Skip to content
Threat Feed

January 2024 (30)

medium advisory

Disabling Windows Defender Security Settings via PowerShell

This rule detects the use of the Set-MpPreference PowerShell command to disable or weaken Windows Defender settings, a common defense evasion tactic.

Windows Defender defense-evasion powershell windows
2r 2t
high advisory

Ech0 Server-Side Request Forgery (SSRF) Vulnerability

Ech0 is vulnerable to Server-Side Request Forgery (SSRF) via the `fetchPeerConnectInfo` function, which uses `httpUtil.SendRequest` without SSRF protection, allowing authenticated users to make the server request arbitrary URLs, including internal/cloud metadata endpoints.

ech0 ssrf github
2r 1t 2i
medium advisory

Execution from Unusual Directory - Command Line

Adversaries may execute commands and scripts from unusual Windows directories to masquerade malware and evade detection, impacting system integrity and security operations.

Windows execution defense-evasion
2r 3t
medium advisory

Execution of COM object via Xwizard

Adversaries can abuse the legitimate system binary Xwizard to execute Component Object Model (COM) objects, evading defensive countermeasures by running COM objects created in the registry.

Windows execution defense-evasion com xwizard
2r 2t
medium advisory

Execution via GitHub Actions Runner

Adversaries compromising GitHub Actions workflows can execute arbitrary commands on runner hosts, leading to code execution, reconnaissance, credential harvesting, or network exfiltration.

github-actions supply-chain execution devops
3r 3t
high advisory

GCP Multiple Failed MFA Requests Imply MFA Fatigue Attack

Detection of multiple failed multi-factor authentication (MFA) requests for a single user in Google Cloud Platform (GCP) within a short time window, potentially indicating an MFA fatigue attack attempting to bypass MFA and gain unauthorized access.

Google Cloud Platform +1 gcp mfa mfa-fatigue credential-access
2r 3t
medium advisory

Google Workspace Marketplace Restrictions Modified to Allow Any App

An adversary may modify Google Workspace Marketplace restrictions to allow installation of any application, potentially enabling the deployment of malicious APKs to end users within the Google Workspace environment, bypassing security restrictions.

Google Workspace google_workspace defense_evasion cloud
2r 2t
critical advisory

Gramps Web API Zip Slip Vulnerability in Media Archive Import

A path traversal vulnerability (Zip Slip) exists in the gramps-webapi media archive import feature, allowing authenticated users with owner privileges to write arbitrary files outside the intended temporary extraction directory via malicious ZIP files, potentially leading to data corruption or replacement.

Gramps Web API path-traversal zip-slip gramps-webapi vulnerability
2r 1t
low advisory

High Variance in RDP Session Duration Detected via Machine Learning

A machine learning job has detected unusually high variance of RDP session duration, potentially indicating lateral movement and session persistence by threat actors.

lateral-movement threat-detection windows
2r 2t
high advisory

IdentityIQ Authenticated Users Can Create New Objects via Debug Pages

A vulnerability in IdentityIQ 8.5 and 8.4 allows authenticated users with the Debug Pages Read Only capability or custom capabilities containing the ViewAccessDebugPage SPRight to create new IdentityIQ objects.

IdentityIQ cve-2026-4857 privilege-escalation
2r 1t 1c
medium advisory

Impact of Poor Security Operation Center (SOC) Metrics

Poorly chosen performance metrics can significantly impair a SOC's ability to detect and respond to threats, leading to ineffective security operations and potential compromise.

SharePoint soc metrics threat-hunting detection
2r 2t
critical advisory

jsrsasign DSA Signature Forgery Vulnerability (CVE-2026-4600)

The jsrsasign package before version 11.1.1 is vulnerable to cryptographic signature forgery (CVE-2026-4600) due to improper DSA domain-parameter validation, allowing attackers to forge DSA signatures or X.509 certificates, potentially leading to unauthorized access or code execution.

jsrsasign signature-forgery dsa cve-2026-4600
2r 1t
critical advisory

Kubernetes Privileged Pod Creation or Update

Detection of Kubernetes privileged pods creation or update, which indicates an attempt to escalate privileges and gain full access to the host's namespace and devices, potentially leading to unauthorized access, data breaches, and service disruptions.

Kubernetes privilege-escalation cloud
2r 1t
medium advisory

Large ICMP Traffic Detection

This analytic identifies excessive ICMP traffic to external IP addresses exceeding 1,000 bytes, potentially indicating command and control activity, data exfiltration, or covert communication channels.

Splunk Enterprise +4 network-traffic command-and-control data-exfiltration
2r 1t
medium advisory

Leveraging Apple's Endpoint Security Framework for Process Monitoring

This brief discusses the use of Apple's Endpoint Security Framework in macOS 10.15 and later for user-mode process monitoring, offering improved capabilities over the older OpenBSM subsystem.

macOS endpoint-security process-monitoring defense-evasion discovery
2r 2t
high advisory

Multiple Azure Storage Account Deletions by User

A single user or service principal deleting multiple Azure Storage Accounts within a short time period may indicate malicious activity such as data destruction, service disruption, or a ransomware attack.

