Skip to content
Threat Feed

Severity

medium 2094 briefs RSS
medium advisory

Vulnerabilities in MISP cti-transmute

The MISP project has patched multiple security vulnerabilities in the cti-transmute tool, including arbitrary file/network access and improper authorization controls for user management.

cti-transmute vulnerability misp patch-management
3i
medium advisory

Integrity Vulnerability in Thermo Fisher Genetic Analyzer Software

Thermo Fisher Applied Biosystems Genetic Analyzer software lacks integrity checks for output data files, enabling local users to modify DNA analysis results (CVE-2026-17583).

Applied Biosystems 3500/3500xL Series Data Collection Software +7
medium advisory

Remote Code Execution Vulnerability in Zyxel Firewalls

A vulnerability in Zyxel firewall firmware allows a remote, authenticated attacker to achieve arbitrary code execution on the device.

Zyxel Firewall vulnerability remote-code-execution firewall
1t
medium advisory

Multiple Denial of Service Vulnerabilities in IBM Tivoli Netcool/OMNIbus

Multiple Denial of Service vulnerabilities in IBM Tivoli Netcool/OMNIbus, potentially involving vulnerable Immutable.js libraries, allow unauthenticated remote attackers to disrupt service availability.

Tivoli Netcool/OMNIbus denial-of-service vulnerability enterprise-monitoring
1t
medium advisory

Multiple Denial of Service Vulnerabilities in PJSIP pjmedia

Multiple vulnerabilities in the PJSIP pjmedia library can be exploited by a remote, unauthenticated attacker to trigger a denial of service condition, potentially disrupting telecommunications services.

pjmedia denial-of-service voip infrastructure
1t
medium advisory

Multiple Vulnerabilities in PaperCut NG/MF

Multiple vulnerabilities, including CVE-2026-8793 and CVE-2026-8794, affect PaperCut NG/MF versions prior to 26.0.3, potentially allowing for data confidentiality breaches and security policy bypass.

PaperCut NG +1
2c
medium advisory

Detection of Destructive NFS File Operations

Detection logic identifies ransomware-like activity on NFS shares by flagging high-frequency bursts of successful WRITE, REMOVE, and RENAME operations from a single client within a one-minute window.

impact nfs ransomware network-security detection-engineering
2t
medium advisory

Apache HttpComponents Denial of Service Vulnerability

A vulnerability in Apache HttpComponents allows a remote, unauthenticated attacker to trigger a Denial of Service condition on targeted applications.

HttpComponents
1t
medium threat

Denial of Service Vulnerability in Red Hat Multicluster Engine for Kubernetes

A vulnerability in Red Hat Multicluster Engine for Kubernetes allows an unauthenticated remote attacker to trigger a denial of service condition by exploiting a software flaw.

exploited multicluster engine for Kubernetes denial-of-service kubernetes cloud-native vulnerability
1t
medium advisory

Suspicious Cross-User Process Spawning Behavior

Detection of common user-space applications being spawned under different user contexts, which often indicates privilege escalation testing or sacrificial process execution.

privilege-escalation stealth windows process-creation
1r 2t
medium advisory

Detection of Suspicious Offline Registry Library Usage

Detection of unauthorized processes loading offreg.dll to perform direct registry hive modification, potentially bypassing standard Windows Registry auditing.

defense-impairment persistence windows telemetry-bypass
1r 1t
medium advisory

Detection of Suspicious Explicit Credential Local Logon

Detection logic for monitoring Windows Event ID 4648 to identify potential privilege escalation through unauthorized explicit credential usage.

windows security-auditing privilege-escalation
1r 1t
medium advisory

Incorrect Default Permissions in Synology Assistant

Synology Assistant versions prior to 7.0.7-50095 contain a vulnerability allowing local users to perform arbitrary file operations and trigger denial-of-service during the installation process.

Synology Assistant
1c
medium advisory

Better Auth Path Normalization Vulnerability (CVE-2025-71399)

Better Auth versions prior to 1.4.5 contain a path normalization vulnerability in the rou3 library that allows attackers to bypass disabledPaths configurations and rate limits via URL path manipulation.

Better Auth web-application security-bypass cve-2025-71399
1c
medium advisory

Unauthorized Memcached Data Manipulation via CVE-2026-29093

Unauthorized actors can leverage the lack of native authentication in Memcached to perform data manipulation or session hijacking, as identified in CVE-2026-29093.

Memcached network-security cve-2026-29093 impact
1r 1t 1c
medium advisory

Detection of Data Exfiltration via Curl Utility

Adversaries frequently abuse the legitimate curl command-line utility to exfiltrate collected sensitive data to external Command and Control (C2) servers via network protocols.

Elastic Agent +1 exfiltration living-off-the-land detection-engineering curl
1r 3t
medium advisory

Unauthorized NFS Root Access via AUTH_SYS Credentials

Detection of unauthorized NFS client access where a remote system asserts root-equivalent (UID 0) privileges over weak RPC/UNIX authentication, facilitating data collection and traversal.

NFS network collection rpc
1r 2t
medium advisory

Sylius Mollie Plugin Payment Status Forgery Vulnerability

The Sylius Mollie Plugin is susceptible to an unauthenticated payment status forgery via the webhook handler, allowing attackers to mark arbitrary orders as paid by reusing valid payment IDs.

Sylius Mollie Plugin web-application e-commerce cve-2026-68500 logic-vulnerability
1r 1c
medium advisory

Detection of SIP REGISTER Brute Force and Credential Spraying

Detection of malicious SIP REGISTER authentication attempts targeting VoIP infrastructure through anomalous 401, 403, and 407 response code patterns.

PBX +1 credential-access voip network-security
1r 2t
medium advisory

Detection of Unauthorized Apache Thrift RPC Invocations from External Networks

Detection logic targeting unauthorized Apache Thrift RPC method invocations from external IP addresses to identify exposed internal microservices or potential exploitation of data platforms.

Thrift network-security initial-access microservices
1r 1t 1c
medium advisory

Redis Authenticated Remote Code Execution Vulnerability

A vulnerability in Redis allows a remote, authenticated attacker to achieve arbitrary code execution on the target server.

Redis vulnerability rce database
1t
medium advisory

Detection of Malicious AMQP Multi-Queue Message Purging

Adversaries may perform rapid multi-queue purges in AMQP-based messaging systems, such as RabbitMQ, to facilitate data destruction or cause widespread application disruption following credential compromise.

RabbitMQ
1t
medium threat

Denial of Service in gnome-remote-desktop via Connection Throttling Bypass

A vulnerability in gnome-remote-desktop allows an unauthenticated remote attacker to exhaust system resources by bypassing connection throttling when RDP is enabled in system mode on Red Hat Enterprise Linux.

exploited Red Hat Enterprise Linux denial-of-service linux rdp cve-2026-18358
1t 1c
medium advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux ABRT

Multiple vulnerabilities in the Automatic Bug Reporting Tool (abrt) within Red Hat Enterprise Linux allow a local attacker to perform privilege escalation, manipulate data, or trigger a denial-of-service condition.

Enterprise Linux +1
1t
medium advisory

Detection of Unusual AWS IAM Guardrail Policy Deletion

This threat brief identifies a detection strategy for attackers attempting defense evasion or persistence by deleting sensitive AWS IAM managed policies using previously unseen identities.

AWS IAM cloud defense-evasion persistence aws iam
1r 2t
medium advisory

Unusual AWS Batch Job Container Command Override Detection

This detection targets the abuse of AWS Batch 'containerOverrides.command' parameters by infrequent users to inject malicious commands or data exfiltration logic into production compute environments.

AWS Batch cloud aws batch cloudtrail execution
1r 1t
medium advisory

Insufficient Redirect URI Validation in MaxKey

MaxKey versions through 4.1.12 are vulnerable to OAuth 2.0 authorization code hijacking due to improper host boundary checks in the DefaultRedirectResolver component.

MaxKey oauth identity-management cve-2026-67345
2t 1c
medium advisory

Credential Exfiltration via koku-metrics-operator SSRF

An SSRF vulnerability in the koku-metrics-operator allows an authenticated user to exfiltrate the cluster-global Red Hat pull-secret token by specifying an arbitrary destination URL within the CostManagementMetricsConfig resource.

Cost Management Metrics Operator
1t
medium advisory

IBM WebSphere Application Server Security Bypass Vulnerability

IBM WebSphere Application Server and Liberty are vulnerable to a security bypass flaw that permits remote, unauthenticated attackers to circumvent established security controls.

WebSphere Application Server +1 vulnerability websphere middleware
1t
medium advisory

Detection of Unauthorized AWS NACL Modification by New Identities

Adversaries may modify AWS Network Access Control Lists (NACLs) to allow all traffic, effectively disabling network-layer defenses to facilitate lateral movement or data exfiltration, a behavior this detection identifies when performed by previously unseen identities.

AWS EC2 aws cloud defense-evasion
1t
medium advisory

AWS S3 Bucket ACL Modification to Public Access by New Identity

Detection of unauthorized S3 bucket ACL modifications to public-read or public-read-write by previously unseen identities, potentially indicating credential compromise for data exfiltration.

AWS S3 cloud aws collection s3
1r 1t
medium advisory

Easy!Appointments Excessive Data Exposure and Appointment Takeover

An excessive data exposure vulnerability in Easy!Appointments version 1.5.2 allows authenticated attackers to retrieve sensitive appointment hashes and hijack other providers' appointments.

Easy!Appointments web-application cve-2026-55651 access-control
1r 1t 1c
medium advisory

Req Library Unbounded Archive/Compression Extraction Denial-of-Service

The Elixir library 'Req' (versions >= 0.1.0, < 0.6.1) is susceptible to a denial-of-service vulnerability (CVE-2026-49755) caused by unbounded archive and compression extraction, which an attacker can leverage by providing a malicious HTTP response with a crafted 'content-type' or 'content-encoding' header, leading to memory exhaustion and application crashes.

Req denial-of-service elixir vulnerability memory-exhaustion
1t 1c
medium advisory

Apache Tomcat Denial of Service Vulnerability (CVE-2026-66299)

A critical vulnerability, CVE-2026-66299, has been discovered in Apache Tomcat versions 9.0.x prior to 9.0.121, 10.1.x prior to 10.1.58, and 11.0.x prior to 11.0.25, allowing a remote attacker to cause a denial of service (DoS).

Apache Tomcat +2 denial-of-service vulnerability apache-tomcat
1t 1c 4i
medium threat

Detection of Container Tunneling and Port Forwarding Tools

Elastic has released a detection rule for its Defend for Containers integration, identifying the use of tunneling and port forwarding tools within Linux containers, indicating potential threat actor activity such as command-and-control, data exfiltration, or lateral movement.

exploited container-security cloud-native command-and-control data-exfiltration lateral-movement linux
1r 2t
medium advisory

DebugFS Execution Detected via Defend for Containers

Attackers can leverage the Linux `debugfs` utility within privileged containers to access and manipulate host file systems (e.g., /dev/sd*), enabling privilege escalation and container escape to the underlying host machine.

container privilege-escalation linux elastic-defend
1r 2t
medium advisory

SSH Authorized Key File Activity Detected in Containers

Adversaries may modify the Secure Shell (SSH) authorized_keys file inside Linux containers to maintain persistence, achieve lateral movement, or escalate privileges by adding their own public keys, with this activity detected by Elastic Defend for Containers.

container linux persistence lateral-movement privilege-escalation ssh
1r 4t
medium advisory

Suspicious Interactive Interpreter Execution in Containers

This brief describes the detection of suspicious inline command execution by scripting interpreters (Perl, PHP, Lua, Python, Ruby) within Linux containers, indicating potential malicious code execution, data exfiltration, or command-and-control by an attacker without dropping files, requiring decoding payloads and investigation of container integrity.

container linux execution command-and-control defense-evasion
1r 6t
medium advisory

Netcat Listener or File Transfer Detected in Containers

This threat brief details the detection of malicious Netcat usage within Linux containers, indicating potential backdoor establishment, persistence, command and control, or data exfiltration by adversaries.

Containers container linux execution command-and-control exfiltration netcat
1r 3t
medium advisory

Container Compromise via File Creation in System Binary Locations

Adversaries leverage tools like wget, curl, or busybox to create files within critical system binary directories such as /etc, /root, /bin, /usr/bin, /usr/local/bin, or /entrypoint inside running Linux containers to establish persistence, execute commands, or evade detection.

container-security linux execution defense-evasion command-and-control
1r 4t
medium advisory

Suspicious File Creation and Execution within Linux Containers

An Elastic Defend for Containers rule detects suspicious activity in Linux containers where a process creates a file in a writable directory and immediately executes it, indicating potential hands-on intrusion, container breakout, unauthorized host access, privilege escalation, or evasion of security controls.

container linux execution command-and-control threat-detection
1r 2t
medium advisory

Direct Kubernetes API Request Detected via Elastic Defend for Containers

Adversaries leveraging initial access within a container may execute direct Kubernetes API requests using tools like curl, wget, or kubectl, often with bearer tokens and insecure TLS, for cluster enumeration, lateral movement, or privilege escalation, which can be detected by Elastic Defend for Containers.

Kubernetes container linux threat-detection execution discovery lateral-movement
1r 4t
medium advisory

Detection of Encoded Payload Deobfuscation in Linux Containers

Attackers are leveraging encoded payloads within Linux containers for defense evasion, using common decoding tools like base64, xxd, or scripting language one-liners to deobfuscate and execute malicious code, allowing for covert command and control, staging, and further compromise.

container linux defense-evasion execution
1r 5t
medium advisory

Kubernetes Service Account Token and Certificate Credential Access

A detection rule from Elastic identifies adversaries reading Kubernetes service account tokens or CA certificates within containers, typically using utilities like `cat` on `/var/run/secrets/kubernetes.io/serviceaccount/token` and `ca.crt` to authenticate to the Kubernetes API server and escalate privileges or expand access within the cluster.

Kubernetes container credential-access linux elastic-defend
2r 2t 5i
medium advisory

Sensitive File Compression Detected in Linux Containers for Credential Access

Elastic Defend for Containers detects the use of compression utilities like tar or zip within Linux containers to collect sensitive files such as SSH keys, AWS credentials, or system configurations, indicating potential credential access and data collection attempts by adversaries.

Defend for Containers container linux credential-access data-collection threat-detection discovery reconnaissance network-scanning +6
3r 8t 1i
medium advisory

Cloud Credential Search in Containers Detected

An attacker using system search utilities like `grep` or `find` within a containerized environment to locate cloud credentials (AWS, Azure, GCP) indicates an attempt to gain unauthorized access to sensitive cloud resources or perform a container breakout to compromise the underlying cloud infrastructure.

Amazon Web Services +2 container credential-access discovery cloud linux
1r 2t
medium advisory

Detecting Interactive File Downloads in Linux Containers via Curl and Wget

This threat brief details how adversaries download files from the internet into Linux containers using `curl` or `wget` to stage tools, payloads, or establish application-layer command and control (C2), which detection engineers can identify by monitoring process execution within containers and correlating with audit logs.

Kubernetes +1 container-security cloud-security linux command-and-control execution elastic-defend threat-detection
1r 3t
medium advisory

Curl SOCKS Proxy Detected via Elastic Defend for Containers

Attackers utilize the `curl` command-line tool with SOCKS proxy options inside Linux containers to bypass network restrictions, enabling command and control communications or data exfiltration, which defenders can detect by monitoring process execution within container environments for suspicious `curl` arguments and network tunneling activity.

container linux command-and-control threat-detection
1r 2t
medium advisory

Apache Tomcat Vulnerability Allows Denial of Service

A vulnerability in Apache Tomcat allows a remote, anonymous attacker to perform a Denial of Service attack, potentially disrupting service availability for applications hosted on the affected server.

Apache Tomcat denial-of-service vulnerability apache
1t
medium advisory

Broadcom Brocade SANnav Vulnerabilities Allow Information Disclosure, SQL Injection, and Data Manipulation

Multiple vulnerabilities in Broadcom Brocade SANnav can be exploited by an attacker from an adjacent network to achieve information disclosure, execute SQL injection attacks, and manipulate data within the system.

SANnav vulnerability sql-injection data-manipulation information-disclosure network-attack
3t
medium advisory

Tanium Endpoint Management Vulnerability Allows Authenticated SQL Injection

A remote, authenticated attacker can exploit a SQL injection vulnerability in Tanium Endpoint Management, enabling the execution of arbitrary SQL commands and potentially leading to data manipulation or unauthorized access.

Tanium Endpoint Management sql-injection vulnerability endpoint-management
2t
medium threat

IBM WebSphere Application Server Liberty: Multiple Vulnerabilities Enable Denial of Service

Multiple vulnerabilities exist in IBM WebSphere Application Server Liberty that an attacker can exploit to perform a Denial of Service attack.

exploited WebSphere Application Server Liberty denial-of-service vulnerability ibm websphere
1t
medium advisory

datamodel-code-generator Vulnerable to SSRF Protection Bypass via DNS Rebinding

The `datamodel-code-generator` tool is vulnerable to a Server-Side Request Forgery (SSRF) protection bypass, identified as CVE-2026-55391, due to a time-of-check/time-of-use (TOCTOU) race condition through DNS rebinding, allowing attackers to access internal services like cloud instance metadata endpoints when processing attacker-influenced URLs.

datamodel-code-generator ssrf dns-rebinding vulnerability supply-chain python
4t 1i
medium advisory

IBM WebSphere Application Server Liberty Denial of Service Vulnerability (CVE-2026-16192)

A denial of service vulnerability, CVE-2026-16192, affects IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8 when the `restConnector-2.0` feature is enabled, allowing an unauthenticated attacker to cause service unavailability.

WebSphere Application Server - Liberty +1 denial-of-service vulnerability websphere
2c
medium advisory

Progress Software Security Advisory Addresses Multiple Vulnerabilities

Progress Software has issued a security advisory (AV26-755) addressing multiple vulnerabilities, identified by CVEs CVE-2026-59686 through CVE-2026-59690, across several of its products including ECS Connection Manager, LoadMaster, MOVEit WAF, Multi Tenant, and Object Scale Connection Manager, with specific versions prior to various patch levels being vulnerable, urging administrators to apply necessary updates to secure their systems.

ECS Connection Manager < 7.2.63.3 +4 vulnerability cve security-advisory patch-management
5c
medium advisory

SIPSorcery: Malformed UDP Packet Can Remotely Terminate Media Sessions (DoS)

A denial-of-service vulnerability (CVE-2026-54632) exists in the SIPSorcery NuGet package versions <= 10.0.8, allowing an unauthenticated attacker to remotely terminate an active RTP or WebRTC media session by sending a single malformed inbound UDP packet to the RTP/ICE socket, which exploits insufficient length checks and an exception handling flaw.

SIPSorcery denial-of-service vulnerability nuget
2t
medium advisory

Poweradmin Vulnerable to Host Header Injection in Authentication Redirects

Poweradmin versions earlier than 4.2.4 and from 4.3.0 up to, but not including, 4.3.3 are vulnerable to CVE-2026-54588, a critical Host Header Injection flaw in OIDC, SAML, and logout authentication flows that allows an unauthenticated attacker to manipulate the HTTP_HOST header, poisoning callback URLs to redirect authorization codes to an attacker-controlled server, leading to full account takeover and potential full DNS zone control.

Poweradmin +1 web-vulnerability host-header-injection oidc saml account-takeover dns-hijacking
3t 1c 1i
medium advisory

QTINeon NeonRelay Unauthenticated Denial-of-Service Amplification Vulnerability

An unauthenticated attacker can exploit an unbounded RECONNECT_REQUEST forwarding vulnerability in QTINeon's NeonRelay component to amplify denial-of-service attacks against a connected host. By sending spoofed RECONNECT_REQUEST packets, the relay forwards each one to the host without proper deduplication or rate limiting, consuming host resources. Additionally, excessive spoofed IPs can reset legitimate rate limiting, further impacting service availability. This vulnerability affects Java, Python, and TypeScript implementations of NeonRelay.

qti-neon = 1.0.0 denial-of-service amplification network vulnerability
3t
medium advisory

Cross-origin OAuth token-request redirects can expose signed request metadata

The 'oauth' Ruby gem versions 0.5.5 through 1.1.5 are vulnerable to a critical issue (CVE-2026-54605) where the 'OAuth::Consumer#token_request' method improperly handles HTTP 3xx redirects during OAuth 1.0 token exchanges, enabling an attacker to redirect the request to a malicious host, exposing sensitive OAuth 1.0 metadata, and facilitating Server-Side Request Forgery (SSRF) and confused-deputy behavior.

oauth vulnerability ssrf ruby gem web-application
3t
medium advisory

Pterodactyl Panel Global Rate-Limit Vulnerability Enables Unauthenticated DoS (CVE-2026-61609)

An unauthenticated attacker can exploit CVE-2026-61609, a global rate-limit vulnerability in Pterodactyl Panel versions up to and including 1.12.4, by sending approximately 10 requests per minute to authentication endpoints, leading to a panel-wide denial of service for all legitimate users and administrators attempting to log in or complete 2FA.

Panel denial-of-service vulnerability web-application pterodactyl
1r 2t
medium advisory

GitHub MCP Server Nil Pointer Dereference DoS in completion/complete Handler (CVE-2026-47427)

A nil pointer dereference vulnerability, tracked as CVE-2026-47427, in the GitHub MCP Server's `completion/complete` handler allows an unauthenticated attacker to cause a complete denial of service by sending a malformed JSON-RPC request with missing or empty parameters for the `ref` field, leading to an immediate server crash.

github-mcp-server denial-of-service vulnerability github
1t
medium advisory

Lettré Library TLS Hostname Verification Bypass Vulnerability (CVE-2026-46428)

An inverted-boolean bug (CVE-2026-46428) in the `lettre` library's `boring-tls` integration silently disables TLS hostname verification for callers using the default strict configuration, allowing an on-path attacker with any chain-valid certificate to intercept SMTP submission, including credentials and message contents, from affected `lettre` clients.

lettre tls mitm library-vulnerability rust mail
3t 1c
medium advisory

Multiple Vulnerabilities in Samba

Multiple vulnerabilities have been discovered in Samba, a network file sharing service, which could allow a remote attacker to trigger a denial of service, compromise data confidentiality, and bypass security policies.

Samba +2 vulnerability denial-of-service data-breach security-bypass
3t 1c
medium advisory

Multiple Vulnerabilities in Apache Wicket Allow XSS and Security Bypass

An anonymous, remote attacker can exploit multiple vulnerabilities in Apache Wicket to perform Cross-Site Scripting (XSS) attacks and bypass existing security measures, potentially leading to unauthorized client-side script execution and further compromise of user sessions or data.

Wicket vulnerability web-application xss security-bypass
2t
medium advisory

binutils: Vulnerability Enables Denial of Service and Data Disclosure

A local attacker can exploit a vulnerability in binutils to cause a Denial of Service condition and disclose sensitive data.

binutils linux macos denial-of-service data-disclosure vulnerability
2t
medium advisory

Netty: Vulnerability Enables Denial of Service

A denial of service vulnerability exists in Netty, which an unauthenticated, remote attacker can exploit, allowing the attacker to disrupt the availability of affected systems or services.

Netty denial-of-service vulnerability
1t
medium advisory

CVE-2026-14169: Ads-tec DVG-IRF Series Vulnerability Allows Remote Admin Lockout

A low-privileged remote attacker can exploit an incorrect behavior order vulnerability (CVE-2026-14169, CWE-696) in multiple ads-tec Industrial IT DVG-IRF series devices (versions prior to 2.3.0) by sending crafted input, leading to inconsistent account states and password overwrites, resulting in complete administrative unavailability of the device.

DVG-IRF1401 +5 vulnerability denial-of-service industrial-control-systems network-device
1t 1c
medium advisory

Credential Manager Access By Uncommon Applications

A SigmaHQ detection rule identifies suspicious processes accessing Windows credential manager and vault files, potentially indicating credential theft by tools like Mimikatz, enabling lateral movement and data exfiltration.

credential-theft mimikatz dpapi windows post-exploitation
1r 1t
medium advisory

Msiexec Quiet Installation for Proxy Execution

Adversaries leverage the Windows Installer utility msiexec.exe to proxy the quiet execution of malicious payloads, bypassing traditional security controls by masquerading as legitimate installation processes.

living-off-the-land proxy-execution persistence execution
1r 1t
medium advisory

Suspicious WSMAN Provider Image Loads

A detection engineering rule targets suspicious loading of Windows Management (WSMAN) provider DLLs by unusual processes, indicating potential local or remote execution and lateral movement through Windows Remote Management (WinRM) by threat actors.

lateral-movement remote-execution windows-management winrm
1r 2t
medium advisory

PowerShell Core DLL Loaded By Non PowerShell Process

This threat brief details a detection for the suspicious loading of PowerShell Core DLLs by non-PowerShell processes, a technique often employed by attackers to execute PowerShell code stealthily and evade security monitoring.

defense-evasion scripting powershell
1r 1t
medium advisory

PSScriptPolicyTest Creation By Uncommon Process

This brief describes a detection opportunity for the stealthy creation of the 'PSScriptPolicyTest' PowerShell script by processes other than standard PowerShell executables or legitimate Windows components, a behavior potentially indicative of advanced adversaries attempting to bypass PowerShell logging and security policies.

stealth detection powershell
1r 1t
medium advisory

Suspicious System Process Names in Unusual File Locations

This brief detects an attacker's attempt to evade detection and maintain persistence by creating executable files with names identical to legitimate Windows system processes in non-standard directories, a tactic associated with stealth and defense evasion.

stealth defense-evasion persistence windows file-event
1r 1t
medium advisory

Suspicious Access to Windows DPAPI Master Keys by Uncommon Applications

Adversaries can access Windows Data Protection API (DPAPI) master keys using uncommon applications like Mimikatz to decrypt user credentials and sensitive data, indicating credential theft activities.

dpapi credential-theft mimikatz windows credential-access
1r 1t
medium advisory

The Demi WordPress Plugin Vulnerable to Arbitrary Directory Deletion (CVE-2026-14490)

Unauthenticated attackers can exploit CVE-2026-14490 in The Demi - One Click Demo Import, WP Backup & Site Migration WordPress plugin (versions up to and including 0.0.7) to achieve arbitrary directory deletion by retrieving a publicly exposed HMAC signing key and forging valid requests to a vulnerable AJAX handler.

The Demi – One Click Demo Import, WP Backup & Site Migration plugin <= 0.0.7 wordpress plugin-vulnerability arbitrary-deletion web-vulnerability
2t 1c
medium threat

Detection of Unauthorized WinSCP Credential Access

This analytic detects unauthorized access to the WinSCP security configuration folder, which stores sensitive SSH and FTP credentials, by processes other than WinSCP, leveraging Windows Security Event 4663 to identify abnormal read or access attempts often indicative of credential-stealing malware like Phantom Stealer.

WinSCP Phantom Stealer credential-theft infostealer windows
1r 1t 2i
medium advisory

Abuse of MSIExec for Remote File Download and Execution

This brief details the abuse of the Windows utility msiexec.exe by attackers to download and execute remote files via HTTP or HTTPS URLs, often leading to unauthorized code execution, system compromise, or further malware deployment.

windows living-off-the-land proxy-execution defense-evasion
1r 2t
medium advisory

Windows AppCertDLL Modification for Persistence and Privilege Escalation

Attackers can modify Windows AppCertDLL registry keys via command-line utilities to achieve persistence and privilege escalation by registering malicious DLLs to be loaded early in the system startup process.

persistence privilege-escalation windows
1r 2t
medium advisory

Detection of Local LLM Framework DNS Queries

This brief details the detection of DNS queries originating from local Large Language Model (LLM) frameworks like Ollama, LM Studio, and GPT4All on Windows endpoints, leveraging Sysmon Event ID 22 to identify potential unauthorized AI tool usage or data exfiltration risks associated with model downloads, updates, and telemetry from repositories such as huggingface.co and ollama.ai.

Claude +16 local-llm shadow-ai dns-monitoring data-exfiltration policy-violation windows endpoint-security
1r 3t 18i
medium advisory

Detection of Local LLM Model File Creation on Endpoints

This brief describes how the creation of Large Language Model (LLM) files, including formats like .gguf, .safetensors, .ggml, and Modelfiles, by local AI inference frameworks such as Ollama, llama.cpp, GPT4All, and LM Studio can be detected on Windows endpoints, indicating potential shadow AI deployments, unauthorized model downloads, or rogue LLM infrastructure which poses data exfiltration risks and policy violations.

Ollama +9 shadow-it llm data-exfiltration policy-violation endpoint shadow-ai local-llm intellectual-property-theft +2
2r 5t
medium advisory

Detecting Rclone Execution with Network Activity for Data Exfiltration

This detection identifies the malicious use of 'rclone', a legitimate file synchronization utility, for data exfiltration or cloud abuse by flagging `rclone.exe` execution when specific suspicious command-line arguments are used, such as those indicating synchronization to remote cloud storage providers like `mega:`, `ftp:`, or generic `remote:`, especially in conjunction with flags like `--transfers`, `--ignore-existing`, or `--auto-confirm`, which is a critical indicator of compromise abused by threat actors for stealthy data exfiltration.

data-exfiltration rclone cloud-abuse endpoint-detection network-detection threat-actor-tool
1r 1t
medium advisory

AWS Bedrock Guardrail Deleted

A detection rule has been developed for Amazon Bedrock that identifies the deletion of guardrails, indicating a potential attempt by an attacker or insider to disable AI model safety controls and facilitate unsafe or unauthorized responses.

AWS Bedrock aws cloud-security defense-impairment cloud ai llm defense-evasion
2r 2t
medium advisory

etcd TLS Listener Denial of Service Vulnerability

A denial-of-service vulnerability in etcd's TLS listener allows a network attacker to exhaust server memory by spawning unbounded goroutines through multiple TCP connections without sending ClientHello messages, leading to loss of availability for etcd clusters and dependent services like Kubernetes.

etcd +2 denial-of-service kubernetes TLS
1t
medium advisory

py-libp2p yamux Connection DoS via Oversized Data Frame

A denial-of-service vulnerability in py-libp2p versions up to 0.6.0 allows an authenticated attacker to send a specially crafted 12-byte DATA or SYN frame with an oversized length field, causing the victim's yamux read loop to block indefinitely and freezing all streams on the affected connection.

py-libp2p denial-of-service vulnerability network python libp2p
1t
medium advisory

Unbounded WebSocket Message Aggregation Leads to Denial of Service in http4s-blaze-server

A vulnerability in `http4s-blaze-server` allows an attacker to cause a denial of service by exploiting unbounded WebSocket message aggregation, enabling an attacker to drive unbounded heap growth in the server's JVM by sending an unterminated fragmented WebSocket message, leading to an `OutOfMemoryError` and server termination, affecting any http4s application serving WebSocket routes over `BlazeServerBuilder` and triggerable by unauthenticated or authenticated clients.

http4s-blaze-server_2.13 +3 denial-of-service webserver jvm websocket
1t
medium advisory

Poweradmin: Broken Access Control (IDOR) Allows DNS Record Modification

A low-privilege authenticated user in Poweradmin (a web front-end for PowerDNS) can exploit an Insecure Direct Object Reference (IDOR) vulnerability, allowing them to modify any DNS record on the server, even those they do not own, by manipulating POST request parameters to bypass access control checks and achieve DNS record repointing, disabling, or hijacking, leading to data integrity and availability issues, and potentially cross-tenant DNS takeover.

Poweradmin +2 idor dns-takeover web-application vulnerability access-control
3t 5i
medium advisory

@anephenix/hub Unauthenticated WebSocket RPC Waiter Resource Exhaustion (CVE-None)

An unauthenticated Denial-of-Service vulnerability in `@anephenix/hub` versions prior to 0.2.16 allows attackers to exhaust server CPU and memory resources by opening numerous WebSocket connections and ignoring server-initiated RPC messages, leading to unbounded timers and heap entries.

@anephenix/hub < 0.2.16 denial-of-service websocket node.js
1t
medium advisory

Netty XmlFrameDecoder CPU Exhaustion Denial of Service

An unauthenticated remote attacker can cause a Denial of Service (DoS) in Netty servers utilizing XmlFrameDecoder by sending a specially crafted XML payload containing repeated '</' characters, leading to CPU exhaustion of the server's EventLoop thread and unresponsiveness.

netty-codec-xml +1 denial-of-service cpu-exhaustion network-attack vulnerability
1t
medium advisory

React Router RSC Mode CSRF Bypass

A high-severity Cross-Site Request Forgery (CSRF) bypass vulnerability in React Router's unstable React Server Components (RSC) APIs allows for action execution before a 400 response, impacting applications utilizing these specific APIs.

react-router react router csrf web-application vulnerability
1t 1c
medium advisory

js-yaml Denial of Service via Exponential Parsing Time in Flow Collections

A denial of service vulnerability exists in the js-yaml library (versions 5.0.0 through 5.2.1) due to an exponential parsing time bug in flow collections, allowing attackers to craft a small YAML document which, when processed by `load()` or `loadAll()` functions, consumes significant CPU resources and blocks the Node.js event loop.

js-yaml denial-of-service yaml javascript vulnerability
1t
medium advisory

Account Takeover via Pre-Account Hijacking in Better Auth Library

An attacker can perform a pre-account hijacking attack against the `better-auth` library if it uses magic-link or email-OTP plugins alongside open email and password registration and allows unverified accounts. The attacker first registers an account using the victim's email with a password they control. When the legitimate victim later uses a passwordless flow to verify their account, the attacker's pre-set password remains active, granting them persistent, unauthorized access to the victim's account and data, potentially leading to account takeover and user lockout.

better-auth < 1.6.22 +1 account-takeover vulnerability web-application pre-account-hijacking
3t
medium advisory

Account Takeover and Stale Access via SCIM Provider-ID Collision in @better-auth/scim

The `@better-auth/scim` package is affected by multiple vulnerabilities, including a critical provider-ID collision flaw that allows authenticated users to craft SCIM tokens impersonating existing account providers, leading to unauthorized account access, profile modification, and user deletion, while additional issues include failed user deactivation and email update vulnerabilities bypassing uniqueness checks in versions `1.4.0-beta.27` through `1.6.21` and `1.7.0-beta.0` through `1.7.0-beta.9`.

@better-auth/scim vulnerability web-application account-takeover sso
5t
medium advisory

LiquidJS pop Filter Bypasses Memory Limit Accounting

A vulnerability (CVE-2026-55575) in the LiquidJS templating library's `pop` filter, affecting versions up to and including 10.27.0, allows an attacker to bypass the `memoryLimit` accounting, leading to uncontrolled memory allocation and potential denial of service when processing untrusted, large arrays in templates.

LiquidJS denial-of-service vulnerability memory-exhaustion nodejs
1t 1c
medium advisory

React Router Denial of Service via Inefficient Route Matching (CVE-2026-55685)

An unauthenticated attacker can exploit CVE-2026-55685 in React Router versions 7.0.0 through 7.17.x, when used in Framework Mode applications, to cause a denial-of-service condition by repeatedly accessing the manifest endpoint, leading to heavy server load and slow response times.

react-router web-vulnerability denial-of-service npm
1t
medium threat

Multiple Vulnerabilities in MongoDB Core Server and Compass

Numerous vulnerabilities across MongoDB Core Server and Compass, identified as CVE-2026-13055 through CVE-2026-13078, CVE-2026-14881, and CVE-2026-9737, enable attackers to bypass security policies and induce denial-of-service conditions, necessitating immediate patching.

exploited Compass +4 vulnerability database mongodb
2t 5c 52i
medium advisory

FFmpeg: Multiple Vulnerabilities Allow Code Execution and DoS

Multiple vulnerabilities in FFmpeg allow an attacker to achieve arbitrary code execution or cause a denial-of-service condition.

ffmpeg vulnerability code-execution dos execution impact
2t
medium advisory

Multiple Netty Vulnerabilities Enable Denial of Service Attacks

Multiple vulnerabilities in Netty can be exploited by an attacker to conduct Denial of Service (DoS) attacks, impacting the availability of services utilizing the Netty framework.

Netty denial-of-service vulnerability framework
1t
medium advisory

RabbitMQ: Multiple Vulnerabilities Allowing Denial of Service and Security Bypass

A remote, authenticated attacker can exploit multiple undisclosed vulnerabilities in RabbitMQ to conduct denial-of-service attacks and bypass existing security measures, impacting the availability and integrity of messaging systems.

RabbitMQ denial-of-service defense-evasion messaging-broker
1t
medium advisory

Red Hat Quay Vulnerability Allows Authenticated Remote Attacker to Bypass Security

An authenticated remote attacker can exploit a vulnerability in Red Hat Quay to bypass security measures, circumventing established security controls within the container registry.

Red Hat Quay red-hat quay vulnerability security-bypass container-registry
1t
medium advisory

QT Vulnerability Enables File Manipulation

A remote, anonymous attacker can exploit a vulnerability in QT to manipulate files, potentially affecting data integrity or system functionality.

QT vulnerability file-manipulation
1t
medium advisory

Suspicious Child Process Creation by Wscript or Cscript

Adversaries commonly use Wscript or Cscript to launch suspicious child processes, including LOLBINs and scripting interpreters, as a defense evasion and execution technique, which can lead to further system compromise or data destruction.

endpoint-detection defense-evasion execution LOLBIN scripting
1r 2t 1i
medium advisory

Apache Tomcat mod_jk Connector: Vulnerability Enables Security Bypass or Information Disclosure

A vulnerability in the Apache Tomcat mod_jk Connector allows a remote, unauthenticated attacker to bypass security measures or disclose sensitive information, which could enable an adversary to gain unauthorized access or collect confidential data.

Tomcat mod_jk Connector defense-evasion network vulnerability
2t
medium advisory

Malware Employs Web Services for Victim IP Reconnaissance

Malware, including Trickbot and various stealers, utilizes DNS queries to public IP checking web services for reconnaissance purposes, aiming to determine the victim's external IP address, which can facilitate further attacks or lateral movement.

reconnaissance malware dns-query windows
1r 1t 27i
medium advisory

Windows DNS Query Request by Telegram Bot API

An analytic detects DNS queries to `api.telegram.org` originating from non-Telegram processes on Windows systems, indicating potential malware command and control (C2) communication or data exfiltration via the Telegram Bot API.

command-and-control malware windows c2 dns telegram
1r 2t 1i
medium advisory

Windows Curl Download to Suspicious Path Detection

This analytic detects the use of Windows Curl.exe to download files to suspicious locations, such as AppData, ProgramData, or Public directories, leveraging Endpoint Detection and Response (EDR) data by focusing on command-line executions that include the -O or --output options; this activity is significant as it can indicate an attempt to bypass security controls or establish persistence, potentially leading to unauthorized code execution, data exfiltration, or further system compromise.

Windows endpoint command-and-control defense-evasion
1r 1t updated
medium advisory

Windows Autostart Execution in Startup Folder for Persistence

Adversaries leverage the Windows %startup% folder to establish persistence by creating malicious files that execute automatically upon system boot or user logon, potentially leading to system compromise and unauthorized access.

persistence autostart windows detection
1r 1t
medium advisory

Anti-Virus Product Reconnaissance via PowerShell or WMI

This brief details the detection of suspicious PowerShell script execution that targets the discovery of installed anti-virus and anti-spyware products using WMI or PowerShell commands, a common reconnaissance tactic employed by malicious actors to map security applications and potentially evade defenses.

reconnaissance discovery defense-evasion powershell wmi endpoint
1r 1t
medium advisory

Denial of Service Vulnerability in find-my-way Node.js Router

A remotely triggerable Denial of Service (DoS) vulnerability exists in the 'find-my-way' router when used with Node.js HTTP/2 servers. Malicious HTTP/2 method values, such as 'constructor' or '__proto__', can be passed to the 'lookup()' function, which then indexes these values against internal data structures. This leads to a crash when the code attempts to access properties of these unexpected values, such as 'currentNode.prefix.length', causing the server to become unavailable. Users are advised to upgrade to version 9.7.0 or validate HTTP methods before processing.

find-my-way denial-of-service nodejs http2 vulnerability
1r 2t
medium advisory

PHPSpreadsheet Denial of Service via Malformed XLS/OLE Sector Chain

PhpSpreadsheet's OLE reader contains a denial-of-service vulnerability where it fails to detect cycles in attacker-controlled XLS/OLE sector chains, leading to infinite loops and memory exhaustion when parsing specially crafted, small malformed XLS/OLE files, which can cause PHP workers to crash and deny service to web applications processing untrusted spreadsheet uploads.

PhpSpreadsheet +4 denial-of-service vulnerability php xls ole
1t
medium advisory

PhpSpreadsheet Gnumeric Reader Unbounded Gzip Expansion Leads to Denial of Service

The PhpOffice PhpSpreadsheet library is vulnerable to a denial of service (DoS) attack, identified as CVE-2026-59932, where its Gnumeric reader processes attacker-supplied `.gnumeric` files containing gzipped content without enforcing a decompressed-size limit, causing memory exhaustion and application crashes.

PhpSpreadsheet +4 denial-of-service vulnerability php ghsa software-supply-chain
1t
medium advisory

Auth.js getToken() Vulnerability Leads to Denial of Service

A vulnerability in the Auth.js `getToken()` helper function (next-auth and @auth/core) allows unauthenticated attackers to trigger an uncaught exception via a malformed `Authorization: Bearer` header, leading to a per-request denial of service in affected applications.

@auth/core +1 denial-of-service vulnerability web-application javascript input-validation
1t
medium advisory

Exim: Multiple Vulnerabilities Allow Local Command Execution and Privilege Escalation

Multiple vulnerabilities in Exim allow a local attacker to execute arbitrary commands and escalate privileges on the affected system, enabling a local adversary to gain higher control over the mail transfer agent and potentially the underlying operating system.

Exim vulnerability privilege-escalation command-execution
2t
medium advisory

Internet Systems Consortium BIND: Multiple Vulnerabilities

Multiple vulnerabilities in Internet Systems Consortium BIND allow an anonymous, remote attacker to bypass security measures, manipulate data, disclose confidential information, or trigger a Denial-of-Service condition, potentially leading to compromise of data integrity, confidentiality, and availability of the DNS service.

BIND dns vulnerability denial-of-service data-manipulation information-disclosure network-infrastructure
3t
medium threat

Intel Ethernet Products: Multiple Vulnerabilities

Multiple vulnerabilities exist in various Intel Ethernet products, which an attacker can exploit to trigger a denial-of-service condition and expose confidential information.

exploited Intel Ethernet Products vulnerability intel network-device dos information-disclosure
2t
medium advisory

Excon Redirection Vulnerability (CVE-2026-54171)

A vulnerability, CVE-2026-54171, has been identified in the Excon library concerning the redaction of sensitive or risky headers when following redirects, which could potentially expose confidential information if not properly addressed.

Excon vulnerability information-disclosure library
1c
medium advisory

HAProxy Denial of Service Vulnerability (CVE-2026-26080)

A denial of service vulnerability (CVE-2026-26080) in HAProxy Community Edition versions 3.2.x through 3.3.x before 3.3.3, HAProxy Enterprise, and ALOHA can lead to a loop or crash due to mishandled varint, impacting service availability.

HAProxy Community Edition +3 denial-of-service vulnerability haproxy load-balancer
1c
medium advisory

Next.js: Denial of Service in App Router using Server Actions

A high-severity denial-of-service vulnerability (CVE-2026-64641) in Next.js applications utilizing the App Router with Server Actions allows an unauthenticated attacker to cause excessive CPU usage, leading to a complete service outage.

Next.js +1 denial-of-service web-application javascript nodejs
1t
medium advisory

Netty Bzip2Decoder Infinite Loop Vulnerability Leads to Event-Loop Thread Hang (CVE-2026-59901)

A denial-of-service vulnerability exists in the `Bzip2Decoder` handler within Netty's `netty-codec-compression` and `netty-codec` libraries, allowing a remote attacker to exploit CVE-2026-59901 by providing a specially crafted bzip2 stream, which causes an infinite loop in the run-length encoding state machine, leading to the permanent hang of an event-loop thread and application denial of service.

netty-codec-compression +1 denial-of-service vulnerability netty
1t
medium advisory

Netty HAProxyMessageDecoder Vulnerability Leads to Unbounded Memory Exhaustion

A vulnerability, CVE-2026-55851, in Netty's `HAProxyMessageDecoder` can lead to unbounded memory exhaustion when an attacker sends a specific PROXY protocol v2 binary prefix followed by a version byte of `0xFF`, causing a signed-byte sentinel collision that traps the decoder in a version-detection loop and ultimately exhausts the JVM's direct memory allocation, resulting in a denial of service.

netty-codec-haproxy +1 denial-of-service memory-exhaustion vulnerability proxy-protocol
1c
medium advisory

Netty SPDY SETTINGS Frame Denial of Service Vulnerability

A high-severity vulnerability, CVE-2026-55831, in Netty's SPDY SETTINGS decoder allows a remote unauthenticated attacker to trigger a denial of service by sending a crafted SPDY/3.1 SETTINGS frame that leads to excessive heap growth and CPU consumption due to unbounded map entries in `DefaultSpdySettingsFrame`.

netty-codec-http +3 denial-of-service vulnerability netty spdy java memory-leak DoS
3t 1c 1i
medium advisory

Question2Answer Session Invalidation Vulnerability

Attackers can exploit CVE-2026-64829, a session invalidation vulnerability in Question2Answer through version 1.8.8, where the forgot-password reset flow fails to clear the sessioncode field, allowing an attacker with a previously obtained remember-me cookie to retain authenticated access even after the account's password has been reset.

Question2Answer <= 1.8.8 question2answer vulnerability session-management web-application cve
2t 1c
medium advisory

CVE-2026-11331: BIND 9 RPZ Bypass and Denial of Service Vulnerability

An attacker can exploit CVE-2026-11331, a flaw in ISC BIND 9's RPZ (Response Policy Zone) processing, by crafting long query names to trigger a mishandled NAMETOOLONG error, leading to either a bypass of RPZ rules or a denial of service due to an unexpected exit of the BIND 9 software.

BIND 9 +4 vulnerability denial-of-service dns bind networking
1c
medium advisory

Multiple Vulnerabilities in Elastic Products

CERT-FR has issued an advisory detailing multiple vulnerabilities in Elastic products, including CVE-2026-42397 and CVE-2026-49092, which could allow an attacker to cause remote denial of service, compromise data confidentiality and integrity, and perform Server-Side Request Forgery (SSRF).

Elasticsearch 8.x +5 vulnerability elastic elasticsearch kibana data-integrity data-confidentiality denial-of-service ssrf
5c
medium advisory

Multiple Vulnerabilities in GLPI

Multiple vulnerabilities have been discovered in GLPI, specifically affecting versions 11.0.x prior to 11.0.8 and all versions prior to 10.0.26, which allow an attacker to compromise data confidentiality and integrity, and bypass security policies.

GLPI < 10.0.26 +1 vulnerability web-application glpi data-breach data-integrity security-policy-bypass
3t
medium advisory

Veeam Backup & Replication: Vulnerability Enables Privilege Escalation

A vulnerability in Veeam Backup & Replication allows a local attacker to escalate privileges on the affected system.

Veeam Backup & Replication privilege-escalation vulnerability veeam backup
1t
medium advisory

Ansible: Local Code Execution Vulnerability

A local attacker can exploit a vulnerability within Ansible software to execute arbitrary code on the affected system, potentially leading to further compromise or unauthorized actions on the host where Ansible is running.

