Skip to content
Threat Feed

June 2026 (24)

medium advisory

Azure Run Command Correlated with Process Execution

This rule detects the abuse of Azure Virtual Machine Run Command to execute scripts remotely, correlating Azure Activity Log events with endpoint process starts, identifying instances where adversaries use Run Command to run scripts as SYSTEM or root.

Azure +1 cloud endpoint execution powershell
2r 2t
medium advisory

Azure Run Command Script Child Process

This rule identifies suspicious process start events where the parent process matches Azure Virtual Machine Run Command execution patterns on Windows (PowerShell with `-ExecutionPolicy Unrestricted` and `script?.ps1`) or Linux (waagent running `script.sh` under `/var/lib/waagent/run-command/`), exposing on-guest payloads.

Azure Virtual Machines cloud endpoint azure execution azure-run-command
2r 3t
medium advisory

CISA ICS Advisories Address Vulnerabilities in Multiple Vendor Products

CISA published ICS advisories between May 25 and 31, 2026, addressing vulnerabilities across various vendors including ABB, CP Plus, Eppendorf, Frontier, Jinan USR IOT, KMW, MacGregor, Schneider Electric, and XCharge, impacting industrial control systems and related applications.

AC500 V2 +19 ics vulnerability cisa
2r
medium threat

Dell Security Advisory Addressing Multiple Product Vulnerabilities

Dell released security advisories in May 2026 to address vulnerabilities in PowerEdge Server Chipset Driver, Data Lakehouse, Dell Enterprise SONiC Distribution, and Dell Unity/UnityVSA/Unity XT.

PowerEdge Server Chipset Driver +5 vulnerability dell patch
2r
high advisory

Attempt to Clear Kernel Ring Buffer via dmesg

The rule detects attempts to clear the kernel ring buffer on Linux systems using the `dmesg` command with options like `-c`, `-C`, `--clear`, or `--read-clear` to evade detection.

Elastic Defend +1 defense-evasion kernel-ring-buffer linux
2r 2t
critical advisory

Multiple Vulnerabilities in JetBrains TeamCity

Multiple vulnerabilities in JetBrains TeamCity allow an attacker to disclose information, perform a cross-site scripting attack, bypass security measures, and execute arbitrary program code.

TeamCity vulnerability code-execution xss information-disclosure
2r 3t
medium advisory

Multiple Vulnerabilities in ImageMagick

A remote, anonymous attacker can exploit multiple vulnerabilities in ImageMagick to cause a denial of service condition, disclose information, and bypass security mechanisms.

ImageMagick denial of service information disclosure security bypass
2r 3t
medium advisory

PostgreSQL JDBC Driver Vulnerability Allows Denial of Service

A remote, anonymous attacker can exploit a vulnerability in the PostgreSQL JDBC Driver to perform a denial-of-service attack, impacting availability.

JDBC Driver denial-of-service postgresql jdbc
2r 1t
high advisory

Multiple Vulnerabilities in IBM Business Automation Workflow

Multiple vulnerabilities in IBM Business Automation Workflow can be exploited by an attacker to bypass security measures, conduct a denial of service attack, disclose information, manipulate files, and conduct a cross-site scripting attack.

Business Automation Workflow vulnerability denial-of-service information-disclosure cross-site-scripting
2r 2t
high advisory

Multiple Vulnerabilities in IBM App Connect Enterprise

Multiple vulnerabilities in IBM App Connect Enterprise could allow an attacker to bypass security measures, manipulate data, disclose sensitive information, cause a denial-of-service condition, or perform other unspecified attacks.

App Connect Enterprise vulnerability denial-of-service data-manipulation
2r
medium advisory

Kubernetes Static Pod Manifest File Access

This rule detects Linux process executions that reference /etc/kubernetes/manifests in process arguments, which may indicate tampering with static pod manifests for persistence or privilege escalation in Kubernetes environments.

Elastic Defend +2 kubernetes container persistence privilege-escalation linux
3r 2t
high advisory

Kubernetes and Cloud Credential Path Access via Process Arguments

This rule detects Linux process executions that access high-value Kubernetes service-account material, kubeconfig or node PKI paths, or common cloud files, potentially indicating credential theft within in-cluster and hybrid environments.

Amazon EKS +6 credential-access threat-detection kubernetes cloud linux
3r 2t
medium advisory

Kubernetes Admission Webhook Created or Modified by Non-System Identity

The creation, modification, or deletion of Kubernetes MutatingWebhookConfigurations or ValidatingWebhookConfigurations by non-system identities can allow attackers to inject malicious sidecars or block security tooling deployments for persistence and defense evasion.

kubernetes persistence defense_evasion
2r 2t
high advisory

AWS AssumeRoleWithWebIdentity from Kubernetes SA and External ASN

Detects successful AWS AssumeRoleWithWebIdentity where the caller identity is a Kubernetes service account and the source autonomous system organization is not Amazon.com, Inc., potentially indicating a stolen or misused service-account token being used off-cluster.

Amazon Web Services aws cloudtrail iam eks irsa initial-access
2r 1t
medium advisory

AWS SSM Session Manager Child Process Execution

This rule detects process start events where the parent process is the AWS Systems Manager (SSM) Session Manager worker, which can indicate remote execution and lateral movement by adversaries abusing legitimate AWS credentials.

