Anomalous Cloud Compute Instance Creation by Unseen User

Detection of cloud compute instance creation by a user with no prior history of creating instances, potentially indicating unauthorized access, account compromise, or misuse of cloud resources leading to data exfiltration, increased costs, or further exploitation.

EC2 cloud_security anomaly_detection aws
2r 1t
high advisory

Apko DirFS Symlink Path Traversal Vulnerability

A symlink-following path traversal vulnerability exists in apko versions prior to 1.2.5 allowing a malicious .apk file to create a symbolic link pointing outside the build root and subsequently modify files on the host system.

apko path-traversal symlink vulnerability CVE-2026-42574
2r 1t
medium advisory

AppInit DLL Registry Persistence Detected

Modification of the AppInit DLLs registry keys can be used for persistence and defense evasion on Windows systems.

Windows persistence defense-evasion
2r 2t
high advisory

AVideo EncoderReceiveImage Local File Inclusion Vulnerability

AVideo is vulnerable to local file inclusion (LFI) via the EncoderReceiveImage endpoint, allowing authenticated uploaders to read sensitive server files by bypassing path traversal restrictions.

AVideo lfi file-disclosure php
2r 1t 1c
high advisory

AVideo Session Fixation Vulnerability (CVE-2026-33492)

AVideo versions 26.0 and earlier are vulnerable to session fixation due to accepting arbitrary session IDs via the `PHPSESSID` GET parameter and disabled session regeneration, allowing attackers to hijack authenticated sessions.

AVideo cve-2026-33492 session-fixation web-application
2r 1t
high advisory

AWS Bedrock GuardRails Deletion Attempt

Detection of AWS Bedrock GuardRails deletion, which are security controls to prevent harmful AI outputs, could indicate an adversary attempting to remove safety measures after credential compromise to enable malicious model outputs.

Bedrock +4 aws cloudtrail defense-evasion
2r 1t
low advisory

AWS CloudShell Environment Created

The creation of a new AWS CloudShell environment is detected, potentially indicating unauthorized access for command execution within AWS by adversaries without needing local CLI credentials.

AWS CloudShell cloud aws cloudshell
2r 1t
medium advisory

AWS CloudTrail Logging Evasion via Oversized IAM Policies

Attackers evade AWS CloudTrail logging by padding IAM policy documents with whitespace, exceeding logging size limits and obscuring unauthorized changes to IAM policies.

CloudTrail +1 aws iam defense-evasion cloud
2r 1t
high advisory

AWS Config Configuration Recorder Stopped

Detection of AWS Config configuration recorder being stopped, potentially by an adversary to evade detection and obscure activity.

AWS Config aws cloudtrail defense-evasion configuration-change
2r 2t
medium advisory

AWS Config Resource Deletion for Defense Evasion

An adversary may delete AWS Config resources to evade detection, hide prior activity, or weaken governance controls, which reduces security visibility and auditability within an AWS environment.

AWS Config cloud defense-evasion aws
2r 2t
medium advisory

AWS Config Service Disabling Detection

Detection of AWS Config Service disabling, potentially indicating an attempt to impair defenses by stopping configuration recording and delivery.

AWS Config +1 attack.defense-impairment attack.t1562.008 aws
2r 1t
high advisory

AWS Credential Access via GetPasswordData API Calls

Detection of anomalous GetPasswordData API calls in AWS CloudTrail logs, indicating potential attempts to retrieve encrypted administrator passwords for Windows instances, leading to unauthorized access.

Amazon EC2 aws credential-access cloudtrail
2r 3t
low advisory

AWS DynamoDB Scan by Unusual User

Detection of unusual DynamoDB scan activity in AWS environments, potentially indicating exfiltration of sensitive information by an adversary using compromised credentials or a rogue insider.

DynamoDB aws exfiltration cloudtrail
2r 3t
low advisory

AWS EC2 Network Access Control List Creation

The rule detects the creation of an AWS EC2 network access control list (ACL) or an entry in a network ACL with a specified rule number, which adversaries may exploit to establish persistence or defense evasion by creating permissive rules.

Amazon EC2 cloud aws ec2 network-acl persistence defense-evasion
2r 3t
high advisory

AWS EC2 Serial Console Access Enabled

The EC2 Serial Console provides direct, text-based access to an instance's serial port, bypassing the network layer, which adversaries may enable for out-of-band communication, evading network-based security monitoring, firewalls, and VPC controls.

AWS EC2 aws cloudtrail defense-evasion ec2
3r 2t
low advisory

AWS ECR Container Scanning Findings Placeholder

This is a placeholder brief due to the provided text being a GitHub navigation page, indicating no specific threat or attack details are available, and therefore serves as a template for future threat intelligence extraction related to AWS ECR container scanning.

Elastic Container Registry cloud aws ecr container-security
2r 3t
high advisory

AWS ECR Container Upload by Unknown User

An unauthorized user uploaded a new container image to AWS Elastic Container Registry (ECR), potentially leading to the deployment of malicious containers and further compromise of the AWS environment.

AWS Elastic Container Registry aws ecr container upload
2r 1t
low advisory

AWS EventBridge Rule Disabled or Deleted

Detection of Amazon EventBridge rule disabling or deletion events, which can disrupt operational workflows and security monitoring.

EventBridge aws impact defense-evasion
2r 2t
medium advisory

Suspicious MS Outlook Child Process

Detection of suspicious child processes spawned by Microsoft Outlook, indicative of spear phishing and malicious file execution leading to potential initial access and further exploitation.

Microsoft Outlook +3 initial-access phishing malware windows
2r 3t
medium advisory

Unusual EC2 Instance Creation with Unseen Instance Type

An attacker may create new EC2 instances with previously unseen instance types, indicating potential unauthorized or suspicious activity such as cryptomining or data exfiltration.

EC2 cloud anomaly cryptomining
2r 1t
critical advisory

Use-After-Free Vulnerability in Firefox, ESR, and Thunderbird CSS Parsing (CVE-2026-4691)

A use-after-free vulnerability (CVE-2026-4691) in the CSS Parsing and Computation component affects Firefox versions prior to 149, Firefox ESR versions prior to 115.34 and 140.9, and Thunderbird versions prior to 149 and 140.9, potentially leading to arbitrary code execution.

Firefox +2 cve-2026-4691 use-after-free thunderbird
2r 3t
medium advisory

Windows Privilege Escalation via Secondary Logon Service

The rule identifies process creation with alternate credentials, which can be used for privilege escalation, by detecting successful logins via the Secondary Logon service (seclogon) from a local source IP address (::1), followed by process creation using the same TargetLogonId.

Windows privilege-escalation access-token-manipulation
2r 2t
medium advisory

Windows Update Client DLL Loading Abuse

Adversaries abuse the Windows Update Auto Update Client (wuauclt.exe) to load arbitrary DLLs from user-writable locations, achieving defense evasion and execution of malicious code.

Windows defense-evasion execution lolbas
2r 2t
medium threat

Zebra Block Discovery Denial-of-Service via Gossip Queue Saturation and Syncer Poisoning

A denial-of-service vulnerability exists in Zebra's block discovery pipeline, allowing an unauthenticated remote attacker to permanently halt all new block discovery on a targeted node by exploiting weaknesses in the gossip, syncer, and download subsystems.

zebrad denial-of-service zebra block-discovery gossip syncer
2r 1t 1c