Ansible vulnerability code-execution red-hat
1t
medium advisory

Avahi Vulnerability Allows Local Denial of Service

A vulnerability in the avahi service allows a local attacker to perform a Denial of Service (DoS) attack, potentially leading to the unavailability of services or the system itself.

avahi denial-of-service vulnerability linux
1t
medium advisory

Libarchive Vulnerability Enables Remote Denial of Service

A remote, unauthenticated attacker can exploit a vulnerability in libarchive to initiate a Denial of Service attack, disrupting the availability of services or systems utilizing the affected library.

libarchive denial-of-service vulnerability library-vulnerability
1t
medium advisory

fast-xml-parser: Repeated DOCTYPE Declarations Bypass Entity Expansion Limits Leading to DoS

A vulnerability in fast-xml-parser allows an attacker to bypass entity expansion limits by crafting XML documents with multiple DOCTYPE declarations, leading to excessive CPU usage, memory exhaustion, and denial of service.

fast-xml-parser denial-of-service vulnerability-exploitation software-supply-chain
1t
medium advisory

Jackson-core Async Parser Max Number Length Bypass via Chunked Digit Accumulation

An incomplete fix for GHSA-72hv-8253-57qq in `jackson-core` versions 2.18.6, 2.21.1, and potentially 3.0.x/3.1.x, allows attackers to bypass `maxNumberLength` constraints in the non-blocking JSON parser by streaming JSON numbers in small chunks, leading to unbounded memory accumulation and denial of service in reactive applications.

jackson-core +3 java json serialization memory-exhaustion denial-of-service
1t
medium advisory

Denial of Service in websocket-driver-ruby via Malformed Host Header (CVE-2026-61666)

A denial of service vulnerability (CVE-2026-61666) exists in the websocket-driver-ruby library when used to implement a WebSocket server via `WebSocket::Driver.server()`, allowing a remote attacker to send a malformed `Host` header causing a `URI::InvalidURIError` exception and subsequent server process crash if unhandled.

websocket-driver denial-of-service vulnerability ruby webserver
1r 1t
medium threat

OPNsense: Multiple Vulnerabilities

An attacker can exploit multiple vulnerabilities in OPNsense to bypass security controls, disclose information, perform Cross-Site Scripting (XSS) attacks, and execute Denial of Service (DoS) attacks.

exploited OPNsense vulnerability firewall network-device
4t
medium advisory

CUPS (libcupsfilters, cups-filters) Denial of Service Vulnerability

A vulnerability in CUPS, specifically affecting libcupsfilters and cups-filters, allows a remote, unauthenticated attacker to exploit the system, leading to a denial-of-service condition that disrupts the availability of the printing system.

CUPS +2 denial-of-service vulnerability linux
1t
medium advisory

ethtool RSS Resource Leak on get_rxfh Failure

A vulnerability, CVE-2026-63999, has been identified in the `ethtool` utility on Linux systems, involving a resource leak of `indir_table` and `hkey` when the `get_rxfh` function related to Receive Side Scaling (RSS) functionality fails, which could lead to system instability or resource exhaustion.

ethtool linux vulnerability resource-leak
1c
medium threat

CVE-2026-64117 Vulnerability in Linux Kernel mac80211 Wi-Fi Subsystem

A vulnerability, CVE-2026-64117, has been disclosed in the Linux kernel's mac80211 Wi-Fi subsystem, potentially leading to unexpected behavior or information exposure due to incorrect handling of fast-RX rates and `skb->cb` buffer reuse in mesh networking contexts.

exploited mac80211 linux vulnerability kernel wifi
1c
medium threat

CVE-2026-64097: AMD Display Module Vulnerability in Linux Kernel

A vulnerability, CVE-2026-64097, affects the `drm/amd/display` module in the Linux kernel due to insufficient validation of GPIO pin LUT table size, potentially leading to system instability or other security impacts on Linux systems utilizing AMD display drivers.

exploited Linux Kernel vulnerability linux kernel amd denial-of-service
1c
medium advisory

File Browser Symlink Following Vulnerability Allows Out-of-Scope File Deletion (CVE-2026-55667)

A File Browser user with only `Create` permission can exploit CVE-2026-55667, an incomplete fix for CVE-2026-54094, to delete arbitrary files and directories outside their authorized scope by abusing the `ScopedFs.RemoveAll` function's symlink-following behavior during failed upload cleanup, leading to data loss, cross-tenant data deletion, or denial of service.

filebrowser vulnerability file-browser symlink-attack data-loss denial-of-service
2t 2c
medium advisory

LLM-Based Triage of Wget Activity on Linux Hosts

Elastic has developed a detection rule that monitors non-allowlisted `wget` activity on Linux hosts using Auditd Manager or Auditbeat, leveraging an Elastic LLM to triage `wget` executions for potential ingress tool transfer, command and control, or data exfiltration attempts to untrusted destinations, generating alerts only for high-confidence positive or suspicious verdicts.

Elastic Stack +6 endpoint llm linux threat-detection collection command-and-control exfiltration auditd +1
1r 3t 13i updated
medium advisory

LLM-Based Detection of Suspicious Curl Activity on Linux

Elastic's LLM-based detection rule identifies suspicious `curl` activity on Linux systems, aiming to detect command and control, data exfiltration, or ingress tool transfer by analyzing command-line parameters and network destinations via Auditd Manager or Auditbeat logs, which, if left unaddressed, could lead to system compromise or data breach.

Azure +3 Endpoint LLM Linux Threat Detection Collection Command and Control Exfiltration Auditd Manager
3t updated
medium threat

Detection of Generative AI Processes Connecting to Unusual Domains

Adversaries may compromise macOS-based Generative AI (GenAI) tools through prompt injection, malicious Model Context Protocol (MCP) servers, or poisoned plugins to establish Command and Control (C2) channels or exfiltrate sensitive data by causing them to connect to unusual domains.

exploited Claude +8 command-and-control genai macos data-exfiltration
1r 1t
medium advisory

LG Monitors Auto-Install Adware-Like App on Windows PCs

Connecting certain LG monitors to Windows PCs triggers Windows Update to automatically install the 'LG Monitor App Installer' without user consent, which then runs at system startup and frequently displays advertisements for McAfee antivirus trials.

LG Monitor App Installer +2 unwanted-software adware privacy-violation windows lg
1t
medium advisory

Detection of XDG-Open Command Execution on Linux Systems

Attackers abuse the `xdg-open` utility on Linux to trick users into opening malicious documents or URLs, leading to potential code execution and system compromise through user interaction.

linux execution user-execution endpoint
1r 2t
medium advisory

Linux Interpreter Downloads and Pipes Payload for Execution

This detection rule targets a Linux defense evasion technique where an interpreter downloads a malicious payload from an external address and immediately pipes its content into another interpreter for in-memory execution, allowing attackers to establish persistence, exfiltrate data, or run stagers without writing files to disk.

linux execution defense-evasion command-and-control
1r 3t
medium advisory

AWS IAM Session Token Used from Multiple Addresses

This threat brief describes a detection for suspicious activity where an AWS IAM user's temporary session token is accessed from multiple distinct IP addresses, networks, cities, and user agents within a short timeframe, indicating potentially compromised credentials used for initial access and resource manipulation.

AWS IAM +1 cloud aws initial-access identity-and-access-audit
1t
medium advisory

Detect Potential Sudo Binary Hijacking on Linux Systems

Attackers may hijack the default sudo binary on Linux systems, located at `/usr/bin/sudo` or `/bin/sudo`, replacing it with a malicious version to capture user passwords for credential access, elevate privileges, or establish persistence on the system every time the sudo binary is executed.

privilege-escalation persistence credential-access linux
1r 3t
medium advisory

Linux Privilege Escalation via CAP_SETUID/SETGID Capabilities

This brief details a Linux privilege escalation technique where attackers leverage misconfigurations in applications with CAP_SETUID or CAP_SETGID capabilities to elevate their privileges to root (UID/GID 0), enabling unauthorized system control and further malicious activities.

privilege-escalation linux capabilities root-access
3t
medium advisory

Potential Privilege Escalation via SUID/SGID Proxy Execution on Linux

Attackers may exploit SUID/SGID binaries like pkexec, su, or sudo on Linux systems to execute commands with elevated privileges, by identifying instances where a process runs with root privileges (user ID 0 or group ID 0) while the real user or group ID is non-root, allowing a low-privilege foothold to gain full system control.

su +17 privilege-escalation linux-security defense-evasion persistence system-exploitation
1r 4t
medium advisory

Suspicious Command Execution via Linux Web Server

This brief describes how attackers exploit vulnerabilities in web applications to execute suspicious shell commands via web server processes on Linux, enabling persistence, discovery, credential access, and reverse shell establishment, which can lead to full system compromise and data exfiltration.

Apache HTTP Server +45 webserver command-injection web-shell vulnerability-exploitation persistence linux
1r 14t
medium threat

Multiple Vulnerabilities in Proxmox Virtual Environment

An attacker can exploit multiple vulnerabilities in Proxmox Virtual Environment to conduct Cross-Site Scripting attacks, bypass security measures, and disclose confidential information, potentially leading to unauthorized data access or session hijacking.

exploited Proxmox Virtual Environment vulnerability web-application xss information-disclosure proxmox
1t
medium advisory

ProFTPD: Vulnerability Enables Denial of Service

An authenticated remote attacker can exploit a vulnerability within ProFTPD to initiate a denial-of-service attack, leading to the unavailability of the FTP service. This flaw could be triggered by legitimate users or adversaries with valid credentials, causing operational disruption.

ProFTPD denial-of-service vulnerability ftp linux
1t
medium threat

CVE-2026-63825: gcov Utility Concurrent Access Crash Vulnerability

A vulnerability, CVE-2026-63825, has been disclosed for the 'gcov' utility, which is part of the GNU Compiler Collection, involving concurrent access crashes fixed by using atomic counter updates to ensure thread-safe operations, potentially leading to system instability or denial of service due to race conditions during data access.

exploited gcov vulnerability denial-of-service cve
1c
medium threat

Potential Out-of-Bounds Write in rust-openssl AES-KW-PAD Cipher Operations

A potential out-of-bounds write vulnerability, CVE-2026-45784, has been identified in the `rust-openssl` library's `CipherCtxRef::cipher_update_inplace` function when processing AES-KW-PAD ciphers, which could lead to unexpected behavior or potential exploitation by corrupting memory.

exploited rust-openssl vulnerability library out-of-bounds
1c
medium threat

KVM Guest-Triggerable Denial-of-Service Vulnerability (CVE-2026-63806)

A denial-of-service vulnerability (CVE-2026-63806) has been identified in KVM's ioeventfd datamatch handling, allowing a guest virtual machine to trigger a BUG_ON() condition on the host, leading to a system crash.

exploited KVM virtualization denial-of-service linux hypervisor
1c
medium advisory

Accepted Default Telnet Port Connection

This threat brief details how threat actors exploit the insecure Telnet protocol on its default port 23 for initial access, lateral movement, and command and control, leveraging its unencrypted nature to compromise systems and exfiltrate data, emphasizing the need for robust detection and mitigation strategies.

telnet network-security remote-access plain-text initial-access lateral-movement command-and-control
1r 4t
medium advisory

Suspicious Child Process Execution via Azure VM CustomScript Extension

Attackers with access to an Azure subscription or VM management plane can leverage the Azure VM CustomScript extension to execute arbitrary code with SYSTEM privileges on Windows virtual machines, leading to various malicious activities such as reconnaissance, malware deployment, and persistence.

Azure Virtual Machines CustomScript Extension windows execution cloud-to-host azure lolbin
1r 4t
medium advisory

AWS Cognito Unauthenticated Identity Pool Credentials Issued

This threat involves adversaries obtaining temporary AWS credentials from a misconfigured Cognito Identity Pool without authentication. If a Cognito Identity Pool is set to allow unauthenticated (guest) access and its associated unauthenticated IAM role has overly broad permissions, attackers can discover the pool ID, call `GetId`, and then `GetCredentialsForIdentity` to acquire AWS credentials. This grants them unauthorized access to AWS resources and sensitive data, bypassing typical authentication mechanisms.

Cognito Identity Pools cloud aws cognito misconfiguration credential-access cloud-security
1r 2t
medium advisory

AWS CloudTrail Management Events Disabled via PutEventSelectors

A malicious actor uses the AWS CloudTrail `PutEventSelectors` API call to explicitly disable logging of management API calls for a trail by setting `includeManagementEvents` to `false`, effectively blinding defenders to subsequent sensitive activities while the trail appears active.

CloudTrail cloud aws defense-evasion
1r 1t
medium advisory

AWS Attempt to Leave Organization

An adversary attempting to remove an AWS member account from its AWS Organization via the LeaveOrganization API constitutes a critical defense evasion maneuver, as it strips the account of security controls and centralized monitoring, requiring immediate investigation by detection engineers.

AWS Organizations cloud aws defense-evasion impact threat-detection
1r 2t
medium advisory

AWS IAM User Console Login Without MFA

This brief identifies successful logins to the AWS Management Console by standard IAM users without Multi-Factor Authentication (MFA). It focuses on the first observed occurrence within a 7-day history window for each user. An adversary who obtains a user's password can gain access if MFA is not enforced, representing a significant initial access vector. This event signals a critical posture gap that allows adversaries to achieve initial access using compromised credentials, leading to potential privilege escalation, data exfiltration, or resource deployment.

AWS Management Console +1 cloud initial-access aws identity-and-access-management mfa-bypass
1r 1t
medium advisory

CVE-2026-15392: DBD::File Module Symlink Vulnerability

CVE-2026-15392 is a medium-severity vulnerability affecting versions of the Perl module DBD::File prior to 1.651, where the module fails to prevent symlinks to untrusted locations, potentially allowing local attackers to achieve information disclosure or local privilege escalation through symlink following.

DBD::File < 1.651 vulnerability symlink perl
1c
medium threat

Libsoup Vulnerability CVE-2026-15714 Allows Out-of-Bounds Read

A vulnerability identified as CVE-2026-15714 in the Libsoup library's soupmultipartinputstream component allows an out-of-bounds read when processing an oversized multipart boundary string, potentially leading to information disclosure or application instability.

exploited Libsoup vulnerability out-of-bounds-read gnome
1c
medium advisory

CoreDNS: Multiple Vulnerabilities Enable Denial of Service

Multiple vulnerabilities exist in CoreDNS that allow a remote, unauthenticated attacker to execute a Denial of Service (DoS) attack against the service, potentially leading to service disruption and unavailability for affected systems utilizing CoreDNS.

CoreDNS +1 dns denial-of-service vulnerability network
1t 1c updated
medium advisory

File Creation in World-Writable Directory by Unusual Process

An Elastic detection rule identifies when an unusual process creates files within world-writable directories on Linux systems, a tactic employed by attackers for defense evasion and lateral movement by staging payloads and hiding malicious activities.

Elastic Defend +5 linux defense-evasion persistence lateral-movement
1r 1t
medium advisory

MCP Python SDK Vulnerability Allows Cross-Client Task Access and Cancellation (CVE-2026-52870)

A high-severity vulnerability (CVE-2026-52870) in the MCP Python SDK's experimental task handlers, specifically in versions 1.23.0 through 1.27.1, allows any connected client to observe, read results from, and cancel tasks belonging to other clients due to a lack of session validation, potentially leading to unauthorized data access and denial of service.

mcp vulnerability server-side-request-forgery data-exfiltration denial-of-service
3t 1c
medium advisory

Rockwell Automation Communication Modules Denial-of-Service Vulnerability

A denial-of-service vulnerability (CVE-2026-9653) in Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT communication modules, due to improper validation of CIP Implicit Connection packets, allows an unauthenticated network attacker to continuously disrupt device connections.

1756-EN2 <=V12.001 +2 industrial-control-systems ics ot vulnerability denial-of-service rockwell-automation
1t 1c
medium threat

NASA Core Flight System Health & Safety Application Denial-of-Service Vulnerability

A high-severity denial-of-service vulnerability, CVE-2026-15352, affects NASA Core Flight System (cFS) Health & Safety (HS) Application versions prior to v7.0.1, allowing an unauthenticated attacker to crash the application via a crafted Housekeeping Telemetry request, leading to service disruption in critical infrastructure sectors like Transportation Systems.

exploited NASA Core Flight System cve vulnerability denial-of-service ics space transportation
1t
medium advisory

Privilege Escalation Vulnerability in SALTO ProAccess Space

An authenticated attacker can exploit CVE-2026-11889, a privilege escalation vulnerability in SALTO ProAccess Space versions prior to 6.13, to bypass authorization controls and access spaces outside their assigned partition within the same installation, provided the partitioning feature is enabled.

SALTO ProAccess Space <6.13 privilege-escalation ICS authorization-bypass
1t 1c
medium advisory

Rockwell Automation Flex 5000 Adapter Vulnerability Leads to Denial of Service

A denial-of-service vulnerability (CVE-2026-12659), categorized as a Double Free issue (CWE-415), exists in Rockwell Automation Flex 5000 Adapter version 6.011 due to improper handling of crafted CIP packets, which could allow an unauthenticated attacker to cause a denial-of-service condition requiring a power cycle to recover.

Flex 5000 Adapter ics ot critical-manufacturing information-technology denial-of-service vulnerability
2t 1c
medium advisory

Rockwell Automation CompactLogix and ControlLogix Vulnerabilities Lead to Denial-of-Service

Multiple Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix product versions are vulnerable to denial-of-service conditions through CVE-2025-12011, CVE-2025-12012, and CVE-2025-11698, which an attacker can exploit via buffer overflows by loading invalid project files or writing invalid data, causing controllers to enter a major non-recoverable fault.

CompactLogix 5370 +13 ics scada denial-of-service critical-manufacturing vulnerability
2t 3c
medium advisory

Denial-of-Service Vulnerability Affects ESET Endpoint Antivirus and Server Security Products (CVE-2026-6424)

A vulnerability, identified as CVE-2026-6424, has been discovered in various ESET Endpoint Antivirus and Server Security product versions, allowing an attacker to cause a denial of service, impacting the availability of the affected systems.

Endpoint Antivirus 12.0.x +11 vulnerability denial-of-service endpoint-security server-security
1t 1c
medium advisory

X.Org X11 Server (libXfont2): Multiple Vulnerabilities Allow Arbitrary Code Execution with Administrator Rights

Multiple vulnerabilities in X.Org X11 Server and libXfont2 allow a local attacker to gain elevated privileges and execute arbitrary code with root rights, posing a significant risk for systems utilizing the X.Org display server.

X11 Server +1 privilege-escalation linux vulnerability
1t
medium threat

Multiple Vulnerabilities in Absolute Secure Access

An attacker can exploit multiple vulnerabilities in Absolute Secure Access to perform a denial of service attack or disclose confidential information.

exploited Absolute Secure Access vulnerability denial-of-service information-disclosure remote-access
2t
medium advisory

Drupal Core: Multiple Vulnerabilities Allowing Information Disclosure and XSS

A remote, unauthenticated attacker can exploit multiple vulnerabilities in Drupal Core to achieve information disclosure and Cross-Site Scripting (XSS) attacks, potentially compromising user data or session integrity.

Drupal Core vulnerability web-application xss information-disclosure cve-less
2t
medium advisory

Apache Ivy: Vulnerability Allows File Manipulation

A remote, authenticated attacker can exploit a vulnerability in Apache Ivy to manipulate files on the system, leading to unauthorized modification of data and potential integrity compromise.

Apache Ivy file-manipulation vulnerability
1t
medium advisory

7-Zip: Vulnerability Enables Code Execution

A remote, anonymous attacker can exploit an unspecified vulnerability in 7-Zip to execute arbitrary code, leading to potential compromise of the system running the vulnerable software.

7-Zip vulnerability rce file-compression
1t
medium advisory

F5 BIG-IP and BIG-IP Next Vulnerability Enables Denial of Service

An unauthenticated, remote attacker can exploit a vulnerability in F5 BIG-IP and BIG-IP Next to perform a Denial of Service attack, potentially disrupting services.

BIG-IP +1 denial-of-service vulnerability network
1t
medium advisory

Detecting Unusually Large Prompts to AWS Bedrock Claude Models

This brief outlines a detection strategy for identifying unusually large prompts sent to AWS Bedrock Claude models, which may indicate prompt injection attacks, data exfiltration attempts, or abuse of the AI service, warranting investigation by detection engineers.

Amazon Bedrock +1 cloud-security aws ai-security prompt-injection data-exfiltration anomaly-detection
1r 3t
medium advisory

Gitea: Multiple Vulnerabilities

An anonymous, remote attacker can exploit multiple vulnerabilities in Gitea to manipulate data or trigger a denial of service.

Gitea vulnerability denial-of-service data-manipulation
2t updated
medium advisory

Argo CD: Multiple Vulnerabilities

A remote, authenticated attacker can exploit multiple vulnerabilities in Argo CD, including Cross-Site Scripting (XSS) and information disclosure flaws, which could lead to sensitive information exposure and potentially allow the attacker to gain administrator privileges.

Argo CD argo-cd vulnerability xss information-disclosure privilege-escalation cloud kubernetes
2t
medium advisory

Red Hat Quay: Multiple Vulnerabilities

Multiple vulnerabilities in Red Hat Quay allow a remote, authenticated attacker to execute arbitrary code and perform Server-Side Request Forgery (SSRF) attacks.

Red Hat Quay vulnerability-exploitation rce ssrf network
3t
medium advisory

dd-trace-rb: Improper Parsing of W3C Baggage Headers Leads to DoS

A vulnerability (CVE-2026-50276) in Datadog tracing libraries, specifically `dd-trace-rb` versions prior to 2.32.0, allows a remote and unauthenticated attacker to perform a Denial of Service (DoS) by sending HTTP requests with malformed W3C baggage headers, leading to unbounded CPU and memory consumption.

dd-trace-rb < 2.32.0 denial-of-service vulnerability ruby web
1t
medium advisory

Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression

Pomerium proxy deployments using the stateless authentication flow (Pomerium Zero or hosted authenticate) are vulnerable to a pre-authentication memory exhaustion denial of service, allowing an unauthenticated attacker to send specially crafted HPKE-encrypted zstd payloads to the `/.pomerium/callback` endpoint, leading to excessive memory allocation and potential proxy crashes.

Pomerium +1 denial-of-service network vulnerability go
1t 1i
medium advisory

Datadog dd-trace-go Library Vulnerability May Lead to Denial of Service

A vulnerability, CVE-2026-50274, in Datadog's `dd-trace-go` library (versions <= 1.24.1 and v2 < 2.8.1) allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending HTTP requests with oversized W3C baggage headers, leading to unbounded CPU and memory consumption in instrumented services.

go/github.com/DataDog/dd-trace-go +1 denial-of-service vulnerability supply-chain go datadog
1t
medium advisory

Datadog dd-trace-dotnet Improper W3C Baggage Header Parsing Leads to DoS

A Denial of Service (DoS) vulnerability exists in Datadog tracing libraries (`dd-trace-dotnet`) due to improper parsing of W3C baggage HTTP headers, allowing remote, unauthenticated attackers to send requests with arbitrarily large baggage headers, causing unbounded CPU and memory consumption and leading to service unavailability for any HTTP service instrumented with affected library versions where baggage propagation is enabled by default. The issue, tracked as CVE-2026-50273, is resolved in version 3.43.0 and later.

Datadog.Trace +1 denial-of-service vulnerability dot-net
1t
medium advisory

Datadog dd-trace-js W3C Baggage Header Denial of Service Vulnerability

The Datadog `dd-trace-js` library, specifically versions older than 5.100.0, is vulnerable to a Denial of Service (DoS) attack where improper parsing of W3C baggage HTTP headers allows a remote, unauthenticated attacker to send requests with an arbitrarily large number of comma-separated key-value pairs, leading to unbounded CPU and memory consumption and enabling a remote DoS against any HTTP service instrumented with the affected library where baggage propagation is enabled.

dd-trace-js denial-of-service vulnerability javascript nodejs datadog
1t
medium advisory

Datadog dd-trace-py Improper Parsing of W3C Baggage Headers Leads to DoS

The Datadog dd-trace-py tracing library, versions prior to 4.8.2, is vulnerable to a Denial of Service (DoS) attack due to improper parsing of W3C baggage HTTP headers, which fails to enforce item-count or byte-size limits on the extraction path, allowing an unauthenticated attacker to send a request with an arbitrarily large baggage header causing unbounded CPU and memory consumption.

dd-trace-py < 4.8.2 denial-of-service vulnerability python supply-chain
1t
medium advisory

Datadog dd-trace-java DoS Vulnerability via W3C Baggage Headers

A denial-of-service vulnerability, CVE-2026-50270, exists in Datadog tracing libraries (dd-trace-java prior to version 1.62.0) that implement W3C baggage propagation. Remote, unauthenticated attackers can exploit this by sending HTTP requests with W3C baggage headers containing an arbitrarily large number of comma-separated key-value pairs. The tracer, when extracting these headers, fails to enforce item-count or byte-size limits, leading to unbounded CPU and memory consumption as it allocates hash-map entries for each pair, thereby causing a denial of service against the instrumented HTTP service.

dd-java-agent denial-of-service java vulnerability w3c datadog
1t
medium advisory

Message Corruption Vulnerability in websocket-driver Library (CVE-2026-54466)

A critical vulnerability, CVE-2026-54466, in the `websocket-driver` npm library allows remote attackers to cause message corruption by sending specially crafted WebSocket frames that exploit improper handling of the protocol's length header, leading to incorrect parsing of subsequent payload data.

websocket-driver vulnerability websocket npm message-corruption
medium advisory

Unbounded Recursion Depth in Elixir Protobuf Decoder Causes Denial of Service

An unauthenticated attacker can trigger a denial-of-service condition in services that decode untrusted protobuf messages using the `Protobuf.Decoder` (Hex package `protobuf`) versions between 0.8.0 and 0.16.1 by crafting deeply nested self-referential message types, leading to memory exhaustion and service crashes.

protobuf denial-of-service vulnerability elixir
1t
medium advisory

NGINX Ingress Controller Injection Vulnerability via CRDs/Annotations (CVE-2026-55723)

An injection vulnerability exists in the NGINX Ingress Controller when configured with Custom Resource Definitions (CRDs) or Ingress annotations. An authenticated attacker with write permissions to these CRDs or annotations via the Kubernetes API can craft values to inject arbitrary NGINX configuration directives. This can lead to creating or deleting files and disabling services, affecting the control plane without exposing the data plane.

NGINX Ingress Controller kubernetes vulnerability injection webserver cve
2t 1c
medium advisory

Vulnerability in Veeam Backup & Replication Allows Privilege Escalation

A privilege escalation vulnerability has been discovered in Veeam Backup & Replication, affecting versions prior to 12.3.0.65, which allows an attacker to elevate their privileges within the system.

Backup & Replication vulnerability privilege-escalation veeam
1i
medium advisory

Perl Denial of Service Vulnerability

A remote, unauthenticated attacker can exploit a vulnerability in Perl to cause a Denial of Service condition.

Perl denial-of-service vulnerability
1t
medium advisory

Multiple WebKitGTK Vulnerabilities

Multiple vulnerabilities exist in WebKitGTK that can be exploited by a remote, unauthenticated attacker for information disclosure, denial of service, data manipulation, and security mechanism bypass.

WebKitGTK vulnerability denial-of-service information-disclosure defense-evasion
4t
medium advisory

Devolutions Server: Multiple Vulnerabilities Allow Authenticated Attackers to Manipulate Data, Bypass Security, and Disclose Information

A remote, authenticated attacker can exploit multiple vulnerabilities in Devolutions Server to manipulate data, bypass security measures, and disclose information.

Devolutions Server initial-access defense-evasion collection impact
4t
medium advisory

Netty: Multiple Vulnerabilities

An attacker can exploit multiple vulnerabilities within the Netty framework to bypass security checks, manipulate requests or headers, circumvent certificate validations, and cause a denial of service.

Netty vulnerability network denial-of-service
1t
medium advisory

AWS Bedrock Model Prompt or Completion Containing Credentials

A detection rule identifies AWS access key IDs, Amazon Bedrock API keys, PEM private-key blocks, and GitHub/GitLab tokens within Amazon Bedrock model prompts or completions, indicating a critical credential exposure event through misconfiguration, data leakage, or prompt injection that necessitates immediate secret rotation and investigation.

Amazon Bedrock +2 llm aws bedrock credential-access data-leakage prompt-injection
1r 1t
medium advisory

Red Hat Enterprise Linux (pacemaker) Vulnerability Enables Denial of Service

A vulnerability in Red Hat Enterprise Linux (pacemaker) allows a remote, unauthenticated attacker to perform a Denial of Service attack, potentially disrupting the availability of affected systems.

Red Hat Enterprise Linux denial-of-service vulnerability linux red-hat
1t
medium advisory

Citrix Secure Access Client for Windows Vulnerabilities Lead to Privilege Escalation and Information Disclosure

Multiple vulnerabilities in Citrix Systems Secure Access Client for Windows can be exploited by a local attacker to achieve privilege escalation and information disclosure on affected Windows systems.

Secure Access Client for Windows vulnerability privilege-escalation information-disclosure windows
2t
medium advisory

Rockwell Automation Studio 5000 Logix Designer: Multiple Vulnerabilities Enable Code Execution

Multiple vulnerabilities in Rockwell Automation Studio 5000 Logix Designer allow a local attacker to execute arbitrary program code, which could lead to a compromise of the affected system or unauthorized control over the design environment.

Studio 5000 Logix Designer ics scada ot rce vulnerability local-exploitation
1t
medium threat

OpenShift GitOps Operator Vulnerability Allows Denial of Service via ClusterRole Name Collision

A high-severity denial of service vulnerability, identified as CVE-2026-14251, exists in the OpenShift GitOps operator where a namespace-scoped Argo CD instance can trigger the deletion of a cluster-scoped Argo CD instance's ClusterRole by exploiting a name collision due to improper resource ownership validation.

exploited OpenShift GitOps operator +1 openshift kubernetes gitops denial-of-service vulnerability
1t 1c
medium advisory

Perl Regex Engine Vulnerability Allows Silently Incorrect Matches

A vulnerability exists in Perl versions up to and including 5.43.9 where regular expression matches can be silently incorrect when an alternation of more than 65535 fixed string branches is compiled into a trie within the Perl_study_chunk function, potentially leading to incorrect logic or data processing.

Perl vulnerability regex software-bug
1c
medium advisory

Multiple Vulnerabilities in Python Lead to Denial of Service

Remote and unauthenticated attackers can exploit multiple unspecified vulnerabilities within Python to conduct Denial of Service attacks, potentially disrupting the availability of services or applications running on the language.

Python denial-of-service vulnerability
1t
medium threat

Denial-of-Service Vulnerability in Pillow EPS Parser (CVE-2026-59203)

A denial-of-service vulnerability, CVE-2026-59203, exists in the Python imaging library Pillow, affecting versions 12.0.0 through 12.2.0, where a specially crafted EPS file with a negative byte count in the `%%BeginBinary` directive can cause an infinite loop and resource exhaustion when processed by the `Image.open()` function, leading to application unresponsiveness.

exploited Pillow 12.0.0 +2 denial-of-service vulnerability python pillow
1t 1c
medium advisory

Netty StompSubframeDecoder Denial of Service Vulnerability (CVE-2026-44891)

A high-severity denial of service vulnerability, identified as CVE-2026-44891, exists in the `StompSubframeDecoder` component of Netty's `netty-codec-stomp` library, allowing an unauthenticated attacker to exhaust server memory and cause an `OutOfMemoryError` by sending a STOMP message with an excessive number of headers, leading to application crashes.

netty-codec-stomp +1 denial-of-service vulnerability netty java application-layer
1t
medium advisory

This rule detects changes to AWS CloudTrail configurations that could indicate a security risk, specifically disabling or altering trails, or failing a security configuration check. Such actions can significantly reduce visibility into AWS activity.

AWS CloudTrail attack.impact attack.defense_evasion attack.t1562.001 attack.t1562.006
3r
medium advisory

Ivanti Xtraction Vulnerabilities CVE-2026-14902 and CVE-2026-14903

Ivanti has published a security advisory (AV26-696) on July 14, 2026, to address two vulnerabilities, CVE-2026-14902 and CVE-2026-14903, affecting Ivanti Xtraction version 2026.2 and prior, urging users to apply necessary updates to mitigate potential risks.

Ivanti Xtraction vulnerability Ivanti security-advisory
2c
medium advisory

Hoverfly Process Crash via Concurrent Map Write Race Condition

Hoverfly, when running in Diff mode, is vulnerable to a denial-of-service condition due to a concurrent map write race condition in the `AddDiff()` function. Multiple proxy requests processed simultaneously cause unsynchronized writes to the shared `responsesDiff` map, triggering Go's built-in race detector and a `fatal error`, which immediately terminates the Hoverfly process. This vulnerability is trivially exploitable by sending multiple concurrent requests to the proxy port, leading to a full denial of service that cannot be recovered without a restart.

Hoverfly race-condition denial-of-service go-lang
1t
medium advisory

MKP Pod Log Read Vulnerability Leads to Memory Exhaustion and Denial of Service

An unauthenticated remote attacker can exploit a vulnerability in the MKP (Model Context Protocol for Kubernetes) server to exhaust its memory and cause a denial of service by sending a crafted `tools/call` request that manipulates `limitBytes` or `tailLines` parameters, leading to unbounded Kubernetes pod log reads into memory.

MKP server kubernetes denial-of-service memory-exhaustion unauthenticated mcp cloud
2t
medium advisory

GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability

A vulnerability, identified as CVE-2026-47282, in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose sensitive information over a network due to insufficiently protected credentials.

GitHub Copilot +1 information-disclosure vulnerability development-tools
medium advisory

Critical Unauthenticated Remote Access Vulnerability in Rockwell Automation 1715-AENTR EtherNet/IP Adapter (CVE-2026-10577)

A critical unauthenticated remote access vulnerability, CVE-2026-10577, in Rockwell Automation 1715-AENTR EtherNet/IP Adapter versions <=3.003 allows an attacker to exploit a network-accessible debug port with missing privilege controls, enabling remote command-line interface access to read/delete files, modify memory, and change I/O states, impacting the confidentiality, integrity, and availability of industrial control systems.

1715-AENTR EtherNet/IP Adapter <=3.003 ics ot vulnerability critical-infrastructure remote-code-execution
1t 1c
medium advisory

Apache ActiveMQ Cross-Site Scripting Vulnerability

A remote, authenticated attacker can exploit a Cross-Site Scripting (XSS) vulnerability in Apache ActiveMQ to execute malicious scripts within a victim's browser.

ActiveMQ xss web-vulnerability apache
1t
medium threat

OpenSSH Vulnerability Allows Privilege Escalation

A local attacker can exploit an unspecified vulnerability in OpenSSH to elevate their privileges on the affected system.

exploited OpenSSH privilege-escalation vulnerability
1t
medium advisory

Ollama: Vulnerability Enables Denial of Service

A remote, unauthenticated attacker can exploit an unspecified vulnerability in Ollama to execute a Denial of Service (DoS) attack, disrupting service availability.

Ollama denial-of-service vulnerability
1t
medium advisory

Potential AWS S3 Bucket Ransomware Note Uploaded

Adversaries exploit misconfigured AWS S3 buckets or compromised credentials to upload ransomware notes, often after deleting or encrypting data, aiming to extort victims.

Amazon S3 cloud aws s3 ransomware impact data-destruction
1r 3t 2i
medium advisory

SAP Approuter HTTP Request Smuggling Vulnerability Allows Confidentiality and Availability Impact (CVE-2026-27690)

An HTTP Request Smuggling vulnerability (CVE-2026-27690, CWE-444) in SAP Approuter allows an unauthenticated attacker to send a specially crafted HTTP request leading to request-response desynchronization, which can result in the exposure of user responses and cause a denial of service by making the system unavailable.

SAP Approuter node.js package http-request-smuggling vulnerability sap web-application denial-of-service data-exposure
3t 1c
medium advisory

Circular JSON Schema $ref Causes Unbounded CPU DoS in json_repair Library

An unbounded CPU Denial-of-Service vulnerability exists in the `json_repair` library's `SchemaRepairer.resolve_schema()` function, allowing an unauthenticated attacker to provide a specially crafted JSON schema containing a circular `$ref` pointer, leading to indefinite CPU consumption and service unavailability.

json_repair denial-of-service supply-chain application-vulnerability python
1t
medium advisory

Decidim JWT Replay Vulnerability Allows Cross-Organization Data Access

A vulnerability, CVE-2026-45414, in Decidim allows an attacker to replay a JSON Web Token (JWT) issued for one organization against another organization's API, permitting an authenticated user from Org 1 to access and retrieve sensitive data, such as GraphQL `participantDetails` and `proposal.answer` mutation paths, from Org 2, effectively bypassing cross-organizational access controls.

Decidim +1 jwt-misconfiguration access-control web-application vulnerability
2t
medium threat

Checkmk: Multiple Vulnerabilities

Multiple vulnerabilities in Checkmk allow an attacker to escalate privileges and bypass security measures, potentially leading to unauthorized access and control within the affected system.

exploited Checkmk vulnerability privilege-escalation defense-evasion
2t
medium advisory

libTIFF Vulnerability Enables Arbitrary Code Execution and Denial of Service

A local attacker can exploit a vulnerability in libTIFF to execute arbitrary code and perform a denial of service attack against the system where the library is used.

libTIFF vulnerability code-execution denial-of-service
1t
medium advisory

Multiple Vulnerabilities in Grafana Could Lead to DoS and XSS

Attackers can exploit multiple vulnerabilities in Grafana to conduct Denial of Service attacks or Cross-Site Scripting attacks, potentially leading to service disruption or client-side code execution.

Grafana vulnerability web DoS XSS
2t
medium advisory

Linux Kernel Vulnerability (xfrm: iptfs) Allows Local DoS and Data Manipulation

A local attacker can exploit a vulnerability in the Linux Kernel's xfrm: iptfs component to potentially trigger a denial-of-service condition or manipulate data on affected systems.

Linux Kernel linux-kernel vulnerability dos data-manipulation kernel
2t
medium advisory

Wget Vulnerability Allows Security Bypass and Server-Side Request Forgery

A local attacker can exploit a vulnerability in wget to bypass existing security measures and perform a Server-Side Request Forgery (SSRF) attack, enabling requests to internal or restricted resources from the local system.

wget ssrf vulnerability local-privilege-escalation linux macos windows defense-evasion
1t
medium advisory

Multiple Vulnerabilities in SaltStack Salt

Multiple vulnerabilities in SaltStack Salt allow an attacker to execute arbitrary program code on affected systems and bypass security measures, potentially leading to unauthorized access and control over managed infrastructure.

Salt saltstack vulnerability rce security-bypass
2t
medium threat

Django, Debian, and Ubuntu Vulnerability Allows Remote Denial of Service

A remote, unauthenticated attacker can exploit a vulnerability in Django, Debian Linux, and Ubuntu Linux to initiate a Denial of Service attack, potentially disrupting services and making them unavailable to legitimate users.

exploited Django +2 denial-of-service vulnerability linux web-application
1t
medium advisory

Django Vulnerability Enables Denial of Service

A remote, unauthenticated attacker can exploit an unspecified vulnerability in Django to conduct a Denial of Service attack, which could disrupt the availability of services running on the affected Django application.

Django denial-of-service web-application
1t
medium advisory

CPython Vulnerability Enables Remote Denial of Service

A remote, unauthenticated attacker can exploit an unspecified vulnerability within CPython to launch a Denial of Service attack, affecting the CPython interpreter across various operating systems.

CPython denial-of-service vulnerability
1t
medium threat

CVE-2026-59869: js-yaml Vulnerability Leading to Quadratic CPU Consumption and DoS

A vulnerability, CVE-2026-59869, in the `js-yaml` library allows attackers to craft malicious YAML merge-key chains, which can lead to quadratic CPU consumption and a Denial of Service condition in applications processing the input.

exploited js-yaml denial-of-service vulnerability yaml
2t 1c
medium advisory

CVE-2026-59928 Mistune block_parser: Quadratic-Time Parsing Leading to Denial of Service

CVE-2026-59928 identifies a vulnerability in the Mistune block_parser component where quadratic-time parsing of long lists of repeated reference-link definitions can be exploited by an attacker to cause a denial-of-service condition due to excessive resource consumption.

Mistune block_parser denial-of-service vulnerability markdown-parser
1c
medium threat

Out-of-Bound Read Vulnerability in mtr (CVE-2026-14461)

CVE-2026-14461 identifies an out-of-bound read vulnerability in the mtr network diagnostic tool that could lead to information disclosure or denial of service on Linux and macOS systems.

exploited mtr vulnerability linux macos network-utility
1c
medium advisory

Setuptools Unicode Normalization Collision Bypass on macOS

A vulnerability, CVE-2026-59890, affects the setuptools project, allowing a MANIFEST.in exclusion bypass during source distribution package creation due to Unicode normalization collisions (NFC/NFD) on macOS systems using APFS or HFS+ file systems.

setuptools python macos vulnerability supply-chain
1c
medium advisory

Mistune Markdown Parser Vulnerability CVE-2026-59930 Allows HTML ID Collision

A vulnerability, CVE-2026-59930, in the Mistune markdown parser's TableOfContents directive creates predictable HTML heading IDs, enabling an attacker to inject content with colliding IDs for client-side content manipulation.

Mistune vulnerability markdown client-side cve
1c
medium advisory

Perl DBI Out-of-Bounds Read Vulnerability CVE-2026-14740

CVE-2026-14740 describes an out-of-bounds read vulnerability in DBI versions prior to 1.650 for Perl, occurring during the preparse stage when deleting an initial SQL comment, which can lead to information disclosure or denial of service.

DBI < 1.650 vulnerability perl memory-corruption information-disclosure
1c
medium advisory

OpenSSH sshd GSSAPI Behavior Vulnerability CVE-2026-59998

CVE-2026-59998 describes an undocumented security-relevant behavior in sshd, a component of OpenSSH, specifically in versions prior to 10.4, where the GSSAPIStrictAcceptorCheck setting reportedly has no value when the server is operating within a Windows Active Directory environment.

sshd in OpenSSH < 10.4 +1 vulnerability openssh gssapi active-directory windows misconfiguration
1c
medium advisory

Excelize Unbounded Row Index Allocation Denial-of-Service Vulnerability

An unbounded row index allocation vulnerability (CWE-770) exists in the `checkSheet()` function of the `github.com/xuri/excelize/v2` library, allowing an unauthenticated attacker to craft a malicious XLSX file with a specially crafted row index value that triggers an out-of-memory error or runtime panic, leading to a denial-of-service condition in Go applications processing untrusted spreadsheets.

excelize v2 vulnerability denial-of-service golang xlsx library cwe-770
1t
medium advisory

CPU DoS Vulnerability in libp2p gossipsub

A critical vulnerability in the `@libp2p/gossipsub` library allows an unauthenticated attacker to cause a CPU-based Denial of Service by sending oversized IHAVE and IWANT control messages, which are synchronously processed, leading to Node.js event loop exhaustion and service disruption.

@libp2p/gossipsub denial-of-service cpu-exhaustion javascript nodejs library-vulnerability
1t
medium advisory

Potential System DLL Sideloading From Non System Locations

This brief describes a common defense evasion technique where malicious actors bypass security controls by loading legitimate system DLLs from non-standard directories, enabling arbitrary code execution within trusted processes.

Windows dll-sideloading defense-evasion execution
1r 3t
medium advisory

CPython Denial-of-Service Vulnerability

A remote denial-of-service vulnerability, CVE-2026-15308, has been discovered in CPython, allowing an attacker to cause service disruption to affected systems not running the latest security patch.

CPython +1 denial-of-service vulnerability python
1t 1c 1i updated
medium advisory

Multiple Python Vulnerabilities Allow Code Execution and DoS

Multiple vulnerabilities in Python allow an attacker to execute arbitrary code or cause a Denial of Service condition, potentially leading to system compromise or service disruption.

Python vulnerability code-execution dos
2t
medium advisory

Python: Vulnerability Enables File Manipulation

An authenticated remote attacker can exploit a vulnerability in Python to manipulate files, which could lead to unauthorized modification of data or disruption of system integrity across Windows, Linux, and macOS environments.

Python vulnerability file-manipulation
1t
medium advisory

Tesla Elixir Client Decompression Bomb (CVE-2026-48594)

A critical vulnerability, CVE-2026-48594, in the Tesla Elixir HTTP client library allows an attacker to cause a denial of service by serving a specially crafted HTTP response with multiple `content-encoding` headers that, when processed by vulnerable versions (0.6.0 through 1.18.2) of the client using `Tesla.Middleware.DecompressResponse` or `Tesla.Middleware.Compression`, leads to exponential memory expansion and application crashes.

tesla resource-exhaustion denial-of-service library-vulnerability elixir
1t 1c
medium advisory

Tesla HTTP Client Library Vulnerable to Atom Exhaustion Leading to Denial of Service (CVE-2026-48597)

A high-severity denial-of-service vulnerability (CVE-2026-48597) in the `Tesla.Adapter.Mint` component of the Elixir Tesla HTTP client library, affecting versions 1.3.0 through 1.18.2, allows an unauthenticated attacker to crash the underlying BEAM VM by supplying untrusted URL schemes, leading to atom exhaustion.

tesla denial-of-service elixir erlang vulnerability web-application
1t 1c
medium advisory

Mistune Markdown Parser Vulnerable to CPU Exhaustion DoS (CVE-2026-49851)

The Mistune Python Markdown parser is vulnerable to a CPU exhaustion Denial of Service (DoS) attack, identified as CVE-2026-49851, due to a superlinear (O(n²)) parsing behavior in the `parse_link_text` function when processing specially crafted input containing repeated square brackets, allowing an attacker to significantly degrade application performance with a small payload.

mistune denial-of-service python library vulnerability markdown
1t 1c
medium advisory

Mint HTTP/2 Client Vulnerable to Unbounded CONTINUATION Frame Accumulation (CVE-2026-49754)

A malicious or compromised HTTP/2 server can exploit CVE-2026-49754 in the Elixir Mint HTTP/2 client by sending an endless chain of CONTINUATION frames without an END_HEADERS flag, leading to unbounded memory accumulation, process exhaustion, and remote unauthenticated denial-of-service.

Mint http/2 denial-of-service vulnerability elixir
1t 1c
medium advisory

Mint HTTP/2 Client Unbounded Stream Map Growth Denial-of-Service (CVE-2026-48862)

A malicious or compromised HTTP/2 server can exploit CVE-2026-48862 in Mint HTTP/2 clients by flooding them with PUSH_PROMISE frames and withholding corresponding HEADERS, leading to unbounded memory consumption and denial-of-service.

Mint denial-of-service http/2 elixir client-side vulnerability
1t 1c
medium advisory

CVE-2026-57028: Juniper Junos OS Evolved License Exhaustion via Improper Communication Channel Restriction

A vulnerability, CVE-2026-57028, in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to gain unauthorized access to internal license management processes via an exposed internal port, leading to license exhaustion and ultimately a denial-of-service condition.

Junos OS Evolved vulnerability network denial-of-service juniper
2t 1c
medium advisory

CVE-2026-57026 - Improper Validation of SIP Input in Juniper Junos OS Leads to DoS

An unauthenticated, network-based attacker can exploit CVE-2026-57026, an improper input validation vulnerability, in the SIP plugin of Juniper Networks Junos OS. If the SIP ALG is enabled on affected MX Series with SPC3 or SRX Series devices, processing a malformed SIP invite packet will cause the flow processing daemon (flowd) to crash and restart, leading to a complete denial of service until the system recovers.

