July 2026 (30)
Credential Exfiltration via koku-metrics-operator SSRF
1 TTPAn SSRF vulnerability in the koku-metrics-operator allows an authenticated user to exfiltrate the cluster-global Red Hat pull-secret token by specifying an arbitrary destination URL within the CostManagementMetricsConfig resource.
Authorization Bypass in Subscriptions for WooCommerce Plugin
1 rule 2 TTPs 1 CVEAn authorization flaw in the Subscriptions for WooCommerce WordPress plugin allows authenticated users with shop manager privileges to remotely install and activate arbitrary plugins.
Authentication Bypass and RCE in CentreStack via Hardcoded Cryptographic Key
1 TTP 1 CVECentreStack versions prior to 17.5 contain a hardcoded cryptographic key vulnerability, allowing unauthenticated attackers to forge authentication tokens and execute arbitrary code.
Critical Vulnerabilities in VMware vCenter and ESX Products
5 TTPs 4 CVEsMultiple critical vulnerabilities, including CVE-2026-59309 and CVE-2026-59310 with CVSS 9.8, affect VMware vCenter and ESX/ESXi products, enabling unauthorized access without credentials, arbitrary code execution, virtualization escape, information disclosure, and defense evasion, which could lead to full system compromise and data breaches.
OctLurk and SilkLurk Memory-Resident Backdoors Targeting Central Asia
1 rule 4 TTPs 6 IOCsOctLurk and SilkLurk are sophisticated, memory-resident backdoors targeting government and research entities in Central Asia since January 2025, utilizing machine-specific key derivation for payload decryption and modular plugin injection.
Microsoft Addresses Two Actively Exploited Zero-Day Vulnerabilities in July 2026 Patch Tuesday
8 TTPs 4 CVEs 8 IOCsMicrosoft's July 2026 Patch Tuesday addressed 622 vulnerabilities, including two actively exploited zero-day elevation of privilege flaws, CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint, allowing local and remote attackers to gain administrative control.
Critical RCE Vulnerability in Langflow AI Pipelines (CVE-2026-33017)
2 rules 2 TTPs 1 IOCA critical remote code execution vulnerability, CVE-2026-33017, exists in Langflow AI pipelines prior to version 1.9.0 that allows an unauthenticated remote attacker to execute code with full server process privileges, impacting availability, integrity, and confidentiality.
IBM WebSphere Application Server Security Bypass Vulnerability
1 TTPIBM WebSphere Application Server and Liberty are vulnerable to a security bypass flaw that permits remote, unauthenticated attackers to circumvent established security controls.
Denial of Service Vulnerabilities in RHEL perl-Archive-Tar and httplib2
1 TTP 2 CVEsMultiple vulnerabilities in Red Hat Enterprise Linux packages perl-Archive-Tar and httplib2 can be exploited by a remote, anonymous attacker to cause a Denial of Service condition.
Remote Code Execution Vulnerability in KDE Konsole
1 TTPA vulnerability in the KDE Konsole application allows a remote, unauthenticated attacker to execute arbitrary code, potentially leading to full system compromise.
Suspicious Windows Public IP Address Discovery via DNS
1 rule 1 TTP 33 IOCsAdversaries frequently use public IP lookup services to perform network reconnaissance and verify egress connectivity prior to establishing C2 channels, a behavior detectable via DNS query analysis from suspicious processes.
Detection of Unauthorized AWS NACL Modification by New Identities
1 TTPAdversaries may modify AWS Network Access Control Lists (NACLs) to allow all traffic, effectively disabling network-layer defenses to facilitate lateral movement or data exfiltration, a behavior this detection identifies when performed by previously unseen identities.
AWS S3 Bucket ACL Modification to Public Access by New Identity
1 rule 1 TTPDetection of unauthorized S3 bucket ACL modifications to public-read or public-read-write by previously unseen identities, potentially indicating credential compromise for data exfiltration.
Unauthenticated Remote Access to Phoenix Contact CHARX SEC MQTT Broker
2 rules 5 TTPs 12 CVEsA critical vulnerability (CVE-2026-44090) in Phoenix Contact CHARX SEC controllers allows unauthenticated remote attackers to gain full device control by bypassing authentication on the MQTT broker.
