July 2026 (30)
Vulnerability in poco-ai poco-claw Leads to Server-Side Request Forgery (CVE-2026-16016)
1 rule 2 TTPs 1 CVEA high-severity server-side request forgery (SSRF) vulnerability, identified as CVE-2026-16016, exists in poco-ai's poco-claw software up to version 0.5.4, allowing remote attackers to manipulate the `callback_url` argument in the `run_task` function to force the server to make arbitrary requests, with a public exploit available posing an immediate risk.
Improper Restriction of XML External Entity Reference in Netcad Software NetGIS (CVE-2026-8396)
2 TTPs 1 CVEA critical XML External Entity (XXE) vulnerability, CVE-2026-8396, in Netcad Software Inc.'s NetGIS allows unauthenticated remote attackers to perform serialized data external linking, potentially leading to sensitive information disclosure or server-side request forgery.
Proliz OBS Vulnerability Allows Sensitive Information Insertion Leading to ACL Bypass (CVE-2026-7189)
1 CVEA high-severity vulnerability, CVE-2026-7189, in Proliz Software Ltd. Co.'s Proliz OBS before version 3.6.0 allows for the insertion of sensitive information into sent data, enabling attackers to access functionality not properly constrained by Access Control Lists (ACLs).
Critical SQL Injection Vulnerability in Hospital Bed Management System (CVE-2026-16014)
1 rule 3 TTPs 1 CVE 6 IOCsA critical SQL injection vulnerability, CVE-2026-16014, has been identified in the Login Form component of code-projects Hospital Bed Management System version 1.0, allowing remote attackers to manipulate the 'Username' argument for unauthorized data access and manipulation, with a public exploit available.
Suspicious Child Process Execution via Azure VM CustomScript Extension
1 rule 4 TTPsAttackers with access to an Azure subscription or VM management plane can leverage the Azure VM CustomScript extension to execute arbitrary code with SYSTEM privileges on Windows virtual machines, leading to various malicious activities such as reconnaissance, malware deployment, and persistence.
Multiple Vulnerabilities in Ubuntu Pro Client
3 TTPsMultiple vulnerabilities exist in the ubuntu-pro-client within Ubuntu Linux, allowing an attacker to execute arbitrary program code with administrator privileges and disclose confidential information.
nginx-ui: Multiple Vulnerabilities
4 TTPsMultiple vulnerabilities in nginx-ui allow an attacker to execute arbitrary code, including with root privileges, gain elevated privileges, perform account takeover, bypass security measures, and disclose or manipulate data.
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
2 rules 6 TTPsA sophisticated Go-based implant, dubbed GoSerpent, has been utilized by an unidentified threat actor since late 2025 to conduct cyber espionage against government and diplomatic entities in Southeast Asia, focusing on long-term access, sensitive data collection, and credential dumping for exfiltration.
AWS Discovery API Calls from VPN ASN for the First Time by Identity
1 rule 2 TTPs 22 IOCsThis threat detection rule identifies initial reconnaissance activities within AWS by flagging an IAM principal's first-time invocation of sensitive discovery APIs, such as GetCallerIdentity, ListUsers, ListBuckets, and DescribeInstances, when the originating IP address is associated with consumer VPNs, high-usage hosting providers, or networks linked to threat groups like TeamPCP, indicating an attacker performing enumeration of cloud resources from a suspicious network origin.
AWS Cognito Unauthenticated Identity Pool Credentials Issued
1 rule 2 TTPsThis threat involves adversaries obtaining temporary AWS credentials from a misconfigured Cognito Identity Pool without authentication. If a Cognito Identity Pool is set to allow unauthenticated (guest) access and its associated unauthenticated IAM role has overly broad permissions, attackers can discover the pool ID, call `GetId`, and then `GetCredentialsForIdentity` to acquire AWS credentials. This grants them unauthorized access to AWS resources and sensitive data, bypassing typical authentication mechanisms.
AWS CloudTrail Management Events Disabled via PutEventSelectors
1 rule 1 TTPA malicious actor uses the AWS CloudTrail `PutEventSelectors` API call to explicitly disable logging of management API calls for a trail by setting `includeManagementEvents` to `false`, effectively blinding defenders to subsequent sensitive activities while the trail appears active.
AWS GuardDuty Detection Suppression
1 rule 1 TTPAdversaries leverage specific AWS GuardDuty API calls including CreateIPSet, UpdateIPSet, CreateThreatIntelSet, UpdateThreatIntelSet, or UpdateDetector with Enable: false to suppress or blind Amazon GuardDuty's detection capabilities, allowing them to operate undetected within a compromised AWS environment.
AWS Attempt to Leave Organization
1 rule 2 TTPsAn adversary attempting to remove an AWS member account from its AWS Organization via the LeaveOrganization API constitutes a critical defense evasion maneuver, as it strips the account of security controls and centralized monitoring, requiring immediate investigation by detection engineers.
AWS Account Closure Detected
1 rule 2 TTPsAdversaries or malicious insiders may close an AWS account using the `CloseAccount` API, a highly destructive action that suspends all access for 90 days before permanent termination, leading to data destruction and significant business disruption.