Junos OS on MX Series with SPC3 +11 denial-of-service vulnerability juniper network
1t 1c
medium advisory

CVE-2026-57023: Juniper Junos OS TCP Proxy Denial of Service

An Improper Validation of Specified Quantity in Input vulnerability (CVE-2026-57023) in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a complete Denial of Service (DoS) by sending a specifically malformed TCP header packet, crashing the flow processing daemon (flowd) until automated recovery.

Junos OS on MX Series with SPC3 +1 denial-of-service vulnerability network juniper
1t 1c
medium advisory

Schneider Electric Easergy MiCOM Px40 Series Information Disclosure via Hard-coded Credentials (CVE-2026-4832)

Schneider Electric Easergy MiCOM Px40 Series products are vulnerable to CVE-2026-4832, a hard-coded credentials flaw (CWE-798) that allows unauthenticated attackers to interrogate the SNMP port and expose basic device identification information from critical manufacturing, energy, and transportation systems assets globally.

Easergy MiCOM P14x +25 ics ot scada vulnerability schneider-electric snmp cve-2026-4832 information-disclosure
2t 1c
medium advisory

CVE-2026-60109 - Zeek Kerberos Protocol Analyzer Null Pointer Dereference

A null pointer dereference vulnerability (CVE-2026-60109) exists in Zeek's Kerberos protocol analyzer before version 8.0.9, allowing unauthenticated remote attackers to crash a Zeek sensor by sending a specially crafted KRB_ERROR message with error-code 25 and specific PA-DATA elements, leading to a denial-of-service condition.

Zeek vulnerability network dos kerberos
1t 1c
medium advisory

CVE-2026-60108 - Zeek FTP Analyzer Uncontrolled Memory Consumption leading to DoS

An uncontrolled memory consumption vulnerability in the Zeek FTP analyzer, versions prior to 8.0.9, allows unauthenticated remote attackers to cause process termination and denial of service of the Zeek sensor. This occurs when a crafted FTP control session with AUTH GSSAPI and a large ADAT control line exploits the NVT_Analyzer component's lack of a maximum line length check, leading to an unbounded internal buffer during base64 decoding.

Zeek cve dos network-protocol vulnerability
1t 1c
medium advisory

AppLocker Audit Events Indicate Potential Policy Violations

This brief describes the detection of Windows AppLocker audit events (Event IDs 8003, 8006, 8021, 8024) that indicate applications, DLLs, scripts, MSIs, or packaged apps would have been blocked by an active AppLocker policy, providing insight into unauthorized software execution attempts or policy violations in audit mode.

AppLocker audit windows-security application-control
1r 6t
medium advisory

Ruby CSS Parser Vulnerable to SSRF and Local File Disclosure via `read_remote_file`

The `css_parser` library, specifically in versions up to and including 2.2.0, is vulnerable to Server-Side Request Forgery (SSRF) and local file disclosure through improper URI validation in the `CssParser::Parser#read_remote_file` method, allowing attackers to access internal network resources or read local files when processing attacker-controlled CSS.

css_parser <= 2.2.0 ssrf lfi supply-chain ruby vulnerability web-application
4t
medium advisory

Soup Sieve Memory Exhaustion via Large Comma-Separated Selector Lists (CVE-2026-49476)

A memory exhaustion vulnerability (CVE-2026-49476) in the soupsieve CSS selector parser, an indirect dependency of Beautiful Soup 4, allows an unauthenticated attacker to cause a denial of service by supplying a crafted, large comma-separated CSS selector string to applications using `soupsieve.compile()` or Beautiful Soup's `.select()`/`.select_one()`, leading to unbounded memory allocation and system resource exhaustion.

soupsieve <= 2.8.3 +1 denial-of-service memory-exhaustion python supply-chain
1t
medium advisory

CVE-2026-59692: GStreamer DTLS Plugin Stack Buffer Overflow Leading to DoS

A stack buffer overflow vulnerability, CVE-2026-59692, exists in GStreamer's DTLS plugin, allowing a remote unauthenticated attacker to cause a denial of service by sending a crafted certificate with an oversized Subject Distinguished Name during a DTLS handshake, which the plugin prints into a fixed-size stack buffer without bounds checking, leading to a process crash.

DTLS plugin +2 denial-of-service buffer-overflow vulnerability dtls gstreamer linux high_confidence_source watchlist_match
2t 1c
medium threat

MailPit: Multiple Vulnerabilities Lead to Denial of Service

Multiple vulnerabilities in MailPit allow an attacker to perform a Denial of Service attack against the application, leading to disruption of service for users.

exploited MailPit denial-of-service vulnerability
1t
medium advisory

Wazuh Denial of Service Vulnerability

A vulnerability in Wazuh allows a remote, authenticated attacker to perform a denial of service attack, which could disrupt the availability of the Wazuh platform.

Wazuh denial-of-service vulnerability
1t
medium threat

Multiple Vulnerabilities in Red Hat Enterprise Linux Components libsolv and aardvark-dns

Multiple vulnerabilities in Red Hat Enterprise Linux components libsolv and aardvark-dns could allow an attacker to perform a Denial of Service attack, manipulate data, or disclose confidential information.

exploited Red Hat Enterprise Linux +2 vulnerability linux red-hat dos data-manipulation data-leak
3t
medium advisory

Red Hat Enterprise Linux: Golang Component Vulnerability Enables Denial of Service

A remote, unauthenticated attacker can exploit a vulnerability in Golang components within Red Hat OpenShift, Red Hat Ansible Automation Platform, and Red Hat Enterprise Linux to conduct a Denial of Service attack, leading to service disruption.

Red Hat OpenShift +2 vulnerability denial-of-service red-hat linux
1t
medium advisory

CVE-2026-59999: OpenSSH sshd Configuration Bypass via PermitTunnel

A logic error in OpenSSH's sshd daemon before version 10.4 allowed the PermitTunnel configuration to take precedence over DisableForwarding=yes, leading to unintended SSH tunnel establishment and potential unauthorized network access through the tunnel feature.

OpenSSH ssh vulnerability configuration-bypass linux macos
1c
medium advisory

OpenSSH sshd Denial-of-Service via GSSAPI Authentication (CVE-2026-60000)

A high-severity denial-of-service vulnerability, CVE-2026-60000, affects OpenSSH versions prior to 10.4, allowing remote attackers to exhaust server resources through excessive and mishandled GSSAPI authentication attempts, leading to service unavailability.

OpenSSH < 10.4 +1 denial-of-service ssh openssh network-attack
1c
medium threat

CVE-2026-59995: OpenSSH SFTP Arbitrary File Placement Vulnerability

CVE-2026-59995 describes a vulnerability in the OpenSSH sftp client, specifically versions before 10.4, that allows an attacker to control the location of downloaded files when a user executes 'sftp server:/path .' against an attacker-controlled server, potentially leading to arbitrary file placement and subsequent system compromise.

exploited OpenSSH sftp < 10.4 vulnerability client-side arbitrary-file-placement openssh sftp
1c
medium advisory

CVE-2026-59996: OpenSSH scp File Placement Vulnerability

CVE-2026-59996 details a vulnerability in OpenSSH's `scp` utility, allowing a remote attacker to cause a copied file to be placed in a parent directory of the intended destination during a remote-to-remote transfer, potentially leading to unintended file system modification.

OpenSSH before 10.4 vulnerability scp openssh linux macos
1c
medium advisory

OpenSSH internal-sftp Vulnerability (CVE-2026-59997) Allows Security Property Bypass

CVE-2026-59997 describes a vulnerability in the internal-sftp component of OpenSSH's sshd service, affecting versions before 10.4, where the service only processes the first nine command-line arguments, potentially leading to a bypass of security controls or unintended configuration.

OpenSSH sshd internal-sftp < 10.4 vulnerability openssh sshd sftp linux macos
1c
medium advisory

Joomla: Multiple Vulnerabilities Allowing XSS and Data Modification

Multiple vulnerabilities in Joomla allow a remote, unauthenticated or authenticated attacker to display false information, launch Cross-Site Scripting (XSS) attacks, and modify data, potentially leading to integrity compromises and further client-side exploitation.

Joomla cms vulnerability xss web-vulnerability data-integrity
1t
medium advisory

CVE-2026-47241: Net::IMAP Denial of Service Vulnerability

A Denial of Service vulnerability, identified as CVE-2026-47241, exists in the Net::IMAP library due to incomplete raw argument validation, potentially allowing an attacker to cause an application crash or unresponsiveness.

Net::IMAP denial-of-service vulnerability imap
1c
medium advisory

Divi Form Builder Missing Authorization Vulnerability (CVE-2026-5523) Leads to Account Takeover

The Divi Form Builder plugin for WordPress versions up to 5.1.8 is vulnerable to Missing Authorization, allowing authenticated attackers with subscriber-level access to change the email and password of any user, including administrators, by exploiting improper authorization checks in the update_user() and handle_register_submission() functions, enabling complete account takeover.

Divi Form Builder plugin <= 5.1.8 wordpress plugin vulnerability web-application account-takeover missing-authorization
3t 1c
medium advisory

Detection of Failed WMI Event Log Clear Attempts

This brief details the detection of failed attempts by an adversary to clear Windows event logs using the WMI `ClearEventLog` method, indicating an unsuccessful defense impairment action due to insufficient privileges or other issues.

defense-evasion host-activity windows
1r 1t
medium advisory

CVE-2026-59803: rpcx Denial-of-Service Vulnerability

A denial-of-service vulnerability (CVE-2026-59803) in rpcx through version 1.9.3 allows an unauthenticated attacker to trigger out-of-memory conditions and service unavailability by sending a small, compressed message that expands to gigabytes of memory during decompression.

rpcx <= 1.9.3 denial-of-service vulnerability rpcx go-lang
1t 1c
medium threat

CVE-2026-0284 PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)

An XML injection vulnerability (CVE-2026-0284) in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS software allows an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data.

exploited PAN-OS 12.1 +17 vulnerability xml-injection pan-os network-device
3t
medium threat

CVE-2026-0286 PAN-OS: Authenticated Command Injection in CLI

A command injection vulnerability, CVE-2026-0286, in the management plane of Palo Alto Networks PAN-OS software allows an authenticated administrator to execute arbitrary OS commands as root on PA-Series and VM-Series firewalls and Panorama (virtual and M-Series) devices, potentially leading to high system compromise.

exploited PAN-OS 12.1 +6 vulnerability command-injection pan-os firewall network-device
3t
medium advisory

CVE-2026-0285 PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface

A server-side request forgery (SSRF) vulnerability, tracked as CVE-2026-0285, exists in the management web interface of Palo Alto Networks PAN-OS software, allowing an authenticated administrator with network access to make unauthorized requests from the firewall to internal services, potentially leading to information disclosure or further network compromise.

PAN-OS < 12.1.4-h8 +17 server-side-request-forgery ssrf vulnerability pan-os palo-alto-networks network-device
3t
medium threat

CVE-2026-0283: Authentication Bypass in Palo Alto Networks PAN-OS Large Scale VPN (LSVPN)

An authentication bypass vulnerability, CVE-2026-0283, in Palo Alto Networks PAN-OS software allows an unauthenticated attacker with network access to establish an unauthorized site-to-site VPN connection when LSVPN functionality with configured satellites is enabled, leading to potential access to internal network resources.

exploited PAN-OS 12.1 +3 authentication-bypass vpn network-device palo-alto-networks pan-os
1t
medium threat

CVE-2026-0278 Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows

CVE-2026-0278 describes multiple protection mechanism failures in the Prisma Access Agent's Data Loss Prevention (DLP) component for Windows, allowing a local user to bypass DLP policy enforcement controls and exfiltrate sensitive data on affected versions prior to 26.2.1.

exploited Prisma Access Agent < 26.2.1 cve vulnerability dlp bypass windows defense-evasion
1t
medium threat

CVE-2026-0277 Prisma Access Agent: Improper Certificate Validation on iOS

An improper certificate validation vulnerability (CVE-2026-0277) in the Prisma Access Agent for iOS, affecting versions prior to 26.2.1, enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic, leading to potential compromise of data confidentiality and integrity.

exploited Prisma Access Agent vulnerability mitm ios vpn palo-alto-networks
1t
medium threat

CVE-2026-0287 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing

Multiple denial of service vulnerabilities, tracked as CVE-2026-0287, in Palo Alto Networks PAN-OS software allow an unauthenticated attacker to cause a DoS condition by sending specially crafted network traffic, potentially forcing the firewall into maintenance mode.

exploited PAN-OS 12.1 +6 denial-of-service vulnerability network firewall palo-alto-networks
1t
medium advisory

CVE-2026-56250: Capgo R2 Bundle Object Deletion via Mutable r2_path

A critical vulnerability, CVE-2026-56250, in Capgo before version 12.128.2 allows an authenticated attacker with upload-scoped API keys to manipulate the app_versions.r2_path field via PostgREST, leading to arbitrary R2 bundle object deletion and denial of service.

Capgo < 12.128.2 vulnerability denial-of-service cloud web-application
2t 1c 2i
medium advisory

Red Hat JBoss Enterprise Application Platform Cross-Site Scripting Vulnerability

A remote, unauthenticated attacker can exploit a Cross-Site Scripting (XSS) vulnerability in the 'io.undertow.jastow' component of Red Hat JBoss Enterprise Application Platform, allowing injection of malicious scripts into web pages which can lead to session hijacking, data theft, or defacement.

JBoss Enterprise Application Platform xss web-application jboss vulnerability red-hat
1t
medium advisory

New Abuse of ClickOnce Technology: Understanding Internals

CrowdStrike details the internal mechanisms of Microsoft's ClickOnce technology, a legitimate software deployment method that offers minimal user interaction and no administrative privilege requirements, making it a double-edged sword with significant potential for threat actor abuse in malware distribution and persistence.

.NET Framework +1 clickonce windows deployment-technology abuse-of-feature defense-evasion execution
2t
medium advisory

CrowdStrike Uncovers New Prompt Injection Techniques

CrowdStrike has identified 18 new prompt injection techniques, expanding its taxonomy to over 200 methods, which enable adversaries to manipulate AI systems and agents through hidden context, delayed triggers, semantic constraints, boundary spoofing, and social engineering to bypass security measures, leading to modified behavior, data exfiltration, or malicious command execution in AI-driven applications and agents like chatbots or those running in Kubernetes.

Gemini +2 AI prompt-injection cloud-security threat-intelligence defense-evasion initial-access privilege-escalation
5t
medium advisory

CrowdStrike Uncovers New Prompt Injection Techniques Targeting AI Agents

Adversaries are leveraging sophisticated prompt injection techniques, including hidden rules, token suppression, payload decomposition, and special token injection, against AI agents to manipulate their behavior, bypass safety mechanisms, and achieve objectives such as data exfiltration or arbitrary command execution, posing a critical threat to AI-powered systems.

ai-security prompt-injection adversarial-ai agentic-ai techniques
6t
medium advisory

AI Agents Mimic Adversarial Behavior, Triggering Security Detections

AI coding agents such as Claude Code, Cursor, Codex, and GStack are increasingly exhibiting behaviors on Windows endpoints that mimic adversarial tradecraft, including credential access, LOLBin usage for ingress, command-line obfuscation, and persistence mechanisms, thereby triggering existing security detection rules designed for malicious activity and posing significant false positive challenges for detection engineers.

Claude Code +9 ai detection-engineering false-positive windows behavioral-detection
9t 9i
medium advisory

Multiple Vulnerabilities in Postfix Mail Server

Multiple vulnerabilities have been identified in various versions of the Postfix mail server, potentially allowing an attacker to cause a denial of service (DoS) and other unspecified security issues, requiring immediate patching across affected installations.

Postfix < 3.5.26 +6 vulnerability mail-server postfix dos patch
1t 1i
medium advisory

Multiple Vulnerabilities in PHP (CVE-2026-12184, CVE-2026-14355)

Multiple critical vulnerabilities (CVE-2026-12184, CVE-2026-14355) have been discovered in various PHP versions, allowing an attacker to cause an unspecified security issue, as reported by CERT-FR on July 7, 2026.

PHP 8.2.x +3 vulnerability php web-application server-side
1c
medium advisory

Hashicorp Terraform: Information Disclosure Vulnerability

A vulnerability in Hashicorp Terraform allows a remote, authenticated attacker to disclose sensitive information, which could lead to the exposure of confidential data.

Terraform information-disclosure vulnerability hashicorp
1t
medium advisory

Detecting Hostile Prompt Sentiment in AWS Bedrock Claude

This brief outlines the detection of hostile or aggressive prompt sentiment sent to AWS Bedrock Claude large language models, indicating potential abuse, harassment, or attempts at model manipulation, requiring the configuration of Bedrock model invocation logging and Splunk ingestion.

Amazon Bedrock +6 llm aws bedrock abuse sentiment cloud
1r updated
medium advisory

Detecting Linux Payload Downloaded and Piped to Interpreter

This brief details a common Linux technique where attackers use scripting interpreters to download malicious payloads from external sources and immediately pipe them into another interpreter for execution, often for purposes like persistence or data exfiltration.

execution defense-evasion command-and-control linux
1r 2t
medium advisory

Suspicious XDG-Open Command Execution on Linux

This brief details a detection rule for the `xdg-open` command on Linux systems, which attackers abuse to trick users into opening malicious documents or URLs, leading to user execution and potential system compromise.

endpoint linux execution user-execution initial-access detection-rule
1r 2t
medium advisory

Shell Execution via Elastic Endpoint on Linux

This brief details the detection of shell command execution initiated by the Elastic Endpoint agent on Linux systems, indicating potential post-exploitation activity such as remote access or command and control via misuse of the endpoint's response capabilities.

Elastic Endpoint +2 linux endpoint-security command-and-control defense-evasion execution detection-rule
1r 3t
medium advisory

GKE Pod Created With HostIPC Sharing

A privilege escalation threat in Google Kubernetes Engine (GKE) involves an attacker creating or modifying a pod to enable host Inter-Process Communication (IPC) namespace sharing, which exposes host IPC mechanisms and can lead to privilege escalation within the cluster by allowing the pod to interact directly with the underlying host's processes.

Google Kubernetes Engine gcp kubernetes privilege-escalation container-security cloud-security host-ipc
1r 2t
medium advisory

Linux Shared Object Load via LoLBin

Adversaries can leverage Living Off The Land Binaries (LoLBins) such as `openssl`, `python`, or `ruby` to load malicious shared object files (`.so`) into memory on Linux systems, aiming to evade detection by disguising the payload as legitimate process activity; detection engineers must investigate the full command line, parent process chain, executing user, and the reputation/location of the referenced shared object file to differentiate malicious activity from legitimate development or administration tasks.

linux defense-evasion execution endpoint
1r 3t
medium advisory

Suspicious DNS Queries to Remote Monitoring and Management Domains from Non-Browser Processes

This brief details the detection of DNS queries targeting commonly abused Remote Monitoring and Management (RMM) or remote access software domains, originating from non-browser processes, which is a common tactic for command and control, persistence, and lateral movement by threat actors.

01com +151 windows command-and-control endpoint rmm remote-access
1r 193i
medium advisory

Multiples vulnérabilités dans OpenSSH

Multiple vulnerabilities in OpenSSH versions prior to 10.4 allow attackers to bypass security policies, cause denial of service, and exploit other unspecified security issues, requiring users to update to OpenSSH 10.4 or later.

OpenSSH vulnerability network
2t
medium advisory

dhcpcd Denial of Service Vulnerability

A vulnerability in the dhcpcd DHCP client daemon allows an attacker from an adjacent network to execute a Denial of Service attack, potentially disrupting network connectivity on affected Linux systems.

dhcpcd denial-of-service linux impact
1t
medium advisory

Kubernetes Secret Access by Node or Pod Service Account

Attackers who have compromised a Kubernetes pod or node are observed attempting to `get` or `list` Kubernetes Secret objects via the API, a common post-compromise technique by various threat actors to achieve credential access and gather sensitive information such as tokens, registry credentials, TLS keys, or application configurations.

Kubernetes credential-access cloud-security container-security threat-detection
1r 1t
medium advisory

CVE-2026-9165 - Red Hat Advanced Cluster Security for Kubernetes Central Component Denial of Service

An authenticated denial of service vulnerability (CVE-2026-9165) exists in the Red Hat Advanced Cluster Security for Kubernetes (RHACS) Central component, allowing attackers with a valid API token to send deeply nested GraphQL queries that cause excessive resource consumption and render the management plane unavailable.

Red Hat Advanced Cluster Security for Kubernetes +1 kubernetes red-hat dos vulnerability graphql
1t 1c
medium advisory

Potential DNS Exfiltration via Excessive Chunked Queries

This brief details the technique of DNS exfiltration where threat actors use chunked DNS queries with subdomain labels following an 'index-payload.base_domain' pattern to exfiltrate data from compromised Windows hosts, allowing them to bypass volume-based detection and extract sensitive information.

exfiltration dns-tunneling data-exfiltration windows endpoint command-and-control
1r 2t
medium advisory

Detecting Potential ICMP Tunneling Activity for Covert C2 and Exfiltration

This brief describes a critical network threat where attackers leverage ICMP tunneling, a technique to embed command and control (C2) or exfiltrated data within large ICMP Echo payloads, enabling covert communication channels that bypass traditional firewall rules, posing a significant risk of data theft and unauthorized system control.

network-security command-and-control data-exfiltration icmp-tunneling elastic-detection-rule
1r 2t
medium advisory

Detection of Deprecated TLS Version or Weak Cipher Negotiated Externally

This rule identifies successful outbound TLS sessions initiated by internal hosts to external destinations that utilize deprecated protocol versions (SSLv3, TLS 1.0, TLS 1.1) or weak cipher suites such as RC4, 3DES, NULL, EXPORT, or anonymous Diffie-Hellman. Such negotiations can indicate an Adversary-in-the-Middle attack or communication with legacy malware, allowing for traffic interception or decryption. Detection engineers should investigate the `source.ip`, `destination.ip`, `tls.version`, and `tls.cipher` to determine if the destination is a legitimate legacy system or a potential compromise, checking for concurrent alerts on the source host.

network tls credential-access command-and-control mitm downgrade weak-cipher
1r 2t
medium advisory

Potential DHCP Starvation via High Client MAC Cardinality

Attackers utilize DHCP starvation by flooding network segments with DHCP DISCOVER messages containing a high cardinality of distinct client MAC addresses to exhaust the DHCP lease pool, potentially leading to denial of service for legitimate clients and facilitating rogue DHCP server deployment.

network-attack denial-of-service network-security-monitoring impact
1t
medium advisory

Suspicious Java Execution from User-Writable Paths with DNS Lookup

This brief describes the detection of suspicious `javaw.exe` execution on Windows systems by adversaries leveraging recently dropped or modified Java payloads from user-writable directories (e.g., `Users`, `ProgramData`, `Windows\Temp`) to establish command and control via immediate DNS lookups, thereby evading application control mechanisms.

java execution command-and-control windows endpoint
1r 3t
medium advisory

AWS Lambda Event Source Mapping Abuse for Persistence and Data Exfiltration

Adversaries can exploit the creation of AWS Lambda event source mappings to establish stealthy persistence and execution, or to continuously siphon records from event sources like Amazon SQS, Kinesis, DynamoDB, MSK, Kafka, or MQ, by mapping an event source to an attacker-controlled Lambda function, enabling durable execution and data exfiltration without requiring further interactive access.

AWS Lambda +6 cloud aws persistence execution data-exfiltration
1r 3t
medium advisory

AWS Lambda Function Deletion

Adversaries may delete AWS Lambda functions to disrupt business operations, remove evidence of their presence, or impede incident response, an action detectable by monitoring for `DeleteFunction` calls in `aws.cloudtrail` logs and correlating with expected change windows.

AWS Lambda cloud aws lambda impact data-destruction service-stop
1r 2t
medium advisory

AWS Lambda Layer Shared Externally

This brief identifies the critical risk of an AWS Lambda layer's permission policy being modified, typically via the `AddLayerVersionPermission` API, to grant external AWS accounts, AWS Organizations, or the public access, potentially leading to the leakage of proprietary code or secrets and creating a supply-chain vector for attacker-influenced code execution in downstream functions.

AWS Lambda +1 cloud aws lambda supply-chain misconfiguration data-leakage
1r 2t
medium advisory

Systemd Service Override Configuration File Creation for Persistence

Attackers can leverage the creation or renaming of Systemd override configuration files in standard or user service directories to achieve persistence or privilege escalation on Linux systems, altering service behavior to execute malicious commands during system startup or at predefined intervals via timers, thereby maintaining unauthorized access or evading detection.

persistence privilege-escalation linux endpoint
1r 2t
medium advisory

VNC (Virtual Network Computing) to the Internet

This brief details the risk of VNC (Virtual Network Computing) traffic originating from internal networks and destined for the internet, indicating potential unauthorized access or a backdoor, as VNC is frequently exploited by threat actors when exposed externally via specific TCP ports (5800-5810).

command-and-control lateral-movement remote-access network
1r 2t
medium advisory

BadPatch Malware Using SMTP on Port 26 for Command and Control

The BadPatch malware family utilizes SMTP on TCP port 26 for covert command and control of Windows systems, an atypical port for SMTP, posing a significant risk of unauthorized access and data exfiltration.

command-and-control exfiltration network windows malware
1r 3t
medium advisory

AWS Lambda Function Invoked by Unusual Principal

Detects the first direct invocation of an AWS Lambda function by a principal within a 14-day period, excluding AWS service invocations, which can indicate adversary lateral movement, credential abuse, or unauthorized data retrieval in AWS environments.

AWS Lambda cloud aws lambda execution lateral-movement
1r 1t
medium advisory

AWS Lambda Function Invoked from Unusual Source ASN

Attackers are abusing stolen AWS execution-role or user credentials to invoke AWS Lambda functions from unusual source networks (ASNs) not previously associated with the legitimate principal, indicating a credential compromise leading to potential unauthorized access or data exfiltration.

AWS Lambda aws cloud credential-theft execution lambda
1r 1t
medium advisory

AWS KMS Imported Key Material Deleted

Adversaries leverage the `DeleteImportedKeyMaterial` API call against AWS KMS customer managed keys (CMKs) with external material, instantly rendering encrypted data inaccessible with no recovery window, facilitating cloud ransomware or data destruction attacks.

AWS KMS cloud aws kms data-destruction ransomware
1r 1t
medium advisory

AWS Lambda Function Invoked Cross-Account

Adversaries leverage cross-account access to invoke AWS Lambda functions from a different account than the function owner, enabling code execution or data retrieval, which requires AWS Lambda data event logging to detect.

AWS Lambda cloud aws aws-lambda execution cloud-security
1t
medium advisory

AWS IAM Permissions Boundary Modification for Privilege Escalation

An adversary can achieve privilege escalation within an AWS environment by modifying or removing an existing IAM permissions boundary on an IAM user or role, thereby unlocking previously restricted permissions defined in attached identity policies.

AWS IAM cloud aws iam privilege-escalation identity threat-detection
1r 1t
medium advisory

AWS IAM Inline Policy Added to a Group

Adversaries can escalate privileges and establish persistence within AWS by leveraging the `PutGroupPolicy` API call to attach an inline policy to an IAM group, granting broad permissions to all group members, including themselves.

AWS IAM aws cloud privilege-escalation persistence identity
1r 2t
medium advisory

IPSEC NAT Traversal Port Activity Used for Command and Control

A detection rule identifies suspicious outbound IPSEC NAT Traversal (NAT-T) tunnels, characterized by UDP traffic where both source and destination ports are 4500, originating from an internal host to an external destination, a technique frequently abused by threat actors to establish covert command and control channels or exfiltrate data while evading network defenses.

command-and-control network vpn exfiltration protocol-tunneling
1r 3t
medium advisory

AWS IAM Login Profile Created or Modified for an IAM User

This rule detects the creation or modification of console login profiles for AWS IAM users via the CreateLoginProfile or UpdateLoginProfile APIs. Adversaries with stolen programmatic credentials can use these actions to establish persistent interactive console access, reset other users' passwords to take over accounts, and maintain access even after original access keys are rotated. Since IAM user console access is increasingly managed through federation or IAM Identity Center, direct use of these APIs, especially by unexpected principals, warrants investigation as a strong indicator of persistence or account compromise.

AWS IAM +1 cloud aws persistence identity
1r 1t
medium advisory

Interactive File Download in Linux Containers via Curl/Wget Detected

An Elastic Defend for Containers rule detects interactive sessions within Linux containers where `curl` or `wget` are used to download files from the internet, indicating potential adversary command and control or execution activity as threat actors often use such methods to stage payloads, tools, or data for subsequent malicious actions within compromised containerized environments.

container linux command-and-control execution cloud file-download
1r 3t
medium advisory

Suspicious Activity: Multiple Remote Management Tool Vendors on Same Host

This brief describes a behavioral detection for Windows hosts where two or more distinct remote monitoring and management (RMM) or remote-access tools from different vendors are observed starting processes within an eight-minute window, indicating potential compromise, shadow IT, or attacker staging of redundant access.

Acronis Cyber Protect Connect +49 command-and-control remote-access-software rmm windows behavioral-detection
1t
medium advisory

AWS IAM User Console Login from Multiple Geolocations

Adversaries leverage adversary-in-the-middle (AiTM) phishing and session theft to compromise AWS IAM user credentials, leading to concurrent successful AWS Management Console logins from multiple distinct geographic locations, indicating account compromise and enabling unauthorized access to cloud resources despite MFA.

AWS Management Console +2 cloud identity aws initial-access credential-access aitm-phishing session-theft impossible-travel
2t
medium advisory

AWS ECR Repository or Registry Policy Granted Public Access

A malicious actor or misconfigured legitimate user can modify an Amazon ECR repository or registry policy to grant public access using a wildcard principal (`Principal:"*"`), which can lead to the exfiltration of proprietary container images and embedded secrets, or facilitate supply-chain implantation if push permissions are also granted.

Amazon ECR cloud aws ecr exfiltration supply-chain
1r 1t
medium advisory

First Time Seen Remote Monitoring and Management Tool Detection

Adversaries are leveraging legitimate Remote Monitoring and Management (RMM) and remote access tools on Windows endpoints for command-and-control, persistence, and execution, with detection focusing on the first observed instance of these tools on a host.

AA +132 command-and-control persistence execution rmm remote-access windows
1r 3t 5i
medium advisory

Detecting Malicious Kernel Module Loading via Built-in Utilities on Linux

Threat actors with root privileges can leverage built-in Linux utilities like `insmod` or `modprobe` to load kernel object files, often for installing rootkits that grant complete system control and enable evasion of security products, representing a significant persistence and defense evasion technique.

persistence defense-evasion rootkit linux endpoint
1r 1t
medium advisory

Web Server Cloud Metadata SSRF Exploitation

Attackers are actively exploiting Server-Side Request Forgery (SSRF) vulnerabilities in public-facing web applications to access cloud instance metadata services, such as those on AWS, GCP, and Azure, to harvest temporary credentials and sensitive instance details.

AWS +8 ssrf cloud-security web-exploitation credential-access initial-access webserver
1r 2t 7i
medium advisory

Detection of Sysmon Configuration Updates for Defense Evasion

This brief describes how to detect an attacker updating or replacing the Sysmon configuration with a bare bones one to avoid monitoring without completely shutting down the service, leveraging Sysmon's `-c` command-line option for defense impairment.

Sysmon windows defense-evasion defense-impairment
1r
medium advisory

Linux Container Escape via Kernel core_pattern Modification

Attackers can exploit a Linux kernel vulnerability allowing a process inside a container to modify the `/proc/sys/kernel/core_pattern` file, enabling the execution of arbitrary code as root on the host system upon a core-dump, thereby achieving a full container-to-host escape and privilege escalation.

Linux kernel container-escape privilege-escalation linux kubernetes endpoint
1r 1t
medium advisory

Suspicious Linux C2 Activity: Network Connection Followed by File Creation

This brief identifies suspicious Command and Control (C2) activity on Linux systems where a C2 agent, such as Poseidon or Athena, connects outbound from a sensitive temporary directory and subsequently creates a file in a similar location, indicative of receiving and executing commands from a C2 framework like Mythic.

command-and-control execution linux endpoint-detection
2r 2t
medium advisory

Unusual File Download From File Sharing Websites - File Stream

This brief details the detection of suspicious file types (batch, command, PowerShell scripts) downloaded from well-known public file and paste sharing domains, leveraging the `Zone.Identifier` Alternate Data Stream to signal potential malware delivery or covert data transfer, which could lead to system compromise and data exfiltration.

file-download delivery windows defense-evasion command-and-control execution
1r 3t
medium advisory

Application Removal Via Wmic.EXE

Adversaries are leveraging the Windows Management Instrumentation Command-line (WMIC) utility, `wmic.exe`, to uninstall legitimate or security applications as a method of defense evasion and system impact within Windows environments.

defense-evasion impact windows
1r 1t
medium advisory

Application Termination Attempt via Wmic.EXE

Adversaries leverage the native Windows Management Instrumentation Command-line (WMIC) utility to terminate applications, specifically security products, as a defense evasion technique.

defense-evasion windows wmic living-off-the-land
1r 2t
medium advisory

Registry Manipulation via WMI Stdregprov for Evasion

Attackers are leveraging `wmic.exe` to modify the Windows registry through the WMI `StdRegProv` class, specifically using methods like `CreateKey` and `SetStringValue`, to evade detection and bypass traditional security monitoring focused on `reg.exe` or `regedit.exe`.

registry-modification defense-evasion wmi windows process-creation
1r 3t
medium advisory

Detection of Service Manipulation via WMIC.exe

This brief describes the detection of adversaries leveraging the native Windows Management Instrumentation Command-line (WMIC.exe) utility to start or stop services on compromised Windows systems, a common technique for persistence, privilege escalation, or lateral movement.

lolbin windows persistence execution lateral-movement
1r 1t
medium advisory

WMIC Remote Command Execution Detection

This brief focuses on detecting the abuse of the Windows Management Instrumentation Command-line (WMIC) utility to execute commands or query information on remote systems, a common technique used by attackers for lateral movement and reconnaissance within compromised networks.

lateral-movement reconnaissance execution wmic windows
1r 1t
medium threat

System Disk And Volume Reconnaissance Via Wmic.EXE

Threat actor Volt Typhoon is observed using the built-in Windows Management Instrumentation Command-line (WMIC.EXE) utility to perform system and volume discovery, gathering critical system information that can facilitate further network exploitation and data exfiltration.

Volt Typhoon +3 discovery reconnaissance wmic living-off-the-land windows
1r 2t
medium advisory

Potential Unquoted Service Path Reconnaissance Via Wmic.EXE

Attackers and pentesters commonly use `wmic.exe` to query Windows service configurations for unquoted paths, a reconnaissance technique that identifies potential privilege escalation opportunities.

reconnaissance privilege-escalation windows wmic
1r 2t 1c
medium threat

Uncommon WMIC System Information Discovery by Aurora Stealer

Aurora Stealer has been observed using the Windows Management Instrumentation Command-line (WMIC) utility to perform extensive system reconnaissance, gathering details like OS version, CPU, GPU, disk drives, memory, and display resolution, indicating early-stage information gathering for subsequent data exfiltration or malware deployment.

Windows Aurora Stealer reconnaissance discovery infostealer
1r 1t
medium advisory

Service Reconnaissance Via Wmic.EXE

Adversaries leverage the native Windows Management Instrumentation Command-line (WMIC) utility to perform service reconnaissance on remote systems, querying for existing services as a prelude to identifying potential targets for lateral movement or privilege escalation.

Windows Operating System windows reconnaissance wmic internal-recon
1r 1t
medium advisory

Potential Product Class Reconnaissance Via Wmic.EXE

Adversaries are leveraging `wmic.exe` on Windows systems to perform reconnaissance, specifically enumerating installed antivirus, antispyware, and firewall products to aid in evasion and subsequent attack planning, posing a medium risk to affected organizations.

reconnaissance discovery windows
1r 2t
medium advisory

WMIC Product Reconnaissance for Defense Evasion

A threat brief details the use of `wmic.exe` by attackers to perform product reconnaissance, specifically to identify installed firewall and antivirus software, facilitating defense evasion and tailored attack execution.

reconnaissance defense-evasion windows wmic
1r 2t
medium advisory

Potential Process Reconnaissance via Wmic.EXE

Adversaries leverage the native Windows Management Instrumentation Command-line (WMIC) utility with the 'process' flag to perform discovery of running processes on compromised systems, enabling further stages of attack such as privilege escalation or lateral movement.

reconnaissance discovery windows
1r 2t
medium advisory

Windows Hotfix Updates Reconnaissance Via Wmic.EXE

Attackers and pentesters utilize `wmic.exe` with the 'qfe' flag to enumerate installed hotfix updates on Windows systems, a common reconnaissance technique often preceding privilege escalation.

reconnaissance privilege-escalation windows attack.execution attack.t1047
1r 1t
medium threat

Hardware Model Reconnaissance Via Wmic.EXE

Adversaries leverage the built-in Windows Management Instrumentation Command-line (WMIC.EXE) utility with the `csproduct` command to perform hardware model and vendor reconnaissance on target systems, a technique observed in campaigns utilizing infostealers like Kuraystealer, enabling further tailored attacks.

Kuraystealer reconnaissance windows infostealer
1r 6t
medium threat

Computer System Reconnaissance Via Wmic.EXE

This brief details the use of `wmic.exe` with the `computersystem` flag for reconnaissance, a technique observed in campaigns by adversaries such as DEV-0270 (Phosphorus), to gather system information like domain, username, and model.

Windows DEV-0270 +5 discovery reconnaissance ransomware
1r 1t
medium advisory

Process Creation Attempt via Wmic.EXE

Adversaries utilize the `wmic.exe` utility on Windows systems to create and execute processes, a technique detected by observing specific command-line arguments, indicating an attempt to run malicious code on compromised hosts.

execution windows
1r 1t
medium advisory

Suspicious Use of PsLogList for Event Log Discovery and Evasion

Adversaries are leveraging the legitimate Sysinternals utility PsLogList to perform account and system discovery by dumping Windows event logs, and for defense evasion by clearing or exporting these logs, increasing their ability to operate undetected and further compromise systems.

sysinternals discovery defense-evasion account-discovery log-clearing windows
1r 3t
medium advisory

Suspicious Service Installation for Defense Evasion

Attackers are installing suspicious services, specifically NalDrv or PROCEXP152, via registry modifications to non-system32 folders to facilitate defense evasion by tools like Ghost-In-The-Logs, aiming to disable or impair security monitoring capabilities.

defense-evasion persistence kernel-driver windows
1r
medium advisory

Abuse of Microsoft Sysinternals PsSuspend Utility

Unidentified threat actors may leverage the legitimate Microsoft Sysinternals PsSuspend utility to suspend critical processes on Windows systems, enabling evasion of security controls or disruption of operations.

Sysinternals PsSuspend sysinternals living-off-the-land process-manipulation windows tool-abuse
1r 4t
medium advisory

Detection of Sysinternals PsService Execution

This brief details the detection of Sysinternals PsService, a legitimate utility that can be abused by threat actors for service reconnaissance, manipulation, and persistence on Windows systems, potentially leading to privilege escalation or system disruption.

Sysinternals PsService sysinternals process-execution service-manipulation windows
1r 3t
medium advisory

Procdump Execution Detection

This brief details the detection of Procdump, a legitimate Sysinternals utility, which is frequently abused by attackers for credential dumping from sensitive processes like LSASS, enabling privilege escalation and lateral movement on Windows systems.

Sysinternals ProcDump sysinternals credential-dumping process-memory windows
1r 1t
medium advisory

Permission Check Via Accesschk.EXE

Attackers are abusing the legitimate Sysinternals `Accesschk.exe` utility to perform permission discovery on Windows systems, a common step in privilege escalation attacks, allowing them to identify misconfigurations for gaining higher privileges.

Accesschk sysinternals privilege-escalation tool-abuse discovery windows
1r 1t
medium advisory

Detecting Suspicious GrantedAccess Flags on LSASS

This brief details a detection for potentially suspicious `GrantedAccess` flags when a process attempts to access `LSASS.exe`, indicating possible credential dumping attempts by adversaries, which can lead to lateral movement and privilege escalation on Windows systems.

credential-dumping windows post-exploitation
1r 2t
medium advisory

Suspicious CredUI.DLL Loading by Uncommon Processes

Attackers may attempt to load the Windows Credential UI DLL (credui.dll) from an unusual or non-standard process to capture or access user credentials, facilitating credential theft and further malicious activity on a compromised system.

windows credential-access image-load-detection
1r 1t
medium advisory

Suspicious Process Monitor Driver Creation by Non-Sysinternals Binary

This brief details a detection strategy for malicious actors attempting to establish persistence or elevate privileges by creating a Process Monitor driver file (`.sys`) from an unauthorized process, indicating potential kernel-level compromise on Windows systems.

persistence privilege-escalation windows detection
1r 2t
medium advisory

Suspicious PROCEXP152.sys Driver Creation in Temporary Folders

This brief details the suspicious creation of the PROCEXP152.sys driver file, associated with Sysinternals Process Explorer, in temporary application data folders, a technique leveraged by tools like KDU and Ghost-In-The-Logs for defense evasion and bypassing Windows Event Logging on affected Windows systems.

defense-evasion driver-abuse windows endpoint
1r
medium advisory

Potential Privileged System Service Operation - SeLoadDriverPrivilege

This brief details the detection of `SeLoadDriverPrivilege` usage on Windows systems, a critical privilege enabling attackers to load malicious kernel drivers for advanced defense evasion and privilege escalation, leading to full system compromise.

windows defense-evasion privilege-escalation detection
1r 2t
medium advisory

Potentially Suspicious AccessMask Requested From LSASS

This brief describes the detection of suspicious access mask requests to the Local Security Authority Subsystem Service (LSASS) process, a common post-exploitation technique used by threat actors for credential dumping on Windows systems.

credential-dumping post-exploitation windows security-event
1r 1t
medium advisory

New Agent Skills Installation Attempt Via Node.EXE

A new detection identifies the use of `npx skills add` commands via `node.exe` on Windows systems, a potentially abusable mechanism for attackers to install malicious AI agent skills or 'skill worms' that can execute arbitrary commands and infect infrastructure.

ai node.js supply-chain attack.execution attack.t1059.007
1r 1t
medium advisory

FortiGate User Group Modification Detected

An attacker with initial access to a Fortinet FortiGate firewall may modify existing user groups to establish persistence or elevate privileges, potentially granting unauthorized VPN access to internal networks.

FortiGate fortinet firewall persistence privilege-escalation
1r 2t
medium advisory

FortiGate - New VPN SSL Web Portal Added

This brief details a detection for the addition of a new VPN SSL Web Portal on FortiGate Firewalls, a configuration change that could be utilized by attackers for establishing persistence or initial access to external remote services, as indicated by observed modifications of VPN SSL settings.

FortiGate Firewall fortigate vpn configuration-change network-device persistence initial-access
1r 2t
medium advisory

FortiGate - New Local User Creation Detection

This brief details the detection of new local user creation on Fortinet FortiGate firewalls, a behavior often leveraged by adversaries for persistence and unauthorized VPN access, underscoring a critical post-exploitation activity for detection engineers.

FortiGate network detection persistence
1r 1t
medium advisory

FortiGate - New Firewall Policy Added

This brief describes a detection for the addition of new firewall policies on Fortinet FortiGate devices, a behavior that can indicate defense impairment or unauthorized network access by a malicious actor.

FortiGate defense-impairment firewall network
1r 1t
medium advisory

Detection of FortiGate Firewall Address Object Addition

This brief details the detection of firewall address objects being added on Fortinet FortiGate devices, a configuration change that, while potentially legitimate, can also indicate post-compromise activity or unauthorized access, especially when tied to vulnerabilities like FG-IR-24-535, enabling threat actors to bypass security controls or facilitate command and control.

FortiGate network-device firewall defense-evasion
1r
medium advisory

FortiGate - New Administrator Account Created

This brief describes how to detect the creation of new administrator accounts on Fortinet FortiGate firewalls, a behavior often used by attackers for persistence (ATT&CK T1136.001) or to maintain unauthorized access after initial compromise.

FortiGate Firewall attack.persistence attack.t1136.001 network-device fortinet
1r 1t
medium advisory

Suspicious User-Agents Related To Recon Tools

This brief details the detection of reconnaissance and scanning tools through their characteristic User-Agent strings observed in web server logs, providing an early warning of potential targeted scanning activity against public-facing applications by adversaries seeking initial access.

reconnaissance web-security attack.initial-access attack.t1190
1r 3t
medium advisory

Potentially Suspicious WDAC Policy File Creation

Attackers may create Windows Defender Application Control (WDAC) policy files from abnormal processes to bypass Endpoint Detection and Response (EDR) or Antivirus (AV) solutions while allowing their own malicious code to execute on compromised Windows systems, impacting defense capabilities.

defense-impairment wdac application-control windows
1r 1t
medium advisory

Suspicious PowerShell Start-Process with PassThru for Stealth Execution

This brief details a PowerShell defense evasion technique where adversaries utilize the `Start-Process` cmdlet with the `-PassThru` parameter to execute commands or programs in a hidden, background manner, enabling covert persistent access or malicious payload execution on Windows systems.

powershell defense-evasion stealth windows
1r 1t
medium advisory

Splunk User Enumeration Attempt Detection

An attacker is attempting to enumerate valid Splunk usernames by repeatedly submitting failed authentication attempts from a single source, as detected by monitoring the `_audit` index for multiple login failures, which is a precursor to credential-based attacks like password spraying or brute force, potentially leading to unauthorized access and sensitive data exposure.

Splunk Enterprise +2 user-enumeration splunk authentication application
1t 1c
medium advisory

Windows Process Injection With Public Source Path

This brief details a hunting analytic that detects process injection attempts on Windows systems using the CreateRemoteThread technique (Sysmon Event ID 8), often employed by advanced malware like Brute Ratel C4 to evade detection and escalate privileges, by monitoring processes originating from non-standard file paths.

endpoint process-injection defense-evasion privilege-escalation windows
1r 1t
medium advisory

Windows Autostart Persistence via Startup Folder

Adversaries commonly leverage file creation in the Windows `%startup%` folder (T1547.001) to establish persistence, ensuring malicious code executes automatically upon system boot or user logon, potentially leading to system compromise and unauthorized access.

persistence execution windows malware
1r 2t
medium advisory

@conform-to/dom Vulnerable to CPU Exhaustion via Crafted Form Submissions

A CPU exhaustion vulnerability (CVE-2026-49250) exists in Conform's `parseSubmission` API when parsing `FormData` or `URLSearchParams` with many unique field names, allowing an attacker to craft a submission that causes excessive synchronous CPU work and potential denial of service by repeatedly scanning submitted entries.

npm/@conform-to/dom vulnerability web-application denial-of-service cpu-exhaustion npm
medium advisory

Zebra Block Suppression Vulnerability (CVE-2026-52736) via P2P Body Poisoning

A remote unauthenticated attacker can exploit CVE-2026-52736 in Zebra's `zebrad` node (versions up to and including `v4.4.1`) to permanently stall a targeted blockchain node by poisoning its sent-hash cache, leading to a denial of service.

zebrad <= 4.4.1 +1 blockchain denial-of-service network vulnerability
2t
medium advisory

JSONata $toMillis Function Vulnerability Leads to Denial of Service (CVE-2026-52746)

A high-severity vulnerability, CVE-2026-52746, in JSONata versions prior to 2.2.0 allows unauthenticated attackers to cause a denial of service by exploiting superlinear backtracking in the ISO-8601 validation regex through malicious inputs to the `$toMillis` function, leading to resource exhaustion and application unresponsiveness.

