September 2026 (30)
Detection of Kubectl Binary Masquerading and Evasion
1 rule 2 TTPsAdversaries may attempt to evade detection by renaming the kubectl binary or executing it from non-standard directories while retaining command-line functionality to perform unauthorized Kubernetes operations.
Detection of Potential HTTP Downgrade Attacks
1 rule 1 TTPAttackers may force HTTP protocol downgrades from secure versions like HTTP/2 to legacy versions to exploit header parsing inconsistencies and facilitate request smuggling or cache poisoning.
Masquerading Malicious Files via Trailing Space
1 rule 2 TTPsAdversaries utilize trailing space characters in filenames on Linux and macOS to obfuscate malicious file types and deceive users into executing them.
Detection of Oversized Base64 Obfuscated Interpreter Commands
1 rule 3 TTPsAdversaries leverage oversized, base64-encoded command lines in scripting interpreters to evade security telemetry that truncates or ignores excessively large command-line arguments.
Detecting Data Exfiltration Preparation via GenAI Processes
1 rule 3 TTPsDetection of unauthorized GenAI workflows utilizing local compression or encoding utilities followed by outbound network communication, indicating potential staging and exfiltration of sensitive data.
Detection of GenAI-Driven Autonomous Malware Compilation
1 rule 2 TTPsAdversaries are leveraging Generative AI tools and agent frameworks to autonomously generate and compile malicious executables or droppers directly on compromised endpoints.
GenAI Tool Configuration Poisoning via MCP Server Injection
1 rule 2 TTPsAdversaries are targeting configuration files of popular GenAI tools to inject malicious Model Context Protocol (MCP) servers, enabling persistence, arbitrary command execution, and data exfiltration.
Unsafe Permission Bypass in GenAI CLI Agents
1 rule 1 TTPThe misuse of permission-bypass or auto-approval flags in GenAI CLI agents disables critical human-in-the-loop guardrails, creating significant risks for prompt injection and unauthorized autonomous system modification on developer workstations.
Detection of ROT-Encoded Python Script Execution
1 rule 3 TTPsAdversaries utilize ROT-encoded Python scripts within packages to obfuscate malicious logic and evade security analysis on Windows and macOS systems.
Tampering of Shell Command-Line History
1 rule 1 TTPAdversaries manipulate shell command-line history files and environment variables on Unix-like systems to evade detection and hinder post-compromise forensic analysis.
Detection of Elastic Agent ID Spoofing and Data Manipulation
1 rule 2 TTPsThis threat brief details the detection of potential agent spoofing, where an adversary hijacks an Elastic Agent ID to inject illegitimate data or masquerade activity across multiple hosts.
Cross-Environment Secret Harvesting via Cloud APIs
1 TTPAdversaries are utilizing compromised credentials and stolen session tokens to perform rapid, automated secret harvesting across AWS, GCP, Azure, and Kubernetes environments from singular source IP addresses.
Detection of Potential Credential Discovery via Recursive Grep
1 rule 2 TTPsThis threat brief details the identification of recursive grep activity on Linux and macOS used by adversaries or insiders to discover credentials, keys, and tokens within the filesystem.
Potential Unauthorized Secret Scanning via Gitleaks
1 rule 2 TTPsThreat actors may leverage the legitimate open-source tool 'Gitleaks' to perform unauthorized secret scanning on compromised hosts to identify and exfiltrate sensitive credentials from source code repositories.
Unauthorized GenAI Tool Access to Sensitive Local System Files
1 rule 2 TTPsAttackers are increasingly leveraging GenAI agent processes to perform unauthorized discovery, harvesting of sensitive credentials, and establishment of persistence via shell configuration modifications.
Uncommon DNS Requests via Node.js or Bun Runtimes
1 rule 1 TTPAdversaries leverage compromised dependencies in Node.js or Bun development workflows to perform anomalous DNS lookups for command-and-control, staging, or exfiltration activities.
Correlation of Palo Alto Networks C2 Alerts with Endpoint Process Activity
1 TTPThis detection capability correlates Palo Alto Networks (PANW) firewall command and control alerts with Elastic Defend endpoint events to identify the specific process responsible for network traffic flagged as malicious.
Detecting Malicious Kubectl Network Configuration Manipulation
1 rule 2 TTPsThis brief documents techniques used to abuse the Kubernetes kubectl CLI for command and control or data exfiltration by manipulating network configurations through port-forwarding and proxying.
Abuse of Google Drive Download URLs for Malicious Payload Delivery
1 rule 2 TTPsAdversaries are exploiting Google Drive by appending parameters to download URLs that instruct the service to bypass antivirus scanning, facilitating the delivery of malicious payloads.
Detection of Suspicious TLD Connections by GenAI and CLI Tools
1 rule 1 TTPDetection rule monitors GenAI tools and CLI package managers for network connections to high-risk Top-Level Domains frequently utilized by threat actors for C2 infrastructure.
Abuse of Node.js Child Process to Execute External Downloaders
1 rule 2 TTPsAdversaries leverage Node.js 'child_process' modules to spawn 'curl' or 'wget' for malicious payload delivery, a technique frequently used to facilitate command-and-control by piping remote content directly into local shell interpreters.
Detection of Malicious Use of LLM Endpoints for Command and Control
1 rule 1 TTPDetection logic identifying unsigned binaries or scripting utilities establishing network connections to various Large Language Model API endpoints for potential command and control.
Detection of sqlmap Automated Tool Usage via User-Agent
1 rule 1 TTPThis brief covers the detection of the sqlmap automated penetration testing tool, which is frequently used by adversaries to perform reconnaissance and exploit SQL injection vulnerabilities in web applications.
CISA Adds Two Exploited Linux Kernel Vulnerabilities to KEV Catalog
2 CVEsCISA has added CVE-2025-39964 and CVE-2026-53266, two actively exploited Linux kernel vulnerabilities, to its Known Exploited Vulnerabilities catalog.
Remote Code Execution in jsonpath-plus via CVE-2025-1302
1 rule 2 TTPs 1 CVECVE-2025-1302 is a critical remote code execution vulnerability in the jsonpath-plus library, exploitable via malicious JSONPath expressions injected through query parameters.
CVE-2026-91149: Denial of Service via Resource Exhaustion in Cockpit
1 TTP 1 CVEAn unauthenticated remote attacker can exploit CVE-2026-91149 in Cockpit by exhausting system resources through numerous simultaneous connections to the cockpit-tls service.
Unauthenticated Routing Table Poisoning in SGLang
1 rule 2 TTPs 1 CVESGLang versions up to 0.5.19 in disaggregation mode expose an unauthenticated PUT /route endpoint allowing remote attackers to poison KV transfer tables and redirect sensitive data.
Stack-based Buffer Overflow in PLANET IGS-5225-8P2T4S Managed Switches
1 TTP 1 CVEA stack-based buffer overflow vulnerability in the web server of PLANET IGS-5225-8P2T4S industrial managed switches allows authenticated remote attackers to achieve denial of service or remote code execution via CVE-2026-81944.
Command Injection in PLANET IGS-5225 Industrial Switches
2 TTPs 1 CVEAn OS command injection vulnerability in the web interface of PLANET IGS-5225-8P2T4S switches allows authenticated remote attackers to execute arbitrary commands with root privileges.
IBM MQ Improper Validation Vulnerability (CVE-2026-11381)
1 CVEIBM MQ contains a vulnerability in the validation of message distribution list structures that allows an authenticated attacker to trigger a denial of service or potentially execute arbitrary code.