AWS Systems Manager aws ssm execution cloud
3r 3t
medium threat

Maltrail IOC List Analysis - June 1, 2026

This brief analyzes a Maltrail IOC list from June 1, 2026, identifying domains and IP addresses associated with various malware and threat actors, including android_fvncbot, lummac2, magentocore, sectoprat, apt_lazarus, offloader, android_joker, cyberstrikeai, and nightshadec2, potentially used for command and control, malware distribution, or phishing campaigns.

maltrail ioc malware command-and-control
2r 1t 50i
medium advisory

Fujitsu ServerView Multiple Vulnerabilities Allow Privilege Escalation

A local attacker can exploit multiple vulnerabilities in Fujitsu ServerView to escalate privileges on the targeted system.

ServerView privilege-escalation fujitsu
1r 1t
high advisory

Red Hat Enterprise Linux (crun) Privilege Escalation Vulnerability

A local attacker can exploit a vulnerability in Red Hat Enterprise Linux (crun) to escalate their privileges, potentially gaining root access.

crun privilege-escalation linux
2r 1t
high advisory

Notepad++ Vulnerability Allows Code Execution

A remote, anonymous attacker can exploit a vulnerability in Notepad++ to execute arbitrary program code, potentially leading to system compromise.

Notepad++ code-execution vulnerability windows
2r 1t
high advisory

SQL Injection Vulnerability in student_management_system_by_php (CVE-2026-10226)

A SQL injection vulnerability (CVE-2026-10226) exists in student_management_system_by_php up to version 310d950e09013d5133c6b9210aff9444382d16d1, allowing remote attackers to execute arbitrary SQL commands by manipulating specific parameters in the delete.php file.

student_management_system_by_php sql-injection web-application cve-2026-10226
2r 1t 1c
high threat

SQL Injection Vulnerability in student_management_system_by_php (CVE-2026-10225)

A SQL injection vulnerability exists in raisulislamg4's student_management_system_by_php up to commit 310d950e09013d5133c6b9210aff9444382d16d1, allowing remote attackers to execute arbitrary SQL commands by manipulating the Username argument in login_check.php.

exploited student_management_system_by_php sql-injection vulnerability web-application
2r 1t 1c
high advisory

NousResearch hermes-agent <= 0.12.0 Code Injection Vulnerability (CVE-2026-10221)

NousResearch hermes-agent up to version 0.12.0 is vulnerable to code injection in the _compress_context function of the run_agent.py file, allowing remote exploitation.

hermes-agent injection code injection cve-2026-10221
2r 1t 1c
high threat

NousResearch hermes-agent Remote Code Injection Vulnerability (CVE-2026-10220)

A remote code injection vulnerability (CVE-2026-10220) exists in NousResearch hermes-agent versions up to 2026.4.30, affecting the _serve_plugin_skill/skill_view function in tools/skills_tool.py, potentially allowing attackers to inject arbitrary code.

exploited hermes-agent cve code-injection
2r 1t 1c
high advisory

GoClaw OS Command Injection Vulnerability (CVE-2026-10219)

nextlevelbuilder GoClaw up to 3.11.3 is vulnerable to remote OS command injection via manipulation of the write_file Tool component's FsBridge.WriteFile function (CVE-2026-10219), with a public exploit available.

GoClaw <= 3.11.3 command-injection vulnerability webserver
2r 1t 1c

May 2026 (6)

high advisory

CVE-2026-10192 - Tenda W12 Stack-Based Buffer Overflow in set_local_time_0

A stack-based buffer overflow vulnerability exists in Tenda W12 version 3.0.0.7(4763) in the `set_local_time_0` function, which allows a remote attacker to execute arbitrary code by manipulating the Time argument.

W12 3.0.0.7 cve buffer_overflow tenda router
2r 1t 1c
critical threat

Totolink N300RH Stack-Based Buffer Overflow Vulnerability (CVE-2026-10187)

A stack-based buffer overflow vulnerability, CVE-2026-10187, exists in the setWiFiBasicConfig function of the wireless.so file in the Web Management Interface of Totolink N300RH version 6.1c.1353_B20190305, allowing a remote attacker to execute arbitrary code by manipulating the KeyStr argument.

N300RH 6.1c.1353_B20190305 stack-buffer-overflow remote-code-execution router
2r 1t 1c
high threat

code-projects Online Music Site 1.0 SQL Injection Vulnerability (CVE-2026-10178)

CVE-2026-10178 is a remote SQL injection vulnerability in code-projects Online Music Site 1.0, affecting the /Administrator/PHP/AdminEditAlbum.php file due to manipulation of the ID argument.

exploited Online Music Site 1.0 sql-injection web-application cve
2r 1t 1c
high advisory

CVE-2025-23167 Node.js HTTP Request Smuggling via llhttp

CVE-2025-23167 describes a request smuggling vulnerability in Node.js 20's HTTP parser due to improper header termination, allowing attackers to bypass proxy access controls.

Node.js +1 cve request smuggling nodejs http
2r 1t 1c
medium advisory

Node.js Permission Model Bypass via Unix Domain Sockets (CVE-2026-21711)

CVE-2026-21711 allows code running under the Node.js permission model without network access to create and expose local IPC endpoints via Unix Domain Sockets, bypassing intended network restrictions and enabling inter-process communication.

Node.js 25.x nodejs permission model uds unix domain socket ipc cve-2026-21711
2r 1t 1c
medium advisory

CVE-2026-21717 Node.js V8 Hash Collision Vulnerability

CVE-2026-21717 is a vulnerability in V8's string hashing mechanism within Node.js that allows attackers to cause hash collisions via predictable integer-like strings in JSON input, leading to denial-of-service by degrading the performance of the Node.js process.

Node.js 20.x +3 dos hash-collision node.js
2r 2t 1c