JSONata denial-of-service nodejs vulnerability CVE-2026-52746
1t
medium advisory

Zebra Node Denial-of-Service via IPv4-Mapped Mempool Misbehavior Panic (CVE-2026-52829)

A remote unauthenticated peer can exploit an address normalization mismatch in Zebra's address book when connecting via IPv4 to a dual-stack IPv6 listener on a Linux host, by then advertising an invalid mempool transaction, which triggers a deterministic assertion panic after a 30-second delay, causing the `zebrad` process to terminate, leading to persistent denial of service.

zebrad <= 4.4.1 +1 denial-of-service vulnerability linux rust
1t
medium advisory

SimpleSAMLphp Vulnerable to Denial-of-Service via Malicious XPath Transform

SimpleSAMLphp and its SAML2 library are vulnerable to CVE-2026-49289, allowing attackers to perform a Denial-of-Service attack by sending specially crafted SAML messages containing XPath transforms, leading to resource exhaustion and service unavailability.

composer/simplesamlphp/saml2 <= 4.20.2 +1 denial-of-service vulnerability saml php
1t
medium advisory

Steeltoe.Discovery.Eureka Deserialization Denial-of-Service (CVE-2026-50196)

The Steeltoe.Discovery.Eureka client contains a vulnerability (CVE-2026-50196) where its `DataCenterInfo.FromJson` method throws an `ArgumentException` if a `DataCenterInfo.name` value other than 'MyOwn' or 'Amazon' is encountered, specifically missing the valid 'Netflix' value from the Java Eureka specification, which causes the local service registry to become permanently empty or stale, leading to a complete service discovery outage for all connected Steeltoe Eureka clients.

Steeltoe.Discovery.Eureka +1 vulnerability service-discovery .net java denial-of-service
1c
medium advisory

dnsmasq Vulnerability Enables Denial of Service

A remote, unauthenticated attacker can exploit a vulnerability in dnsmasq to initiate a Denial of Service attack, disrupting the service's availability.

dnsmasq vulnerability dos network linux
1t
medium advisory

ClamAV Vulnerabilities Lead to Denial of Service in Cisco Secure Endpoint Products

Multiple vulnerabilities (CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, CVE-2026-20244) in ClamAV, as integrated into Cisco Secure Endpoint Connector, allow a remote attacker to cause a denial of service (DoS) condition by interrupting scanning operations, with a High severity impact on Windows platforms and Medium on Linux/Mac.

Cisco Secure Endpoint Connector +3 vulnerability dos clamav cisco security-software
1t 7c updated
medium advisory

CVE-2026-56081: Cap-go Authentication Logic Flaw Leading to Account Takeover

An authentication logic flaw in Cap-go versions prior to 12.128.2 allows attackers to register an account with a victim's unverified email address, then enable two-factor authentication on this pre-registered account to gain full control, read/modify data, enforce organization-level policies, and deny the legitimate user access.

Cap-go < 12.128.2 account-takeover authentication-bypass web-application logic-flaw cloud
2r 2t
medium advisory

Azure VM Managed Run Command Abuse for Execution and Persistence

Adversaries can abuse the Azure VM Managed Run Command feature (MICROSOFT.COMPUTE/VIRTUALMACHINES/RUNCOMMANDS/WRITE) to achieve code execution as System or root and establish persistence on Azure Virtual Machines or Virtual Machine Scale Sets by an unusual identity, potentially evading detections focused solely on action-based Run Commands.

Azure Virtual Machines +2 cloud azure execution persistence defense-evasion vm iac
2r 1t
medium advisory

undici WebSocket Client Vulnerable to Denial of Service (CVE-2026-12151)

The `undici` WebSocket client is vulnerable to CVE-2026-12151, a high-severity denial of service attack where a malicious WebSocket server can stream numerous small continuation frames that bypass `maxPayloadSize` checks, causing unbounded memory growth and exhaustion in affected client processes.

undici +2 denial-of-service vulnerability javascript npm nodejs
2r 1t
medium advisory

Vim Denial of Service Vulnerability

A vulnerability in the vim text editor allows a remote, unauthenticated attacker to perform a Denial of Service attack by exploiting a weakness to disrupt the service without requiring prior authentication.

vim denial-of-service vulnerability text-editor linux macos windows
2r 1t
medium advisory

libssh2 Vulnerability: Denial of Service and Information Disclosure

A vulnerability in the libssh2 library allows a remote, unauthenticated attacker to perform a Denial of Service (DoS) attack or disclose sensitive information, potentially leading to service disruption or unauthorized data exposure.

libssh2 ssh vulnerability dos information-disclosure library
3r 2t
medium advisory

Multiple Vulnerabilities in expat XML Parser Library

Multiple vulnerabilities have been discovered in the expat XML parser library that can be exploited by a local attacker, potentially leading to a Denial of Service condition or allowing for arbitrary code execution on the affected system.

expat vulnerability library xml denial-of-service code-execution local-exploitation
2r 2t
medium advisory

OpenBSD Information Disclosure Vulnerability

A remote, anonymous attacker can exploit a vulnerability in OpenBSD to disclose sensitive information, potentially leading to unauthorized data exposure.

OpenBSD vulnerability information-disclosure linux
3r 1t
medium advisory

PHP JWT Library PBES2-HS*+A*KW Unbounded p2c Iteration Count Leads to DoS

An unauthenticated attacker can exploit a vulnerability in the PHP JWT Library's PBES2AESKW::unwrapKey() function when processing JWE tokens that use PBES2-HS*+A*KW algorithms by crafting a JWE with an excessively large 'p2c' (PBKDF2 iteration count) parameter in the JOSE header, forcing the server to perform an unbounded and CPU-intensive PBKDF2 computation, resulting in a CPU-amplification denial of service.

jwt-library +3 denial-of-service web php jwt jwe cwe-400
2r 1t
medium advisory

spomky-labs/otphp Unbounded Digits Parameter Leads to Denial of Service

The spomky-labs/otphp library is vulnerable to a denial of service (GHSA-g7m4-839x-ch6v) where an unbounded 'digits' parameter in an otpauth provisioning URI causes a DivisionByZeroError, leading to unhandled fatal errors in applications trying to generate or verify OTPs.

otphp < 11.4.3 php denial-of-service vulnerability ghsa
2r 1t
medium threat

Azure VM Serial Console Exploitation for Lateral Movement

Adversaries with privileged Azure RBAC roles are exploiting the Azure VM Serial Console to gain SYSTEM/root access on virtual machines, bypassing network controls like NSGs and JIT policies, with detections focusing on unusual user and source network combinations.

Azure Virtual Machine +1 cloud azure lateral-movement defense-evasion initial-access vm
3r 2t
medium advisory

CVE-2026-55204: HAProxy Null Pointer Dereference Leads to Denial of Service

An unauthenticated attacker can exploit CVE-2026-55204, a null pointer dereference vulnerability in HAProxy through version 3.4.0, by triggering excessive HPACK dynamic table insertions under memory pressure, causing HAProxy worker processes to crash and resulting in a denial of service.

HAProxy 3.4.0 denial-of-service vulnerability HAProxy CVE-2026-55204
2r 1t
medium advisory

Entra ID OAuth Application Redirect URI Modified

Adversaries are modifying OAuth application redirect URIs (ReplyUrls) in Microsoft Entra ID to intercept OAuth authorization codes and steal tokens, granting unauthorized access without new application registration or user consent.

Entra ID +1 cloud identity azure persistence credential-access token-theft microsoft-entra-id
2r 2t
medium advisory

Microsoft Entra ID Guest Account Promoted to Member

A sophisticated threat actor, having compromised an existing guest account in Microsoft Entra ID, can establish persistent access and elevate privileges by performing a Guest-to-Member account conversion, which grants full directory read access and bypasses Conditional Access restrictions, enabling stealthy long-term access and reconnaissance.

Microsoft Entra ID cloud identity persistence azure microsoft-entra-id
1r 1t
medium advisory

Google Workspace Custom Admin Role Created for Persistence

Adversaries may create custom administrative roles in Google Workspace to establish persistence with tailored, elevated permissions, which are then assigned to compromised or attacker-controlled accounts to bypass security controls, grant OAuth access, or modify mail routing.

Google Workspace google-workspace cloud-security persistence privilege-escalation iam
1r 2t
medium advisory

Google Workspace Admin Role Deletion

Adversaries with elevated privileges within Google Workspace may delete custom administrative roles to impede security operations, remove delegated administrator access, or obfuscate their activities during an active incident, leading to disrupted delegated administration, loss of security team access, or hindrance of incident response efforts.

Google Workspace cloud google-workspace identity-and-access-audit impact defense-evasion admin-role-deletion
2r 2t
medium advisory

Pipecat Telephony Runner Unauthenticated Call-Control Abuse

An unauthenticated remote attacker can leverage a missing authorization vulnerability (CWE-862) in the Pipecat development runner's `/ws` WebSocket endpoint to supply a crafted `callSid` in a handshake message, compelling the server to use its configured Twilio, Telnyx, or Plivo credentials to issue authenticated API requests that terminate active calls, resulting in denial of service and credential abuse.

pipecat development runner api-security websocket telephony cwe-862 python
1r 3t 3i
medium advisory

Multiple Vulnerabilities in Microsoft Edge Allow Security Policy Bypass

Multiple vulnerabilities, including CVE-2026-10883, CVE-2026-10892, and others, have been discovered in Microsoft Edge versions prior to 149.0.4022.53, enabling an attacker to bypass security policies and potentially cause other unspecified security issues within the browser environment.

Microsoft Edge browser-vulnerability security-policy-bypass client-side-exploit microsoft-edge
2r 2t 5c 48i
medium advisory

Multiple Vulnerabilities in Microsoft .Net (CVE-2026-45491, CVE-2026-45591)

Multiple vulnerabilities, CVE-2026-45491 and CVE-2026-45591, have been discovered in Microsoft .Net and ASP.NET Core versions, allowing a remote attacker to cause a denial of service and compromise data integrity across Windows, Linux, and macOS platforms.

.NET 10.0 +5 vulnerability denial-of-service data-integrity dotnet microsoft
2r 2t 2c
medium threat

Kimsuky APT Domains and URLs from Maltrail Feed

This brief summarizes newly published IOCs consisting of domains and URLs associated with the Kimsuky APT group as of June 2nd, 2026, sourced from a Maltrail feed.

Kimsuky +4 apt ioc malware
2r 2t 50i
medium advisory

FreePBX Hardcoded Credentials Vulnerability (CVE-2026-46376)

A critical vulnerability, CVE-2026-46376, exists in FreePBX due to the use of hard-coded credentials in the User Control Panel (UCP) generic template setup process, allowing an unauthenticated, remote attacker to gain unauthorized access to user accounts and manipulate user settings if default template credentials are not immediately changed by the administrator after enabling UCP.

FreePBX cve voip credential-access
2r 1t 1c
medium advisory

Red Hat Cloud Services npm Packages Hijacked

Multiple npm packages within the legitimate @redhat-cloud-services namespace have been hijacked with malicious code, posing a supply chain risk.

@redhat-cloud-services namespace npm supply-chain package-hijacking
2r
medium advisory

SourceCodester SEO Meta Tag Extractor 1.0 - Server-Side Request Forgery (SSRF) - CVE-2026-10287

SourceCodester SEO Meta Tag Extractor 1.0 is vulnerable to server-side request forgery (SSRF) via manipulation of the 'url' argument in the get_headers function of the /index.php file, potentially allowing a remote attacker to make requests to internal or external systems.

SEO Meta Tag Extractor 1.0 cve cve-2026-10287 ssrf server-side request forgery
2r 1t 1c
medium threat

Unusual Child Process Execution from Linux Web Servers

This rule detects unusual child process executions originating from web server processes on Linux systems, which attackers may use to maintain persistence on a compromised system by exploiting web server vulnerabilities.

Jira +20 persistence execution command_and_control initial_access linux webserver
2r 4t
medium threat

Suspicious Command Execution via Web Server on Linux

Identifies suspicious command executions via a web server on Linux systems, which may suggest a vulnerability and remote shell access.

Elastic Defend +43 persistence initial-access vulnerability linux
2r 3t
medium advisory

Unusual Child Execution via Web Server

This rule detects unusual child process executions originating from web server processes on Linux systems, potentially indicating attackers exploiting web servers for persistence.

Elastic Defend persistence web-shell linux
2r 4t
medium advisory

Suspicious Command Execution via Web Server on Linux

Identifies suspicious command executions via a web server on Linux systems, potentially indicating a vulnerability exploitation or remote shell access for persistence.

Elastic Defend endpoint linux persistence initial-access vulnerability
3r 2t
medium advisory

Laravel Security Policy Bypass Vulnerability

A vulnerability in Laravel allows an attacker to bypass the security policy; specifically, laravel/framework versions 12.x before 12.60.0 and 13.x before 13.10.0 are affected (CVE-2026-48019).

laravel/framework security-bypass web-application laravel
1r 1t
medium advisory

Azure Run Command Correlated with Process Execution

This rule detects the abuse of Azure Virtual Machine Run Command to execute scripts remotely, correlating Azure Activity Log events with endpoint process starts, identifying instances where adversaries use Run Command to run scripts as SYSTEM or root.

Azure +1 cloud endpoint execution powershell
2r 2t
medium advisory

Azure Run Command Script Child Process

This rule identifies suspicious process start events where the parent process matches Azure Virtual Machine Run Command execution patterns on Windows (PowerShell with `-ExecutionPolicy Unrestricted` and `script?.ps1`) or Linux (waagent running `script.sh` under `/var/lib/waagent/run-command/`), exposing on-guest payloads.

Azure Virtual Machines cloud endpoint azure execution azure-run-command
2r 3t
medium advisory

CISA ICS Advisories Address Vulnerabilities in Multiple Vendor Products

CISA published ICS advisories between May 25 and 31, 2026, addressing vulnerabilities across various vendors including ABB, CP Plus, Eppendorf, Frontier, Jinan USR IOT, KMW, MacGregor, Schneider Electric, and XCharge, impacting industrial control systems and related applications.

AC500 V2 +19 ics vulnerability cisa
2r
medium threat

Dell Security Advisory Addressing Multiple Product Vulnerabilities

Dell released security advisories in May 2026 to address vulnerabilities in PowerEdge Server Chipset Driver, Data Lakehouse, Dell Enterprise SONiC Distribution, and Dell Unity/UnityVSA/Unity XT.

PowerEdge Server Chipset Driver +5 vulnerability dell patch
2r
medium advisory

Multiple Vulnerabilities in ImageMagick

A remote, anonymous attacker can exploit multiple vulnerabilities in ImageMagick to cause a denial of service condition, disclose information, and bypass security mechanisms.

ImageMagick denial of service information disclosure security bypass
2r 3t
medium advisory

PostgreSQL JDBC Driver Vulnerability Allows Denial of Service

A remote, anonymous attacker can exploit a vulnerability in the PostgreSQL JDBC Driver to perform a denial-of-service attack, impacting availability.

JDBC Driver denial-of-service postgresql jdbc
2r 1t
medium advisory

Kubernetes Static Pod Manifest File Access

This rule detects Linux process executions that reference /etc/kubernetes/manifests in process arguments, which may indicate tampering with static pod manifests for persistence or privilege escalation in Kubernetes environments.

Elastic Defend +2 kubernetes container persistence privilege-escalation linux
3r 2t
medium advisory

Kubernetes Admission Webhook Created or Modified by Non-System Identity

The creation, modification, or deletion of Kubernetes MutatingWebhookConfigurations or ValidatingWebhookConfigurations by non-system identities can allow attackers to inject malicious sidecars or block security tooling deployments for persistence and defense evasion.

kubernetes persistence defense_evasion
2r 2t
medium advisory

AWS SSM Session Manager Child Process Execution

This rule detects process start events where the parent process is the AWS Systems Manager (SSM) Session Manager worker, which can indicate remote execution and lateral movement by adversaries abusing legitimate AWS credentials.

AWS Systems Manager aws ssm execution cloud
3r 3t
medium threat

Maltrail IOC List Analysis - June 1, 2026

This brief analyzes a Maltrail IOC list from June 1, 2026, identifying domains and IP addresses associated with various malware and threat actors, including android_fvncbot, lummac2, magentocore, sectoprat, apt_lazarus, offloader, android_joker, cyberstrikeai, and nightshadec2, potentially used for command and control, malware distribution, or phishing campaigns.

maltrail ioc malware command-and-control
2r 1t 50i
medium advisory

Fujitsu ServerView Multiple Vulnerabilities Allow Privilege Escalation

A local attacker can exploit multiple vulnerabilities in Fujitsu ServerView to escalate privileges on the targeted system.

ServerView privilege-escalation fujitsu
1r 1t
medium advisory

Node.js Permission Model Bypass via Unix Domain Sockets (CVE-2026-21711)

CVE-2026-21711 allows code running under the Node.js permission model without network access to create and expose local IPC endpoints via Unix Domain Sockets, bypassing intended network restrictions and enabling inter-process communication.

Node.js 25.x nodejs permission model uds unix domain socket ipc cve-2026-21711
2r 1t 1c
medium advisory

CVE-2026-21717 Node.js V8 Hash Collision Vulnerability

CVE-2026-21717 is a vulnerability in V8's string hashing mechanism within Node.js that allows attackers to cause hash collisions via predictable integer-like strings in JSON input, leading to denial-of-service by degrading the performance of the Node.js process.

Node.js 20.x +3 dos hash-collision node.js
2r 2t 1c
medium threat

CVE-2026-44839: RabbitMQ Management UI XSS via Unsanitized vhost Names

CVE-2026-44839 is a cross-site scripting (XSS) vulnerability in the RabbitMQ management UI that arises from unsanitized virtual host (vhost) names, potentially allowing an attacker to execute arbitrary JavaScript in the context of a user's browser.

RabbitMQ xss cve-2026-44839 web-application
2r 1t 1c
medium threat

CVE-2026-42790 nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification

CVE-2026-42790 is a vulnerability in Microsoft products related to name constraints DNS bypass via subject CommonName fallback in public_key hostname verification.

cve-2026-42790 certificate-validation hostname-verification tls
2r 1c
medium advisory

WinMTR 0.91 Denial of Service Vulnerability (CVE-2018-25426)

WinMTR 0.91 is vulnerable to a denial-of-service attack where a malformed payload file containing a buffer overflow can crash the application (CVE-2018-25426).

WinMTR 0.91 dos buffer overflow cve-2018-25426
1r 1t 1c
medium advisory

CVE-2026-41184 ServiceAccount Token Disclosure via install-cni Container Logs

CVE-2026-41184 is a ServiceAccount token disclosure vulnerability in container logs addressed by a Microsoft security update.

vulnerability token-disclosure kubernetes CVE-2026-41184
2r 1t 1c
medium advisory

Stigmem-node Federation Peer Token Timestamp Validation Vulnerability

A timestamp handling issue in Stigmem-node's federation peer token validation could cause valid peer tokens to be incorrectly treated as expired, impacting availability and reliability of authenticated federation flows, affecting versions prior to 0.9.0a2.

stigmem-node stigmem token-validation authentication
1r 1t
medium advisory

Gotenberg Denial-of-Service Vulnerability via Multipart downloadFrom Handling

Gotenberg is vulnerable to a remote denial-of-service (DoS) in multipart `downloadFrom` handling, where a crafted multipart request with multiple `downloadFrom` entries causes concurrent goroutines to write to shared maps without synchronization, leading to process termination.

Gotenberg denial-of-service race-condition webserver
2r 1t
medium advisory

External User Added to Google Workspace Group

Detects an external Google Workspace user account being added to an existing group, potentially allowing adversaries to intercept shared files or emails.

Google Workspace google_workspace initial_access persistence cloud
2r 2t
medium advisory

Linux Segfault from Sensitive Process Detected

This rule detects segfault messages in kernel logs originating from sensitive processes on Linux systems, indicating potential exploitation attempts that could lead to arbitrary code execution or credential access.

Elastic Agent +2 credential-access execution linux
2r 3t
medium advisory

yamcs-core Authentication Endpoint Brute-Force Vulnerability (CVE-2026-44596)

A public exploit has been published for CVE-2026-44596, a vulnerability in yamcs-core where the /auth/token authentication endpoint lacks rate limiting, allowing unauthenticated remote attackers to perform unlimited password guessing attempts against any user account, fixed in version 5.12.7.

yamcs-core cve authentication brute-force
1r 1t
medium advisory

M365 Exchange Inbox Forwarding Rule Created

This rule detects the creation of new inbox forwarding rules in Microsoft 365, which can be abused by attackers to intercept and exfiltrate email data to external addresses.

Microsoft 365 cloud saas email microsoft_365 configuration_audit email_collection
2r 1t
medium advisory

Microsoft Edge Security Update Released

Microsoft released a security update on May 28, 2026, to address vulnerabilities in Microsoft Edge Stable Channel versions prior to 148.0.3967.96, advising users to apply the necessary updates.

Microsoft Edge Stable Channel < 148.0.3967.96 browser update edge
2r
medium advisory

OpenShift Router SSRF via FQDN EndpointSlice (CVE-2026-42965)

CVE-2026-42965 describes a server-side request forgery (SSRF) vulnerability in the OpenShift Router where a user with EndpointSlice write access can expose instance credentials by creating a service that proxies requests to a cloud metadata endpoint.

OpenShift Router ssrf cve openshift
1r 1t 1c
medium advisory

M365 Exchange Inbox Rule with Obfuscated Name

This rule detects when a Microsoft Exchange inbox rule is created or modified with a name composed only of special characters, which adversaries may use to evade detection and hide malicious forwarding or deletion rules.

Microsoft 365 +1 cloud saas email exchange defense evasion persistence
2r 2t
medium advisory

Azure VM Extension Deployment by Interactive User

Successful deployment of a high-risk Azure Virtual Machine extension by an interactive user principal can lead to arbitrary code execution, backdoor account creation, credential harvesting, and persistence on Azure-hosted virtual machines.

Azure Virtual Machines +4 azure vm-extension persistence cloud threat-detection
2r 3t
medium advisory

Media Library Assistant WordPress Plugin vulnerable to CSRF (CVE-2026-6075)

The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery (CVE-2026-6075) due to missing nonce verification, allowing unauthenticated attackers to trick an administrator into performing unauthorized bulk actions.

Media Library Assistant plugin for WordPress <= 3.35 wordpress csrf plugin
2r 1t 1c
medium advisory

Mautic SQL Injection Vulnerability

A remote, authenticated attacker can exploit a vulnerability in Mautic to perform a SQL injection attack, potentially leading to unauthorized data access or modification.

Mautic sql-injection vulnerability
2r 1t
medium advisory

CVE-2025-11262: WordPress Link Whisper Free Plugin Stored XSS Vulnerability

The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS), allowing unauthenticated attackers to inject arbitrary web scripts into pages, which execute when a user accesses the injected page, affecting versions up to and including 0.9.0.

Link Whisper Free plugin wordpress xss plugin
2r 1t 1c
medium advisory

CVE-2026-46174: AMD Zen2 Improper Isolation of Shared Resources in Op Cache

CVE-2026-46174 describes a vulnerability in AMD Zen2 processors related to improper isolation of shared resources within the operation cache, potentially leading to information disclosure or other security impacts.

hardware vulnerability information disclosure AMD
2r 1c
medium advisory

CVE-2026-46185 Out-of-Bounds Read in SMB Client symlink_data()

CVE-2026-46185 is an out-of-bounds read vulnerability in the SMB client component within the symlink_data() function, potentially leading to information disclosure or denial of service.

cve smb out-of-bounds read information disclosure denial of service symlink
2r 1t 1c
medium advisory

CVE-2026-46153: 8021q Delete Cleared Egress QoS Mappings Vulnerability

Microsoft published information regarding CVE-2026-46153, a vulnerability in 8021q that allows deleting cleared egress QoS mappings.

cve network qos
2r 1c
medium advisory

CVE-2026-46155: Out-of-bounds Read in SMB Client

CVE-2026-46155 describes an out-of-bounds read vulnerability within the smb2_compound_op() function of the SMB client, requiring a security update from Microsoft to address the issue.

smb out-of-bounds read information disclosure
2r 1t 1c
medium threat

CVE-2026-46107 dm-thin Metadata Refcount Underflow

CVE-2026-46107 is a reported vulnerability in dm-thin, leading to a metadata refcount underflow.

cve dm-thin refcount underflow Microsoft
2r 1c
medium advisory

CVE-2026-46172 Vulnerability in IPv6 xfrm6_rcv_encap()

CVE-2026-46172 is a vulnerability related to ipv6: xfrm6: release dst on error in xfrm6_rcv_encap(), potentially leading to a denial-of-service condition.

ipv6 denial-of-service CVE-2026-46172
2r 1t 1c
medium advisory

Red Hat OpenShift Tempo Vulnerabilities Allow Remote Exploitation

Multiple vulnerabilities in Red Hat OpenShift Tempo allow an unauthenticated remote attacker to bypass security measures, disclose sensitive information, manipulate data, or cause a denial of service condition.

OpenShift Tempo openshift tempo vulnerability
1r 3t
medium advisory

strongSwan 5.9.13 Denial-of-Service Vulnerability (CVE-2026-35333)

A denial-of-service vulnerability exists in strongSwan version 5.9.13 due to a flaw in the eap-radius plugin when built with DAE enabled, allowing remote attackers to exhaust worker threads by sending a crafted RADIUS Access-Request (CVE-2026-35333).

strongSwan <= 5.9.13 denial-of-service radius strongswan CVE-2026-35333
2r 1t
medium threat

CVE-2026-46835 - Oracle Database Server Net Service Denial of Service

CVE-2026-46835 is an easily exploitable vulnerability in Oracle Database Server's Net Service component, affecting versions 23.4.0 to 23.26.2, allowing an unauthenticated attacker with network access via TLS to cause a complete denial-of-service (DoS).

Database Server cve dos oracle
2r 1c
medium advisory

CVE-2026-46834 - Oracle Database Server Net Service Denial of Service

CVE-2026-46834 is a vulnerability in the Net Service component of Oracle Database Server versions 23.4.0 to 23.26.2 that allows an unauthenticated attacker with network access via TLS to cause a denial-of-service (DoS) condition.

Database Server vulnerability dos oracle
2r 1t 1c
medium advisory

CVE-2026-46829: Oracle REST Data Services Unauthenticated Denial of Service

An unauthenticated attacker with network access via HTTPS can exploit CVE-2026-46829 in Oracle REST Data Services versions 24.2.0 through 26.1.0, leading to a denial of service.

REST Data Services dos oracle rest CVE-2026-46829
2r 1t 1c
medium advisory

CVE-2026-46828 - Oracle Payroll Vulnerability Allows Unauthorized Data Access and Modification

CVE-2026-46828 is an easily exploitable vulnerability in Oracle Payroll versions 12.2.3-12.2.15, allowing a low-privileged attacker with network access via HTTP to perform unauthorized creation, deletion, or modification of critical payroll data, as well as gain unauthorized access to sensitive information.

Payroll cve oracle ebusiness suite rce
2r 1t 1c
medium advisory

CVE-2026-46823 - Oracle Public Sector Financials (International) Unauthorized Data Access

CVE-2026-46823 is an easily exploitable vulnerability in Oracle Public Sector Financials (International) versions 12.2.6-12.2.15, allowing a low privileged attacker with network access via HTTPS to gain unauthorized access to critical data or complete access to all accessible data, potentially impacting additional products.

Public Sector Financials +10 cve oracle e-business suite data access
1r 1t 1c
medium advisory

CVE-2026-46821 - Oracle E-Business Suite Financials Common Modules Unauthorized Data Access

CVE-2026-46821 is an easily exploitable vulnerability in Oracle Financials Common Modules of Oracle E-Business Suite versions 12.2.3-12.2.15, allowing a low-privileged attacker with network access via HTTP to gain unauthorized access to critical data.

E-Business Suite +1 cve oracle ebusiness suite financials data access
2r 1t 1c
medium advisory

CVE-2026-46820: Oracle Financials Common Modules Vulnerability in E-Business Suite

CVE-2026-46820 is a vulnerability in Oracle Financials Common Modules within Oracle E-Business Suite versions 12.2.3-12.2.15, allowing a low-privileged attacker with network access via HTTP to gain unauthorized access to critical data and modify some data, resulting in a confidentiality and integrity impact.

E-Business Suite +1 cve oracle ebusiness suite financials
2r 1t 1c
medium advisory

CVE-2026-35266: Oracle REST Data Services Vulnerability Allows Unauthorized Data Access and Modification

A vulnerability exists in Oracle REST Data Services versions 24.2.0 to 26.1.0, where a low-privileged attacker with network access via HTTPS can, with human interaction, gain unauthorized data access, modification, and cause a partial denial of service.

REST Data Services vulnerability oracle ords
2r 1c
medium advisory

Detect Large ICMP Traffic

This analytic identifies ICMP traffic to external IP addresses with total bytes greater than 1,000 bytes, leveraging the Network_Traffic data model to detect potential information smuggling, covert communication, or command-and-control (C2) activities.

Palo Alto Network Traffic +4 network command-and-control icmp
2r 1t
medium threat

Windows Cabinet File Extraction via Expand.exe

Detection of expand.exe being used to extract Microsoft Cabinet (CAB) archives, specifically when extracting to C:\ProgramData or similar staging locations, potentially indicating ingress tool transfer and payload staging by threat actors like APT37.

Splunk Enterprise +2 APT37 cabinet_extraction expand.exe windows endpoint
2r 2t
medium advisory

ESXi External Root Login Detection

This detection identifies instances where the ESXi UI is accessed using the root account instead of a delegated administrative user, which bypasses role-based access controls and may indicate risky behavior or unauthorized activity.

ESXi +3 vmware root_login privilege_escalation
2r 1t
medium advisory

Windows AD Object Owner Updated

This Splunk search detects when the owner of an Active Directory object is updated, potentially granting full control privileges and enabling object hiding, focusing on Windows Event Log ID 5136, and includes lookups for SID resolution.

Splunk Enterprise +3 active-directory privilege-escalation persistence
2r 2t
medium advisory

Tanium Connect Multiple Vulnerabilities

Tanium released security advisories addressing vulnerabilities in Connect versions prior to Update 25 (v5.26.191), Update 19 (v5.29.237), and Update 9 (v5.37.140), potentially leading to unauthorized access and data compromise.

Connect +2 vulnerability tanium security advisory
3r
medium advisory

Unauthorized Asset Detection via DHCP Request Analysis

This analytic identifies potentially unauthorized devices attempting to connect to an organization's network by inspecting DHCP request packets and comparing MAC addresses against a list of known authorized devices.

Splunk Enterprise +2 asset-tracking unauthorized-access network
2r 1t
medium advisory

Monitor Email for Brand Abuse via Domain Permutations

This analytic identifies emails claiming to originate from domains similar to those being monitored for abuse by cross-referencing sender addresses with a lookup table of domain permutations, indicating potential phishing or brand impersonation.

Splunk Enterprise +2 brand-abuse email phishing impersonation
2r 1t
medium advisory

Windows Registry Modification Risk Behavior Detection

This analytic identifies instances where three or more distinct registry modification events associated with MITRE ATT&CK Technique T1112 are detected, leveraging Splunk's Risk data model to detect persistence, hiding malicious configurations, or erasing forensic evidence.

Splunk Enterprise +2 registry persistence defense-evasion windows
2r 2t
medium advisory

Living Off The Land Activity Detection

This correlation search identifies multiple risk events associated with 'Living Off The Land' activity, leveraging the Risk data model to aggregate events, focusing on systems with a high count of distinct sources, potentially enabling attackers to execute code, escalate privileges, or persist within the environment using trusted system utilities.

Splunk Enterprise +2 living-off-the-land persistence privilege-escalation execution
2r 5t
medium advisory

Monitor Web Traffic For Brand Abuse

This analytic identifies web requests to domains that closely resemble a monitored brand's domain, indicating potential brand abuse indicative of phishing or malware distribution attempts.

Splunk Enterprise +2 brand-abuse phishing network
2r 1t
medium threat

Cisco Secure Firewall - High Volume of Intrusion Events Per Host

This analytic detects internal systems generating an unusually high volume of intrusion detections within a 30-minute window using Cisco Secure Firewall Threat Defense logs, identifying hosts triggering more than 15 Snort-based signatures, which may indicate suspicious activity like malware execution, command-and-control communication, vulnerability scanning, or lateral movement.

exploited Secure Firewall Threat Defense +3 network intrusion_detection anomaly_detection
2r 3t
medium advisory

phpMyFAQ Unauthenticated Password Reset Vulnerability (CVE-2026-35676)

phpMyFAQ before 4.1.3 is vulnerable to an unauthenticated password reset, allowing attackers to change account passwords without token validation by sending crafted PUT requests to the /api/index.php/user/password/update endpoint.

phpMyFAQ cve vulnerability password reset unauthenticated
2r 1t 1c
medium advisory

Google Workspace Drive Data Transfer or Takeout Export Initiated

This rule detects when Google Workspace administrators initiate bulk movement or export of user Drive data, including admin data transfer requests and Customer Takeout export jobs which can be abused by adversaries with administrative access to stage or exfiltrate sensitive files.

Google Workspace +1 google_workspace data_exfiltration cloud
2r 2t
medium advisory

Zimbra Security Advisory Addresses Vulnerabilities in Zimbra Daffodil

Zimbra released a security advisory on May 28, 2026, addressing unspecified vulnerabilities in Zimbra Daffodil versions prior to v10.1.17, urging users to apply necessary updates.

Zimbra Daffodil < v10.1.17 zimbra vulnerability patch
2r
medium advisory

Google Workspace Device Registration Burst for Single User

Detects bursts of Google Workspace device registration events for a single user exceeding three distinct device registrations within one minute, indicative of AiTM phishing or stolen OAuth token replay attacks.

Google Workspace google_workspace device_registration persistence initial_access credential_access
1r 3t
medium advisory

Google Workspace User Sign-in from Atypical Device Type

This rule detects when a Google Workspace user authenticates from a device type that hasn't been observed for that user in the past 14 days, potentially indicating account compromise via AiTM kits or stolen OAuth refresh tokens.

Google Workspace google_workspace persistence account_compromise device_registration
2r 2t
medium advisory

Multiple Vulnerabilities in GitLab Lead to DoS and Security Policy Bypass

Multiple vulnerabilities in GitLab CE/EE allow attackers to cause remote denial of service and bypass security policies in versions 18.11.x before 18.11.4, 19.x before 19.0.1, and before 18.10.7; these vulnerabilities are tracked as CVE-2026-1402, CVE-2026-2601, CVE-2026-2710, CVE-2026-4868, CVE-2026-5296, CVE-2026-6713, and CVE-2026-8716.

GitLab Community Edition +1 gitlab vulnerability denial-of-service security-bypass CVE-2026-1402 CVE-2026-2601 CVE-2026-2710 CVE-2026-4868 +3
2r 2t 5c
medium advisory

Gitea Unauthenticated Container Registry Access (CVE-2026-27771)

A vulnerability in Gitea's built-in container registry (CVE-2026-27771) allows unauthenticated attackers to pull private container images, potentially exposing source code, secrets, and production infrastructure details, affecting over 30,000 deployments.

Gitea +2 vulnerability container registry access control cloud git
2r 1t 1c 2i updated
medium advisory

AWS S3 Credential File Retrieved from Bucket

This rule detects successful S3 GetObject calls targeting high-value credential and secret files commonly stored in S3 buckets, indicating potential credential access.

Amazon S3 credential-access cloud aws
2r 2t
medium advisory

WordPress SlimStat Analytics Plugin Stored XSS Vulnerability (CVE-2026-7634)

The SlimStat Analytics plugin for WordPress is vulnerable to stored cross-site scripting (XSS) via the User-Agent header, allowing unauthenticated attackers to inject arbitrary web scripts if the 'show_complete_user_agent_tooltip' setting is enabled.

SlimStat Analytics plugin <= 5.4.11 cve xss wordpress
2r 1t 1c
medium advisory

HT Contact Form WordPress Plugin Vulnerable to Stored XSS (CVE-2026-7052)

The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting (CVE-2026-7052) via the 'file_upload' parameter in versions up to 2.8.2, allowing unauthenticated attackers to inject arbitrary web scripts.

HT Contact Form – Drag & Drop Form Builder for WordPress plugin <= 2.8.2 stored-xss wordpress plugin CVE-2026-7052
2r 1t 1c
medium threat

Apache Tika Vulnerability Allows Information Disclosure or Manipulation

A remote, anonymous attacker can exploit a vulnerability in Apache Tika to read sensitive data or trigger malicious requests to internal resources or third-party servers.

Tika apache-tika vulnerability infoleak
2r 1t
medium threat

VMware Tanzu Spring Framework Denial of Service Vulnerability

A remote, anonymous attacker can exploit a vulnerability in VMware Tanzu Spring Framework to perform a denial of service attack.

Tanzu Spring Framework denial-of-service vmware tanzu
1r 1t
medium advisory

VMware Tanzu Spring Security Vulnerability Allows File Manipulation

A local attacker can exploit a vulnerability in VMware Tanzu Spring Security to manipulate files, potentially leading to privilege escalation.

Tanzu Spring Security vulnerability file-manipulation privilege-escalation
2r 1t
medium advisory

Multiple Vulnerabilities in Vim Could Lead to Arbitrary Code Execution or Denial of Service

Multiple vulnerabilities in Vim could allow an attacker to execute arbitrary code or cause a denial of service condition.

vim vulnerability code-execution denial-of-service
2r 3t
medium advisory

IBM DB2 Multiple Vulnerabilities Leading to Denial of Service

A remote, authenticated attacker can exploit multiple vulnerabilities in IBM DB2 to perform a denial of service attack, potentially disrupting database services.

DB2 denial-of-service
2r 1t
medium advisory

CVE-2026-46099: IPv6 NOREF DST Use Vulnerability in seg6 and rpl lwtunnels

CVE-2026-46099 describes a vulnerability in the IPv6 network stack related to NOREF dst use in seg6 and rpl lwtunnels, requiring a security update to address potential exploitation.

ipv6 network denial-of-service information-disclosure
2r 1c
medium advisory

CVE-2026-46072 ntfs3 Buffer Boundary Check Vulnerability

CVE-2026-46072 is a buffer boundary check vulnerability in ntfs3 affecting an unspecified Microsoft product, requiring further investigation upon patch application to understand exploitation vectors and develop detections.

vulnerability ntfs3 buffer-overflow
2r 1c
medium threat

CVE-2026-45842: Unspecified Vulnerability in Microsoft Products

CVE-2026-45842 is an unspecified vulnerability affecting Microsoft products, requiring further investigation to determine the specific attack vector, impact, and affected systems.

Unspecified Microsoft Product vulnerability microsoft
2r 1t 1c
medium threat

CVE-2026-44899 Mistune Image Directive CSS Injection Vulnerability

CVE-2026-44899 is a CSS Injection vulnerability in the Mistune Image Directive, potentially allowing for malicious CSS injection if user-supplied content is not properly sanitized.

Mistune Image Directive css-injection vulnerability mistune
2r 1c
medium threat

CVE-2025-71305 Published - Insufficient DP MST VCPI Protection

Microsoft published CVE-2025-71305, addressing a vulnerability related to insufficient protection against zero VCPI values in DisplayPort Multi-Stream Transport (MST), although specifics on exploitation and impact are not detailed in the provided source.

cve vulnerability displayport
2r 1c
medium threat

CVE-2026-45843 slip: bound decode() vulnerability

CVE-2026-45843 is a Microsoft vulnerability with unspecified details at the time of this brief.

cve vulnerability microsoft
1r 1c
medium advisory

CVE-2026-44844 eml_parser Recursion Denial-of-Service

CVE-2026-44844 is a denial-of-service vulnerability in Microsoft's eml_parser due to recursion in nested message/rfc822 attachments, potentially causing a service outage.

eml_parser dos vulnerability
2r 1t 1c
medium advisory

CVE-2026-45932 bpf: Fix tcx/netkit Detach Permissions

CVE-2026-45932 is a vulnerability affecting the bpf component, related to tcx/netkit detach permissions when the prog fd isn't given, requiring a security update from Microsoft.

cve bpf permissions microsoft
2r 1c
medium advisory

CVE-2026-45991 UDF Partition Descriptor Append Bookkeeping Vulnerability

CVE-2026-45991 is a security vulnerability affecting a Microsoft product, related to UDF partition descriptor append bookkeeping.

udf vulnerability msft
2r 1c
medium advisory

CVE-2026-46084 RDMA/mana_ib: Disable RX steering on RSS QP destroy

CVE-2026-46084 is a vulnerability related to RDMA/mana_ib that requires disabling RX steering on RSS QP destroy, potentially leading to denial of service or privilege escalation.

rdma mana_ib rss_qp rx_steering cve-2026-46084
2r 1c
medium advisory

Pimcore CustomReports Share Bypass Vulnerability

Pimcore's CustomReports feature has a share bypass vulnerability due to inconsistent authorization checks between the report listing endpoint and the report detail endpoint, allowing low-privileged users to access report configurations without explicit sharing permissions.

Pimcore CustomReports privilege-escalation defense-evasion web-application
1r 2t
medium advisory

Google Chrome Security Update Released

Google released a security update on May 27, 2026, to address vulnerabilities in Chrome for Desktop versions prior to 0.7778.216/217 for Windows, 148.0.7778.215/216 for Mac, and 148.0.7778.215 for Linux, requiring users to apply the necessary updates to mitigate potential exploitation.

Chrome for Desktop browser vulnerability chrome patch
2r
medium advisory

Threat Actors Spoofing FIFA Websites in Advance of the 2026 World Cup

Cyber threat actors are conducting spoofing attacks against FIFA websites in advance of the 2026 FIFA World Cup to steal personal information and facilitate monetary scams.

fifa.com fifa spoofing phishing typo-squatting
2r 1t 36i
medium advisory

Kaspersky Anti Targeted Attack Platform Multiple XSS Vulnerabilities

Multiple vulnerabilities have been discovered in Kaspersky Anti Targeted Attack Platform versions prior to 7.1.7, allowing an attacker to cause a remote cross-site scripting (XSS) vulnerability, tracked as CVE-2026-28348 and CVE-2026-28350.

Anti Targeted Attack Platform xss vulnerability web-application
2r 2t 2c
medium advisory

CVE-2026-8180: IBM Aspera High-Speed Transfer Denial of Service

IBM Aspera High-Speed Transfer Endpoint and Server versions 3.7.4 through 4.4.7 Fix Pack 1 are vulnerable to a denial-of-service (DoS) attack where an unauthenticated user can crash the asperahttpd service.

Aspera High-Speed Transfer Endpoint +18 denial-of-service cve
2r 1t 1c
medium advisory

IBM Langflow OSS Uncontrolled Resource Consumption Denial-of-Service (CVE-2026-7528)

IBM Langflow OSS versions 1.0.0 through 1.9.0 are vulnerable to a denial-of-service (DoS) attack due to uncontrolled resource consumption as tracked by CVE-2026-7528.

Langflow OSS dos cve-2026-7528 ibm
2r 1t 1c
medium advisory

Samba NTFS Reparse Point Vulnerability (CVE-2026-1933)

CVE-2026-1933 describes a vulnerability in Samba's handling of NTFS-style reparse points on read-only shares, allowing authenticated users with filesystem write permissions to modify reparse point metadata and potentially alter SMB-visible file behavior.

Samba cve cve-2026-1933 reparse point privilege escalation smb
2r 1t 1c
medium advisory

IBM Db2 Vulnerable to Denial-of-Service via Crafted Query (CVE-2026-1718)

IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 are vulnerable to a denial-of-service (DoS) attack via a specially crafted query when autonomous transactions are enabled, potentially leading to service disruption.

Db2 +1 dos cve-2026-1718 denial of service
2r 1t 1c
medium threat

Suspicious Instance Metadata Service (IMDS) API Request

This rule detects suspicious network activity from tools or scripts attempting to access the cloud service provider's Instance Metadata Service (IMDS) API endpoint, potentially retrieving sensitive instance-specific information and credentials.

exploited credential-access discovery cloud imds
3r 4t 1i
medium threat

Suspicious Instance Metadata Service (IMDS) API Command Line Execution

The rule identifies command-line executions that attempt to access cloud service provider's Instance Metadata Service (IMDS) API endpoints, potentially retrieving sensitive instance information and temporary security credentials, ultimately leading to credential access and privilege escalation within the cloud environment.

exploited Microsoft Defender XDR +4 credential-access cloud imds
2r 4t
medium advisory

OpenVPN Connect MacOS Local Privilege Escalation Vulnerability

A local attacker can exploit a vulnerability in OpenVPN Connect on MacOS to escalate their privileges.

OpenVPN Connect privilege-escalation macos
2r 1t
medium advisory

HBook WordPress Plugin Stored XSS Vulnerability (CVE-2026-8143)

The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'hb_country_iso', 'hb_usa_state_iso', and 'hb_canada_province_iso' parameters (CVE-2026-8143) in versions up to 2.1.6, potentially leading to arbitrary script execution in the administrator's browser.

HBook plugin wordpress xss plugin
2r 1t 1c
medium advisory

LiteSpeed Cache Plugin Stored XSS Vulnerability (CVE-2026-3375)

The LiteSpeed Cache plugin for WordPress is vulnerable to stored Cross-Site Scripting (XSS) via the /wp-json/litespeed/v1/notify_ccss and /wp-json/litespeed/v1/notify_ucss REST API endpoints, affecting versions up to 7.7, allowing unauthenticated attackers to inject arbitrary JavaScript into CCSS/UCSS content by bypassing IP-based access controls.

LiteSpeed Cache plugin for WordPress cve xss wordpress litespeed plugin
1r 1t 1c
medium advisory

Multiple Vulnerabilities in IBM DB2

Multiple vulnerabilities in IBM DB2 allow a remote, authenticated, or local attacker to disclose information, bypass security measures, or cause a denial of service.

DB2 vulnerability denial-of-service information-disclosure
2r 3t
medium advisory

Fedify LD-Signature Bypass via JSON-LD Named-Graph Restructuring

Fedify is vulnerable to CVE-2026-42462, a Linked Data Signature bypass via JSON-LD Named-Graph Restructuring, allowing attackers to alter third-party signed activities by manipulating the document structure without invalidating the signature, potentially leading to integrity, availability, and confidentiality issues.

@fedify/fedify fedify ld-signature-bypass json-ld cve-2026-42462
2r
medium threat

GnuTLS Certificate Spoofing Vulnerability (CVE-2026-42012)

CVE-2026-42012 describes a vulnerability in GnuTLS where a remote attacker can spoof legitimate services or intercept sensitive information by presenting a specially crafted certificate with URI or SRV SANs, causing the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN).

GnuTLS vulnerability certificate spoofing tls
2r 1t 1c
medium advisory

JeecgBoot Improper Access Control Vulnerability (CVE-2026-9580)

JeecgBoot up to version 3.9.1 is vulnerable to improper access control in the LoginController.selectDepart function, allowing remote attackers to bypass intended restrictions.