Azure +1 cloud storage impact
2r 2t
high advisory

Non-Discord Application Accessing Discord LevelDB Database

This analytic detects non-Discord applications accessing the Discord LevelDB database by monitoring Windows Security Event logs (event code 4663), which may indicate attempts to steal Discord credentials or access sensitive user data, potentially compromising user profiles, messages, and other critical information.

Discord credential-access stealer windows
2r 1t
high advisory

Non-Firefox Process Accessing Firefox Profile Directory

Detection of non-Firefox processes accessing the Firefox profile directory, potentially indicating malware attempting to steal user credentials and data.

Firefox credential-access stealer
2r 1t
critical advisory

OpenClaw Feishu Webhook Vulnerability: Unauthenticated Command Execution

OpenClaw versions before 2026.4.15 are vulnerable to unauthenticated webhook or card-action traffic due to missing encryption key configuration and improper handling of card-action callbacks, potentially allowing network-triggered access to OpenClaw command handling without Feishu signature or replay protection.

OpenClaw feishu webhook vulnerability
2r 1t
high advisory

OpenClaw: Unauthorized Profile Reset via browser.request

OpenClaw version 2026.3.22 allows authenticated users with `operator.write` access to the `browser.request` method to reset persistent browser profiles via a `POST /reset-profile` request due to a missing check in the persistent-profile mutation classifier, leading to data loss and service disruption.

OpenClaw authorization profile-reset
2r 1t
high advisory

Optimole WordPress Plugin Stored XSS Vulnerability

The Optimole WordPress plugin before version 4.2.3 is vulnerable to stored cross-site scripting (XSS) due to insufficient input sanitization and output escaping on the 's' parameter (srcset descriptor) in the unauthenticated /wp-json/optimole/v1/optimizations REST endpoint, allowing unauthenticated attackers to inject arbitrary web scripts.

Optimole WordPress Plugin wordpress xss plugin cve-2026-5217
2r 1t 1c
critical advisory

Pipecat Remote Code Execution via Pickle Deserialization in LivekitFrameSerializer

A critical vulnerability, CVE-2025-62373, exists in Pipecat's LivekitFrameSerializer where the deserialize() method uses Python's pickle.loads() on WebSocket data without validation, allowing a malicious WebSocket client to execute arbitrary code on the Pipecat server if LivekitFrameSerializer is explicitly enabled.

pipecat-ai remote code execution deserialization pipecat
2r 1t 1c
high advisory

PocketMine-MP ModalFormResponsePacket Denial-of-Service

A vulnerability in PocketMine-MP servers allows an attacker to cause a denial-of-service by sending a malformed ModalFormResponsePacket containing an excessively large JSON payload, impacting server performance and availability.

PocketMine-MP denial-of-service minecraft
2r 1t
medium advisory

Potential Exploitation of Unquoted Service Path Vulnerability

This rule detects potential exploitation of unquoted service paths on Windows systems, which can lead to privilege escalation by identifying suspicious processes starting from common unquoted paths, indicating a potential attempt to execute malicious code.

Windows privilege-escalation unquoted-service-path
2r 1t
high advisory

PowerShell Obfuscation via Backtick-Escaped Variable Expansion

PowerShell scripts use backtick-escaped characters inside `${}` variable expansion to reconstruct strings at runtime, enabling attackers to split keywords, hide commands, and evade static analysis and AMSI.

windows +1 powershell obfuscation defense-evasion variable-expansion
2r 1t
medium advisory

Remote Execution of Windows Services via RPC

Detection of remote execution of Windows services over RPC by correlating `services.exe` network connections and spawned child processes, potentially indicating lateral movement.

SCCM lateral-movement execution windows
2r 2t
medium advisory

Remote Execution via File Shares

This rule identifies potential lateral movement via network file shares by detecting the execution of a file that was created by the virtual system process.

Windows lateral-movement file-share
2r 1t
medium advisory

Suspicious CertUtil Commands for Defense Evasion and Lateral Movement

This rule detects suspicious use of certutil.exe, a native Windows utility often abused by attackers for downloading/deobfuscating malware and exfiltrating data, by identifying commands involving decoding, encoding, URL caching, CTL verification, and PFX exporting, which are frequently used for command and control and defense evasion.

Windows defense-evasion command-and-control credential-access certutil
2r 3t
high advisory

Suspicious DNS Queries to Telegram Bot API

Detection of DNS queries to api.telegram.org by processes other than telegram.exe indicates potential command and control communication via Telegram bots, a technique leveraged by malware to establish covert communication channels.

Telegram Bot API telegram bot c2 command-and-control dns
2r 2t 1i
medium advisory

Suspicious Execution via Windows Subsystem for Linux

This rule detects suspicious execution via the Windows Subsystem for Linux (WSL), which adversaries may leverage to execute Linux commands and bypass traditional Windows security measures.

Windows Subsystem for Linux wsl windows-subsystem-for-linux defense-evasion
2r 3t