August 2026 (6)
Unauthorized Memcached Data Manipulation via CVE-2026-29093
1 rule 1 TTP 1 CVEUnauthorized actors can leverage the lack of native authentication in Memcached to perform data manipulation or session hijacking, as identified in CVE-2026-29093.
Automated LLM-Based User Account Compromise Triage
3 TTPsAn automated detection framework that uses Large Language Models to correlate disparate security alerts and assess potential account compromise based on behavioral indicators.
LLM-Based Triage of Wget Activity on Linux Hosts
1 rule 3 TTPs 13 IOCsElastic has developed a detection rule that monitors non-allowlisted `wget` activity on Linux hosts using Auditd Manager or Auditbeat, leveraging an Elastic LLM to triage `wget` executions for potential ingress tool transfer, command and control, or data exfiltration attempts to untrusted destinations, generating alerts only for high-confidence positive or suspicious verdicts.
LLM-Based Detection of Suspicious Curl Activity on Linux
3 TTPsElastic's LLM-based detection rule identifies suspicious `curl` activity on Linux systems, aiming to detect command and control, data exfiltration, or ingress tool transfer by analyzing command-line parameters and network destinations via Auditd Manager or Auditbeat logs, which, if left unaddressed, could lead to system compromise or data breach.
Detection of Data Exfiltration via Curl Utility
1 rule 3 TTPsAdversaries frequently abuse the legitimate curl command-line utility to exfiltrate collected sensitive data to external Command and Control (C2) servers via network protocols.
Unauthorized NFS Root Access via AUTH_SYS Credentials
1 rule 2 TTPsDetection of unauthorized NFS client access where a remote system asserts root-equivalent (UID 0) privileges over weak RPC/UNIX authentication, facilitating data collection and traversal.
July 2026 (24)
Adobe Security Updates — July 2026
5 CVEs 15 IOCsRoundup of Adobe security advisories published in July 2026.
Unauthenticated Remote Code Execution in ComfyUI via Unsafe Deserialization
1 rule 2 TTPs 1 CVEComfyUI version 0.23.0 is vulnerable to unauthenticated remote code execution via unsafe deserialization of malicious pickle files.
Arbitrary Code Execution in sentence-transformers via Logic Flaw
1 TTP 1 CVEA security control bypass vulnerability in sentence-transformers (CVE-2026-68770) allows arbitrary code execution during model loading by exploiting a logic flaw in the import_module_class helper.
Remote Code Execution in Savon::Model via WSDL Injection
1 TTPThe Savon Ruby library is vulnerable to remote code execution (CVE-2026-53510) due to insecure use of module_eval when processing untrusted WSDL operation names.
Redaxo Mediapool File Extension Validation Bypass and RCE
1 rule 2 TTPsA security regression in Redaxo allows authenticated backend users to achieve RCE by bypassing extension filters using multi-segment filenames on misconfigured Apache web servers.
NocoBase Authenticated SQL Injection to RCE
1 rule 2 TTPs 1 CVEA critical SQL injection vulnerability in NocoBase allows authenticated attackers to achieve remote code execution on the underlying PostgreSQL container via stacked statements.
Unauthenticated Remote Execution in dynatrace-mcp-server HTTP Transport
1 ruleThe dynatrace-mcp-server package v1.8.5 contains a critical authentication bypass vulnerability in its HTTP transport mode that allows unauthenticated, network-reachable attackers to invoke sensitive Model Context Protocol tools.
Pterodactyl Wings SFTP Service Denial of Service
1 TTP 1 CVEAn unauthenticated remote attacker can trigger a panic and crash the Pterodactyl Wings service by sending a maliciously crafted packet during the SFTP handshake.
NLTK pathsec DNS Rebinding SSRF Filter Bypass
1 TTPA DNS rebinding vulnerability in the NLTK pathsec module allows attackers to bypass SSRF filters and access restricted internal resources by manipulating hostname resolution during the validation and connection phases.