JeecgBoot cve access control
1r 1t 1c
medium advisory

CVE-2026-3603: IBM Engineering Lifecycle Management XXE Vulnerability

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 are vulnerable to XML external entity injection (XXE), allowing an authenticated attacker to expose sensitive information or consume memory resources.

Engineering Lifecycle Management 7.0.3 +2 cve xxe injection
2r 1t 1c
medium threat

CVE-2026-8856 - IBM HTTP Server Denial of Service Vulnerability

IBM HTTP Server 8.5 and 9.0 is vulnerable to a denial of service (DoS) in configurations where an attacker possesses write access to server configuration files, as tracked by CVE-2026-8856.

HTTP Server 8.5 +1 cve-2026-8856 dos ibm
2r 1t 1c
medium advisory

CVE-2026-8854 - IBM HTTP Server mod_mem_cache Denial-of-Service

IBM HTTP Server 8.5 and 9.0 are vulnerable to a denial-of-service (DoS) attack due to a flaw in the optional `mod_mem_cache` module that can be triggered remotely.

HTTP Server 8.5 +1 cve dos denial-of-service
2r 1t 1c
medium advisory

CVE-2026-8835: IBM HTTP Server Invalid Pointer Dereference Vulnerability

IBM HTTP Server versions 8.5 and 9.0 are susceptible to an invalid pointer dereference, potentially allowing a privileged, authenticated user to expose sensitive information or cause a denial of service.

HTTP Server 8.5 +1 cve pointer dereference dos information disclosure
2r 1t 1c
medium threat

CVE-2026-8620: IBM WebSphere Application Server HTTP Request Smuggling Vulnerability

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5 and 9.0 are vulnerable to HTTP request smuggling due to inconsistent interpretation of HTTP requests, potentially leading to unauthorized access and data manipulation.

WebSphere Application Server +3 http-request-smuggling websphere cve-2026-8620
2r 1t 1c
medium advisory

D-Link DSL2600U 'rom-0' Admin Password Disclosure Vulnerability

A hardware exploit has been published on Exploit-DB for D-Link DSL2600U, detailing a 'rom-0' Admin Password Disclosure vulnerability that allows unauthorized access to the device's administration interface.

DSL2600U hardware password-disclosure d-link
2r
medium advisory

ABB PPT30 Operating System Vulnerability (CVE-2025-11482)

A vulnerability, CVE-2025-11482, exists in ABB's PPT30 Operating System related to handling concurrent connections in the PPT30 OPC-UA Server, affecting versions prior to 1.8.0.

PPT30 Operating System industrial control system denial of service vulnerability
1r 1t 1c
medium advisory

KLiK SocialMediaWebsite Unrestricted File Upload Vulnerability (CVE-2026-9421)

CVE-2026-9421 is an unrestricted file upload vulnerability in the File Handler component of KLiK SocialMediaWebsite 1.0 that can be exploited remotely.

SocialMediaWebsite 1.0 unrestricted file upload CVE-2026-9421 web application
2r 1t 1c
medium advisory

NordVPN Denial-of-Service Vulnerability (CVE-2018-25368)

NordVPN version 6.14.31 is vulnerable to a denial-of-service attack (CVE-2018-25368) where an unauthenticated attacker can crash the application by submitting an excessively long string in the password field.

Nord VPN 6.14.31 dos denial-of-service cve-2018-25368
2r 1t 1c
medium advisory

userSpice Username Enumeration Vulnerability (CVE-2018-25350)

userSpice 4.3.24 contains a username enumeration vulnerability, allowing unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint and analyzing the response for the 'taken' string.

userSpice username-enumeration cve-2018-25350 web-application
2r 1t 1c
medium advisory

ItzCrazyKns Vane SSRF Vulnerability (CVE-2026-9372)

A server-side request forgery (SSRF) vulnerability, identified as CVE-2026-9372, exists in ItzCrazyKns Vane up to version 1.12.1, allowing a remote attacker to manipulate the baseURL argument in the Model Provider API component and potentially conduct internal reconnaissance or access sensitive data.

Vane <= 1.12.1 ssrf cve-2026-9372 web application
2r 3t 1c
medium advisory

CVE-2026-26147: Azure Compute Gallery Information Disclosure via Improper Input Validation

CVE-2026-26147 is an improper input validation vulnerability in Azure Compute Gallery that allows an authorized attacker to disclose information over a network.

Azure Compute Gallery cve-2026-26147 information-disclosure cloud
2r 1t 1c
medium threat

CVE-2022-31231 - Dell ECS Improper Access Control in IAM Module

Dell ECS versions 3.5 and 3.6 contain an improper access control vulnerability (CVE-2022-31231) in the Identity and Access Management (IAM) module, potentially allowing a remote unauthenticated attacker to gain unauthorized read access to data.

Elastic Cloud Storage cve-2022-31231 access-control dell-ecs iam
2r 1t
medium advisory

Dell PowerFlex Manager Directory Listing Vulnerability (CVE-2025-32749)

Dell PowerFlex Manager versions 4.6.2 and earlier contain a directory listing vulnerability (CVE-2025-32749) that allows an unauthenticated remote attacker to expose sensitive information.

PowerFlex Appliance Intelligent Catalog +2 cve-2025-32749 information-disclosure directory-listing
2r 1t 1c
medium advisory

CVE-2025-32747: Dell PowerFlex Manager Incorrect Privilege Assignment Vulnerability

Dell PowerFlex Manager versions 4.6.2 and earlier contain an Incorrect Privilege Assignment vulnerability (CVE-2025-32747) that allows a low-privileged attacker with local access to elevate privileges.

PowerFlex Appliance Intelligent Catalog +2 privilege-escalation cve-2025-32747 dell
1r 1t
medium threat

CVE-2025-26483: Dell PowerFlex Manager Open Redirect Vulnerability

Dell PowerFlex Manager versions 4.6.2 and prior contains an open redirect vulnerability (CVE-2025-26483) that allows an unauthenticated attacker to redirect a targeted user to an arbitrary web URL, potentially enabling phishing attacks.

PowerFlex Manager +2 open-redirect cve-2025-26483 phishing dell
2r 1t
medium advisory

Mattermost Uncontrolled Resource Consumption Vulnerability (CVE-2026-5308)

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request body size limits on plugin HTTP endpoints, allowing an attacker to cause a denial of service via crafted oversized HTTP requests.

Mattermost Server dos cve webserver
2r 1t
medium threat

Mattermost File Access Vulnerability (CVE-2026-3473)

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, allowing an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests using valid file IDs.

Mattermost Server cve vulnerability mattermost authorization bypass
1r 1t 1c
medium advisory

Firefox for iOS Security Policy Bypass Vulnerability

A vulnerability in Firefox for iOS versions prior to 151.1 allows an attacker to bypass the security policy (CVE-2026-9078).

Firefox for iOS security-bypass firefox ios
2r 1t
medium advisory

Spring AI Data Integrity Vulnerability (CVE-2026-41863)

A data integrity vulnerability exists in Spring AI versions 1.1.x before 1.1.7, potentially allowing an attacker to compromise data integrity, as identified by CVE-2026-41863.

Spring AI vulnerability data-integrity spring-ai
2r
medium advisory

CPython Unspecified Vulnerability (CVE-2026-8328)

An unspecified vulnerability in CPython, tracked as CVE-2026-8328, allows an attacker to cause an unspecified security issue.

CPython vulnerability CVE-2026-8328
2r 1c
medium advisory

Ivanti Secure Access Client: Local Privilege Escalation Vulnerabilities

A local attacker can exploit vulnerabilities in Ivanti Secure Access Client to manipulate files or escalate privileges, potentially gaining elevated access to the system.

Secure Access Client privilege-escalation ivanti windows linux macos
2r 1t
medium advisory

Multiple Vulnerabilities in Devolutions Server

Multiple vulnerabilities in Devolutions Server could allow an attacker to bypass security measures, disclose information, and manipulate files.

Devolutions Server vulnerability data-breach file-manipulation
2r
medium advisory

Multiple Vulnerabilities in PuTTY Allow for DoS, Data Manipulation, and Spoofing

A remote, anonymous attacker can exploit multiple vulnerabilities in PuTTY to perform a denial of service attack, manipulate data, and possibly carry out spoofing attacks.

PuTTY vulnerability denial-of-service spoofing
2r 2t
medium advisory

Intel NPU Driver Vulnerabilities Allow Privilege Escalation and DoS

Multiple vulnerabilities in the Intel NPU Driver allow a local attacker to escalate privileges and cause a denial of service.

NPU Driver privilege-escalation denial-of-service intel-npu-driver
2r 2t
medium advisory

macOS TCC Database Modification for Privacy Control Bypass

Adversaries may attempt to bypass macOS privacy controls by directly modifying the Transparency, Consent, and Control (TCC) SQLite database using sqlite3, potentially gaining unauthorized access to sensitive resources.

macOS privacy-bypass defense-evasion
2r 2t 1c
medium advisory

CISA ICS Security Advisories Address Vulnerabilities in Multiple Vendor Products

CISA published ICS advisories addressing vulnerabilities in products from ABB, Hitachi Energy, Kieback & Peter, ScadaBR, Siemens, and ZKTeco, recommending mitigations and updates.

B&R Automation Runtime +10 ics scada vulnerability
2r
medium advisory

Suspicious AWS S3 Connection via Script Interpreter

The rule detects script interpreters (osascript, Node.js, Python) making outbound connections to AWS S3 or CloudFront domains on macOS, which may indicate command and control or data exfiltration activity.

AWS S3 +1 command-and-control exfiltration macos
2r 5t
medium advisory

Parse Server Pre-authentication Denial of Service via Client Version Header

A denial-of-service vulnerability, CVE-2026-47138, exists in Parse Server due to inefficient regular expression handling of the client SDK version field in HTTP requests, allowing an unauthenticated attacker to exhaust server resources by sending a crafted request with a malicious `X-Parse-Client-Version` header or `_ClientVersion` body field.

parse-server denial-of-service regex-backtracking CVE-2026-47138
2r 1t
medium advisory

Nezha Monitoring RoleMember SSRF with Full Response Body Reflection

Nezha Monitoring is vulnerable to a server-side request forgery (SSRF) vulnerability, where a low-privilege RoleMember user can call notification routes and send HTTP requests to a user-controlled URL, with the entire response body reflected back to the caller, potentially exposing intranet resources and causing denial of service.

Nezha Monitoring ssrf nezha vulnerability
2r 3t
medium advisory

Rare Connection to WebDAV Target via Rundll32

This rule identifies rare connection attempts to a Web Distributed Authoring and Versioning (WebDAV) resource, where attackers may inject WebDAV paths in files or features opened by a victim user to leak their NTLM credentials via forced authentication using rundll32.exe.

Elastic Defend +1 credential-access defense-evasion windows
2r 2t
medium advisory

HPE Telco Universal SLA Management Multiple Vulnerabilities

HPE published a security advisory addressing multiple unspecified vulnerabilities in HPE Telco Universal SLA Management version 4.6 and prior, prompting users to apply necessary updates.

HPE Telco Universal SLA Management vulnerability hpe sla management
2r
medium advisory

Microsoft Releases Security Update for Edge Stable Channel

Microsoft released a security update on May 21, 2026, to address vulnerabilities in Microsoft Edge Stable Channel versions prior to 148.0.3967.83, urging users to apply the update.

Microsoft Edge Stable Channel browser update patch
2r
medium advisory

Stormshield Network Security (SNS) Remote Denial-of-Service Vulnerability

A remote denial-of-service vulnerability exists in Stormshield Network Security (SNS) versions 4.3.x before 4.3.43, 4.4.x to 4.8.x before 4.8.16, and 5.x before 5.0.6, allowing an attacker to disrupt service availability.

Network Security +3 denial-of-service network-security cve-2025-9086
2r 1t 1c
medium advisory

Multiple Vulnerabilities in Tenable Sensor Proxy

Multiple vulnerabilities in Tenable Sensor Proxy versions prior to 1.4.0 could allow a remote attacker to cause a denial of service, data confidentiality breaches, and other unspecified security impacts.

Sensor Proxy vulnerability dos dataleak
1r 1t 5c
medium advisory

SPIP Security Policy Bypass Vulnerability

A vulnerability in SPIP versions prior to 4.4.15 allows an attacker to bypass the security policy, potentially leading to unauthorized actions.

SPIP vulnerability security-bypass web-application
2r 1t
medium advisory

Sparx Systems Enterprise Architect Security Bypass Vulnerability

A remote, authenticated attacker can exploit a vulnerability in Sparx Systems Enterprise Architect to bypass security precautions.

Enterprise Architect defense-evasion security-bypass
2r 1t
medium advisory

TeamViewer Vulnerability Allows Privilege Escalation

A remote, authenticated attacker can exploit a vulnerability in TeamViewer to escalate privileges on a compromised system.

TeamViewer privilege-escalation platform
2r 1t
medium threat

Royal Elementor Addons Vulnerability Allows Cross-Site Scripting

A remote, unauthenticated attacker can exploit a cross-site scripting (XSS) vulnerability in the Royal Elementor Addons plugin for WordPress.

Royal Elementor Addons xss wordpress royal-elementor-addons
2r 1t
medium advisory

XWiki Multiple Vulnerabilities Allow File Manipulation and Information Disclosure

An authenticated remote attacker can exploit multiple vulnerabilities in XWiki to manipulate files and disclose information.

XWiki vulnerability file-manipulation information-disclosure
2r 2t
medium threat

CVE-2026-9011: Ditty WordPress Plugin Authorization Bypass Vulnerability

The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress versions up to 3.1.65 is vulnerable to an authorization bypass (CVE-2026-9011) that allows unauthenticated attackers to retrieve the full content of non-public Dittys by exploiting the ditty_init AJAX endpoint.

Ditty – Responsive News Tickers, Sliders, and Lists plugin <= 3.1.65 cve cve-2026-9011 wordpress authorization bypass plugin vulnerability cloud
2r 1t 1c
medium advisory

AudioIgniter WordPress Plugin Vulnerable to Insecure Direct Object Reference (CVE-2026-8679)

The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference (CVE-2026-8679) in versions up to 2.0.2, allowing unauthenticated attackers to view track metadata of any playlist, regardless of its status.

AudioIgniter plugin for WordPress <= 2.0.2 idor wordpress plugin cve-2026-8679 vulnerability
2r 1t
medium threat

cPanel cPanel/WHM Vulnerability Allows Header Manipulation

A remote, anonymous attacker can exploit a vulnerability in cPanel cPanel/WHM to perform an HTTP response header injection, enabling cross-site scripting (XSS), open redirect attacks, and cache or header manipulation.

cPanel/WHM cpanel header-injection xss open-redirect
2r 1t
medium threat

Multiple Vulnerabilities in PHP Allow for Information Disclosure, DoS, SSRF, and Unknown Impacts

A remote attacker can exploit multiple vulnerabilities in PHP to disclose information, cause a denial-of-service condition, perform a Server-Side Request Forgery (SSRF) attack, or achieve unknown impacts.

PHP vulnerability ssrf dos information-disclosure
2r 3t
medium advisory

PowerDNS Authoritative Server Multiple Vulnerabilities

Multiple vulnerabilities in PowerDNS Authoritative Server allow an attacker to disclose information, manipulate data, and cause a denial-of-service condition.

Authoritative Server vulnerability denial-of-service information-disclosure
2r 2t
medium threat

js-libp2p Gossipsub Memory Exhaustion via Subscription Flood

A memory exhaustion vulnerability exists in `@libp2p/gossipsub` due to unbounded subscription handling, allowing a single attacker to exhaust a Node.js heap by flooding unique topic subscriptions, leading to denial-of-service.

js-libp2p +1 dos memory-exhaustion libp2p
1r 2t
medium advisory

Hijacked npm Package Attempts to Deliver PolinRider-Linked RAT

Attackers are compromising npm packages to distribute a RAT linked to PolinRider, directly injecting malicious code into the software supply chain.

supply-chain npm rat polinrider
2r 1t
medium advisory

@hulumi/policies Evidence Bypass Vulnerability

@hulumi/policies versions before 1.3.2 allowed unrelated compliant-looking evidence to suppress violations for different zones, hostnames, origins, or repositories in the same stack, bypassing Cloudflare and deployment-governance guardrails.

@hulumi/policies dependency-confusion security-bypass cloud
2r
medium advisory

Entra ID OAuth User Impersonation to Microsoft Graph

This rule detects potential session hijacking or token replay in Microsoft Entra ID, identifying cases where a user signs in and subsequently accesses Microsoft Graph from a different IP address using the same session ID, which may indicate a successful OAuth phishing attack, session hijacking, or token replay attack.

Entra ID +1 cloud identity api azure oauth session hijacking
2r 2t
medium advisory

Nimiq Primitives Trie Chunk Processing Denial-of-Service (CVE-2026-46545)

A remote denial-of-service vulnerability (CVE-2026-46545) exists in Nimiq primitives where an unauthenticated peer can send a malicious chunk with an empty key, leading to a panic when `put_raw` attempts to store a value at the root node, causing the node process to abort.

nimiq-primitives denial-of-service rust
2r 1t
medium advisory

LMDeploy Hardcoded trust_remote_code Enables Remote Code Execution (CVE-2026-46517)

LMDeploy <= 0.12.3 is vulnerable to remote code execution (CVE-2026-46517) because it hardcodes `trust_remote_code=True` when calling `transformers.AutoConfig.from_pretrained()`, allowing a malicious Hugging Face repository to execute arbitrary Python code when loaded without user opt-out.

transformers +1 remote code execution supply chain lmdeploy
2r 2t 1i
medium advisory

Open ISES Tickets Hardcoded Database Credentials Vulnerability

Open ISES Tickets before version 3.44.2 contains hardcoded MySQL database connection credentials in import_mdb.php, allowing unauthorized database access.

Tickets +1 cve-2026-48242 hardcoded-credentials database-access
2r 1c
medium advisory

BadIIS Malware-as-a-Service Ecosystem Targeting IIS Servers

A commodity BadIIS malware variant is fueling a thriving malware-as-a-service (MaaS) ecosystem for Chinese-speaking cybercrime groups, allowing them to execute malicious SEO fraud, hijack server content, and redirect traffic to illicit sites.

Photoshop +3 iis malware maas seo fraud
2r 1t 6i
medium advisory

ConnectWise Automate Vulnerability Addressed in Security Update

ConnectWise released a security advisory addressing a vulnerability in ConnectWise Automate versions prior to 2026.5, prompting users to apply the necessary updates.

Automate vulnerability security-update connectwise
2r
medium advisory

Hitachi Energy GMS600 Vulnerable to Bleichenbacher Attack via CVE-2022-4304

Hitachi Energy GMS600 versions 1.3.0 and 1.3.1 are affected by CVE-2022-4304, a vulnerability in the OpenSSL RSA Decryption implementation; an attacker could exploit this timing-based side channel to recover plaintext across a network in a Bleichenbacher-style attack by sending trial messages to the server and recording processing times, eventually decrypting application data.

GMS600 versions 1.3.0 and 1.3.1 bleichenbacher timing attack openssl critical infrastructure
2r 1t 1c
medium advisory

ABB B&R Automation Runtime Multiple Vulnerabilities

ABB B&R Automation Runtime versions before 6.4 are vulnerable to predictable number generation (CVE-2025-3449), reflected XSS (CVE-2025-3448), and CSV injection (CVE-2025-11498), potentially allowing attackers to hijack sessions or execute arbitrary code in a user's browser context.

Automation Runtime ics xss session hijacking csv injection cve-2025-3449 cve-2025-3448 cve-2025-11498
2r 1t 3c
medium advisory

ABB Terra AC Wallbox Vulnerabilities Allow Remote Control and Firmware Alteration

Multiple buffer overflow vulnerabilities in ABB Terra AC Wallbox versions <=1.8.33, exploitable via Bluetooth hijacking, could allow an attacker to remotely control the device and alter its firmware.

Terra AC wallbox ics buffer overflow cve-2025-10504 cve-2025-12142 cve-2025-12143
2r 2t 3c
medium threat

Trend Micro Security Advisory Addressing Apex One and Vision One Vulnerabilities

Trend Micro released a security advisory addressing vulnerabilities in Apex One (on-premise), Apex One as a service, and Trend Vision One Endpoint, prompting users to apply necessary updates to mitigate potential risks.

exploited Apex One +2 vulnerability patch endpoint_security
2r
medium threat

SolarEdge CSRF and Out-of-Band Injection Vulnerability

A CSRF-OOB-Injection vulnerability exists in SolarEdge Monitoring Platform's `/solaredge-web/p/initClient` endpoint due to improper validation of session parameters, allowing attackers to manipulate headers to initiate requests to attacker-controlled domains, potentially leading to session compromise and unauthorized system control.

SolarEdge Monitoring Platform - Framework /solaredge-web/ solaredge csrf oob-injection webapps
2r 1t 1i
medium threat

Lenovo LegionSpace 1.7.11.2 Unquoted Service Path Vulnerability

A local exploit has been published for Lenovo LegionSpace 1.7.11.2, detailing an Unquoted Service Path vulnerability in the 'DAService', potentially leading to local privilege escalation.

LegionSpace unquoted-service-path privilege-escalation windows
2r 1t
medium advisory

BookStack 25.12.1 Denial-of-Service Vulnerability

A denial-of-service vulnerability exists in BookStack version 25.12.1, and a public exploit (EDB-52571) is available, increasing the risk to unpatched systems.

BookStack denial-of-service webapps exploit
2r 1t
medium advisory

Multiple Vulnerabilities in Apereo Java CAS Client

Multiple vulnerabilities have been discovered in Apereo Java CAS client versions prior to 4.1.1, potentially leading to data confidentiality breaches as detailed in the casc-jwt-vuln security bulletin.

Java CAS client credential-access java
2r 1t 1i
medium threat

Internet Systems Consortium BIND Multiple Vulnerabilities Lead to DoS

A remote, anonymous attacker can exploit multiple vulnerabilities in Internet Systems Consortium BIND to trigger memory corruption or cause a denial-of-service condition.

BIND dns denial-of-service
1r 1t
medium advisory

MongoDB Compass Vulnerability Allows File Manipulation and Potential Code Execution

An anonymous remote attacker can exploit a vulnerability in MongoDB Compass to manipulate files and potentially execute arbitrary code.

Compass vulnerability file-manipulation code-execution
2r 1t
medium advisory

ffmpeg Vulnerability Allows Code Execution and Potential Denial of Service

A vulnerability in ffmpeg allows an attacker to execute arbitrary program code and potentially conduct a denial of service attack.

ffmpeg code-execution denial-of-service
2r 1t
medium advisory

vllm Vulnerability Allows Information Disclosure and DoS

A remote, authenticated attacker can exploit a vulnerability in vllm to disclose information or cause a denial-of-service condition.

vllm vulnerability denial-of-service information-disclosure
2r 2t
medium advisory

CVE-2026-45736: Uninitialized Memory Disclosure Vulnerability in Microsoft Products

CVE-2026-45736 is an uninitialized memory disclosure vulnerability affecting Microsoft products, potentially allowing an attacker to read sensitive information from process memory.

memory-disclosure cve microsoft
2r 1c
medium advisory

CVE-2026-44390 Unbounded Name Compression Denial-of-Service Vulnerability

CVE-2026-44390 is a denial-of-service vulnerability in Microsoft products due to unbounded name compression.

dos cve denial-of-service
2r 1t 1c
medium threat

CVE-2026-47783: memcached Timing Side Channel Vulnerability in SASL Authentication

CVE-2026-47783 is a timing side channel vulnerability in memcached before 1.6.42, affecting SASL password database authentication due to premature loop exit upon finding a valid username, potentially leading to information disclosure.

timing side channel information disclosure memcached
2r 1t 1c
medium threat

TeamPCP Leaks Shai-Hulud Worm Source Code, European Governments Seek Secure Messaging Alternatives

The TeamPCP hacking group released the source code of the Shai-Hulud worm impacting npm and PyPI, prompting European governments to seek secure messaging alternatives due to phishing risks and data sovereignty concerns, while historical analysis reveals the Fast16 malware targeted Iran's nuclear program by tampering with simulation software.

Signal +3 TeamPCP open-source worm phishing secure messaging data sovereignty
2r 1t
medium threat

Maltrail IOCs for APT Kimsuky, Lummac2, MagentoCore, and FakeApp Campaigns

This brief summarizes indicators of compromise (IOCs) from a Maltrail feed update on 2026-05-20, detailing network activity associated with APT Kimsuky, Lummac2, MagentoCore, and FakeApp campaigns, providing actionable intelligence for detection and response.

APT Kimsuky ioc apt network_activity kimsuky lummac2 magentocore fakeapp
3r 1t 50i
medium advisory

Taiko AG1000-01A SMS Alert Gateway Stored XSS (CVE-2026-9144)

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 is vulnerable to stored cross-site scripting (CVE-2026-9144) in the web configuration interface, allowing authenticated attackers to execute persistent JavaScript by fragmenting malicious payloads across multiple administrative form fields for persistent code execution.

AG1000-01A SMS Alert Gateway xss stored_xss CVE-2026-9144 web_application
2r 1t 1c
medium advisory

Splunk Releases Security Advisory Addressing Multiple Products

Splunk released security advisories on May 20, 2026, addressing vulnerabilities in Splunk User Behavior Analytics, AppDynamics Agents, Universal Forwarder, Enterprise, Cloud Platform, and AI Toolkit, prompting users to apply necessary updates.

Splunk User Behavior Analytics +12 vulnerability splunk
2r
medium advisory

Splunk Enterprise and Cloud Platform Information Disclosure Vulnerability (CVE-2026-20239)

Splunk Enterprise and Cloud Platform versions prior to 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13 are vulnerable to information disclosure (CVE-2026-20239), allowing users with access to the `_internal` index to view sensitive data.

Splunk Enterprise +1 information-disclosure splunk cloud
2r 2t 1c
medium advisory

Microsoft Defender Denial of Service Vulnerability (CVE-2026-45498)

CVE-2026-45498 is a denial-of-service vulnerability in Microsoft Defender that could disrupt endpoint protection capabilities, requiring timely mitigation per vendor instructions.

Defender denial-of-service vulnerability microsoft-defender
2r 1t 1c
medium advisory

CVE-2026-7613: Cost of Goods by PixelYourSite WordPress Plugin Stored XSS

The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0][cost_of_goods_value]' parameter in versions up to, and including, 1.2.12 due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user accesses an injected page.

Cost of Goods by PixelYourSite plugin for WordPress xss wordpress CVE-2026-7613
2r 1c
medium advisory

CVE-2026-5783: CityPLus Reflected XSS Vulnerability

CVE-2026-5783 is a reflected cross-site scripting (XSS) vulnerability in Beyaz Computer Software Design Industry and Trade Ltd. Co. CityPLus before version V24.29750.1.0, allowing attackers to inject malicious scripts into web pages viewed by users.

CityPLus cve xss reflected-xss web-application
2r 1t 1c
medium advisory

Cisco ThousandEyes Enterprise Agent BrowserBot Command Injection Vulnerability

CVE-2026-20206 describes a command injection vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent where an authenticated remote attacker with transaction test management privileges could execute arbitrary commands within the BrowserBot container as the node user.

ThousandEyes Enterprise Agent +1 command-injection cve cisco
2r 1t
medium threat

Cisco ThousandEyes Virtual Appliance Authenticated Remote Code Execution Vulnerability

CVE-2026-20199 - A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user.

ThousandEyes Virtual Appliance cve-2026-20199 rce cisco thousandeyes ssl
2r 1t
medium advisory

Cisco Nexus 3000 and 9000 Series Switches BGP Denial of Service Vulnerability

CVE-2026-20171 describes a vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 and 9000 Series Switches that could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial-of-service (DoS) condition.

Nexus 3000 Series Switches +1 bgp dos cisco network
2r 1t
medium advisory

Plug Multipart Header Parsing Denial-of-Service Vulnerability (CVE-2026-8468)

Plug versions 1.4.0 to 1.19.1 are vulnerable to denial-of-service (CVE-2026-8468) due to unbounded buffer accumulation in multipart header parsing, allowing an unauthenticated attacker to exhaust server memory by sending a crafted multipart/form-data request.

plug denial-of-service multipart web-application
2r 1t 1c
medium threat

FreePBX Security Advisories for Security-Reporting Module Vulnerabilities

FreePBX released security advisories addressing authenticated SQL injection and local file inclusion vulnerabilities in the Security-Reporting cdr and dashboard modules for FreePBX 16 and 17.

Security-Reporting cdr +3 freepbx sql_injection lfi vulnerability
2r 1t
medium advisory

Multiple Vulnerabilities in Symfony Framework

Multiple vulnerabilities in Symfony, including CVE-2026-45070, CVE-2026-45077, CVE-2026-45304, CVE-2026-45305, CVE-2026-45753, CVE-2026-45754, CVE-2026-45755, CVE-2026-45756, CVE-2026-46626, and CVE-2026-47212, can lead to remote denial of service, cross-site scripting (XSS), and cross-site request forgery (CSRF) attacks.

symfony/html-sanitizer +10 symfony vulnerability dos xss csrf
3r 1t
medium advisory

Wireshark Remote Denial of Service Vulnerability

A vulnerability in Wireshark versions 4.4.x before 4.4.16 and 4.6.x before 4.6.6 allows a remote attacker to cause a denial of service.

Wireshark 4.4.x +1 denial-of-service wireshark
2r 1t
medium advisory

CVE-2026-3039: BIND TKEY Authentication Memory Consumption Vulnerability

BIND servers configured for TKEY-based authentication using GSS-API tokens are susceptible to excessive memory consumption upon receiving and processing crafted packets, impacting availability.

BIND 9 cve cve-2026-3039 bind9 denial-of-service memory-consumption
2r 1t 1c
medium advisory

CVE-2026-5946: BIND 9 `named` Assertion Failure Vulnerability

Multiple flaws in BIND 9's `named` component, specifically versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1, can be exploited by sending specially crafted DNS requests with non-`IN` CLASS or meta-classes, leading to assertion failures and potential denial-of-service.

BIND 9 denial-of-service dns bind9 CVE-2026-5946
2r 1c
medium advisory

Squid Vulnerability Allows Security Bypass and Information Disclosure

A remote, anonymous attacker can exploit a vulnerability in Squid to bypass security precautions and disclose information, potentially leading to unauthorized access or data leakage.

Squid defense-evasion discovery proxy
2r 2t
medium advisory

CVE-2026-9064: 389-ds-base Unauthenticated Remote Denial-of-Service

CVE-2026-9064 describes a denial-of-service vulnerability in 389-ds-base where an unauthenticated attacker can send a crafted LDAP request with excessive controls, causing excessive CPU consumption and heap allocation, leading to latency degradation, worker thread starvation, or out-of-memory termination.

389-ds-base denial-of-service ldap CVE-2026-9064
2r 1t 1c
medium advisory

CVE-2026-43492 Integer Underflow in mpi_read_raw_from_sgl()

CVE-2026-43492 is an integer underflow vulnerability in the mpi_read_raw_from_sgl function within the lib/crypto component that could lead to unexpected behavior or denial-of-service.

integer underflow denial of service cryptographic library CVE-2026-43492
1r 1c
medium advisory

CVE-2026-45585: Windows BitLocker Security Feature Bypass Vulnerability ('YellowKey')

CVE-2026-45585 is a security feature bypass vulnerability in Windows BitLocker, known as 'YellowKey', for which a public proof of concept exists, prompting Microsoft to release mitigation guidance prior to a security update.

BitLocker vulnerability security feature bypass
2r
medium advisory

SQLFluff Uncontrolled Resource Consumption Vulnerability (CVE-2026-46374)

SQLFluff versions prior to 4.2.0 are vulnerable to uncontrolled resource consumption (CVE-2026-46374), allowing an attacker to cause a denial of service by submitting a maliciously crafted, long SQL query.

sqlfluff denial-of-service resource-exhaustion
2r 1t
medium advisory

Dasel Selector Lexer Index-Out-of-Range Panic on Trailing Backslash (CVE-2026-46377)

The dasel selector lexer is vulnerable to an index-out-of-range panic when tokenizing a quoted string that ends with a trailing backslash (e.g., `"\` or `'\`), leading to a process crash if an attacker can control the selector string.

dasel dos panic go
2r
medium advisory

Dasel Denial-of-Service Vulnerability via Unterminated Regex

Dasel versions 3.0.0 to 3.3.1 are vulnerable to a denial-of-service attack (CVE-2026-46378) where the selector lexer enters a non-terminating loop when tokenizing an unterminated regex pattern, causing 100% CPU usage on one core, which can be triggered by an attacker-controlled selector/query string.

dasel denial-of-service CVE-2026-46378
2r 1t
medium threat

@libp2p/kad-dht Unvalidated PUT_VALUE Records Allow Unbounded Disk Exhaustion

An unauthenticated remote peer can exhaust the disk storage of any `@libp2p/kad-dht` node running in server mode by sending an unbounded stream of `PUT_VALUE` messages with crafted keys to bypass validation and cause disk exhaustion.

@libp2p/kad-dht libp2p kad-dht denial-of-service disk-exhaustion
2r 2t
medium advisory

Dell Security Advisory Addresses Vulnerabilities in Multiple Products

Dell published security advisories between May 11 and 17, 2026, addressing vulnerabilities in Dell Enterprise Sonic Distribution, Dell Live Optics Collector, Intel 800 Series Ethernet Adapters, Dell PowerEdge with AMD Graphics, and PowerScale InsightIQ, prompting users to apply necessary updates.

Dell Enterprise Sonic Distribution +4 vulnerability dell intel
2r
medium advisory

Wire Protobuf Negative Length Vulnerability (CVE-2026-45799)

A vulnerability in Wire's protobuf group-skipping logic allows a crafted payload with a negative length to cause a runtime exception and potentially crash services decoding untrusted protobuf, addressed in version 6.3.0.

wire-runtime +1 protobuf denial-of-service CVE-2026-45799 wire
2r 2t
medium advisory

Bandit HTTP/1 Chunked Request Trailer Denial of Service

Bandit versions 1.6.0 through 1.11.0 are vulnerable to an unauthenticated denial-of-service (CVE-2026-39806) via a chunked request with trailers, where sending a request with `Transfer-Encoding: chunked` and a trailer field causes the connection's worker process to spin forever in an infinite recursion, exhausting the listener pool and rendering the server unresponsive.

bandit denial-of-service chunked-transfer-encoding
2r 1t 1c
medium advisory

Bandit HTTP/1 Chunked Request DoS Vulnerability

Bandit's HTTP/1 chunked-body reader silently drops the request size cap, leading to excessive memory buffering. An unauthenticated attacker can crash Bandit-fronted Phoenix/Plug applications by sending a single 'Transfer-Encoding: chunked' request to any URL, causing BEAM memory exhaustion and a denial-of-service.

bandit dos vulnerability
1r 1t 1c
medium advisory

Mozilla Firefox Security Updates Released

Mozilla released security updates on May 19, 2026, addressing vulnerabilities in Firefox versions prior to 151, Firefox ESR versions prior to 115.36, and Firefox ESR versions prior to 140.11.

Firefox +2 vulnerability mozilla
1r
medium advisory

libcrux-chacha20poly1305: Potential Panic on Overlong Ciphertext Buffer

An application that passes an overlong ciphertext buffer to `libcrux_chacha20poly1305::encrypt` or `libcrux_chacha20poly1305::xchacha20_poly1305::encrypt` can experience a panic, leading to a crash if the buffer length is attacker-controlled, affecting libcrux-chacha20poly1305 versions prior to 0.0.8.

libcrux-chacha20poly1305 denial-of-service availability
1t
medium threat

GitHub Actions GITHUB_TOKEN Disclosure via Composer Validation Failure

Composer leaks GitHub OAuth tokens in GitHub Actions logs if they do not match the expected format due to a validation regex, leading to potential unauthorized access.

github.com github actions composer token-leak cve-2026-45793
2r 1t
medium advisory

Kieback & Peter DDC Building Controllers Cross-Site Scripting Vulnerability (CVE-2026-4293)

A cross-site scripting vulnerability, CVE-2026-4293, exists in multiple Kieback & Peter DDC Building Controllers that could allow an attacker to take control of the victim's browser.

DDC4002 +10 xss vulnerability building-automation
2r 1t
medium advisory

Mailpit Unauthenticated Remote Memory Exhaustion DoS Vulnerability

Mailpit is vulnerable to an unauthenticated remote memory-exhaustion denial-of-service attack due to missing size limits on incoming SMTP DATA and HTTP requests, leading to unbounded memory and disk growth, potentially crashing the application.

mailpit dos memory exhaustion cve-2026-45713
3r 1t
medium threat

Keycloak OIDC Implicit Flow Bypass Vulnerability (CVE-2026-7571)

CVE-2026-7571 describes a vulnerability in Keycloak where a low-privilege user can bypass security controls intended to disable the implicit flow in OpenID Connect (OIDC) clients by manipulating client data during session restart, potentially exposing access tokens.

Keycloak oidc implicit-flow cve-2026-7571 credential-access
2r 1t 1c
medium advisory

Apache Tomcat Security Bypass Vulnerability

A remote, anonymous attacker can exploit a vulnerability in Apache Tomcat to bypass security measures.

Tomcat apache security-bypass
2r 1t
medium advisory

Podman Vulnerability Allows File Manipulation

A remote, authenticated attacker can exploit a vulnerability in Podman to manipulate files on the host system.

Podman file-manipulation linux
1r 1t
medium threat

Unbound Cache Poisoning Vulnerability

A vulnerability in Unbound allows an attacker from an adjacent network to manipulate the cache, potentially leading to domain hijacking.

Unbound dns cache poisoning domain hijacking defense-evasion
1r
medium threat

Red Hat Enterprise Linux Valkey Vulnerabilities Lead to File Manipulation and Denial of Service

An authenticated or anonymous attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux regarding Valkey to manipulate files or cause a denial-of-service condition.

Red Hat Enterprise Linux valkey denial-of-service file-manipulation linux
2r 1t
medium advisory

Multiple Vulnerabilities in Mattermost Products

Multiple unspecified vulnerabilities in Mattermost Desktop App and Mattermost Server allow an attacker to cause an unspecified security issue.

Mattermost Desktop App +4 mattermost vulnerability unspecified
2r
medium threat

Multiple Vulnerabilities in Docker Allow Privilege Escalation and DoS

Multiple vulnerabilities in Docker allow a local attacker to execute arbitrary code with administrator privileges, cause a denial-of-service condition, or manipulate data.

Docker vulnerability privilege-escalation denial-of-service
2r 3t
medium advisory

Keycloak Security Bypass Vulnerability

An authenticated remote attacker can exploit a vulnerability in Keycloak to bypass security measures.

Keycloak security-bypass authentication
2r 1t
medium advisory

Multiple Vulnerabilities in Red Hat Build of Quarkus

An authenticated or unauthenticated remote attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux and Quarkus to perform a denial of service attack, disclose sensitive information, or manipulate data.

Quarkus +1 vulnerability redhat denial of service information disclosure data manipulation
2r 2t
medium threat

BigBlueButton Vulnerability Allows Cross-Site Scripting

An authenticated remote attacker can exploit a vulnerability in BigBlueButton to conduct a Cross-Site Scripting (XSS) attack.

BigBlueButton cross-site scripting web application
2r 1t
medium advisory

Multiple Vulnerabilities in Ruby Allow for DoS and Information Disclosure

A remote, anonymous attacker can exploit multiple vulnerabilities in Ruby to cause a denial-of-service condition and disclose confidential information.

ruby vulnerability denial-of-service information-disclosure
2r 3t
medium advisory

CVE-2026-7168 Cross-Proxy Digest Authentication State Leak

Microsoft published information regarding CVE-2026-7168, a cross-proxy Digest authentication state leak.

authentication state-leak proxy cve
2r 1c
medium advisory

CVE-2026-37459: FRRouting BGP UPDATE Message Integer Underflow DoS

An integer underflow vulnerability, CVE-2026-37459, in FRRouting (FRR) versions stable/10.0 to stable/10.6 allows a remote attacker to cause a Denial of Service (DoS) by sending a crafted BGP UPDATE message.

FRR bgp dos frrouting network
2r 1t 1c
medium advisory

CVE-2026-5773: SMB Connection Reuse Vulnerability

Microsoft published information about CVE-2026-5773, a vulnerability related to the incorrect reuse of SMB connections.

smb vulnerability cve-2026-5773
2r 1c
medium advisory

CVE-2026-6429 netrc Credential Leak Vulnerability

CVE-2026-6429 is a credential leak vulnerability affecting Microsoft products.

credential-leak microsoft
1r 1c
medium threat

FRRouting CVE-2026-37458 Denial of Service Vulnerability

A denial-of-service vulnerability, identified as CVE-2026-37458, exists in the MP_REACH_NLRI component of FRRouting versions stable/10.0 to stable/10.6, where authenticated attackers can trigger a DoS by sending a crafted UPDATE message due to missing input validation.

FRR stable/10.0 +6 denial-of-service network frrouting cve-2026-37458
1r 1t 1c
medium threat

CVE-2026-31704 ksmbd u16 DACL Size Overflow Vulnerability

CVE-2026-31704 is a vulnerability in ksmbd related to the use of check_add_overflow() to prevent a u16 DACL size overflow, potentially leading to denial of service or privilege escalation.

ksmbd dacl overflow denial of service privilege escalation
2r 2t 1c
medium advisory

LiteLLM SQL Injection Vulnerability (CVE-2025-45809)

A SQL Injection vulnerability (CVE-2025-45809) in LiteLLM versions prior to 1.81.0 allows unauthenticated attackers to potentially steal database contents and read server files via time-based blind SQL injection in the `/key/block` and `/key/unblock` endpoints.

LiteLLM sqli sql-injection CVE-2025-45809
2r 1t 1i
medium advisory

OpenTelemetry eBPF Instrumentation (OBI) Memcached Integer Overflow DoS

A remotely reachable integer overflow in OpenTelemetry eBPF Instrumentation's (OBI) memcached text protocol parser can crash the OBI process, causing a denial of service due to unchecked arithmetic when handling large payload sizes in memcached storage commands.

go.opentelemetry.io/obi denial-of-service integer-overflow memcached opentelemetry
1r 2t
medium threat

OpenTelemetry eBPF Instrumentation MongoDB Parser Denial-of-Service

Malformed MongoDB wire messages can trigger uncaught panics in the OpenTelemetry eBPF Instrumentation agent's MongoDB TCP parser, allowing a remote unauthenticated attacker to crash the telemetry agent and cause a denial of service.

go.opentelemetry.io/obi opentelemetry mongodb denial-of-service CVE-2026-45685
2r 1t
medium advisory

OpenTelemetry eBPF Instrumentation Postgres Parser Vulnerable to Panic via Malformed BIND Payloads (CVE-2026-45678)

The OpenTelemetry eBPF Instrumentation (OBI) Postgres protocol parser is vulnerable to a remote availability issue - when processing BIND messages, the parser assumes payloads contain a valid NUL-terminated portal name; a crafted empty or unterminated payload can cause OBI to slice beyond the end of the captured buffer, triggering a runtime panic and crashing the agent.

go/go.opentelemetry.io/obi denial-of-service postgres ebpf CVE-2026-45678
2r 1t
medium advisory

Multiparty Denial of Service via Prototype Pollution (CVE-2026-8161)

Multiparty versions 4.2.3 and lower are vulnerable to denial of service via prototype pollution, where a crafted multipart/form-data request with a field name colliding with an Object.prototype property triggers a TypeError, leading to an uncaught exception and process crash.

multiparty prototype-pollution denial-of-service nodejs
2r 1t 1c
medium advisory

parse-nested-form-data Prototype Pollution Vulnerability (CVE-2026-45302)

parse-nested-form-data versions 1.0.0 and earlier are vulnerable to prototype pollution via crafted FormData field names, allowing an unauthenticated remote client to mutate `Object.prototype` and potentially corrupt application state, alter control flow, or cause denial of service.

parse-nested-form-data prototype-pollution javascript web-application
1r 1t
medium advisory

form-data-objectizer Prototype Pollution Vulnerability (CVE-2026-46510)

The form-data-objectizer npm package version 1.0.0 is vulnerable to prototype pollution (CVE-2026-46510) via crafted form keys, allowing an attacker to modify Object.prototype and potentially cause denial-of-service, bypass security checks, or inject unintended values.

form-data-objectizer prototype-pollution javascript node.js
2r 1t
medium advisory

GnuTLS DTLS Packet Reordering Vulnerability (CVE-2026-42009)

A remote attacker could exploit a flaw in GnuTLS's DTLS packet reordering logic (CVE-2026-42009) to cause unstable packet ordering or undefined behavior, resulting in a denial of service.

GnuTLS dtls dos cve-2026-42009
2r 1t 1c
medium advisory

AWS EKS Control Plane Logging Disabled

This rule detects successful Amazon EKS UpdateClusterConfig requests that disable control plane logging, potentially indicating defense evasion via compromised AWS credentials or unauthorized administrative access that reduces visibility into cluster activity.

EKS cloud kubernetes aws defense_evasion
2r 1t
medium advisory

Avro Map Decoder Vulnerable to Denial-of-Service via Unbounded Memory Allocation

The Avro map decoder accepted attacker-controlled block-element counts, leading to unbounded map growth and potential denial-of-service via memory exhaustion; upgrading to v2.33.0 requires explicit configuration of MaxMapAllocSize to mitigate the vulnerability.

avro +1 denial-of-service memory-exhaustion data-serialization
2r 1t
medium advisory

macOS Finder Sync Plugin Persistence via Pluginkit

This rule detects suspicious Finder Sync plugin registrations on macOS, where adversaries abuse the pluginkit process to establish persistence by repeatedly executing malicious payloads.

OneDrive +5 persistence macos pluginkit finder sync plugin
2r 1t
medium advisory

Q1 2026 Mobile Threat Landscape: SparkCat and Triada Updates

The Q1 2026 mobile threat landscape saw a decrease in overall attack volume driven by reduced adware and RiskTool detections, while the number of unique users targeted remained stable, with new SparkCat variants on app stores and increased banking Trojan and Triada backdoor activity.

Google Play +2 mobile malware trojan cryptostealer sparkcat triada android ios
2r 1t
medium advisory

Kubernetes Static Pod Manifest File Access

This rule detects Linux process executions that access Kubernetes static pod manifest files, potentially indicating malicious tampering for persistence or privilege escalation.

kubernetes persistence privilege_escalation linux
2r 2t
medium advisory

Entra ID Register Device with Unusual User Agent (Azure AD Join)

Detects suspicious Microsoft Entra ID audit events for device registration where details indicate an Azure AD join and the user agent is not a standard registration client, potentially indicating scripted registration, third-party tooling, or malicious device registration for persistence or token abuse.

Entra ID azure entra_id persistence
2r 1t
medium advisory

Entra ID Microsoft Authentication Broker Sign-In to Unusual Resource

Detects successful Microsoft Entra ID sign-ins where the client application is the Microsoft Authentication Broker (MAB) and the requested resource identifier is outside a short list of commonly observed first-party targets, potentially indicating abuse to obtain tokens for unexpected APIs or enterprise applications.