AWS IAM User Console Login Without MFA
1 rule 1 TTPThis brief identifies successful logins to the AWS Management Console by standard IAM users without Multi-Factor Authentication (MFA). It focuses on the first observed occurrence within a 7-day history window for each user. An adversary who obtains a user's password can gain access if MFA is not enforced, representing a significant initial access vector. This event signals a critical posture gap that allows adversaries to achieve initial access using compromised credentials, leading to potential privilege escalation, data exfiltration, or resource deployment.
pyasn1: Quadratic Complexity in OBJECT IDENTIFIER and RELATIVE-OID Processing Allows Denial of Service
1 CVEA denial of service vulnerability, identified as CVE-2026-59885, exists in the pyasn1 library caused by quadratic complexity in the processing of OBJECT IDENTIFIER and RELATIVE-OID, which can lead to a denial of service.
CVE-2026-15392: DBD::File Module Symlink Vulnerability
1 CVECVE-2026-15392 is a medium-severity vulnerability affecting versions of the Perl module DBD::File prior to 1.651, where the module fails to prevent symlinks to untrusted locations, potentially allowing local attackers to achieve information disclosure or local privilege escalation through symlink following.
libsoup Websocket Unbounded Decompression Denial of Service Vulnerability
1 CVEA remote denial of service vulnerability, CVE-2026-15709, exists in the libsoup library's websocket permessage-deflate extension, allowing an attacker to trigger a denial of service through unbounded decompression.
Libsoup WebSocket Remote Denial of Service Vulnerability
1 CVEA remote denial of service vulnerability, CVE-2026-15711, exists in the libsoup library's WebSocket connection handling due to an oversized control frame protocol violation, allowing an attacker to cause service disruption.
Vulnerability in Perl DBI Module Before 1.651 (CVE-2026-60082)
1 CVEA vulnerability, identified as CVE-2026-60082, exists in the DBI module for Perl, specifically in versions before 1.651, related to the module not enforcing statement handle consistency with the row.
Libsoup Vulnerability CVE-2026-15714 Allows Out-of-Bounds Read
1 CVEA vulnerability identified as CVE-2026-15714 in the Libsoup library's soupmultipartinputstream component allows an out-of-bounds read when processing an oversized multipart boundary string, potentially leading to information disclosure or application instability.
Libsoup HTTP/2 Frame Window Exhaustion Remote Denial of Service
1 CVEA remote denial of service vulnerability, CVE-2026-15713, exists in the soupcache component of the Libsoup library due to a memory leak that leads to HTTP/2 frame window exhaustion, potentially causing application crashes or unresponsiveness.
CVE-2026-48863: libsolv Stack-Based Buffer Overflow Leading to Denial of Service
1 CVEA critical stack-based buffer overflow vulnerability, CVE-2026-48863, has been identified in the PGP verification component of libsolv, allowing a remote attacker to trigger a denial of service by crafting a malicious Ed25519 PGP signature with mismatched MPI lengths, impacting automated package or repository processing workflows.
AWS Potential Cryptomining via ECS Task Definition Deployment
1 TTP 5 IOCsAdversaries, after compromising AWS credentials, deploy cryptomining operations on Amazon ECS and AWS Fargate by registering task definitions with public high-CPU container images and then launching them, leading to unauthorized resource consumption and increased cloud costs.
Abuse of AWS Bedrock AgentCore Execution Role Credentials for Cloud Privilege Escalation
1 rule 2 TTPsAnomalous AWS API calls by an Amazon Bedrock AgentCore execution role indicate potential credential exfiltration and abuse for cloud privilege escalation, lateral movement, or reconnaissance outside its intended runtime environment.
Privilege Escalation Vulnerability in Aimogen Pro WordPress Plugin
2 TTPs 1 CVEA critical privilege escalation vulnerability, CVE-2026-15982, exists in the Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit WordPress plugin, affecting versions up to and including 2.8.4, allowing unauthenticated attackers to leverage the 'aimogen_wp_god_mode' tool to clear function blacklists, execute arbitrary PHP functions, and create administrator accounts, leading to full compromise of the WordPress site.
Sensitive Information Exposure in LearnPress WordPress Plugin (CVE-2026-13765)
1 rule 2 TTPs 1 CVEAn unauthenticated sensitive information exposure vulnerability (CVE-2026-13765) in the LearnPress - WordPress LMS Plugin for Create and Sell Online Courses, versions up to 4.4.1, allows attackers to extract quiz answers, options, explanations, and question content, including for paid courses.
Arbitrary File Upload Vulnerability in ProfilePress WordPress Plugin (CVE-2026-13352)
3 TTPs 1 CVEAn arbitrary file upload vulnerability, CVE-2026-13352, affects the ProfilePress plugin for WordPress up to version 4.16.18, allowing authenticated attackers with author-level privileges or higher to upload executable files, which can lead to remote code execution.
Kali Forms WordPress Plugin Vulnerable to Stored Cross-Site Scripting via digitalSignature Field
1 rule 6 TTPs 1 CVEThe Kali Forms - Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'digitalSignature' field in versions up to and including 2.4.18, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user accesses an affected page.
Grav API Plugin Vulnerable to CORS Misconfiguration Allowing Data Exposure and Unauthorized Operations
1 rule 3 TTPs 1 CVEThe Grav API plugin before version 1.0.0-rc.16 contains a CORS misconfiguration that sets `Access-Control-Allow-Origin: *` by default, enabling an attacker to perform authenticated cross-origin requests from a malicious website after obtaining a valid API token, leading to sensitive data exfiltration and unauthorized write operations.