NLTK NKJPCorpusReader Path Traversal Vulnerability
1 TTPA path-traversal vulnerability in NLTK's NKJPCorpusReader allows attackers to read arbitrary files by bypassing the nltk.pathsec security sandbox.
Netty HTTP/2 Decompressor Direct Memory Leak
1 CVEA vulnerability in Netty's HTTP/2 decompressor allows an unauthenticated attacker to trigger an uncontrolled memory leak leading to a JVM OutOfMemoryError via crafted HTTP/2 DATA frames.
Sylius Mollie Plugin Payment Status Forgery Vulnerability
1 rule 1 CVEThe Sylius Mollie Plugin is susceptible to an unauthenticated payment status forgery via the webhook handler, allowing attackers to mark arbitrary orders as paid by reusing valid payment IDs.
SSRF Vulnerability in dssrf npm Package via DNS Resolver Logic
1 CVEThe dssrf npm package (versions 1.0.4 and earlier) fails to correctly validate URLs when using 1.1.1.1 as a DNS resolver, incorrectly treating localhost as safe and enabling server-side request forgery (SSRF) when NXDOMAIN responses occur.
Path Traversal and Query Injection in hashi-vault-js
1 CVEThe hashi-vault-js library is vulnerable to path traversal and query injection due to insufficient URI encoding, potentially allowing attackers to redirect administrative Vault requests if untrusted input is passed to the library.
Prototype Pollution in @phun-ky/defaults-deep
1 TTP 1 CVEThe @phun-ky/defaults-deep library is vulnerable to prototype pollution (CVE-2026-54737) via improper handling of recursive property merging, potentially allowing attackers to modify Object.prototype.
Thumbor Path Traversal via URL Decoding Bypass
1 rule 2 TTPs 1 CVE 1 IOCThumbor version 7.7.7 and earlier is vulnerable to arbitrary file read via a path traversal flaw in file_loader.py, where security checks are performed before decoding percent-encoded traversal sequences.
Pterodactyl Wings Configuration Secret Exposure via Egg Templating
1 TTP 1 CVEThe Pterodactyl Wings daemon improperly exposes its full configuration to the egg templating engine, allowing low-privileged users to exfiltrate sensitive node secrets, including daemon tokens and registry credentials, via crafted configuration placeholders.
SSRF and Credential Exfiltration in vault-secrets-webhook
3 TTPs 1 CVEThe vault-secrets-webhook is vulnerable to SSRF and ServiceAccount token theft due to unvalidated annotation handling, allowing attackers to exfiltrate JWTs via unauthorized outbound requests.
Detection of SIP REGISTER Brute Force and Credential Spraying
1 rule 2 TTPsDetection of malicious SIP REGISTER authentication attempts targeting VoIP infrastructure through anomalous 401, 403, and 407 response code patterns.
Detection of Unauthorized Apache Thrift RPC Invocations from External Networks
1 rule 1 TTP 1 CVEDetection logic targeting unauthorized Apache Thrift RPC method invocations from external IP addresses to identify exposed internal microservices or potential exploitation of data platforms.
Apache Cassandra JavaScript User-Defined Function Execution
1 rule 1 TTP 1 CVEAdversaries can exploit the creation of JavaScript-based user-defined functions in Apache Cassandra to escape the Nashorn sandbox and achieve remote code execution, particularly when vulnerable to CVE-2021-44521.
PostgreSQL COPY PROGRAM Command Execution
1 rule 1 TTPThe PostgreSQL 'COPY ... PROGRAM' feature enables users with elevated privileges to execute arbitrary operating-system commands, a technique frequently abused by attackers to deploy cryptominers or establish persistence.
Oracle Security Updates — July 2026
5 CVEs 1 IOCRoundup of Oracle security advisories published in July 2026.
CVE-2026-18141: mTLS Bypass in Ansible Automation Platform
1 TTP 1 CVEAn unauthenticated remote attacker can bypass mTLS authentication in the aap-gateway component of Event-Driven Ansible to inject arbitrary events and trigger automated workflows.