Entra ID cloud identity azure entra_id microsoft_entra_id sign_in_logs threat_detection initial_access
2r 2t
medium advisory

Curl or Wget Execution from Container Context

Detects execution of curl or wget from processes running inside OCI/runc-backed containers, potentially indicating ingress tool transfer or data exfiltration after a container breakout.

command-and-control execution container linux
2r 1t
medium advisory

Kubernetes Multi-Resource Discovery

Detects potential reconnaissance activity in Kubernetes environments where adversaries or automated scripts attempt to map the environment by rapidly querying multiple API resource kinds, indicative of initial setup before actions like privilege escalation or data exfiltration.

kubernetes discovery
2r 1t
medium advisory

Kubernetes Secret Access by Node or Pod Service Account

This rule detects Kubernetes audit events where node or pod service accounts are accessing secrets via `get` or `list` operations, which may indicate credential access attempts by attackers sweeping Secret objects for sensitive information.

kubernetes credential-access cloud
2r 1t
medium advisory

AWS SSM Session Manager Child Process Execution

This rule identifies process start events where the parent process is the AWS Systems Manager (SSM) Session Manager worker, which adversaries may abuse for remote execution and lateral movement using legitimate AWS credentials and IAM permissions.

AWS Systems Manager cloud aws execution lateral-movement
3r 3t
medium advisory

Tycoon2FA AiTM Phishing via Microsoft Entra ID Sign-Ins

Detects Microsoft Entra ID sign-ins consistent with Tycoon2FA phishing-as-a-service (PhaaS) adversary-in-the-middle (AiTM) activity targeting Microsoft 365 and Gmail, where the Microsoft Authentication Broker requests tokens for Microsoft Graph or Exchange Online, or the Office web client application authenticates to itself, combined with Node.js-style user agents (node, axios, undici).

Microsoft Entra ID +3 tycoon2fa aitm entra_id phishing credential_access
2r 2t
medium advisory

Microsoft Graph Multi-Category Reconnaissance Burst

The rule detects Microsoft Graph activity from delegated user tokens where a single user session and source IP rapidly touches multiple high-value Graph paths indicative of reconnaissance, suggesting a broad enumeration playbook.

Microsoft Graph cloud identity api azure microsoft-entra-id microsoft-graph threat-detection discovery
2r 2t
medium advisory

Potential macOS SSH Brute Force Detected

This rule identifies a high number of inbound SSH login attempts on a macOS host within a short time window by monitoring the `sshd-keygen-wrapper` process, indicating potential brute-force attacks against exposed SSH services.

Elastic Defend credential-access brute-force macos
2r 2t
medium advisory

Vercel AI Server-Side Request Forgery Vulnerability (CVE-2026-8768)

Vulnerability CVE-2026-8768 describes a server-side request forgery (SSRF) flaw in the validateDownloadUrl function of the provider-utils component in Vercel AI versions up to 3.0.97, enabling remote attackers to potentially make internal requests.

ai SSRF CVE-2026-8768 vercel
2r 1t 1c
medium advisory

Fuel CMS 1.4.13 Blind SQL Injection Vulnerability (CVE-2021-47980)

Fuel CMS 1.4.13 is vulnerable to blind SQL injection via the 'col' parameter in the Activity Log interface, allowing authenticated attackers to manipulate database queries and extract information through time-based delays (CVE-2021-47980).

Fuel CMS 1.4.13 cve cve-2021-47980 sql-injection web-application
2r 1t 1c
medium threat

WP Learn Manager Stored XSS Vulnerability (CVE-2021-47975)

WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability (CVE-2021-47975) that allows unauthenticated attackers to inject malicious scripts through the fieldtitle parameter via a POST request to the jslm_fieldordering page, resulting in arbitrary JavaScript execution when administrators view the field ordering interface.

WP Learn Manager 1.1.2 cve xss web wordpress
1r 1t 1c
medium advisory

Sticky Notes Widget Denial-of-Service Vulnerability (CVE-2021-47973)

Sticky Notes Widget 3.0.6 is vulnerable to a denial-of-service attack (CVE-2021-47973), where an attacker can crash the application on iOS devices by pasting excessively long character strings into note fields.

Sticky Notes Widget 3.0.6 denial of service ios cve-2021-47973
1r 1t 1c
medium advisory

Sticky Notes & Color Widgets 1.4.2 Denial of Service Vulnerability (CVE-2021-47972)

Sticky Notes & Color Widgets 1.4.2 is vulnerable to denial of service via excessively long character strings (CVE-2021-47972), allowing attackers to crash the application.

Sticky Notes & Color Widgets 1.4.2 denial of service application crash cve-2021-47972
2r 1t 1c
medium advisory

My Notes Safe 5.3 Denial-of-Service Vulnerability (CVE-2021-47971)

My Notes Safe 5.3 is vulnerable to a denial-of-service attack (CVE-2021-47971) where an attacker can crash the application by pasting excessively long character strings into note fields.

My Notes Safe dos denial-of-service cve-2021-47971
2r 1t 1c
medium threat

Macaron Notes 5.5 Denial of Service Vulnerability (CVE-2021-47970)

Macaron Notes 5.5 is vulnerable to a denial-of-service condition (CVE-2021-47970) due to its handling of excessively long character strings in notes, leading to application crashes.

Notes 5.5 denial-of-service cve-2021-47970 application-crash
2r 1t 1c
medium threat

Color Notes 1.4 Denial-of-Service Vulnerability (CVE-2021-47969)

Color Notes 1.4 is vulnerable to a denial-of-service attack (CVE-2021-47969) where pasting excessively long character strings into note fields can crash the application, achieved by generating and pasting a 350,000-character payload twice into a new note.

Color Notes denial-of-service application-crash CVE-2021-47969
2r 1t 1c
medium advisory

CVE-2026-43490: ksmbd inherited ACE SID length validation vulnerability

Microsoft published information about CVE-2026-43490, a vulnerability in ksmbd related to the validation of inherited ACE SID length.

ksmbd ACE SID CVE-2026-43490 vulnerability
2r 1c
medium advisory

LSASS Memory Dump Handle Access

Detection of handle requests to the LSASS process with specific access masks commonly used by tools to dump memory, indicating potential credential access attempts.

Windows credential-access lsass memdump
2r 1t
medium threat

CVE-2021-47959: WPGraphQL Plugin Denial of Service via Batched Queries

The WordPress Plugin WPGraphQL version 1.3.5 is vulnerable to a denial-of-service attack where unauthenticated attackers can exhaust server resources by sending batched GraphQL queries with duplicated fields, potentially causing server out-of-memory conditions and MySQL connection errors.

WPGraphQL 1.3.5 denial-of-service wordpress graphql
2r 1t 1c
medium advisory

phpMyFAQ Unauthenticated Information Disclosure via Solution ID Enumeration

phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the getIdFromSolutionId() method, allowing unauthenticated attackers to enumerate restricted FAQ entries and read their titles via predictable URL patterns.

phpMyFAQ information-disclosure enumeration
2r 1t 1c
medium advisory

phpMyFAQ Unauthenticated TOTP Bypass via Brute-Force (CVE-2026-45010)

phpMyFAQ before 4.1.2 is vulnerable to improper restriction of excessive authentication attempts in the /admin/check endpoint, allowing unauthenticated attackers to brute-force any user's six-digit TOTP code and bypass two-factor authentication, potentially gaining full administrative access (CVE-2026-45010).

phpMyFAQ cve brute-force totp credential-access authentication-bypass
2r 1t 1c
medium advisory

epa4all-client Library Vulnerable to TLS Certificate Validation Issue (CVE-2026-45574)

The epa4all-client library before version 1.2.2 is vulnerable to a TLS certificate validation issue, allowing a man-in-the-middle attacker to intercept SOAP traffic and sensitive patient data by presenting a malicious TLS certificate.

epa4all-client tls certificate-validation mitm credential-access cve-2026-45574
2r 1t 1i
medium advisory

Better Auth Rate Limiter Bypass via IPv6 Prefix Rotation (CVE-2026-45364)

Better Auth versions before 1.4.17 and pre-release versions before 1.5.0-beta.9 are vulnerable to CVE-2026-45364, a rate-limiting bypass that allows IPv6 clients to rotate through numerous source addresses or vary the textual encoding of one IPv6 address, effectively defeating rate limiting on authentication endpoints, potentially leading to credential stuffing, account enumeration, and amplification of password-reset email fan-out.

better-auth +4 rate-limiting authentication ipv6 cve-2026-45364
2r
medium advisory

Nimiq nimiq-keys Ed25519 Signature Length Vulnerability (CVE-2026-40092)

A malicious network peer can crash a Nimiq full node by publishing a crafted Kademlia DHT record due to unchecked Ed25519 signature length in `TaggedPublicKey::verify` (CVE-2026-40092).

nimiq-keys dos nimiq signature-validation
2r 1t
medium advisory

PureLogs Infostealer Delivered via PawsRunner Steganography

A steganography-based malware campaign uses PawsRunner to deliver the PureLogs infostealer, highlighting evolving delivery methods.

PureLogs steganography infostealer malware
2r 1t
medium advisory

Windows Snipping Tool NTLMv2 Hash Hijack Vulnerability (CVE-2026-33829)

A local exploit has been published for Windows Snipping Tool (CVE-2026-33829), enabling NTLMv2 Hash Hijacking by forcing authentication to a remote SMB server via a crafted ms-screensketch:edit URI, potentially leading to credential theft and lateral movement.

Windows Snipping Tool credential-access ntlmv2 pass-the-hash cve-2026-33829
2r 1t 1c
medium advisory

Remote Sunrise Helper for Windows 2026.14 - Unauthenticated File/Directory Listing

A local exploit has been published for Remote Sunrise Helper for Windows 2026.14, detailing an unauthenticated file/directory listing vulnerability. Successful exploitation allows unauthenticated attackers to list files and directories on the affected system.

Remote Sunrise Helper for Windows unauthenticated-access file-listing windows
2r 1t
medium advisory

Multiple Vulnerabilities in Shibboleth Products Leading to DoS and Security Policy Bypass

Multiple vulnerabilities have been discovered in Shibboleth Identity Provider and OpenSAML Java library that allow an attacker to cause a remote denial of service and security policy bypass, addressed in versions 5.2.2 and later.

Identity Provider +1 shibboleth denial-of-service security-policy-bypass
2r 1t 1c
medium advisory

Shibboleth Identity Provider Vulnerabilities Leading to SMTP Injection and Denial of Service

Multiple vulnerabilities in Shibboleth Identity Provider allow an attacker to perform SMTP injection or cause a denial of service.

Identity Provider vulnerability denial-of-service smtp-injection
1r 1t
medium advisory

File Creation in World-Writable Directory by Unusual Process

This rule detects the creation of files in world-writable directories on Linux systems by an unusual process, which is a common defense evasion tactic for potential lateral movement or malicious payload staging.

Elastic Defend +2 defense-evasion file-creation linux
2r 1t
medium threat

Maltrail IOC Feed Update - 2026-05-15

This brief summarizes a Maltrail IOC feed update on 2026-05-15, containing indicators associated with APT_Kimsuky, CyberstrikeAI, Android_Joker, Sectoprat, EK_Landupdate808, and MagentoCore campaigns involving suspicious domains and IP addresses.

github.com APT_Kimsuky maltrail ioc threat-intelligence
3r 2t 50i
medium advisory

Multiple Vulnerabilities in GStreamer

Multiple vulnerabilities in GStreamer can be exploited by a remote, anonymous attacker to disclose information, conduct a denial-of-service attack, corrupt data, or execute arbitrary code.

GStreamer vulnerability denial-of-service code-execution
2r 3t
medium advisory

GNU libc Vulnerabilities Allow DNS Response Manipulation

A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to manipulate DNS responses, potentially leading to redirection to malicious sites.

libc dns spoofing glibc cache_poisoning
2r 1t
medium advisory

Multiple Vulnerabilities in GIMP

Multiple vulnerabilities in GIMP could allow an attacker to execute arbitrary code, disclose sensitive information, manipulate data, or cause a denial-of-service condition.

GIMP vulnerability code-execution information-disclosure dos
2r 3t
medium advisory

Multiple Vulnerabilities in AMD EPYC, Athlon, and Ryzen Processors

Multiple vulnerabilities in AMD EPYC, Athlon, and Ryzen processors can be exploited by an attacker to execute arbitrary code, escalate privileges, bypass security measures, cause a denial-of-service condition, disclose sensitive information, or manipulate data.

EPYC processors +2 amd processor vulnerability privilege-escalation defense-evasion execution denial-of-service information-disclosure +1
2r 7t
medium advisory

CVE-2026-4094: FOX – Currency Switcher Professional for WooCommerce Plugin Vulnerability

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss (CVE-2026-4094) due to a missing capability check, allowing authenticated attackers with Contributor-level access or higher to delete the multi-currency configuration.

FOX – Currency Switcher Professional for WooCommerce plugin <= 1.4.5 wordpress woocommerce plugin csrf data-loss cve-2026-4094
2r 1t 1c
medium advisory

Open WebUI Broken Authorization Allows Task Cancellation

Open WebUI is vulnerable to broken object-level authorization, allowing low-privilege authenticated users to enumerate and stop global background tasks across the system, leading to a denial-of-service condition and is tracked as CVE-2026-45399 and CVE-2025-63681.

open-webui authorization denial-of-service cve-2026-45399
2r 1t 1c
medium advisory

Svelte devalue Denial-of-Service via Sparse Array Deserialization (CVE-2026-42570)

The `devalue` package is vulnerable to a denial-of-service (DoS) attack (CVE-2026-42570) due to excessive memory allocation during sparse array deserialization via `devalue.parse`, affecting versions 5.6.3 through 5.8.0.

devalue denial-of-service cve-2026-42570
2r 1t
medium advisory

CVE-2026-42897 Microsoft Exchange Server Cross-Site Scripting Vulnerability

CVE-2026-42897 is a cross-site scripting (XSS) vulnerability in Microsoft Exchange Server that allows an attacker to perform spoofing attacks by injecting malicious scripts into web pages.

PoC Exchange Server +6 xss spoofing exchange
2r 2t 1c 7i updated
medium advisory

Synapse CPU Starvation Denial of Service Vulnerability

A denial-of-service vulnerability exists in Synapse where local authenticated users can cause CPU starvation, leading to request failures for other users (CVE-2026-45078).

matrix-synapse denial-of-service synapse cpu-starvation
2r 1t 1i
medium advisory

Kubernetes Ephemeral Container Added to Pod for Privilege Escalation

This rule detects allowed updates to Kubernetes pods/ephemeralcontainers subresource by non-system identities, which can be abused for privilege escalation, lateral movement, or persistence by injecting tooling into running pods.

kubernetes privilege-escalation execution
2r 2t
medium advisory

MongoDB Timeseries Collection Vulnerability (CVE-2026-8053)

MongoDB published a security advisory to address CVE-2026-8053, an undefined behavior vulnerability when inserting data with duplicate field names into timeseries collections, affecting versions 5.0.0 through 8.3.1.

MongoDB 8.3.0 +11 mongodb cve-2026-8053 timeseries denial of service
1r 1c
medium advisory

AWS EKS Access Entry Modification Detected

Successful Amazon EKS Access Entries API operations that create, update, attach, detach, or delete authentication mappings between IAM principals and the cluster, potentially indicating persistence or privilege escalation are detected.

EKS cloud kubernetes aws persistence privilege-escalation
2r 2t
medium advisory

Vvveb Uncontrolled Recursion Denial of Service (CVE-2026-41935)

Vvveb before version 1.0.8.3 is vulnerable to an uncontrolled recursion vulnerability in the admin controller dispatch cycle that allows a low-privilege attacker to cause denial of service by exhausting PHP memory.

Vvveb +1 denial of service web application recursion
1r 2t 1c
medium advisory

Siemens SIPROTEC 5 Insufficient Session ID Randomness Leads to Session Hijacking (CVE-2024-54017)

Siemens SIPROTEC 5 devices are vulnerable to session hijacking (CVE-2024-54017) due to the use of insufficiently random numbers in session identifier generation, potentially allowing an unauthenticated remote attacker to brute-force a valid session and gain unauthorized read access.

SIPROTEC 5 6MD84 +62 ics session hijacking cve-2024-54017 siemens critical infrastructure
2r 1t 1c
medium advisory

Siemens SIMATIC HMI Unified Comfort Panels Unauthenticated Access Vulnerability

Siemens SIMATIC HMI Unified Comfort Panels before V21.0 are vulnerable to unauthenticated access via the help link and Control Panel (CVE-2026-27662), potentially leading to unauthorized configuration changes and discovery of backdoors.

SIMATIC HMI MTP1000 Unified Comfort Panel +49 ics siemens hmi cve-2026-27662 unauthenticated access
2r 1t 1c
medium advisory

Siemens Ruggedcom Rox Improper Access Control Vulnerability

Siemens Ruggedcom Rox is vulnerable to improper access control, allowing an authenticated remote attacker to read arbitrary files with root privileges from the underlying operating system's filesystem via the web server's JSON-RPC interface, as tracked by CVE-2025-40948.

RUGGEDCOM ROX MX5000 +10 cve siemens ruggedcom ics file-access attack.credential_access
2r 1t 1c
medium advisory

FlowiseAI Exposes Basic Auth Credentials via API

FlowiseAI exposes a basic authentication endpoint without rate limiting, allowing attackers to brute-force credentials and gain unauthorized access to the application.

flowise credential-access brute-force flowiseai
2r 1t
medium advisory

Kubernetes API Server Proxying Request to Kubelet

Detection of non-system identities using the Kubernetes nodes/proxy API to proxy requests through the API server directly to a node's Kubelet, potentially leading to privilege escalation and sensitive information exposure.

kubernetes privilege-escalation lateral-movement discovery
2r 3t
medium advisory

Strapi Unauthenticated Account Takeover via Relational Filtering Vulnerability (CVE-2026-27886)

Strapi versions prior to 5.37.0 are vulnerable to an unauthenticated boolean-oracle attack against private fields on the joined `admin_users` table, including the `resetPasswordToken` field, via the 'where' query parameter on publicly accessible content-types; extracting an admin reset token via this oracle makes full administrative account takeover possible without authentication.

@strapi/strapi cve strapi account takeover vulnerability
2r 1t
medium advisory

Absinthe GraphQL Fragment Validation Denial-of-Service (CVE-2026-43967)

A denial-of-service vulnerability exists in the Absinthe GraphQL library (versions 1.2.0 to 1.10.1), where an unauthenticated attacker can exhaust server resources by submitting a crafted GraphQL query with a large number of fragment definitions due to the quadratic complexity of fragment name uniqueness validation.

absinthe denial of service graphql algorithmic complexity CVE-2026-43967
2r 1t 1c
medium advisory

Absinthe GraphQL Atom Table Exhaustion Vulnerability

Absinthe versions 1.5.0 before 1.10.2 are vulnerable to a denial-of-service attack (CVE-2026-42793) due to unbounded atom creation when parsing GraphQL SDL documents, allowing an attacker to exhaust the Erlang VM's atom table and crash the entire node by submitting a crafted document with numerous unique directive names.

absinthe denial-of-service graphql atom-table-exhaustion
2r 1t 1c
medium advisory

CVE-2026-3892 - WordPress Motors Plugin Arbitrary File Deletion

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in versions up to 1.4.107 due to insufficient file path validation in the become-dealer logo upload flow, allowing authenticated attackers with subscriber level access and above to delete arbitrary files on the server.

The Motors – Car Dealership & Classified Listings Plugin <= 1.4.107 arbitrary-file-deletion wordpress plugin
1r 1t 1c
medium advisory

ManageWP Worker Plugin Vulnerable to Stored XSS via HTTP Header

The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'MWP-Key-Name' HTTP request header, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator visits the plugin's connection management page with debug parameters; this affects all versions up to and including 4.9.31.

ManageWP Worker plugin <= 4.9.31 wordpress xss cve-2026-3718
2r 1t 1c
medium advisory

HPE Security Advisory for Telco Intelligent Assurance Vulnerabilities

HPE released a security advisory addressing multiple vulnerabilities in Telco Intelligent Assurance version 4.2.14, prompting users to apply necessary updates to mitigate potential risks.

Telco Intelligent Assurance 4.2.14 hpe vulnerability telco
2r
medium advisory

CVE-2026-42409 - F5 BIG-IP TMM Process Termination via HTTP/2 and iRules

CVE-2026-42409 describes a vulnerability in F5 BIG-IP where undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate when an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, potentially leading to denial of service.

denial-of-service f5
2r 1t 1c
medium threat

CVE-2026-41956: F5 TMM Termination Vulnerability on UDP Virtual Servers

CVE-2026-41956 describes a vulnerability in F5 Networks' Traffic Management Microkernel (TMM) where undisclosed requests can cause TMM termination when a classification profile is configured on a UDP virtual server, leading to a denial-of-service condition.

cve-2026-41956 denial-of-service f5 tmm
2r 1t 1c
medium advisory

Lenovo Personal Cloud Storage Improper File Path Validation Vulnerability (CVE-2026-6282)

CVE-2026-6282 describes a potential improper file path validation vulnerability in Lenovo Personal Cloud Storage devices, allowing a remote authenticated user to move or access files belonging to other users.

Personal Cloud Storage devices cve path traversal lenovo
2r 1t 1c
medium threat

CVE-2026-42920 - F5 BIG-IP TMM Termination Vulnerability

CVE-2026-42920 describes a vulnerability where undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate when a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server.

BIG-IP cve dos f5
2r 1t 1c
medium threat

CVE-2026-41227: F5 Networks Traffic Management Microkernel (TMM) Process Termination via HTTP/2 Traffic

CVE-2026-41227 describes a vulnerability in an F5 Networks product where undisclosed traffic on an HTTP/2 virtual server with Layer 7 DoS Protection enabled can lead to increased memory consumption and termination of the Traffic Management Microkernel (TMM) process.

dos cve http2
2r 1t 1c
medium threat

CVE-2026-40629: F5 Networks Virtual Server Denial of Service

CVE-2026-40629 describes a vulnerability in F5 Networks products where, when SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections, leading to a denial of service.

cve dos f5
1r 1t 1c
medium advisory

BIG-IP VE TMM Termination Vulnerability (CVE-2026-40618)

CVE-2026-40618 describes a vulnerability in F5 BIG-IP Virtual Edition (VE) where specific traffic can cause the Traffic Management Microkernel (TMM) to terminate when an SSL profile is configured without Intel QuickAssist Technology (QAT) or with crypto.hwacceleration disabled, potentially leading to a denial-of-service.

BIG-IP Virtual Edition cve dos big-ip
2r 1t 1c
medium advisory

CVE-2026-40423: F5 Traffic Management Microkernel (TMM) Termination Vulnerability

CVE-2026-40423 describes a vulnerability in F5 Networks products where undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate when a SIP profile is configured on a virtual server, leading to a denial-of-service condition.

cve dos f5
2r 1t 1c
medium advisory

F5 BIG-IP APM Undisclosed Traffic Denial-of-Service Vulnerability (CVE-2026-40067)

A vulnerability exists in F5 BIG-IP APM where, when an APM access policy is configured on a virtual server, undisclosed network traffic can cause the apmd process to terminate, resulting in a denial of service (CVE-2026-40067).

BIG-IP APM dos cve-2026-40067 f5
2r 1t 1c
medium advisory

BIG-IP Advanced WAF/ASM Denial-of-Service Vulnerability (CVE-2026-40060)

CVE-2026-40060 describes a vulnerability in F5 BIG-IP Advanced WAF and ASM security policies where undisclosed requests can cause the `bd` process to terminate, leading to a denial-of-service condition.

BIG-IP Advanced WAF +1 denial-of-service web application firewall F5 CVE-2026-40060
2r 1t 1c
medium advisory

BIG-IP Configuration Utility LDAP Authentication Denial-of-Service (CVE-2026-39455)

CVE-2026-39455 describes a denial-of-service vulnerability in the BIG-IP Configuration utility when configured with LDAP authentication, where undisclosed traffic can cause the httpd process to exhaust file descriptors.

BIG-IP Configuration utility denial-of-service cve
2r 1t 1c
medium threat

Kuicms Php EE 2.0 Persistent Cross-Site Scripting Vulnerability (CVE-2020-37222)

Kuicms Php EE 2.0 is vulnerable to persistent cross-site scripting (CVE-2020-37222), allowing unauthenticated attackers to inject malicious scripts via the bbs reply endpoint, leading to arbitrary script execution in users' browsers.

Kuicms Php EE xss cve-2020-37222 kuicms
2r 1t 1c
medium advisory

Joomla com_fabrik Directory Traversal Vulnerability (CVE-2020-37219)

Joomla com_fabrik 3.9.11 is vulnerable to a directory traversal attack (CVE-2020-37219) where an unauthenticated attacker can list arbitrary files by manipulating the folder parameter in a GET request to the onAjax_files method, using path traversal sequences to access system directories outside the web root.

com_fabrik 3.9.11 directory-traversal web-application joomla
2r 1t 1c
medium advisory

CVE-2026-0259 Arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire Appliance

CVE-2026-0259 allows a low-privileged user to read sensitive information and delete arbitrary files on Palo Alto Networks WildFire WF-500 and WF-500-B appliances running in the default non-FIPS configuration.

WildFire WF-500 +1 cve arbitrary file read arbitrary file delete wildfire
2r
medium advisory

CVE-2026-0243: Prisma SD-WAN Denial-of-Service via Crafted IPv6 Packet

An unauthenticated, adjacent attacker can disrupt Palo Alto Networks Prisma SD-WAN ION devices by sending a specially crafted IPv6 packet, leading to a denial-of-service condition.

Prisma SD-WAN ION denial-of-service network Prisma SD-WAN
2r 1t
medium advisory

CVE-2026-0245 Prisma Access Agent Information Disclosure Vulnerability

CVE-2026-0245 describes multiple information disclosure vulnerabilities in Palo Alto Networks Prisma Access Agent before version 26.2.1 on macOS and Windows, allowing a local user to access sensitive configuration data and credentials.

Prisma Access Agent cve-2026-0245 information-disclosure prisma-access-agent
1r 1t
medium advisory

CVE-2026-0257 PAN-OS GlobalProtect Authentication Bypass Vulnerability

An authentication bypass vulnerability exists in Palo Alto Networks PAN-OS GlobalProtect portal and gateway (CVE-2026-0257) when authentication override cookies are enabled, allowing an attacker to establish an unauthorized VPN connection.

PAN-OS +1 authentication bypass vpn cve-2026-0257
1r 1t
medium advisory

CVE-2026-0249 GlobalProtect App: Certificate Validation Bypass Vulnerabilities

CVE-2026-0249 describes multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect app that could allow an attacker to intercept encrypted communications and potentially compromise the endpoint, especially on macOS, Android, and ChromeOS.

GlobalProtect App cve-2026-0249 certificate validation man-in-the-middle globalprotect vpn
2r 1t
medium advisory

CVE-2026-0239 Chronosphere Chronocollector Information Disclosure Vulnerability

CVE-2026-0239 is an information disclosure vulnerability in Chronosphere Chronocollector versions earlier than v0.116.0, allowing an unauthenticated attacker with network access to retrieve sensitive information.

Chronosphere Chronocollector < v0.116.0 information disclosure vulnerability network
1r
medium advisory

CVE-2026-0256 PAN-OS Stored Cross-Site Scripting (XSS) Vulnerability

A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS allows a malicious authenticated administrator to inject a JavaScript payload via the web interface, potentially impacting other administrators.

PAN-OS 12.1 +3 xss cve web-interface
2r 1t
medium advisory

CVE-2026-0244 Prisma SD-WAN ION Improper Certificate Validation Vulnerability

CVE-2026-0244 is an improper certificate validation vulnerability in Palo Alto Networks Prisma SD-WAN ION that allows a man-in-the-middle (MitM) attacker to impersonate the controller.

Prisma SD-WAN ION vulnerability mitm certificate validation
2r 1t
medium advisory

CVE-2026-0261 PAN-OS Authenticated Admin Command Injection Vulnerability

CVE-2026-0261 describes multiple command injection vulnerabilities in Palo Alto Networks PAN-OS software that allow an authenticated administrator to bypass system restrictions and execute arbitrary commands as root.

PAN-OS cve command injection palo alto networks
2r 1t
medium threat

CVE-2026-0242: Trust Protection Foundation SQL Injection Vulnerability

A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL commands against the product database, potentially leading to sensitive data exposure, data modification, and privilege escalation.

exploited Trust Protection Foundation cve sql-injection palo alto networks
2r 1t
medium threat

CVE-2026-0241: Trust Protection Foundation Authorization Bypass Vulnerabilities

CVE-2026-0241 describes multiple incorrect authorization vulnerabilities in Palo Alto Networks Trust Protection Foundation that allow attackers to bypass access controls and perform unauthorized actions on restricted resources.

exploited Trust Protection Foundation cve authorization bypass palo alto networks
2r 1t
medium advisory

CVE-2026-0258 PAN-OS SSRF vulnerability in IKEv2 certificate URL fetching

CVE-2026-0258 is a medium severity server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS that allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations, potentially leading to a denial of service (DoS).

PAN-OS ssrf cve-2026-0258 network palo alto networks
2r 1t
medium advisory

CVE-2026-0250 Palo Alto Networks GlobalProtect App Buffer Overflow Vulnerability

CVE-2026-0250 is a medium severity buffer overflow vulnerability in Palo Alto Networks GlobalProtect App that could allow a man-in-the-middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges by intercepting and manipulating requests and responses between the Portal and Gateway.

GlobalProtect App +1 cve-2026-0250 buffer-overflow man-in-the-middle
2r 1t
medium advisory

CVE-2026-0240 Trust Protection Foundation Sensitive Information Disclosure Vulnerability

CVE-2026-0240 is a medium severity information disclosure vulnerability in Palo Alto Networks Trust Protection Foundation, allowing an authenticated attacker to obtain sensitive information from the server's vault, potentially leading to user impersonation and arbitrary modification of configuration settings.

Trust Protection Foundation information-disclosure cve-2026-0240 palo alto networks
2r 2t
medium advisory

CVE-2026-0262 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing

Unauthenticated attackers can cause a denial of service (DoS) condition on Palo Alto Networks PAN-OS firewalls by sending specially crafted network traffic, as described in CVE-2026-0262.

PAN-OS +1 dos denial of service CVE-2026-0262
2r 2t
medium advisory

CVE-2026-0246 Prisma Access Agent Local Privilege Escalation Vulnerability

A local privilege escalation vulnerability exists in Palo Alto Networks Prisma Access Agent versions prior to 26.2.1 on Linux, macOS, and Windows, allowing a locally authenticated non-administrative user to gain root or NT AUTHORITY\SYSTEM privileges and execute arbitrary code.

Prisma Access Agent privilege-escalation cve
2r 1t
medium advisory

CVE-2026-0251: Palo Alto Networks GlobalProtect App Local Privilege Escalation

Multiple local privilege escalation vulnerabilities exist in Palo Alto Networks GlobalProtect App, allowing a local user to escalate privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux, enabling arbitrary command execution with administrative privileges.

GlobalProtect App privilege-escalation cve-2026-0251 palo alto networks globalprotect
3r 1t
medium advisory

CVE-2026-0248 Prisma Access Agent Improper Certificate Validation Vulnerability

CVE-2026-0248 is an improper certificate validation vulnerability in Prisma Access Agent for Android and Chrome OS, enabling a man-in-the-middle (MitM) attack to intercept VPN traffic and capture sensitive device information by presenting a certificate issued by a trusted Certificate Authority.

Prisma Access Agent cve-2026-0248 mitm vpn certificate-validation
2r 2t
medium advisory

CVE-2026-0247 Prisma Access Agent Endpoint DLP: Authorization Bypass Vulnerabilities

Multiple authorization bypass vulnerabilities exist in the Endpoint DLP component of Prisma Access Agent, allowing a local attacker to bypass authentication controls and execute privileged operations on macOS and Windows systems with Endpoint DLP enabled; versions prior to 26.2.1 are affected.

Prisma Access Agent cve-2026-0247 privilege-escalation authorization-bypass endpoint-dlp
2r 1t
medium advisory

CVE-2026-6177 - Custom Twitter Feeds WordPress Plugin Stored XSS

The Custom Twitter Feeds plugin for WordPress is vulnerable to stored cross-site scripting (XSS) in versions up to and including 2.5.4 due to insufficient output escaping, allowing unauthenticated attackers to inject arbitrary web scripts.

Custom Twitter Feeds plugin <= 2.5.4 xss wordpress CVE-2026-6177
2r 1t 1c
medium advisory

coreActivity: Activity Logging for WordPress Plugin Vulnerable to PHP Object Injection (CVE-2026-7635)

The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection (CVE-2026-7635), allowing unauthenticated attackers to inject a crafted PHP serialized payload via the User-Agent header, leading to a persistent Denial of Service condition.

coreActivity: Activity Logging for WordPress plugin <= 3.0 cve wordpress php object injection denial of service
2r 1t 1c
medium advisory

Anchor: InterfaceAccount Allows Account Substitution

The `InterfaceAccount` in `anchor-lang` allows an unexpected account type to be passed due to disabled discriminator checking, patched in version 1.0.0-rc.2 and later.

anchor-lang anchor solana interfaceaccount account-substitution
2r
medium advisory

Goobi Viewer Unauthenticated Solr Streaming Expression Proxy Vulnerability

The Goobi viewer REST endpoint accepted an arbitrary Solr streaming expression from unauthenticated network clients, enabling attackers to read, modify, or delete the complete Solr index; this was resolved by removing the affected API endpoint.

Goobi viewer solr proxy unauthenticated CVE-2026-45083 critical
2r 1t
medium advisory

Leveraging Linux Cgroups for Threat Detection and Investigation

This brief outlines how Linux cgroups, a kernel feature for resource management, can be repurposed to provide valuable telemetry for detecting malicious processes, particularly in systemd, Docker, and Kubernetes environments, aiding in investigations of server compromises.

Red Hat Enterprise Linux +5 linux cgroups container kubernetes docker systemd threat-detection
2r
medium threat

Kyverno Vulnerability Allows Cross-Site Scripting

A remote, authenticated attacker can exploit a vulnerability in Kyverno to perform a cross-site scripting attack.

Kyverno xss web-application
2r 1t
medium advisory

Devolutions Server Vulnerability Allows File Manipulation

A remote, anonymous attacker can exploit a vulnerability in Devolutions Server to manipulate files.

Devolutions Server file-manipulation vulnerability devolutions-server
2r 1t
medium advisory

Multiple Vulnerabilities in Zoom Workplace and Rooms

A local attacker can exploit multiple vulnerabilities in Zoom Video Communications Workplace and Zoom Video Communications Rooms to disclose information or escalate privileges.

Workplace +1 privilege-escalation information-disclosure zoom
2r 1t
medium advisory

Pega Platform Vulnerability Allows Cross-Site Scripting

A remote, anonymous attacker can exploit a vulnerability in Pega Platform to perform a cross-site scripting (XSS) attack, potentially leading to session hijacking or malicious script execution in a user's browser.

Pega Platform cross-site scripting web application vulnerability
2r 1t
medium advisory

Multiple Vulnerabilities in Adobe Creative Cloud Applications

A local attacker can exploit multiple vulnerabilities in Adobe Creative Cloud applications to execute arbitrary program code, disclose confidential information, or cause a denial-of-service condition.

Creative Cloud adobe creative-cloud vulnerability code-execution information-disclosure denial-of-service
2r 3t
medium threat

Fortinet FortiAnalyzer and FortiManager Vulnerability Allows Denial of Service

A remote, authenticated attacker can exploit a vulnerability in Fortinet FortiAnalyzer and FortiManager to perform a denial-of-service attack, disrupting normal operations.

FortiAnalyzer +1 denial-of-service fortinet network
2r 1t
medium advisory

VMware Tanzu Spring Framework Security Bypass Vulnerability

A remote, anonymous attacker can exploit a vulnerability in VMware Tanzu Spring Framework to bypass security measures.

Tanzu Spring Framework security-bypass vmware spring-framework
2r 1t
medium advisory

Keycloak Vulnerability Allows Arbitrary Email Sending

An anonymous, remote attacker can exploit a vulnerability in Keycloak to send arbitrary emails, potentially leading to phishing or social engineering attacks.

Keycloak email vulnerability spoofing
2r 1t
medium advisory

Intel Server Firmware Update Utility Software Privilege Escalation Vulnerability

A local attacker can exploit a vulnerability in Intel Server Firmware Update Utility Software to escalate their privileges on the targeted system.

Server Firmware Update Utility Software privilege-escalation intel
2r 1t
medium advisory

Langflow Vulnerability Allows Denial of Service

An authenticated remote attacker can exploit a vulnerability in Langflow to perform a denial-of-service attack, impacting system availability.

Langflow denial-of-service web-application
1r 1t
medium advisory

nginx-ui Information Disclosure Vulnerability

A remote, authenticated attacker can exploit a vulnerability in nginx-ui to disclose sensitive information.

nginx-ui information-disclosure web-application
2r 1t
medium threat

Klever-Go MultiDataInterceptor Remote OOM via Compressed Payload

Klever-Go's MultiDataInterceptor is vulnerable to a remote denial-of-service (DoS) attack. By sending a crafted compressed P2P payload, an unauthenticated attacker can trigger excessive memory allocation on the receiving node, leading to an out-of-memory (OOM) condition and potentially disrupting chain liveness.

klever-go denial-of-service decompression-bomb
2r 2t
medium advisory

UltraJSON Memory Leak in ujson.dump() on Write Failure (CVE-2026-44660)

A memory leak vulnerability exists in UltraJSON's `ujson.dump()` function; when writing to a file-like object, if the write operation raises an exception, the serialized JSON string object is not properly de-referenced, leading to a memory leak (CVE-2026-44660).

ujson memory leak denial of service python CVE-2026-44660
2r 1t
medium advisory

SillyTavern Session Reuse After Password Change

SillyTavern versions 1.17.0 and earlier do not invalidate existing sessions after a password change, allowing attackers with stolen session cookies to retain access, even after the victim resets their password, and nullifies the password reset as a recovery measure against session theft.

sillytavern credential-access session-reuse web-application
2r 1t
medium advisory

CAI Content Credentials Uncontrolled Resource Consumption Vulnerability (CVE-2026-34665)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are susceptible to an uncontrolled resource consumption vulnerability, potentially leading to a denial-of-service condition by exhausting system resources.

CAI Content Credentials denial-of-service resource-consumption cve
2r 1t 1c
medium advisory

CVE-2026-34652: Adobe Commerce Dependency on Vulnerable Third-Party Component Leading to DoS

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, and 2.4.4-p17 and earlier are vulnerable to a denial-of-service due to a dependency on a vulnerable third-party component, which an attacker can exploit to crash the application without user interaction.

Commerce +6 cve dos adobe commerce third-party component
2r 1t 1c
medium advisory

CVE-2026-34651 - Adobe Commerce Uncontrolled Resource Consumption Vulnerability

Adobe Commerce versions 2.4.9-beta1 and earlier are vulnerable to uncontrolled resource consumption, potentially leading to application denial-of-service due to an attacker's ability to exhaust system resources without user interaction.

Commerce dos cve-2026-34651 adobe commerce
2r 1t 1c
medium advisory

Adobe Commerce Uncontrolled Resource Consumption Vulnerability (CVE-2026-34650)

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are susceptible to an uncontrolled resource consumption vulnerability (CVE-2026-34650) that allows an unauthenticated attacker to cause a denial-of-service condition by exhausting system resources.

Commerce versions 2.4.9-beta1 +5 dos resource-exhaustion cve
2r 1t 1c
medium advisory

CVE-2026-34649: Adobe Commerce Uncontrolled Resource Consumption Vulnerability

Adobe Commerce versions 2.4.9-beta1 and earlier are susceptible to an uncontrolled resource consumption vulnerability (CVE-2026-34649), allowing an unauthenticated attacker to trigger a denial-of-service condition by exhausting system resources.

Commerce cve-2026-34649 dos resource-consumption
2r 1t 1c
medium advisory

Adobe Commerce SSRF Vulnerability (CVE-2026-34647)

Adobe Commerce versions 2.4.9-beta1 and earlier are vulnerable to Server-Side Request Forgery (SSRF) via a maliciously crafted URL, potentially leading to security feature bypass and unauthorized read access.

Commerce ssrf security-bypass cve-2026-34647 adobe-commerce
2r 1t 1c
medium advisory

LSASS Process Access via Windows API

This rule identifies access attempts to the LSASS handle, which may indicate an attempt to dump credentials from LSASS memory by detecting specific API calls (OpenProcess, OpenThread, ReadProcessMemory) targeting the 'lsass.exe' process.

Microsoft Defender XDR +1 credential-access windows lsass
2r 2t
medium advisory

Intel Addresses Vulnerabilities in Multiple Software Products

Intel released security advisories addressing vulnerabilities in Display Virtualization for Windows OS driver software, Intel EMA software, AI Playground software, and Intel Vision software, requiring users to update to the latest versions.

Display Virtualization for Windows OS driver software +3 vulnerability intel software update windows
3r
medium advisory

CVE-2026-42899 - ASP.NET Core Infinite Loop Denial of Service

CVE-2026-42899 describes an infinite loop vulnerability in ASP.NET Core that allows an unauthorized attacker to perform a denial of service attack over a network.

ASP.NET Core denial-of-service asp.net CVE-2026-42899
2r 1t 1c
medium advisory

CVE-2026-42832 - Microsoft Office Improper Access Control Vulnerability Leading to Spoofing

CVE-2026-42832 is an improper access control vulnerability in Microsoft Office that allows an unauthorized attacker to perform local spoofing.

Office cve-2026-42832 spoofing microsoft-office access-control
2r 2t 1c
medium threat

CVE-2026-41102: Microsoft PowerPoint Improper Access Control Vulnerability Leading to Local Spoofing

CVE-2026-41102 is an improper access control vulnerability in Microsoft Office PowerPoint that allows an authorized attacker to perform spoofing locally.

Office PowerPoint access-control spoofing ms-office
2r 1t 1c
medium advisory

CVE-2026-41101: Microsoft Office Word Improper Access Control Vulnerability Leading to Local Spoofing

CVE-2026-41101 is a vulnerability in Microsoft Office Word due to improper access control, which allows an authorized attacker to perform spoofing locally, with a CVSS v3.1 base score of 7.1.

Office Word cve spoofing office word
2r 1t 1c
medium advisory

CVE-2026-40414: Windows TCP/IP Null Pointer Dereference Denial-of-Service

A null pointer dereference vulnerability exists in Windows TCP/IP, allowing an unauthorized attacker on an adjacent network to cause a denial-of-service condition.

Windows TCP/IP cve denial-of-service windows
2r 3t 1c
medium threat

CVE-2026-40413: Windows TCP/IP Null Pointer Dereference Denial of Service

CVE-2026-40413 is a null pointer dereference vulnerability in Windows TCP/IP that allows an unauthenticated attacker on an adjacent network to cause a denial-of-service condition.

Windows TCP/IP cve dos denial of service null pointer dereference
2r 1t 1c
medium advisory

CVE-2026-40406 - Windows TCP/IP Use-After-Free Information Disclosure

CVE-2026-40406 is a use-after-free vulnerability in Windows TCP/IP that allows an unauthorized attacker to disclose sensitive information over a network.

Windows TCP/IP cve-2026-40406 use-after-free information-disclosure windows tcp/ip
2r 1t 1c
medium advisory

CVE-2026-40405 - Windows TCP/IP Null Pointer Dereference DoS

CVE-2026-40405 describes a null pointer dereference vulnerability in Windows TCP/IP, allowing an unauthenticated attacker to cause a denial of service over a network.

TCP/IP dos cve windows
2r 1t 1c
medium threat

CVE-2026-40401 - Windows TCP/IP Null Pointer Dereference Denial of Service

CVE-2026-40401 is a null pointer dereference vulnerability in Windows TCP/IP that allows a local, unauthorized attacker to cause a denial of service.

Windows TCP/IP cve denial-of-service windows null pointer dereference
2r 1t 1c
medium advisory

CVE-2026-40360: Microsoft Excel Out-of-Bounds Read Information Disclosure

CVE-2026-40360 is an out-of-bounds read vulnerability in Microsoft Office Excel that allows an unauthorized attacker to disclose sensitive information locally.

Office Excel cve information-disclosure excel
2r 1t 1c
medium advisory

CVE-2026-35424: Windows IKE Protocol Memory Leak Denial-of-Service

CVE-2026-35424 is a denial-of-service vulnerability in the Windows Internet Key Exchange (IKE) Protocol caused by a missing release of memory after its effective lifetime, allowing an unauthenticated remote attacker to trigger a denial of service over a network.

Internet Key Exchange dos vulnerability windows ike
1r 1c
medium advisory

CVE-2026-34336 - Windows DWM Core Library Buffer Over-Read Information Disclosure

CVE-2026-34336 is a buffer over-read vulnerability in the Windows DWM Core Library, allowing a local, authenticated attacker to disclose sensitive information.

DWM Core Library vulnerability information-disclosure windows
2r 2t 1c
medium advisory

Ivanti Addresses Multiple Vulnerabilities in Various Products

Ivanti released security advisories on May 12, 2026, to address vulnerabilities in Xtraction, Endpoint Manager (EPM), Virtual Traffic Manager (vTM), and Secure Access Client (Windows), urging users to apply necessary updates to mitigate potential risks from CVE-2026-8043, CVE-2026-8051, CVE-2026-7431, and CVE-2026-7432.

Xtraction +3 ivanti vulnerability patch cve
2r 4c
medium advisory

Dalfox Unauthenticated Remote DoS via Closed-Channel Write in ParameterAnalysis

Dalfox is vulnerable to an unauthenticated remote denial-of-service (DoS) vulnerability (CVE-2026-45090) due to a closed channel write in the `ParameterAnalysis` function, triggered by a crafted POST request that crashes the Dalfox server process.

dalfox dos vulnerability
2r 1t
medium advisory

Schneider Electric Security Advisory AV26-449 Addressing Multiple Vulnerabilities

Schneider Electric published advisories on May 12, 2026, addressing vulnerabilities in multiple products including Ecostruxure Machine Expert HVAC, Easergy MiCOM C264, Easergy C5, Easergy MiCOM P30, Easergy MiCOM P40, EcoStruxure Power Automation System, iPMFLS, PowerLogic, Saitel DP, EasyLogic T150, EasyLogic T150 Remote Terminal Unit and Controller, Saitel DP Remote Terminal Unit and Controller, EcoStruxure Panel Server PAS400, PAS600, PAS600V2, PAS800, PAS800V2 and Easergy MiCOM Px40 Series related to clear text storage, insufficient entropy, improper path restrictions and insecure defaults.

Ecostruxure Machine Expert HVAC +17 vulnerability scada ics ot
2r
medium advisory

Siemens Security Advisory Addressing Multiple Product Vulnerabilities

Siemens released a security advisory on May 12, 2026, addressing vulnerabilities in a range of products including RUGGEDCOM, SCALANCE, Solid Edge, and SIMATIC, prompting users to apply necessary updates.

RUGGEDCOM ROX II family +20 siemens security-advisory industrial-control-systems
2r
medium advisory

Multiple Vulnerabilities in Microsoft Azure

Multiple vulnerabilities exist in Microsoft Azure, specifically affecting azl3 kernel and azl3 krb5, potentially leading to an unspecified security issue.

Azure +2 vulnerability
2r 3c
medium advisory

CPython Security Policy Bypass Vulnerability

A vulnerability in CPython, tracked as CVE-2026-7210, allows an attacker to bypass the security policy, requiring the latest security patch for mitigation.