Privilege Escalation Vulnerability in Phoenix Contact CHARX Controllers
3 TTPs 1 CVEA local OS command injection vulnerability (CVE-2026-44095) in Phoenix Contact CHARX charging controllers allows low-privileged users to execute arbitrary commands as root.
Command Injection in Phoenix Contact CHARX SEC Controllers
2 TTPs 1 CVEAn unauthenticated remote command injection vulnerability in Phoenix Contact CHARX SEC controllers allows attackers to execute arbitrary code as root via malformed system configuration inputs.
Toy Ghouls Deploying Custom GenieLocker Ransomware
1 rule 4 TTPs 1 IOCThe Toy Ghouls threat actor is deploying a custom ransomware family called GenieLocker against manufacturing organizations, utilizing compromised VPN credentials and legitimate system tools for lateral movement and encryption.
Fortinet FortiOS CVE-2025-68686 Sensitive Information Exposure Bypass
1 TTP 3 CVEs 4 IOCsA remote unauthenticated attacker can exploit CVE-2025-68686 in Fortinet FortiOS to bypass a previously applied patch, allowing sensitive information exposure and enabling persistence post-exploitation, provided the product was already compromised at the filesystem level via another vulnerability.
Privilege Escalation Vulnerability in Performance Co-Pilot linux_sockets Module
1 rule 1 TTP 1 CVEA file descriptor leak in the Performance Co-Pilot (PCP) linux_sockets module allows an attacker with initial code execution to escalate privileges to root.
Command Injection in PCP linux_sockets PMDA
1 TTP 1 CVEA command injection vulnerability (CVE-2026-16524) in the PCP linux_sockets PMDA allows local attackers to execute arbitrary commands by injecting shell metacharacters into the network.persocket.filter metric.
BuddyPress Insecure Deserialization Vulnerability
1 TTPAn insecure deserialization vulnerability in the BuddyPress WordPress plugin allows authenticated attackers to inject arbitrary PHP objects, potentially leading to remote code execution.
Authorization Bypass in FleekDash V2 WordPress Plugin
1 ruleThe FleekDash V2 plugin for WordPress contains an authorization bypass vulnerability (CVE-2026-14356) that allows authenticated attackers to overwrite user credentials, including administrative accounts, leading to full site compromise.
VaahCMS OTP Template Cross-Site Scripting and Code Execution
3 TTPs 1 CVEVaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload in OTP email templates that executes unauthorized code in victim browsers, enabling credential theft and DOM manipulation.
Unauthenticated Remote Code Execution in ASE Pro WordPress Plugin
1 rule 1 CVEThe ASE Pro WordPress plugin up to version 8.9.0 is vulnerable to unauthenticated remote code execution via insecure input handling in the recursive_html function.
Authentication Bypass and Information Disclosure in Senior Rubiweb
1 rule 1 TTPSenior Rubiweb versions 6.2.34.28 and 6.2.34.37 contain an authentication bypass vulnerability (CVE-2019-19550) allowing remote, unauthenticated attackers to access administrative functions and sensitive system information via specifically crafted HTTP requests.
Cisco Security Updates — July 2026
5 CVEs 55 IOCsRoundup of Cisco security advisories published in July 2026.
Unauthenticated Remote Code Execution in RSFiles! Joomla Component
1 rule 1 CVECVE-2026-57827 allows unauthenticated attackers to achieve remote code execution via an unrestricted file upload vulnerability in the RSFiles! Joomla component.
SSRF Bypass Vulnerability in V Library
1 TTP 1 CVEThe V library (versions 0.5.2 and below) contains a server-side request forgery (SSRF) bypass vulnerability allowing attackers to circumvent host-based allowlists via URL parsing differentials.
SSRF Vulnerability in IBM WebSphere Application Server
1 CVEIBM WebSphere Application Server and Liberty are vulnerable to unauthenticated Server-Side Request Forgery (SSRF) when the SIP container feature is enabled, allowing attackers to perform unauthorized requests to internal services.
Hard-coded Credentials in Care Everywhere Gateway WildFly Management Interface
2 TTPs 1 CVEAn unauthenticated remote code execution vulnerability exists in Care Everywhere Gateway 14.3.10 due to hard-coded credentials within the bundled WildFly 8.2.0.Final management interface.