CPython security-bypass vulnerability
2r 1t 1c
medium threat

LibreNMS Multiple XSS Vulnerabilities

Multiple reflected cross-site scripting (XSS) vulnerabilities exist in LibreNMS versions 25.12.0 to before 26.3.0, allowing an attacker to inject malicious code into a user's browser session.

LibreNMS xss reflected-xss
2r 1t
medium advisory

Traefik Security Policy Bypass Vulnerability

A security policy bypass vulnerability exists in Traefik versions prior to v2.11.46, v3.6.x before v3.6.17, and v3.7.x before v3.7.1, allowing attackers to potentially circumvent intended access controls.

Traefik < 2.11.46 +2 security-policy-bypass vulnerability traefik
1r 1t
medium advisory

Siemens SIMATIC S7 PLCs Web Server Vulnerabilities Allow Cross-Site Scripting

A remote, authenticated attacker can exploit multiple vulnerabilities in Siemens SIMATIC S7 PLCs Web Server to perform cross-site scripting attacks, potentially leading to information disclosure or further unauthorized actions.

SIMATIC S7 PLCs Web Server xss web-application plc
2r 1t
medium advisory

Siemens SIPROTEC 5 Information Disclosure Vulnerability

A remote, anonymous attacker can exploit a vulnerability in Siemens SIPROTEC 5 devices to disclose sensitive information.

SIPROTEC 5 information-disclosure ics siemens
2r 1t
medium advisory

Siemens Teamcenter Hardcoded Key Vulnerability (CVE-2026-33893)

CVE-2026-33893 describes a vulnerability in Siemens Teamcenter where hardcoded keys used for obfuscation are stored directly within the application, potentially allowing an attacker to obtain these keys and gain unauthorized access.

Teamcenter V2312 +4 cve vulnerability hardcoded-key teamcenter
2r 2t 1c
medium advisory

Siemens Teamcenter Vulnerability CVE-2026-33862 - Cross-Site Scripting

Siemens Teamcenter versions V2312 (before V2312.0014), V2406 (before V2406.0012), V2412 (before V2412.0009), V2506 (before V2506.0005), and V2512 are vulnerable to cross-site scripting (XSS) due to improper encoding or filtering of user-supplied data, potentially leading to arbitrary code execution by other users.

PoC Teamcenter V2312 +6 cve xss siemens teamcenter
2r 1t 3c 3i updated
medium advisory

CVE-2026-25789 - Firmware Update Page Filename Sanitization Vulnerability

CVE-2026-25789 describes a vulnerability where affected devices do not properly validate and sanitize filenames on the Firmware Update page, potentially allowing a remote attacker to execute malicious JavaScript in the context of the user's session through social engineering, leading to session hijacking or credential theft.

xss filename-sanitization web-application
2r 2t 1c
medium advisory

CVE-2026-22925: Siemens SIMATIC CN 4100 Resource Exhaustion via TCP SYN Flood

Siemens SIMATIC CN 4100 versions before V5.0 are vulnerable to resource exhaustion due to processing a high volume of TCP SYN packets, leading to a denial-of-service condition.

SIMATIC CN 4100 dos resource-exhaustion cve-2026-22925
1r 1c
medium advisory

CVE-2025-40833 Null Pointer Dereference in Affected Devices Leads to Denial of Service

A null pointer dereference vulnerability exists in affected devices while processing specially crafted IPv4 requests, potentially allowing a remote attacker to cause a denial of service, requiring a manual restart to recover the system.

dos cve-2025-40833
2r 1t 1c
medium advisory

Siemens SIMATIC CN 4100 Unauthenticated Resource Exhaustion (CVE-2026-22924)

Siemens SIMATIC CN 4100 versions before V5.0 are vulnerable to resource exhaustion due to improper restriction of unauthenticated connections, potentially leading to disruption of operations and unauthorized actions.

SIMATIC CN 4100 resource-exhaustion dos ics cve-2026-22924
2r 1t 1c
medium advisory

CODESYS Modbus Vulnerability Enables Denial of Service

A remote, anonymous attacker can exploit a vulnerability in CODESYS Modbus to perform a denial of service attack.

CODESYS Modbus dos modbus codesys
2r 1t
medium advisory

Multiple Vulnerabilities in ImageMagick Allow for DoS and Potential Data Exposure

A local attacker can exploit multiple vulnerabilities in ImageMagick to perform a denial of service attack or affect confidentiality, availability, and integrity.

ImageMagick vulnerability dos local-access
2r 2t
medium advisory

JetBrains TeamCity On-Premises Privilege Escalation Vulnerability

A remote, authenticated attacker can exploit a vulnerability in JetBrains TeamCity On-Premises to escalate privileges.

TeamCity On-Premises privilege-escalation teamcity webserver
2r 1t
medium advisory

CVE-2026-6690: LifePress WordPress Plugin Stored XSS Vulnerability

The LifePress plugin for WordPress is vulnerable to stored cross-site scripting (XSS) due to insufficient input sanitization and output escaping within the `lp_update_mds` AJAX action, allowing unauthenticated attackers to inject arbitrary web scripts via the 'n' parameter that execute when a user accesses the injected page; this affects versions up to and including 2.2.2.

LifePress plugin <= 2.2.2 wordpress xss cve-2026-6690 lifepress stored-xss plugin
2r 1t 1c
medium advisory

Kubernetes Service Account Token Created via TokenRequest API by Non-System Identity

The rule detects the creation of Kubernetes service account tokens through the TokenRequest API by non-system identities, which can be abused to escalate privileges, pivot to cloud resources, or generate persistent tokens, bypassing file system-based detection.

kubernetes credential-access tokenrequest cloud
2r 1t
medium advisory

Sonatype Nexus Repository Manager Security Bypass Vulnerability

An authenticated remote attacker can exploit a vulnerability in Sonatype Nexus Repository Manager to bypass security precautions.

Nexus Repository Manager security-bypass vulnerability nexus
2r 1t
medium advisory

Linux Kernel: Local Privilege Escalation Vulnerabilities

A local attacker can exploit multiple vulnerabilities in the Linux Kernel to escalate privileges or manipulate files.

linux kernel privilege-escalation linux kernel
2r 1t
medium advisory

Multiple Vulnerabilities in 7-Zip Allow File Manipulation and Information Disclosure

An anonymous remote attacker can exploit multiple vulnerabilities in 7-Zip to manipulate files or disclose sensitive information on Windows systems.

7-Zip vulnerability file-manipulation information-disclosure windows
2r 2t
medium advisory

CVE-2026-7287 - Zyxel NWA1100-N Buffer Overflow Vulnerability

A buffer overflow vulnerability in Zyxel NWA1100-N firmware allows a remote attacker to cause a denial-of-service by sending a crafted HTTP request to the webs binary.

NWA1100-N customized firmware dos buffer overflow cve-2026-7287
2r 2t 1c
medium advisory

GhostLock Tool Abuses Windows API to Block File Access

GhostLock is a proof-of-concept tool that abuses the Windows CreateFileW API to block access to files on local and SMB network shares, causing a denial-of-service condition.

Windows +1 denial-of-service file-access
2r 1t
medium advisory

JetBrains TeamCity Vulnerability

A security advisory released by JetBrains on May 11, 2026, addresses a vulnerability in JetBrains TeamCity versions prior to 2026.1 and 2025.11.5, requiring users to apply updates to mitigate potential risks.

TeamCity vulnerability jetbrains
2r
medium advisory

Broadcom Patches Multiple Vulnerabilities in VMware Tanzu RabbitMQ on Kubernetes

Broadcom published a security advisory addressing vulnerabilities in VMware Tanzu RabbitMQ on Kubernetes versions prior to 4.3.0, 4.2.6, 4.1.11, 4.0.20 and 3.13.15, potentially allowing an attacker to compromise the affected system.

VMware Tanzu RabbitMQ on Kubernetes vulnerability patch kubernetes
2r
medium advisory

Bird-lg-go Unbounded JSON Decode Denial of Service (CVE-2026-45047)

Bird-lg-go is vulnerable to a denial-of-service (DoS) attack (CVE-2026-45047) where an unauthenticated remote attacker can cause an out-of-memory error by streaming an extremely large JSON payload to the apiHandler, leading to termination of the bird-lg-go daemon.

bird-lg-go denial-of-service json CVE-2026-45047 linux
2r 1t
medium advisory

Suspicious macOS MS Office Child Process

This rule identifies suspicious child processes of Microsoft Office applications on macOS, which often result from exploitation or malicious macros, by detecting unexpected processes like curl, bash, osascript, and python spawned by Office apps, while filtering out false positives related to product version discovery, error reporting, and legitimate software.

Microsoft Word +7 endpoint macos initial_access microsoft_office
2r 6t
medium advisory

CVE-2026-32226 .NET Framework Denial of Service Vulnerability

CVE-2026-32226 is a denial of service vulnerability in the .NET Framework that can be mitigated by applying the latest security update.

.NET Framework dotnet dos cve
2r 1t 1c
medium advisory

Next.js Cache Components Vulnerable to Denial-of-Service via Connection Exhaustion (CVE-2026-44579)

Next.js applications using Partial Prerendering through Cache Components are vulnerable to connection exhaustion (CVE-2026-44579), where crafted POST requests to a server action trigger a request-body handling deadlock, consuming server capacity and leading to denial of service.

next +1 denial-of-service connection-exhaustion next.js cve-2026-44579
2r 1t
medium advisory

Ubuntu Linux Kernel Vulnerabilities Addressed in Security Notices

Ubuntu released security notices between May 4 and 10, 2026, addressing vulnerabilities in the Linux kernel affecting Ubuntu 20.04 LTS, 22.04 LTS, 24.04 LTS, and 25.10, requiring timely updates.

Ubuntu 20.04 LTS +3 linux kernel vulnerability patch
2r
medium advisory

Urllib3 Decompression Bomb Vulnerability in Streaming API (CVE-2026-44432)

Urllib3 versions before 2.7.0 are vulnerable to excessive resource consumption when using the streaming API to decompress responses, particularly when using the Brotli library or calling HTTPResponse.drain_conn() after partial decompression, leading to high CPU usage and memory allocation, potentially causing a denial-of-service condition (CVE-2026-44432).

urllib3 decompression-bomb denial-of-service vulnerability
2r 1t
medium advisory

@vitejs/plugin-rsc Denial-of-Service Vulnerability in React Server Components

@vitejs/plugin-rsc is vulnerable to a denial-of-service attack due to an embedded vulnerable version of react-server-dom-webpack, potentially causing resource exhaustion.

@vitejs/plugin-rsc +1 denial-of-service react vite
2r 1t 1c
medium advisory

OpenTelemetry Prometheus Exporter Denial-of-Service via Malformed HTTP Request (CVE-2026-44902)

A malformed HTTP request can crash any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics endpoint has no error handling around URL parsing, so a request with an invalid URI causes an uncaught `TypeError` that terminates the process, leading to a denial of service. Update `@opentelemetry/exporter-prometheus` and `@opentelemetry/sdk-node` to version **0.217.0** or later and `@opentelemetry/auto-instrumentations-node` to version **0.75.0** or later to remediate.

@opentelemetry/exporter-prometheus +2 denial-of-service otel prometheus CVE-2026-44902
2r 1t
medium advisory

Apache Airflow Providers OpenSearch and Elasticsearch Information Disclosure Vulnerabilities

A remote, authenticated attacker can exploit multiple vulnerabilities in Apache Airflow Providers OpenSearch and Elasticsearch to disclose sensitive information.

Airflow Providers OpenSearch +1 airflow information-disclosure apache
1r 1t
medium advisory

jq Vulnerability Allows Security Bypass

A local attacker can exploit a vulnerability in jq to bypass security measures.

jq vulnerability security-bypass
1r
medium advisory

HCL BigFix WebUI Information Disclosure Vulnerabilities

A remote, authenticated attacker can exploit multiple vulnerabilities in HCL BigFix WebUI applications to disclose sensitive information.

BigFix WebUI information-disclosure webui hcl
2r 1t
medium threat

Rancher Fleet Helm Deployer Vulnerability Allows Security Bypass

A remote, authenticated attacker can exploit a vulnerability in Rancher Fleet Helm Deployer to bypass security measures and disclose sensitive information, which may enable further attacks.

Fleet Helm Deployer security-bypass information-disclosure rancher
2r 2t
medium advisory

FRRouting Project FRRouting Vulnerability Allows Data Manipulation

A remote, authenticated attacker can exploit a vulnerability in FRRouting Project FRRouting to manipulate data.

FRRouting
2r
medium advisory

Multiple Vulnerabilities in Red Hat Hardened Images RPMs

A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Hardened Images RPMs to cause a denial-of-service condition and possibly manipulate data or perform path traversal attacks.

Hardened Images RPMs vulnerability denial-of-service path-traversal
2r 1t
medium advisory

CVE-2026-23377 Vulnerability

CVE-2026-23377 is a reported vulnerability with no further details available from the Microsoft Security Response Center.

vulnerability
1c
medium advisory

CVE-2026-23276: Net Recursion Limit Vulnerability in Tunnel Xmit Functions

CVE-2026-23276 is a net vulnerability affecting tunnel xmit functions, requiring a fix to add an xmit recursion limit.

cve denial-of-service network
1r 1c
medium advisory

CVE-2025-37877 iommu: Clear iommu-dma ops on cleanup

CVE-2025-37877 is a vulnerability in the iommu component requiring proper cleanup, affecting Microsoft products.

vulnerability iommu cleanup
1c
medium threat

CVE-2026-31712: ksmbd Minimum ACE Size Vulnerability

CVE-2026-31712 is a security vulnerability in ksmbd requiring a minimum ACE size check in smb_check_perm_dacl(), potentially leading to unauthorized access or privilege escalation.

cve smb acl privilege-escalation
2r 1t 1c
medium threat

CVE-2026-31706 ksmbd num_aces Validation Vulnerability

CVE-2026-31706 is a vulnerability in ksmbd related to improper validation of num_aces and insufficient hardening of the ACE walk in smb_inherit_dacl(), potentially leading to unauthorized access or privilege escalation.

ksmbd acl privilege escalation
2r 1c
medium threat

CVE-2025-38717 KCM Race Condition Vulnerability

CVE-2025-38717 is a race condition vulnerability in the kcm_unattach() function of a Microsoft product, potentially leading to denial of service or privilege escalation.

race-condition vulnerability net kcm
2r 1c
medium advisory

CVE-2024-26756: Unspecified Vulnerability in Microsoft Products

Microsoft released details for CVE-2024-26756, an unspecified vulnerability affecting Microsoft products, but provided no further information.

vulnerability microsoft
2r 1c
medium advisory

CVE-2024-26757: Unspecified Vulnerability in Microsoft md

CVE-2024-26757 is an unspecified vulnerability in a Microsoft product, potentially allowing an attacker to perform unauthorized actions.

vulnerability microsoft
2r 1c
medium advisory

memono Notepad 4.2 Denial of Service Vulnerability (CVE-2021-47944)

memono Notepad 4.2 is vulnerable to a denial-of-service attack, allowing attackers to crash the application by pasting excessively long character buffers (specifically, two pastes of 350,000 repeated characters) into note fields on iOS devices, as tracked by CVE-2021-47944.

memono Notepad 4.2 denial-of-service ios CVE-2021-47944
1r 1t 1c
medium advisory

CVE-2026-39826 Escaper Bypass Leads to XSS Vulnerability

CVE-2026-39826 is an escaper bypass vulnerability that leads to cross-site scripting (XSS).

XSS CVE-2026-39826 web-application
1r 1t 1c
medium advisory

free5GC NEF PATCH Handler Vulnerability Leads to Denial of Service

A nil pointer dereference vulnerability exists in free5GC's NEF PATCH /3gpp-pfd-management/v1/{afId}/transactions/{transId}/applications/{appId} handler when UDR access fails, causing a denial-of-service condition.

nef 4.2.1 denial-of-service vulnerability free5GC NEF CVE-2026-44322
2r 1t 3i
medium threat

free5GC SMF Unauthenticated Process-Kill Denial-of-Service via UPI Endpoint

free5GC's SMF is vulnerable to an unauthenticated denial-of-service attack where a crafted POST request to the `/upi/v1/upNodesLinks` endpoint can trigger a `Fatalf` call, terminating the entire SMF process, effectively disrupting network services.

SMF free5GC DoS unauthenticated UPI CVE-2026-44321
2r 1t 1i
medium advisory

Fastify accepts-serializer Denial of Service via Unbounded Accept Header Cache Growth

The @fastify/accepts-serializer package is vulnerable to a denial of service (DoS) attack due to unbounded cache growth, where an attacker can send many distinct Accept header variants, causing the cache to grow unbounded, exhausting the Node.js heap, and crashing the process.

@fastify/accepts-serializer dos denial-of-service fastify
2r 1t 1c
medium advisory

Dronecode PX4 Autopilot MavlinkLogHandler Stack Buffer Overflow DoS (CVE-2026-32743)

A stack-based buffer overflow vulnerability exists in Dronecode PX4 Autopilot versions up to and including 1.17.0-rc2 that allows an attacker with MAVLink link access to cause a denial of service by creating a deeply nested directory via MAVLink FTP and then requesting the log list, crashing the MAVLink task.

Px4_Drone_Autopilot +1 px4 autopilot drone denial-of-service buffer-overflow
2r 3t 1c
medium advisory

Zebra Node Denial-of-Service Vulnerability via Crafted Orchard Transactions (CVE-2026-41584)

A crafted Orchard transaction with a zero-value rk field can cause a Zebra node to crash due to a panic in the orchard crate, leading to a denial-of-service condition; this vulnerability is identified as CVE-2026-41584 and patched in zebrad version 4.3.1 and zebra-chain version 6.0.2.

zebra-chain +1 denial-of-service zcash cryptography
1r 1t 1c
medium advisory

Mozilla Firefox Multiple Vulnerabilities

Mozilla released security updates to address vulnerabilities in Firefox and Firefox ESR versions, potentially allowing for exploitation if left unpatched.

Firefox +1 vulnerability browser mozilla
2r 2t
medium threat

Dronecode PX4-Autopilot tattu_can Stack Buffer Overflow (CVE-2026-32707)

A stack-based buffer overflow vulnerability exists in the `tattu_can` driver of Dronecode PX4-Autopilot versions 1.17.0-rc1 and earlier; by injecting specially crafted CAN frames, an attacker can trigger an unbounded memcpy operation, leading to a stack corruption and subsequent crash of the PX4 process, resulting in a denial of service.

PX4-Autopilot Mohammed Idrees Banyamer stack buffer overflow denial of service CVE-2026-32707
2r 1t 1c
medium advisory

Ruby Multiple Vulnerabilities Lead to DoS and Information Disclosure

A remote, anonymous attacker can exploit multiple unspecified vulnerabilities in Ruby to perform a denial of service attack or disclose sensitive information.

Ruby dos information_disclosure vulnerability
2r 1t
medium advisory

Microsoft 365 Copilot Business Chat Information Disclosure Vulnerabilities

Multiple vulnerabilities in Microsoft 365 Copilot Business Chat allow an anonymous remote attacker to disclose sensitive information.

Microsoft 365 Copilot Business Chat information-disclosure cloud microsoft365
2r 1t
medium advisory

Avast Antivirus Privilege Escalation Vulnerability

A local attacker can exploit a vulnerability in Avast Antivirus and AVG Technologies Anti-Virus to escalate privileges on a Windows system.

Avast Antivirus +1 privilege-escalation antivirus windows
2r 1t
medium advisory

WordPress Auto Affiliate Links Plugin Stored XSS Vulnerability (CVE-2026-7330)

The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to 6.8.8 due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into the admin statistics page.

Auto Affiliate Links plugin <= 6.8.8 wordpress xss plugin
2r 1t 1c
medium advisory

CVE-2026-41675 xmldom XML Node Injection Vulnerability

CVE-2026-41675 is an XML node injection vulnerability in the xmldom library, potentially leading to code execution or information disclosure in applications that process XML data using the affected library.

xmldom xml-injection cve
2r 1c
medium advisory

Zebra Block Validator Sigops Undercount Vulnerability

Zebra's block validator undercounts signature operations, allowing it to accept invalid blocks, leading to a network split between Zebra and zcashd nodes.

zebra blockchain consensus-failure zcash
2r
medium advisory

CVE-2026-42826 Azure DevOps Information Disclosure Vulnerability

CVE-2026-42826 is an information disclosure vulnerability in Azure DevOps that allows unauthorized disclosure of sensitive information over a network.

Azure DevOps information disclosure cloud
2r 1t
medium advisory

CVE-2026-40379 Microsoft Enterprise Security Token Service (ESTS) Spoofing Vulnerability

CVE-2026-40379 is a spoofing vulnerability in Microsoft Enterprise Security Token Service (ESTS) where exposure of sensitive information in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.

Enterprise Security Token Service +1 entra_id spoofing cloud
2r 1t
medium advisory

CVE-2026-35428 Azure Cloud Shell Spoofing Vulnerability

CVE-2026-35428 is a command injection vulnerability in Azure Cloud Shell that allows an unauthorized attacker to perform spoofing over a network.

Azure Cloud Shell command-injection spoofing cloud
1r 1t
medium advisory

CVE-2026-33823 Microsoft Teams Information Disclosure Vulnerability

CVE-2026-33823 is an information disclosure vulnerability in Microsoft Teams that allows an authorized attacker to disclose sensitive information over a network due to improper authorization.

Teams information-disclosure cloud microsoft-teams
1r 1t
medium advisory

CVE-2026-33111 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability

CVE-2026-33111 is a command injection vulnerability in Microsoft Edge's Copilot Chat feature that allows an unauthorized attacker to disclose information over a network.

Copilot Chat cve-2026-33111 command injection information disclosure
2r 1t
medium advisory

CVE-2026-32207 Azure Machine Learning Notebook Spoofing Vulnerability

CVE-2026-32207 is a cross-site scripting vulnerability in Azure Machine Learning, allowing an unauthorized attacker to perform spoofing over a network.

Azure Machine Learning xss spoofing azure
2r 1t
medium advisory

CVE-2026-26164 M365 Copilot Information Disclosure Vulnerability

CVE-2026-26164 is an information disclosure vulnerability in M365 Copilot due to improper neutralization of special elements, allowing unauthorized information disclosure over a network.

M365 Copilot information disclosure cloud vulnerability
2r 1t
medium advisory

DivvyDrive Stored XSS Vulnerability

DivvyDrive versions 4.8.2.9 before 4.8.3.2 are susceptible to stored cross-site scripting (XSS) due to improper neutralization of user-supplied input during web page generation, potentially allowing attackers to execute arbitrary JavaScript in a user's browser.

DivvyDrive xss stored-xss web-application
2r 1t 1c
medium advisory

DivvyDrive Cross-Site Scripting (XSS) Vulnerability (CVE-2026-6002)

DivvyDrive versions 4.8.2.9 before 4.8.3.2 are susceptible to cross-site scripting (XSS) due to improper neutralization of script-related HTML tags, potentially allowing an attacker to inject malicious scripts.

DivvyDrive xss cve-2026-6002 web-application
2r 1t 1c
medium advisory

Proticaret E-Commerce Reflected XSS Vulnerability (CVE-2026-3953)

A reflected cross-site scripting (XSS) vulnerability exists in Gosoft Software Industry and Trade Ltd. Co.'s Proticaret E-Commerce software (versions v5.0.0 before V 6.0.1767.1383) due to improper neutralization of input during web page generation, potentially allowing attackers to execute arbitrary JavaScript in a user's browser.

Proticaret E-Commerce xss cross-site scripting reflected xss web application vulnerability
2r 1t 1c
medium advisory

MAXHUB Pivot Client Application Vulnerability CVE-2026-6411

A vulnerability exists in MAXHUB Pivot client application versions prior to v1.36.2, where a hardcoded AES key allows attackers to decrypt tenant email addresses and associated metadata, and potentially cause a denial-of-service via unauthorized device enrollment through MQTT.

MAXHUB Pivot client application cve-2026-6411 maxhub pivot broken-crypto dos
2r 1t
medium advisory

Google Chrome Security Update Required

Google released a security advisory addressing vulnerabilities in Chrome for Desktop versions prior to 148.0.7778.96/97 on Windows/Mac and 148.0.7778.96 on Linux, requiring users to update to mitigate potential exploits.

Chrome +1 vulnerability browser
2r
medium advisory

Cisco Crosswork Network Controller and Network Services Orchestrator Connection Exhaustion Denial of Service

An unauthenticated remote attacker can cause a denial-of-service condition on Cisco Crosswork Network Controller and Network Services Orchestrator by exhausting connection resources via a high volume of connection requests.

Crosswork Network Controller +1 denial-of-service cisco network
2r 1t
medium advisory

Broadcom Tanzu Jammy Stemcell Vulnerability (CVE-2026-341431)

A vulnerability in Broadcom's Tanzu Jammy Stemcell versions prior to 1.1193, tracked as CVE-2026-341431, requires patching to prevent potential exploitation.

Tanzu Jammy Stemcell vmware tanzu vulnerability
2r 1t
medium advisory

CPython Multiple Vulnerabilities Allow File Manipulation and DoS

A remote, authenticated attacker can exploit multiple vulnerabilities in CPython to manipulate files or cause a denial-of-service condition.

CPython vulnerability dos file_manipulation
2r 2t
medium advisory

Erlang/OTP Information Disclosure Vulnerability

A remote, authenticated attacker can exploit an unspecified vulnerability in Erlang/OTP to disclose sensitive information.

Erlang/OTP information-disclosure vulnerability erlang
2r 1t
medium advisory

Red Hat OpenShift Service Mesh Multiple Vulnerabilities

An anonymous remote attacker can exploit multiple vulnerabilities in Red Hat OpenShift Service Mesh to manipulate files, disclose information, or cause a denial-of-service condition.

OpenShift Service Mesh openshift servicemesh vulnerability dos
2r 4t
medium advisory

CallPhantom Android Apps Falsely Promise Call History for Payment

ESET researchers discovered 28 fraudulent Android apps, named CallPhantom, on Google Play that falsely claim to provide call logs for any phone number in exchange for payment, generating random data or requesting email addresses and amassing over 7.3 million downloads before being removed.

Google Play android scam callphantom fraud
2r
medium advisory

Microsoft CVE-2026-25833 Vulnerability Published

Microsoft published CVE-2026-25833, a security vulnerability for which details are currently unavailable, impacting systems and requiring further investigation upon release of additional information.

vulnerability microsoft cve-2026-25833
1c
medium advisory

Microsoft Published Information Regarding CVE-2025-66442

Microsoft has published information regarding the vulnerability CVE-2025-66442; details are currently unavailable, limiting specific analysis and detection strategies.

cve vulnerability microsoft
2r 1t 1c
medium advisory

Microsoft Published Information Regarding CVE-2026-25835

Microsoft has published information regarding the vulnerability CVE-2026-25835, but details about the vulnerability, affected products, and exploitation are currently unavailable.

cve vulnerability microsoft
2r 1c
medium advisory

Threat Actors Use Claude AI to Target Water Utility OT Assets

An unidentified threat actor used Claude AI to identify and target a vNode SCADA/IIoT management interface at a Mexican water utility between December 2025 and February 2026, ultimately failing to gain access.

AI OT SCADA password-spraying reconnaissance
2r 2t
medium advisory

OSX.Dummy Malware Targeting Cryptocurrency Community

OSX.Dummy is a new macOS malware targeting the cryptocurrency community, as reported by Objective-See.

OSX.Dummy malware cryptocurrency macos
2r
medium advisory

Mac Adware Injecting Malicious JavaScript via Obfuscated Python Script

A Mac adware, likely a component of OSX.Pirrit, uses multiple layers of obfuscation, including base64 encoding, zlib compression, and variable renaming, to evade detection and inject malicious JavaScript from hxxps://1049434604.rsc.cdn77.org/ij1.min.js.

CleanMyMac X +1 adware macos python javascript_injection
2r 2t 1i
medium advisory

Free5GC UDM Information Disclosure via Malformed Request

The free5GC UDM component fails to validate the `supi` path parameter in six GET handlers, allowing an unauthenticated attacker to inject control characters and trigger a `500 Internal Server Error` that exposes internal infrastructure details.

udm information-disclosure input-validation free5GC
2r 2t 1c
medium advisory

Netty HttpContentDecompressor Brotli/Zstd/Snappy Decompression Bomb Vulnerability

Netty's HttpContentDecompressor and DelegatingDecompressorFrameListener are vulnerable to a decompression bomb denial-of-service attack because the maxAllocation parameter is not enforced when Content-Encoding is set to br (Brotli), zstd, or snappy, allowing attackers to bypass decompression limits and cause unbounded memory allocation.

netty-codec-http +3 decompression-bomb denial-of-service netty http
3r 1t
medium advisory

Netty Lz4FrameDecoder Resource Exhaustion Vulnerability

Netty's Lz4FrameDecoder is vulnerable to resource exhaustion, where an attacker can cause excessive memory allocation by sending a small, crafted header, leading to a denial-of-service condition; this affects netty-codec-compression versions up to 4.2.12.Final and netty-codec versions up to 4.1.132.Final.

netty-codec-compression +1 resource-exhaustion denial-of-service netty
2r 1t
medium advisory

Netty DNS Codec Input Validation Bypass Vulnerability

Netty's DNS codec fails to enforce RFC 1035 domain name constraints, leading to potential DNS cache poisoning, denial-of-service, and domain validation bypass through null byte injection, overlength labels, silent truncation, and unbounded memory allocation.

Netty 4.2.12.Final netty dns vulnerability cache-poisoning
2r 1t
medium advisory

ldap3_proto LDAP Filter Stack Exhaustion Vulnerability

The ldap3_proto package is vulnerable to LDAP Filter stack exhaustion due to unbounded query depth, potentially causing a denial of service in applications processing LDAP queries, affecting versions before 0.7.1.

ldap3_proto ldap denial-of-service rust
2r 1t
medium advisory

Netty epoll Transport Denial of Service via RST on Half-Closed TCP Connection

Netty's epoll transport fails to properly close TCP connections that receive a RST after a half-close, leading to resource exhaustion and potential CPU busy-loops, impacting service availability.

netty-transport-native-epoll denial-of-service netty epoll resource-exhaustion
2r 1t
medium advisory

Snappier SnappyStream Decompression Infinite Loop Vulnerability

Snappier versions 1.3.0 and earlier are vulnerable to a denial-of-service condition where a malformed Snappy stream input to `SnappyStream` decompression causes an infinite loop, consuming a thread until the process is terminated.

Snappier denial-of-service compression infinite-loop
2r 1t
medium advisory

Mezo L1 Bridge Vulnerability Leads to Potential ERC-20 Drain

A vulnerability in the Mezo bridge allows for the potential full drain of the L1 bridge without changing the bridged balance on Mezo due to a stale StateDB overwrite, enabling a malicious user to steal ERC-20 tokens locked in the L1 bridge.

MezoBridge blockchain smart-contract bridge state-overwrite
3r 2t
medium advisory

Samsung Mobile Devices Multiple Vulnerabilities

Samsung released a security update to address multiple vulnerabilities in Samsung mobile devices running versions prior to SMR-MAY-2026 Release 1, potentially allowing attackers to exploit these vulnerabilities for malicious purposes.

Samsung mobile devices mobile vulnerability patch samsung
2r
medium advisory

Mistune Markdown Parser Denial-of-Service Vulnerability

A denial-of-service vulnerability exists in Mistune version 3.2.0 due to excessive parsing and CPU consumption when processing specially crafted reference links, leading to application hangs and service unavailability.

mistune dos vulnerability
2r 1t
medium advisory

Cisco Slido Insecure Direct Object Reference Vulnerability

An insecure direct object reference in Cisco Slido's REST API could have allowed an authenticated remote attacker to access social profile data or affect quiz/poll results.

Slido idor cisco credential-access
2r 1t
medium advisory

Cisco SG350 and SG350X Series Managed Switches SNMP Denial-of-Service Vulnerability

A remote, authenticated attacker can cause a denial-of-service condition on vulnerable Cisco SG350 and SG350X Series Managed Switches by sending a crafted SNMP request due to improper error handling.

SG350 Series Managed Switches +1 snmp denial-of-service cve-2026-20185
2r 1t
medium advisory

Cisco Prime Infrastructure Information Disclosure Vulnerability

Cisco Prime Infrastructure is vulnerable to an information disclosure vulnerability, allowing authenticated remote attackers to download arbitrary log files due to insufficient authorization checks.

Prime Infrastructure information-disclosure vulnerability cisco
2r 3t
medium advisory

Cisco Identity Services Engine Authentication Bypass Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to bypass authorization mechanisms or examine error messages to gain access to sensitive information.

Identity Services Engine cisco authentication-bypass vulnerability
2r 1t
medium advisory

Cisco Enterprise Chat and Email Lite Agent File Upload Vulnerability

An authenticated attacker with agent privileges can upload malicious files to Cisco Enterprise Chat and Email (ECE) via the Lite Agent feature, leading to potential browser-based attacks against other users.

Enterprise Chat and Email cve xss file-upload web-application
2r 1t
medium advisory

Broadcom Patches Vulnerabilities in Tanzu GemFire Management Console

Broadcom released a security advisory addressing vulnerabilities in Tanzu GemFire Management Console versions prior to 1.4.4, prompting users to apply necessary updates to mitigate potential risks.

Tanzu GemFire Management Console < 1.4.4 vulnerability broadcom tanzu
2r 1t
medium advisory

Plug.Cowboy HTTP/2 Atom Table Exhaustion DoS

An unauthenticated remote denial-of-service vulnerability in Plug.Cowboy allows attackers to exhaust the BEAM atom table via HTTP/2 requests, crashing the Erlang VM.

plug_cowboy +1 denial-of-service http2 atom-exhaustion
2r 1t 1c
medium advisory

Dell Security Advisories Address Multiple Vulnerabilities

Dell published security advisories addressing vulnerabilities in APEX Cloud Platform, Automation Platform, Command | Monitor, CyberSense, NativeEdge Orchestrator, SmartFabric Manager, iDRAC, Disk Library, and PowerProtect Cyber Recovery, requiring users to apply necessary updates.

APEX Cloud Platform for Red Hat OpenShift +9 vulnerability patch dell
2r
medium advisory

CISA ICS Advisories Addressing ABB and NSA Products

CISA published ICS advisories addressing vulnerabilities in multiple ABB products including AWIN Gateways, Ability OPTIMAX, Symphony Plus Engineering, Edgenius Management Portal, PCM600, System 800xA, Symphony Plus IEC 61850, and NSA GRASSMARLIN, prompting users to apply mitigations and updates.

AWIN Gateways +7 ics vulnerability abb nsa ot
2r
medium advisory

ABB B&R PVI Sensitive Information Logging Vulnerability

An authenticated local attacker can gather credential information from ABB B&R PVI client application logs when logging is enabled, addressed in version 6.5.0 (CVE-2026-0936).

ABB B&R PVI ics industrial control systems credential access logging
2r 1c
medium advisory

Argo CD Information Disclosure Vulnerability

A remote, authenticated attacker can exploit a vulnerability in Argo CD to disclose sensitive information.

argo cd argocd information-disclosure cloud
2r 2t
medium advisory

MinIO Information Disclosure Vulnerability

A remote, authenticated attacker can exploit a vulnerability in MinIO to disclose sensitive information.

MinIO information-disclosure
2r 1t
medium advisory

Multiple Vulnerabilities in Rapid7 Velociraptor

Multiple vulnerabilities in Rapid7 Velociraptor could allow an attacker to perform a denial-of-service attack or disclose sensitive information.

Velociraptor vulnerability denial-of-service information-disclosure
2r 2t
medium advisory

Phone Number Reuse in Scam Email Campaigns

Talos has begun tracking phone numbers in emails as indicators of compromise, revealing insights into their reuse in scam campaigns where attackers use API-driven VoIP services for cost-effective operations, rotating phone number blocks to evade security filters, and maximizing reach by recycling numbers across diverse lures.

Geek Squad email phishing voip scam
2r 1t 2i
medium advisory

Red Hat OpenShift Container Platform Security Bypass Vulnerability

A remote, authenticated attacker can exploit a vulnerability in Red Hat OpenShift Container Platform to bypass security measures.

OpenShift Container Platform openshift security-bypass defense-evasion
2r 1t
medium advisory

X.Org X11 and Xwayland Multiple Vulnerabilities

A local attacker can exploit vulnerabilities in X.Org X11 and Xwayland to perform unspecified attacks, including memory corruption, information disclosure, or a denial-of-service condition.

X.Org X11 +1 privilege-escalation information-gathering denial-of-service linux
2r 3t
medium advisory

Multiple Vulnerabilities in OpenSSL Allow for DoS, Information Disclosure, and Ciphertext Recovery

Multiple vulnerabilities in OpenSSL can be exploited by a remote attacker to conduct a denial-of-service attack, disclose information, or recover ciphertext over a network.

OpenSSL vulnerability denial-of-service information-disclosure ciphertext-recovery
2r 2t
medium advisory

LatePoint WordPress Plugin Vulnerable to Stored XSS (CVE-2026-7448)

The LatePoint WordPress plugin is vulnerable to stored cross-site scripting (XSS) via the 'first_name' parameter, affecting versions up to 5.5.0, allowing unauthenticated attackers to inject malicious scripts.

LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.5.0 wordpress xss cve-2026-7448
2r 1t 1c
medium advisory

Microsoft Releases Security Update for CVE-2026-43964

Microsoft has released a security update to address the vulnerability CVE-2026-43964.

vulnerability patch
2r 1c
medium advisory

Multiple Vulnerabilities in Zabbix

Multiple vulnerabilities in Zabbix versions 6.0.x before 6.0.45, 7.0.x before 7.0.24, and 7.4.x before 7.4.8 allow for data confidentiality breaches and remote cross-site scripting (XSS) attacks.

Zabbix < 6.0.45 +2 zabbix xss vulnerability
2r 1t 3c
medium advisory

Multiple Vulnerabilities in Asterisk Allow for Remote Denial of Service

Multiple vulnerabilities in Asterisk versions 20.18.x before 20.19.0, 21.12.x before 21.12.2, 22.8.x before 22.9.0, 23.2.x before 23.3.0, certified-asterisk 20.x before 20.7-cert10, and certified-asterisk 22.x before 22.8-cert2 allow a remote attacker to cause a denial of service.

Asterisk versions 20.18.x +5 asterisk voip denial-of-service
2r 1t 3c
medium advisory

Multiple Unspecified Vulnerabilities in Google Chrome

Multiple unspecified vulnerabilities in Google Chrome prior to version 148.0.7778.96 for Linux and 148.0.7778.96/97 for Windows and Mac could allow an attacker to cause an unspecified security issue.

Chrome +1 vulnerability browser
2r
medium advisory

Prometheus Remote Read Endpoint Denial-of-Service Vulnerability

The Prometheus remote read endpoint is vulnerable to denial of service due to a missing validation of the declared decoded length in snappy-compressed request bodies, allowing unauthenticated attackers to exhaust memory resources.

go/github.com/prometheus/prometheus denial-of-service prometheus snappy
2r 1t 1c
medium advisory

gix-pack Denial-of-Service Vulnerabilities

Multiple denial-of-service vulnerabilities exist in `gix-pack`; crafted delta data can cause unchecked array indexing, leading to panics, and uncapped attacker-controlled size headers enable out-of-memory process kills, triggered by malicious pack data during clone/fetch operations.

gix-pack denial-of-service git gitoxide
2r 1t
medium advisory

Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities

Multiple stored cross-site scripting (XSS) vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to inject malicious code into specific pages of the interface, leading to arbitrary script execution or sensitive information access.

Identity Services Engine xss cisco web-application
2r 1t 2c
medium advisory

graphql-php OverlappingFieldsCanBeMerged Quadratic Complexity Vulnerability

The `OverlappingFieldsCanBeMerged` validation rule in `webonyx/graphql-php` has an `O(n^2 x m^2)` worst-case complexity due to flattened inline fragments, leading to potential resource exhaustion.

graphql-php graphql php resource-exhaustion vulnerability
2r 1t 1c
medium advisory

IObit Advanced SystemCare 19 Symlink Vulnerability (CVE-2026-7832)

IObit Advanced SystemCare 19 is vulnerable to a local symlink following attack due to improper handling in ASC.exe, potentially allowing a local attacker to escalate privileges.

Advanced SystemCare 19 symlink privilege-escalation iobit
2r 1t 1c
medium advisory

OpenClaw Denial-of-Service via Oversized WebSocket Frames

OpenClaw versions prior to 2026.4.10 are vulnerable to a denial-of-service attack where remote attackers can send oversized WebSocket frames to the voice-call realtime path, causing service unavailability.

openclaw < 2026.4.10 denial-of-service websocket cve-2026-42437
2r 1t 1c
medium advisory

ABB B&R Automation Studio Improper Certificate Validation Vulnerability

ABB B&R Automation Studio versions before 6.5 are vulnerable to improper certificate validation (CVE-2025-11043), potentially allowing an unauthenticated attacker to intercept and interfere with data exchanges, necessitating patching and secure network configurations.

B&R Automation Studio <6.5 ics certificate validation man-in-the-middle
2r 2t 1c
medium advisory

ABB B&R Automation Runtime Denial-of-Service Vulnerability

A denial-of-service vulnerability (CVE-2025-11044) exists in ABB B&R Automation Runtime versions prior to 6.5 and R4.93, where an unauthenticated attacker can exploit a race condition to cause permanent denial-of-service.

ABB B&R Automation Runtime dos ics cve-2025-11044
2r 1t 1c
medium advisory

Potential Protocol Tunneling via Cloudflared

Adversaries may abuse Cloudflare Tunnel (cloudflared) on Windows systems to proxy command and control traffic or exfiltrate data through Cloudflare's edge, evading direct connection blocking.

M365 Defender +1 cloudflare tunneling command and control proxy
2r 2t 1i
medium advisory

Microsoft Product Vulnerability CVE-2026-37457

CVE-2026-37457 is a vulnerability affecting a Microsoft product, for which details are currently unavailable.

vulnerability microsoft
2r 1c
medium advisory

RTGS2017 NagaAgent Path Traversal Vulnerability

RTGS2017 NagaAgent up to version 5.1.0 is vulnerable to path traversal via manipulation of the 'Name' argument in the Skills Endpoint, potentially leading to unauthorized file access.

NagaAgent path-traversal web-application cve-2026-7784
2r 2t 1c
medium advisory

Argo Workflows Webhook Interceptor Vulnerable to Unauthenticated Memory Exhaustion (CVE-2026-42294)

Argo Workflows is vulnerable to a denial-of-service (DoS) attack due to unbounded memory allocation in the Webhook Interceptor component.

Argo Workflows < 3.7.14 +2 denial-of-service argo-workflows cloud
2r 1t
medium advisory

Contact Form 7 WordPress Plugin Uncontrolled Resource Consumption Vulnerability

The Contact Form 7 WordPress plugin through version 2.6.7 is vulnerable to uncontrolled resource consumption, allowing unauthenticated attackers to exhaust server memory and crash the PHP process by supplying an arbitrarily large integer value to the REST API endpoint, leading to unbounded loop execution.

Contact Form 7 WordPress plugin wordpress resource-exhaustion denial-of-service cve-2026-25863
2r 1t 1c
medium advisory

Windows Port Forwarding Rule Addition via Registry Modification

An adversary may abuse port forwarding to bypass network segmentation restrictions by creating a new port forwarding rule through modification of the Windows registry.

Elastic Defend +3 port-forwarding registry-modification command-and-control defense-evasion windows
2r 3t
medium advisory

Suspicious Zoom Child Process Execution

A suspicious Zoom child process was detected, indicating a potential attempt to run unnoticed by masquerading as Zoom.exe or exploiting a vulnerability, resulting in the execution of cmd.exe, powershell.exe, pwsh.exe, or powershell_ise.exe.

Microsoft Defender XDR +1 defense-evasion execution windows
2r 6t
medium advisory

Suspicious Windows PowerShell Arguments Detected

This rule identifies the execution of PowerShell with suspicious argument values, often observed during malware installation, by detecting unusual PowerShell arguments indicative of abuse, focusing on patterns like encoded commands, suspicious downloads, and obfuscation techniques.

Elastic Defend +5 powershell malware execution
3r 4t
medium advisory

Suspicious Execution via Windows Command Debugging Utility

Adversaries can abuse the Windows command line debugging utility cdb.exe to execute commands or shellcode from non-standard paths, evading traditional security measures.

Microsoft Defender XDR +5 lolbas defense-evasion windows
2r 2t
medium advisory

SIP Provider Modification for Defense Evasion

This rule detects modifications to the registered Subject Interface Package (SIP) providers, which are used by the Windows cryptographic system to validate file signatures, potentially indicating an attempt to bypass signature validation or inject code for defense evasion.

Microsoft Defender XDR +2 defense-evasion windows registry-modification
2r 1t
medium advisory

Service DACL Modification via sc.exe

Detection of service DACL modifications via `sc.exe` using the `sdset` command, potentially leading to defense evasion by denying service access to legitimate users or system accounts.

Microsoft Defender XDR +2 defense-evasion persistence windows
2r 2t
medium advisory

Remote Desktop File Opened from Suspicious Path

Adversaries may abuse RDP files delivered via phishing from suspicious locations to gain unauthorized access to systems.

M365 Defender +4 initial-access rdp phishing windows
2r 2t
medium advisory

Potential WSUS Abuse for Lateral Movement via PsExec

Adversaries may exploit Windows Server Update Services (WSUS) to execute PsExec for lateral movement within a network by abusing the trusted update mechanism to run signed binaries.

Windows Server Update Services lateral-movement wsus psexec windows
2r 2t
medium advisory

Potential WPAD Spoofing via DNS Record Creation

Detection of a Windows DNS record creation event (5137) with an ObjectDN attribute containing 'DC=wpad', which indicates a potential WPAD spoofing attack to enable privilege escalation and lateral movement.

credential-access wpad-spoofing windows
2r 1t
medium advisory

Potential Pass-the-Hash (PtH) Attempt Detection

This rule detects potential Pass-the-Hash (PtH) attempts in Windows environments by monitoring successful authentications with specific user IDs (S-1-5-21-* or S-1-12-1-*) and the `seclogo` logon process, where attackers use stolen password hashes to authenticate and move laterally across systems without needing plaintext passwords.

Windows lateral-movement threat-detection
2r 1t
medium advisory

Potential NetNTLMv1 Downgrade Attack via Registry Modification

This brief details a registry modification attack that downgrades the system to NTLMv1 authentication, enabling NetNTLMv1 downgrade attacks, typically performed with local administrator privileges on Windows systems.

Microsoft Defender XDR +2 defense-evasion ntlm registry-modification windows
2r 2t
medium advisory

Potential Evasion via Windows Filtering Platform Blocking Security Software

Adversaries may add malicious Windows Filtering Platform (WFP) rules to prevent endpoint security solutions from sending telemetry data, impairing defenses, which this rule detects by identifying multiple WFP block events where the process name is associated with endpoint security software.

Windows Filtering Platform +2 defense-evasion windows-filtering-platform endpoint-security
2r 2t
medium advisory

Potential DLL Side-Loading via Trusted Microsoft Programs

This rule detects potential DLL side-loading attempts by identifying instances of Windows trusted programs (WinWord.exe, EXPLORER.EXE, w3wp.exe, DISM.EXE) being started after being renamed or from a non-standard path, which is a common technique to evade defenses by side-loading a malicious DLL into the memory space of a trusted process.

WinWord.exe +4 defense-evasion execution dll-side-loading windows
2r 2t
medium advisory

Potential Data Exfiltration via Rclone

Attackers are abusing the legitimate file synchronization tool rclone, often renamed to masquerade as legitimate software, to exfiltrate data to cloud storage or remote endpoints.

Elastic Defend data-exfiltration rclone masquerading
2r 3t
medium advisory

Potential Computer Account NTLM Relay Activity

Detection of potential NTLM relay attacks targeting computer accounts by identifying authentication events originating from hosts other than the account's owner, indicating possible credential theft and misuse.

credential-access threat-detection windows
2r 2t
medium advisory

Potential Active Directory Replication Account Backdoor

Attackers can modify Active Directory object security descriptors to grant DCSync rights to unauthorized accounts, creating a backdoor to extract credential data.

Active Directory credential-access persistence active-directory dcsync
2r 2t
medium advisory

Potential Account Takeover - Logon from New Source IP

The rule identifies a user account that normally logs in with high volume from one source IP suddenly logging in from a different source IP, potentially indicating account takeover or use of stolen credentials from a new location.

Elastic Security account-takeover credential-access windows
2r 1t
medium advisory

Local Account TokenFilter Policy Modification for Defense Evasion and Lateral Movement

Adversaries may modify the LocalAccountTokenFilterPolicy registry key to bypass User Account Control (UAC) and gain elevated privileges remotely by granting high-integrity tokens to remote connections from local administrators, facilitating lateral movement and defense evasion.

Elastic Defend +3 defense-evasion lateral-movement persistence registry-modification
2r 4t
medium advisory

Code Signing Policy Modification Through Built-in Tools

Attackers may attempt to disable or modify code signing policies on Windows systems by using built-in tools like bcdedit.exe in order to execute unsigned or self-signed malicious code.

M365 Defender +1 defense-evasion code-signing windows
2r 1t
medium threat

Multiple Vulnerabilities in Mutt Email Client Lead to Potential DoS

A remote, anonymous attacker can exploit multiple vulnerabilities in mutt to bypass security measures and cause a denial-of-service condition.

exploited mutt denial-of-service email
2r 3t
medium advisory

libexif Vulnerability Allows Code Execution

A local attacker can exploit a vulnerability in libexif to potentially execute arbitrary code, cause a denial of service, or disclose sensitive information.

libexif vulnerability code-execution denial-of-service
2r 2t
medium advisory

Grafana Multiple Vulnerabilities Leading to XSS and Information Disclosure

Multiple vulnerabilities in Grafana allow a remote, anonymous attacker to conduct a Cross-Site Scripting attack or disclose information.

Grafana xss information-disclosure cloud
2r 1t
medium advisory

Tegsoft Online Support Application Reflected XSS Vulnerability (CVE-2025-14320)

CVE-2025-14320 is a reflected cross-site scripting (XSS) vulnerability in Tegsoft Online Support Application versions V3 through 31122025, allowing attackers to inject arbitrary web scripts into user browsers.

Online Support Application xss reflected-xss cve-2025-14320
2r 1t 1c
medium advisory

Multiple Vulnerabilities in Rapid7 Velociraptor

Multiple vulnerabilities in Rapid7 Velociraptor could allow an attacker to disclose information or cause a denial of service.

Velociraptor vulnerability denial-of-service information-disclosure
2r 3t
medium advisory

osrg GoBGP Integer Underflow Vulnerability

osrg GoBGP up to version 4.3.0 is vulnerable to an integer underflow in the parseRibEntry function, potentially allowing a remote attacker to cause a denial of service or other unspecified impacts; version 4.4.0 addresses this issue.

GoBGP cve vulnerability integer underflow bgp
2r 1t 1c
medium advisory

Microsoft Product Vulnerability CVE-2026-37555

CVE-2026-37555 is a vulnerability affecting a Microsoft product, requiring further investigation upon patch release.

vulnerability microsoft cve-2026-37555
2r 1c
medium advisory

NEX-Forms WordPress Plugin Vulnerable to Stored Cross-Site Scripting (CVE-2026-5063)

The NEX-Forms WordPress plugin is vulnerable to stored XSS via POST parameter key names, allowing unauthenticated attackers to inject arbitrary web scripts.

NEX-Forms – Ultimate Forms Plugin for WordPress plugin <= 9.1.11 wordpress xss stored-xss cve-2026-5063
2r 1t 1c
medium advisory

TRENDnet TEW-821DAP Firmware Update Buffer Overflow Vulnerability

A buffer overflow vulnerability exists in TRENDnet TEW-821DAP version 1.12B01, allowing a remote attacker to execute arbitrary code by manipulating the 'str' argument in the auto_update_firmware function of the Firmware Update component.

TEW-821DAP buffer-overflow firmware-update network-device
2r 1t 1c
medium advisory

Gravity Forms Plugin Stored XSS Vulnerability (CVE-2026-5113)

The Gravity Forms plugin for WordPress is vulnerable to stored cross-site scripting (XSS) via Consent field hidden inputs, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the entries list page.

Gravity Forms plugin <= 2.10.0 xss wordpress gravityforms cve-2026-5113 stored-xss
2r 2t 1c
medium advisory

libssh2 Integer Overflow Vulnerability (CVE-2026-7598)

An integer overflow vulnerability exists in libssh2 versions up to 1.11.1 within the userauth_password function of src/userauth.c, which can be triggered remotely by manipulating username_len/password_len arguments.

libssh2 <= 1.11.1 cve integer_overflow libssh2
2r 1t 1c
medium advisory

AWS SSM Session Manager Child Process Execution Abuse

Adversaries abuse AWS Systems Manager (SSM) Session Manager to gain remote execution and lateral movement within AWS environments by spawning malicious child processes from the SSM session worker, leveraging legitimate AWS credentials and IAM permissions.

AWS Systems Manager Session Manager aws ssm session-manager execution cloud
2r 3t
medium advisory

AWS EC2 Role GetCallerIdentity from New Source AS Organization

The rule detects when an EC2 instance role session calls AWS STS GetCallerIdentity from a new source autonomous system (AS) organization name, indicating potential credential theft and verification from outside expected egress paths.

Amazon Web Services cloud aws getcalleridentity ec2 discovery
2r 1t
medium advisory

AWS Discovery API Calls from VPN ASN by New Identity

This rule detects the initial use of AWS discovery APIs from VPN-associated ASNs by a previously unseen identity, indicating potential reconnaissance activity.

Amazon Web Services cloud aws discovery vpn
2r 1t
medium advisory

JetBrains IntelliJ IDEA Vulnerability

A vulnerability exists in JetBrains IntelliJ IDEA versions prior to 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1 and 2026.1.1, requiring users to update to the latest versions.

IntelliJ IDEA vulnerability jetbrains intellij-idea
2r
medium advisory

Prosody Memory Exhaustion Vulnerability (CVE-2026-43506)

Prosody versions before 0.12.6, versions 1.0.0 through 13.0.0, and before version 13.0.5 are vulnerable to a denial of service due to memory leaks from unauthenticated connections, leading to memory exhaustion.

Prosody denial-of-service memory exhaustion
2r 1t 1c
medium advisory

Microsoft Edge Stable Channel Vulnerabilities Addressed in April 2026 Update

Microsoft addressed vulnerabilities in Microsoft Edge Stable Channel versions prior to 147.0.3912.98 with a security update released on April 30, 2026, requiring users to update to the latest version.

Microsoft Edge Stable Channel vulnerability browser patch
2r
medium advisory

Microsoft Product Vulnerability CVE-2026-41526

CVE-2026-41526 is a vulnerability affecting an unspecified Microsoft product, requiring further investigation upon patch release for exploitation details.

vulnerability microsoft
1c
medium advisory

Libssh Denial-of-Service Vulnerability via Inefficient Regular Expression Processing (CVE-2026-0967)

CVE-2026-0967 is a denial-of-service vulnerability in libssh, stemming from inefficient regular expression processing that could lead to defense evasion and impact availability on affected systems.

libssh denial-of-service CVE-2026-0967 defense-evasion
2r 1t 1c
medium advisory

IBM Langflow Desktop Unauthenticated Image Access via IDOR

IBM Langflow Desktop versions 1.0.0 through 1.8.4 are vulnerable to an indirect object reference (IDOR) vulnerability (CVE-2026-4503), allowing unauthenticated users to view other users' images due to a user-controlled key.

Langflow Desktop idor vulnerability privilege-escalation
2r 1t 1c
medium advisory

Sentry SAML SSO Improper Authentication Allows User Identity Linking

A critical vulnerability (CVE-2026-42354) exists in Sentry's SAML SSO implementation that allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance, affecting self-hosted users with multiple organizations configured if a malicious user has permissions to modify SSO settings, while Sentry SaaS was patched in April and self-hosted users are advised to upgrade to version 26.4.1 or higher.

sentry +1 authentication saml sso account takeover vulnerability
2r 1t
medium advisory

HPE Security Advisory for Telco Service Orchestrator and Activator

HPE released a security advisory addressing multiple vulnerabilities in HPE Telco Service Orchestrator (versions prior to v5.6.0) and HPE Telco Service Activator (versions 10.5.0 and prior), urging users to apply necessary updates.

HPE Telco Service Orchestrator +1 vulnerability hpe telco
2r
medium advisory

Hickory DNS Recursor Cache Poisoning via Sibling Zone Delegation

The experimental `hickory-recursor` crate in Hickory DNS is vulnerable to cross-zone cache poisoning due to storing DNS records keyed by record name/type instead of query, enabling an attacker to redirect queries for a victim zone to an attacker-controlled nameserver.

hickory-recursor +1 dns cache-poisoning zone-delegation
2r
medium advisory

GNU InetUtils Vulnerabilities Prior to 2.8

GNU released a security advisory addressing critical vulnerabilities in GNU InetUtils versions prior to 2.8, prompting users to apply necessary updates.

InetUtils vulnerability gnu
2r
medium advisory

MeWare PDKS Improper Control of Interaction Frequency Vulnerability (CVE-2026-7402)

MeWare PDKS versions V16.20200313 before VMYR_3.5.2025117 are vulnerable to improper control of interaction frequency, potentially leading to flooding attacks.

PDKS dos cve-2026-7402
1r 1c
medium advisory

ABB System 800xA and Symphony Plus IEC 61850 Denial-of-Service Vulnerability

A vulnerability in ABB's IEC 61850 communication stack allows a remote attacker with access to the IEC 61850 network to cause a denial-of-service condition by sending a specially crafted packet, leading to device faults or communication driver crashes.

ABB System 800xA +5 ics denial-of-service industrial-control-system iec61850
2r 1t 1c
medium advisory

ABB PCM600 Path Traversal Vulnerability (CVE-2018-1002208)

A path traversal vulnerability in ABB PCM600 versions 1.5 to 2.13 (CVE-2018-1002208) allows a local attacker with low privileges to execute arbitrary code by sending a specially crafted message to the system node.

ABB PCM600 ics path traversal industrial control system
2r 1t 1c
medium advisory

libsndfile Vulnerability Allows Denial of Service

A remote, unauthenticated attacker can exploit an unpatched vulnerability in libsndfile to cause a denial of service.

libsndfile denial-of-service vulnerability
2r 1t
medium advisory

DNSdist Multiple Vulnerabilities Leading to Denial of Service

Multiple vulnerabilities in DNSdist can be exploited by an attacker to perform a denial of service attack, impacting the availability of DNS services.

DNSdist denial-of-service vulnerability
2r 1t 1c
medium advisory

CVE-2026-32283 Unauthenticated TLS 1.3 KeyUpdate DoS Vulnerability

CVE-2026-32283 is a vulnerability in crypto/tls that allows unauthenticated TLS 1.3 KeyUpdate records, leading to persistent connection retention and a denial-of-service condition.

denial-of-service tls crypto/tls
2r 1t 1c
medium advisory

CVE-2026-28388 NULL Pointer Dereference in Delta CRL Processing

CVE-2026-28388 is a NULL Pointer Dereference vulnerability in an unspecified Microsoft product when processing a Delta CRL, potentially leading to a denial-of-service condition.

cve-2026-28388 denial-of-service certificate revocation list
2r 1c
medium advisory

Microsoft Published Information on CVE-2026-32776

Microsoft published information regarding CVE-2026-32776, however, further details require JavaScript to be enabled, limiting the actionable intelligence at this time.

cve vulnerability
1c
medium advisory

Microsoft CVE-2026-32778 Vulnerability Published

Microsoft published information regarding vulnerability CVE-2026-32778, but no details regarding the vulnerability are available at this time.

cve vulnerability
2r 1c
medium advisory

CVE-2026-34073: Incomplete DNS Name Constraint Enforcement Vulnerability

CVE-2026-34073 is a vulnerability in unspecified Microsoft products due to incomplete DNS name constraint enforcement on peer names, potentially leading to certificate validation bypass.

certificate validation man-in-the-middle dns name constraint tls cve-2026-34073
2r 1c
medium advisory

1024-lab smart-admin Improper Access Control Vulnerability (CVE-2026-7468)

CVE-2026-7468 is an improper access control vulnerability in 1024-lab smart-admin up to version 3.30.0, affecting the /smart-admin-api/druid/index.html file, which can be exploited remotely.

smart-admin access-control vulnerability web-application
2r 1t 1c
medium advisory

Netgate pfSense XSS Vulnerability

A cross-site scripting (XSS) vulnerability affects Netgate pfSense CE (<= 2.8.1) and pfSense Plus (<= 26.03), potentially allowing attackers to inject malicious code.

pfSense CE +1 xss vulnerability pfSense
2r
medium advisory

Multiple Vulnerabilities in SonicWall Products Allow for DoS and Security Policy Bypass

Multiple vulnerabilities in SonicWall firewalls could allow an attacker to cause a remote denial of service and security policy bypass, potentially disrupting network services and compromising security controls.

SOHOW +65 sonicwall firewall dos security_bypass
2r 2t 3c
medium advisory

Admidio SAML Signature Validation Bypass Allows Forged AuthnRequests and LogoutRequests

Admidio's SAML Identity Provider implementation fails to properly validate signatures on SAML AuthnRequests and LogoutRequests, enabling attackers to bypass signature enforcement, potentially disclose user attributes via forged SSO requests, and terminate user sessions via forged SLO requests.

admidio saml signature-bypass authentication authorization web-application
2r 5t
medium advisory

Jenkins Security Advisory Addressing Multiple Plugin Vulnerabilities

Jenkins released a security advisory on April 29, 2026, detailing vulnerabilities in Credentials Binding Plugin, GitHub Plugin, GitHub Branch Source Plugin, HTML Publisher Plugin, Matrix Authorization Strategy Plugin, Microsoft Entra ID Plugin, and Script Security Plugin, urging users to apply necessary updates.

Credentials Binding Plugin +6 jenkins vulnerability plugin
2r
medium advisory

Atomic Red Team MCP Server Automates Adversary Emulation

The Atomic Red Team Model Context Protocol (MCP) server integrates security tests from the Atomic Red Team project with AI assistants, enabling natural language interaction with security tools, bridging the gap between threat intelligence and execution, allowing for automated validation, multi-platform testing, and rapid playbook creation.

Splunk +5 red-teaming adversary-emulation ai
2r 4t
medium advisory

Large-Scale Smishing Campaign Impersonating Transport Authorities

A smishing campaign has been active since December 2025, targeting drivers in 12 countries with fraudulent text messages impersonating transport authorities, toll operators, and parking services, resulting in over 79,000 fraudulent messages sent as of April 2026.

smishing fraud social-engineering
2r 1t
medium advisory

SmarterTools SmarterMail Vulnerability Prior to Build 9610

SmarterTools released a security advisory addressing a vulnerability in SmarterMail versions prior to Build 9610, prompting users to update their software.

SmarterMail vulnerability mail-server
2r
medium advisory

OpenClaw Webhook Replay Vulnerability (CVE-2026-41395)

OpenClaw before 2026.3.28 is vulnerable to webhook replay attacks due to improper signature verification, allowing attackers to reorder query parameters and trigger duplicate voice-call processing.

OpenClaw webhook replay-attack plivo
2r 1t 1c
medium advisory

OpenClaw MS Teams Webhook Resource Exhaustion Vulnerability

OpenClaw before 2026.3.31 parses MS Teams webhook request bodies before performing JWT validation, allowing unauthenticated attackers to exhaust server resources by sending malicious Teams webhook payloads.

OpenClaw resource-exhaustion webhook cve-2026-41405
1r 1c
medium threat

Notepad++ Vulnerability in Version 8.9.3 and Prior

A vulnerability exists in Notepad++ version 8.9.3 and prior, prompting a security advisory and the release of version 8.9.4 to address the issue.

exploited Notepad++ 8.9.3 vulnerability notepad++ patch
2r 1t
medium advisory

Mozilla Firefox Multiple Vulnerabilities

Mozilla released a security advisory addressing vulnerabilities in Firefox and Firefox ESR versions prior to 150.0.1, 140.10.1, and 115.35.1, potentially leading to arbitrary code execution or information disclosure.

Firefox +1 vulnerability mozilla
2r 3t
medium threat

Citrix XenServer Vulnerabilities Addressed in Security Advisory AV26-400

Citrix released security advisory AV26-400 on April 28, 2026, addressing vulnerabilities in XenServer versions prior to 8.4, prompting users to apply mitigations.

XenServer virtualization vulnerability
2r 1t
medium advisory

Google Chrome Security Update Released

Google released a security advisory to address vulnerabilities in Chrome for Desktop versions prior to 147.0.7727.137/138 on Windows/Mac and 147.0.7727.137 on Linux, prompting users to apply necessary updates.

Chrome browser vulnerability update
2r
medium advisory

AI-Powered Honeypots: Deceptive Environments for Automated Threat Actors

Generative AI can be used to rapidly deploy adaptive honeypot systems that simulate diverse environments, like Linux shells or IoT devices, to trick and observe AI-driven attacks that prioritize speed over stealth.

honeypot ai deception threat-intelligence
2r 3t 1c
medium advisory

Multiple Vulnerabilities in GNU libc

A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to execute arbitrary program code, cause a denial-of-service condition, or disclose sensitive information.

libc vulnerability glibc denial-of-service code-execution
2r 3t 5c
medium advisory

CVE-2025-68146 filelock TOCTOU Race Condition Enables Symlink Attacks

CVE-2025-68146 describes a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in the filelock library that could allow for symlink attacks during lock file creation, potentially leading to unauthorized file access or modification.

TOCTOU symlink filelock CVE-2025-68146 race condition
2r 1c
medium advisory

rust-openssl Memory Leak via Unchecked Callback Length (CVE-2026-41898)

CVE-2026-41898 describes a vulnerability in rust-openssl where unchecked callback-returned length in PSK and cookie generation can cause OpenSSL to leak adjacent memory to a network peer.

rust-openssl memory-leak tls cve
2r 1c
medium advisory

OpenTelemetry-Go Multi-Value Baggage Header Extraction DoS Vulnerability (CVE-2026-29181)

A vulnerability in OpenTelemetry-Go related to the extraction of multi-value baggage headers can lead to excessive resource allocation, resulting in a remote denial-of-service amplification.

OpenTelemetry-Go dos opentelemetry cve-2026-29181
2r 1t 1c
medium advisory

CoreDNS DoQ Server Denial-of-Service Vulnerability

CoreDNS' DNS-over-QUIC (DoQ) server can be driven into large goroutine and memory growth by a remote client that opens many QUIC streams and stalls after sending only 1 byte, leading to denial of service in versions before 1.14.3.

coredns dos denial-of-service vulnerability
2r 3t 1c
medium advisory

OpenClaw Unauthenticated WebSocket Denial-of-Service Vulnerability

OpenClaw before 2026.3.28 is vulnerable to a denial-of-service attack by accepting unbounded concurrent unauthenticated WebSocket upgrades, allowing attackers to exhaust server resources.

OpenClaw denial-of-service websocket cve
2r 1t 1c
medium advisory

ChatGPTNextWeb NextChat Server-Side Request Forgery Vulnerability

A server-side request forgery (SSRF) vulnerability in ChatGPTNextWeb NextChat up to version 2.16.1 allows remote attackers to manipulate the proxyHandler function, potentially leading to unauthorized internal resource access.

NextChat ssrf cve-2026-7177 web-application
2r 1t 1c
medium advisory

Detection of Github Delete Actions in Audit Logs

This brief focuses on detecting deletion actions within GitHub audit logs, specifically targeting the deletion of codespaces, environments, projects, and repositories, potentially indicating malicious activity or insider threats.

Github audit data-loss impact
2r 1t
medium advisory

Google Workspace Login Attempt with Government Attack Warning

A Google Workspace login attempt flagged as a potential attack by a government-backed threat actor, indicating potential privilege escalation, defense evasion, persistence, initial access, or impact.

Google Workspace googleworkspace intrusion initial-access persistence privilege-escalation
2r 1t
medium advisory

Linux Persistence via Sudoers.d File Manipulation

Attackers can achieve persistence and privilege escalation on Linux systems by creating or modifying files in the /etc/sudoers.d/ directory to grant unauthorized users or groups sudo privileges.

persistence privilege-escalation linux sudoers
3r 2t
medium advisory

Dell Security Advisories Address Vulnerabilities in Multiple Products

Dell published security advisories addressing vulnerabilities in Dell Networking OS10, Dell Storage Monitoring and Reporting, Dell Storage Resource Manager, and Dell VxRail Appliance, urging users to apply necessary updates.

Networking OS10 +3 vulnerability dell
2r
medium advisory

Typecho <= 1.3.0 Server-Side Request Forgery Vulnerability (CVE-2026-7025)

A server-side request forgery (SSRF) vulnerability exists in Typecho up to version 1.3.0, allowing remote attackers to manipulate the X-Pingback/link argument in the Service::sendPingHandle function to potentially make arbitrary HTTP requests.

Typecho ssrf cve-2026-7025
2r 1t 1c
medium advisory

CVE-2026-31622 NFC-A Cascade Depth Bounds Check Failure

CVE-2026-31622 describes a vulnerability related to an NFC bounds check issue, specifically a failure to properly validate NFC-A cascade depth in the SDD response handler within Microsoft products, potentially leading to unexpected behavior or security compromise.

nfc bounds-check-failure cve-2026-31622
2r 1t 1c
medium advisory

CVE-2026-23398 ICMP NULL Pointer Dereference

CVE-2026-23398 is a vulnerability related to a NULL pointer dereference in the ICMP protocol, potentially leading to a denial-of-service condition in affected Microsoft products.

icmp denial-of-service vulnerability cve
2r 1t 1c
medium advisory

vanna-ai vanna Improper Authorization Vulnerability (CVE-2026-6977)

An improper authorization vulnerability (CVE-2026-6977) exists in vanna-ai vanna up to version 2.0.2 due to manipulation of an unknown function within the Legacy Flask API, potentially allowing remote attackers to bypass intended access restrictions.

vanna vulnerability authorization web application
2r 1t 1c
medium advisory

Microsoft Product Vulnerability CVE-2026-41080

CVE-2026-41080 is a vulnerability affecting a Microsoft product; the specific product, impact, and exploitation details are currently undisclosed.

CVE-2026-41080 vulnerability microsoft
2r 1c
medium advisory

OpenClaw Cross-Site Request Forgery Vulnerability

OpenClaw before 2026.3.31 is vulnerable to cross-site request forgery (CSRF) attacks due to missing browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode, allowing attackers to perform unauthorized actions.

OpenClaw csrf web-application vulnerability
2r 1t 1c
medium advisory

Argo Workflows Controller Denial-of-Service via Malformed Pod Annotation

A malformed `workflows.argoproj.io/pod-gc-strategy` annotation in an Argo Workflow pod can trigger an unchecked array index in the `podGCFromPod()` function, leading to a controller-wide panic and denial-of-service.

Argo Workflows argo-workflows denial-of-service kubernetes
2r 2t
medium advisory

xmldom Uncontrolled Recursion DoS Vulnerability

The xmldom library is vulnerable to a denial-of-service (DoS) attack due to uncontrolled recursion in XML serialization leading to application crashes.

xmldom dos recursion javascript
2r 1t
medium advisory

Cisco Integrated Management Controller (IMC) Multiple XSS Vulnerabilities

Multiple cross-site scripting (XSS) vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow a remote attacker to conduct an XSS attack against a user of the interface.

Integrated Management Controller xss cisco cimc vulnerability
2r 1t 5c
medium advisory

Microsoft Product Vulnerability CVE-2026-22005

CVE-2026-22005 is a newly published vulnerability affecting a Microsoft product, requiring further investigation to determine the specific product, attack vector, and potential impact.

CVE-2026-22005 vulnerability microsoft
3r 1c
medium advisory

Microsoft Discloses Information Regarding CVE-2026-22004

Microsoft has released information regarding the vulnerability CVE-2026-22004, but details about the vulnerability and its exploitation are currently unavailable.

cve-2026-22004 vulnerability microsoft
1r 1t 1c
medium advisory

CVE-2026-34303 Affecting Microsoft Products

CVE-2026-34303 is a vulnerability affecting an unspecified Microsoft product, requiring further investigation upon disclosure of details.

vulnerability cve microsoft
2r 1c
medium advisory

IBM WebSphere Liberty Identity Spoofing Vulnerability (CVE-2026-3621)

IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.4 are susceptible to identity spoofing when applications are deployed without proper authentication and authorization configurations, potentially leading to unauthorized access and privilege escalation.

WebSphere Application Server - Liberty cve-2026-3621 websphere identity spoofing cwe-269
2r 1t 1c
medium advisory

Suspicious Processes Connecting to Large Language Model Endpoints

This rule detects DNS queries to known Large Language Model (LLM) domains by unsigned binaries or common Windows scripting utilities, indicating potential command and control activity leveraging LLMs for dynamic actions on compromised systems.

command_and_control malware llm
3r 1t
medium threat

NVIDIA KAI Scheduler Authentication Bypass Vulnerability

CVE-2026-24177 describes an authentication bypass vulnerability in NVIDIA KAI Scheduler that could allow unauthorized access to API endpoints, leading to information disclosure.

exploited vulnerability authentication-bypass nvidia
2r 2t 1c
medium advisory

FreeScout Privilege Escalation via Email Address Reassignment (CVE-2026-40589)

FreeScout versions before 1.8.214 are vulnerable to privilege escalation, allowing a low-privileged agent to reassign email addresses from hidden customers to visible customers, leading to information disclosure and unauthorized access to conversations.

privilege-escalation cve-2026-40589 freescout
2r 1t 1c
medium advisory

FreeScout Incorrect Authorization Vulnerability via Save Draft

FreeScout before 1.8.215 has an incorrect authorization vulnerability where a direct POST request to the `save_draft` AJAX path can create a draft inside a hidden conversation when `APP_SHOW_ONLY_ASSIGNED_CONVERSATIONS` is enabled, potentially allowing unauthorized access or modification of data.

cve authorization web application
2r 1t 1c
medium advisory

FreeScout Incorrect Authorization Vulnerability (CVE-2026-41189)

FreeScout versions before 1.8.215 are vulnerable to an incorrect authorization issue where users without conversation access can edit customer threads due to a flaw in the `ThreadPolicy::edit()` function.

freescout authorization vulnerability
2r 1t 1c
medium advisory

util-linux Vulnerability Allows DoS and Information Disclosure

A local attacker can exploit a vulnerability in util-linux to perform a denial of service attack and disclose sensitive information.

util-linux denial-of-service information-disclosure linux
2r 2t
medium advisory

BigBlueButton Vulnerabilities Allow Data Manipulation and Redirects

Multiple vulnerabilities in BigBlueButton can be exploited by an attacker to manipulate data and redirect users to attacker-controlled domains.

bigbluebutton vulnerability datamanipulation redirect
2r 1t
medium advisory

Oracle VirtualBox Unauthenticated RDP Denial-of-Service Vulnerability (CVE-2026-35245)

An unauthenticated attacker with network access via RDP can exploit CVE-2026-35245 in Oracle VM VirtualBox version 7.2.6 to cause a denial-of-service (DOS) condition.

virtualbox rdp dos cve-2026-35245
2r 1t 1c
medium advisory

ConnectWise Automate Solution Center Cleartext Communication Vulnerability (CVE-2026-6066)

ConnectWise Automate is vulnerable to CVE-2026-6066, a cleartext transmission of sensitive information vulnerability, where certain client-to-server communications could occur without transport-layer encryption, potentially allowing network-based interception of Solution Center traffic, and the issue is resolved in Automate 2026.4 by enforcing secure communication.

cve-2026-6066 connectwise cleartext rmm
2r 1t 1c 1i
medium advisory

Cisco Catalyst SD-WAN Manager Password Disclosure Vulnerability (CVE-2026-20128)

Cisco Catalyst SD-WAN Manager stores passwords in a recoverable format, allowing an authenticated local attacker to gain DCA user privileges by accessing a credential file.

Catalyst SD-WAN Manager cve-2026-20128 credential-access sd-wan cisco
2r 1t 1c
medium advisory

libarchive Multiple Vulnerabilities Allow Information Disclosure and DoS

Multiple vulnerabilities in libarchive can be exploited by a remote attacker to disclose information or cause a denial-of-service condition.

vulnerability denial-of-service information-disclosure
2r 2t
medium advisory

Microsoft CVE-2026-41254 Security Update

Microsoft released a security update for CVE-2026-41254, a vulnerability with unspecified details.

cve vulnerability microsoft
2r 1c
medium advisory

Suspicious RDP File Execution

This rule identifies attempts to open a remote desktop file from suspicious paths, indicative of adversaries abusing RDP files for initial access via phishing.

rdp phishing initial-access windows
2r 2t
medium advisory

CVE-2026-26149 Microsoft Power Apps Spoofing Vulnerability

A spoofing vulnerability exists in Microsoft Power Apps, identified as CVE-2026-26149, potentially allowing an attacker to mislead users or gain unauthorized access.

CVE-2026-26149 powerapps spoofing
2r 1c
medium advisory

Langflow Multiple Vulnerabilities

Multiple vulnerabilities in Langflow allow an attacker to manipulate files, disclose sensitive information, or conduct cross-site scripting attacks.

langflow vulnerability xss file-manipulation information-disclosure
2r 2t
medium advisory

Multiple Vulnerabilities in Gitea

Multiple vulnerabilities in Gitea could allow an attacker to disclose information, bypass security measures, and perform cross-site scripting attacks.

gitea vulnerability xss
1r 1t
medium advisory

Moxi Blog v2 <= 5.2 Server-Side Request Forgery Vulnerability

A server-side request forgery (SSRF) vulnerability exists in moxi624 Mogu Blog v2 up to version 5.2, specifically affecting the `LocalFileServiceImpl.uploadPictureByUrl` function, allowing remote attackers to potentially interact with internal resources.

SSRF Mogu Blog CVE-2026-6625
2r 1t
medium advisory

OpenClaw Webchat Media Embedding Local-Root Containment Bypass

A vulnerability in OpenClaw versions 2026.4.7 to before 2026.4.15 allows a crafted tool-result media reference to cause the host to attempt local file reads or Windows UNC/network path access, potentially disclosing files or network credentials.

openclaw local-file-inclusion unc-path
2r 2t
medium advisory

Movary SSRF Vulnerability (CVE-2026-40348)

Movary versions before 0.71.1 are vulnerable to server-side request forgery (SSRF) via the `/settings/jellyfin/server-url-verify` endpoint, allowing authenticated users to probe internal network resources.

ssrf cve-2026-40348 movary web-application
2r 2t 1c
medium advisory

WeGIA Stored Cross-Site Scripting Vulnerability (CVE-2026-40286)

A stored Cross-Site Scripting (XSS) vulnerability exists in WeGIA versions prior to 3.6.10, allowing attackers to inject malicious scripts into the 'Member Name' field during member registration, leading to persistent execution upon user access.

xss web-application cve-2026-40286
2r 1t 1c
medium advisory

Firebird FB3 Client Library Information Leak (CVE-2025-65104)

Firebird FB3 client library incorrectly handles data lengths when communicating with FB4+ servers, leading to an information leak exploitable by a local attacker.

cve-2025-65104 information-leak firebird
2r 1t 1c
medium advisory

Mobatek MobaXterm Home Edition Uncontrolled Search Path Vulnerability (CVE-2026-6421)

CVE-2026-6421 is an uncontrolled search path vulnerability in Mobatek MobaXterm Home Edition up to version 26.1, affecting msimg32.dll, that can be exploited locally with high complexity.

cve vulnerability mobaxterm dll hijacking
2r 1t 1c
medium advisory

HashiCorp Vault Denial-of-Service Vulnerability (CVE-2026-5807)

HashiCorp Vault is vulnerable to a denial-of-service (DoS) condition, identified as CVE-2026-5807, where an unauthenticated attacker can repeatedly initiate or cancel root token generation or rekey operations, preventing legitimate operators from completing these workflows.

denial-of-service vault cve-2026-5807
2r 1t 1c
medium advisory

Vault kvv2 Policy Bypass Vulnerability Leading to Denial-of-Service (CVE-2026-3605)

An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write, resulting in denial-of-service, addressed in Vault versions 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

vault kvv2 denial-of-service cve-2026-3605
2r 1t 1c
medium advisory

Google Chrome V8 Type Confusion Vulnerability (CVE-2026-6363)

A type confusion vulnerability (CVE-2026-6363) in Google Chrome's V8 JavaScript engine before version 147.0.7727.101 allows a remote attacker to potentially perform out-of-bounds memory access via a crafted HTML page.

cve-2026-6363 chrome v8 type confusion
2r 2t 1c
medium advisory

PowMix Botnet Targeting Czech Workforce

The PowMix botnet campaign targets Czech organizations, particularly HR, legal, and recruitment agencies, using compliance-themed lures delivered via phishing emails, with the attack employing a Windows shortcut file that executes a PowerShell loader to bypass AMSI and deploy the botnet payload in memory.

powmix botnet czech-republic heroku
3r 5t 1i
medium advisory

Weblate Path Traversal Vulnerability in ZIP Download Feature (CVE-2026-34242)

Weblate versions before 5.17 are vulnerable to path traversal due to improper verification of downloaded files in the ZIP download feature, potentially allowing attackers to access files outside the intended repository.

weblate path-traversal zip-archive cve-2026-34242
2r 2t 1c
medium advisory

Git for Windows NTLM Hash Leak Vulnerability (CVE-2026-32631)

Git for Windows versions prior to 2.53.0.windows.3 are vulnerable to NTLM hash theft by attackers who can trick users into cloning malicious repositories or checking out malicious branches, leading to potential credential compromise.

cve credential-access windows git
2r 1t 1c
medium advisory

Windows Remote Desktop Spoofing Vulnerability (CVE-2026-26151)

CVE-2026-26151 is a spoofing vulnerability in Windows Remote Desktop due to an insufficient UI warning for dangerous operations, allowing an unauthorized attacker to perform spoofing over a network.

cve-2026-26151 rdp spoofing windows
2r 2t 1c
medium advisory

Microsoft Excel Out-of-Bounds Read Vulnerability (CVE-2026-32188)

An out-of-bounds read vulnerability in Microsoft Office Excel (CVE-2026-32188) allows a local attacker to potentially disclose sensitive information through a maliciously crafted Excel file.

excel out-of-bounds read cve-2026-32188 information disclosure vulnerability
2r 1t 1c
medium advisory

Adobe ColdFusion Improper Input Validation Vulnerability (CVE-2026-27306)

An improper input validation vulnerability in Adobe ColdFusion versions 2023.18, 2025.6, and earlier (CVE-2026-27306) could lead to arbitrary code execution if a privileged user opens a specially crafted malicious file.

cve-2026-27306 coldfusion code execution input validation
2r 1t 1c
medium advisory

Keycloak Cross-Site Scripting Vulnerability

An authenticated remote attacker can exploit a vulnerability in Keycloak to perform a Cross-Site Scripting attack, potentially leading to unauthorized access and data compromise.

keycloak xss cross-site scripting cloud
2r 1t
medium advisory

.NET Spoofing Vulnerability (CVE-2026-32178)

CVE-2026-32178 is a vulnerability in .NET that allows for network spoofing due to improper neutralization of special elements, potentially enabling attackers to impersonate legitimate entities.

dotnet spoofing cve-2026-32178
2r 1t 1c
medium advisory

Suspicious Registry Modifications by Scripting Engines

Scripting engines such as WScript, CScript, and MSHTA are being used to make registry modifications, potentially for persistence or defense evasion.

registry-modification persistence defense-evasion scripting-engine
1r 3t
medium advisory

jq JSON Processor Hash Table Collision Denial-of-Service Vulnerability (CVE-2026-40164)

A denial-of-service vulnerability exists in jq versions prior to commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784 due to the use of a hardcoded seed in MurmurHash3, enabling attackers to craft JSON objects that trigger hash collisions and cause excessive CPU consumption.

jq denial-of-service hash-collision CVE-2026-40164 linux
2r 1t 1c
medium advisory

ImageMagick XML Bomb Denial-of-Service Vulnerability (CVE-2026-33908)

ImageMagick versions prior to 7.1.2-19 and 6.9.13-44 are susceptible to a denial-of-service (DoS) attack due to unbounded recursion during XML parsing, potentially leading to stack exhaustion.

dos imagemagick xml cve-2026-33908
2r 1t 1c
medium advisory

UniFi Play Improper Access Control Vulnerability (CVE-2026-22566)

An improper access control vulnerability in UniFi Play PowerAmp and Audio Port allows a malicious actor with access to the UniFi Play network to obtain WiFi credentials.

vulnerability access-control unifi
2r 1t 1c
medium advisory

Huawei Communication Module Use-After-Free Vulnerability (CVE-2026-34856)

A use-after-free vulnerability, tracked as CVE-2026-34856, exists in Huawei's communication module due to improper synchronization in concurrent execution, potentially leading to a denial-of-service condition.

vulnerability uaf dos
2r 1t 1c
medium advisory

Chamilo LMS Session Fixation Vulnerability (CVE-2026-31940)

Chamilo LMS versions prior to 1.11.38 and 2.0.0-RC.3 are vulnerable to session fixation due to user-controlled request parameters being used to set the PHP session ID, potentially allowing attackers to hijack user sessions.

session-fixation web-application cve-2026-31940
2r 1t 1c
medium advisory

TREK Travel Planner Missing Authorization Vulnerability (CVE-2026-40185)

TREK collaborative travel planner before version 2.7.2 is vulnerable to missing authorization checks on the Immich trip photo management routes, potentially allowing unauthorized access to trip photos.

cve-2026-40185 authorization-bypass web-application
2r 1t 1c
medium advisory

Entra ID ADRS Token Request by Microsoft Authentication Broker

Detects suspicious OAuth 2.0 token requests where the Microsoft Authentication Broker requests access to the Device Registration Service on behalf of a user principal, potentially indicating an attempt to abuse device registration for unauthorized persistence.

azure entra_id persistence oauth
2r 2t 1i
medium advisory

GitHub Exfiltration via High Number of Repository Clones

A single user rapidly cloning a high number of GitHub repositories indicates potential exfiltration of sensitive data such as proprietary code, embedded secrets, and build artifacts.

github exfiltration code_repository
2r 3t
medium advisory

AWS STS GetCallerIdentity API Called for the First Time

An adversary with access to compromised AWS credentials may attempt to verify their validity and determine the account they are using by calling the STS GetCallerIdentity API, potentially indicating credential compromise and unauthorized discovery activity.

cloud aws sts discovery
2r 2t
medium threat

Azure Service Principal Sign-In Followed by Arc Cluster Credential Access

Detects a service principal authenticating to Azure AD followed by listing credentials for an Azure Arc-connected Kubernetes cluster, indicating potential adversary activity with stolen service principal secrets to establish a proxy tunnel into Kubernetes clusters.

exploited azure azure-arc credential-access initial-access
2r 3t
medium advisory

AWS EC2 LOLBin Execution via SSM SendCommand

Detection of Living Off the Land Binaries (LOLBins) or GTFOBins execution on EC2 instances via AWS Systems Manager (SSM) SendCommand API, potentially indicating malicious activity.

aws ec2 ssm lolbin execution cloud
2r 2t
medium advisory

Zootemplate Cerato Theme Reflected XSS Vulnerability (CVE-2025-58920)

A reflected cross-site scripting (XSS) vulnerability exists in the Zootemplate Cerato WordPress theme (versions n/a through 2.2.18) due to improper neutralization of user-supplied input, potentially allowing attackers to execute arbitrary JavaScript in a user's browser.

xss wordpress reflected-xss
2r 1t 1c 1i
medium advisory

Gravity SMTP Plugin Missing Authorization Vulnerability (CVE-2026-4162)

The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization, allowing authenticated attackers with subscriber-level access or higher to uninstall/deactivate the plugin and delete plugin options, and is also exploitable via Cross-Site Request Forgery.

wordpress missing-authorization plugin cve-2026-4162
2r 1t 1c
medium advisory

Google Chrome Device Bound Session Credentials (DBSC) Mitigates Cookie Theft

Google's rollout of Device Bound Session Credentials (DBSC) in Chrome 146 for Windows, with a future release planned for macOS, cryptographically binds authentication sessions to the user's device, rendering stolen session cookies unusable and mitigating credential access.

cookie-theft credential-access chrome
2r 1t
medium advisory

Juniper Junos OS and Junos OS Evolved BGP Session Reset Denial of Service (CVE-2026-33797)

CVE-2026-33797 is an improper input validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved that allows an unauthenticated adjacent attacker to reset established BGP sessions via a specific BGP packet, leading to a denial of service condition.

cve-2026-33797 denial-of-service juniper bgp network
3r 2t 1c
medium advisory

Saleor GraphQL Batch Query Resource Exhaustion Vulnerability (CVE-2026-33756)

Unauthenticated attackers can exploit a resource exhaustion vulnerability (CVE-2026-33756) in Saleor e-commerce platform versions before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118 by sending a single HTTP request with a large number of GraphQL operations, bypassing query complexity limits and exhausting server resources.

resource-exhaustion graphql cve-2026-33756 dos
2r 1t 1c
medium advisory

First Time Python Process Creates macOS Launch Agent or Daemon

This rule detects the initial creation or modification of a macOS LaunchAgent or LaunchDaemon plist file by a Python process, a common persistence technique employed by attackers using malicious scripts, compromised dependencies, or model file deserialization.

persistence macos python
2r 2t
medium advisory

LORIS Directory Traversal Vulnerability

LORIS, a neuroimaging research data management web application, is vulnerable to directory traversal (CVE-2026-35446) due to an incorrect order of operations in the FilesDownloadHandler, allowing authenticated attackers to access unauthorized files.

directory-traversal web-application neuroimaging
2r 2t 1c
medium advisory

Saleor GraphQL Resource Exhaustion Vulnerability (CVE-2026-35401)

A remote, unauthenticated attacker can cause resource exhaustion in Saleor e-commerce platforms via maliciously crafted GraphQL API requests, leading to denial of service.

cve-2026-35401 graphql resource-exhaustion denial-of-service saleor
2r 1t 1c
medium advisory

Red Hat Quay Image Upload Interference Vulnerability (CVE-2026-32589)

CVE-2026-32589 describes a vulnerability in Red Hat Quay's container image upload process where an authenticated user can interfere with other users' uploads, potentially leading to unauthorized access and modification.

quay image upload vulnerability
2r 2t 1c
medium advisory

Kibana Fleet Plugin Privilege Escalation via CVE-2026-4498

CVE-2026-4498 allows an authenticated Kibana user with Fleet sub-feature privileges to read index data beyond their direct Elasticsearch RBAC scope due to improper privilege handling in debug route handlers.

cve privilege-escalation kibana
2r 1t 1c
medium advisory

Dell ECS and ObjectScale Sensitive Information Logging Vulnerability (CVE-2026-28261)

Dell Elastic Cloud Storage and ObjectScale are vulnerable to local privilege escalation due to sensitive information being logged, potentially allowing a low-privileged attacker with local access to expose secrets and gain unauthorized access.

cve-2026-28261 secret-leak privilege-escalation
2r 1t 1c
medium advisory

OpenClaw Agent Suspicious Child Process Execution

Malicious actors are exploiting OpenClaw, Moltbot, and Clawdbot AI coding agents via Node.js to execute arbitrary shell commands and download-and-execute commands, potentially targeting cryptocurrency wallets and credentials.

ai-agent execution malware credential-theft
2r 10t 3i
medium advisory

IBM Tivoli Netcool Impact Sensitive Information Leak via Log Files (CVE-2026-4788)

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.37 stores sensitive information in log files, potentially exposing it to unauthorized local users, tracked as CVE-2026-4788.

cve-2026-4788 information-disclosure log-files
2r 1t 1c
medium advisory

IBM Verify and Security Verify Access Container Server-Side Request Forgery Vulnerability (CVE-2026-1343)

CVE-2026-1343 allows an attacker to contact internal authentication endpoints protected by the Reverse Proxy in IBM Verify Identity Access Container and IBM Security Verify Access Container.

cve cve-2026-1343 ssrf ibm
2r 2t 1c
medium advisory

OpenSSH GSSAPI Vulnerability Leads to Potential Denial-of-Service

A remote, anonymous attacker can exploit a vulnerability in OpenSSH GSSAPI and Ubuntu Linux to trigger undefined behavior or a potential denial-of-service attack.

openssh gssapi denial-of-service linux
2r 1t
medium advisory

CSRF Vulnerability in WordPress Under Construction Plugin (CVE-2026-34896)

A cross-site request forgery (CSRF) vulnerability exists in the Analytify Under Construction, Coming Soon & Maintenance Mode WordPress plugin (versions n/a through 2.1.1), potentially allowing attackers to execute unauthorized actions on behalf of legitimate users.

wordpress csrf vulnerability
2r 2t 1c
medium advisory

Brave CMS Insecure Direct Object Reference Vulnerability (CVE-2026-35183)

Brave CMS versions prior to 2.0.6 are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability allowing authenticated users with edit permissions to delete images attached to articles owned by other users due to missing ownership verification in the deleteImage method.

idor brave-cms vulnerability
1r 1t 1c
medium advisory

openFPGALoader Heap-Buffer-Overflow Read Vulnerability

A heap-buffer-overflow read vulnerability exists in openFPGALoader 1.1.1 and earlier, allowing out-of-bounds heap memory access via a crafted .pof file, potentially leading to denial of service or information disclosure.

heap-buffer-overflow openFPGALoader denial-of-service information-disclosure
2r 1t 1c
medium advisory

Qualcomm Transient Denial-of-Service via FILS Discovery Frames (CVE-2026-21367)

CVE-2026-21367 describes a transient denial-of-service vulnerability in Qualcomm products that occurs when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans, potentially leading to service disruption.

dos qualcomm cve-2026-21367
2r 2t 1c
medium advisory

GLPI Cross-Site Scripting Vulnerability (CVE-2026-25932)

CVE-2026-25932 is a cross-site scripting vulnerability in GLPI versions 0.60 to before 10.0.24, where an authenticated technician user can store a malicious XSS payload within supplier fields, potentially leading to arbitrary code execution in the context of other users' browsers.

xss glpi cve-2026-25932
2r 1t 1c
medium advisory

Microsoft VPN Browser+ 1.1.0.0 Denial of Service Vulnerability (CVE-2018-25241)

An unauthenticated attacker can cause a denial of service by crashing Microsoft VPN Browser+ 1.1.0.0 via oversized input to the search functionality, leading to application termination.

dos cve-2018-25241 microsoft
2r 1t 1c
medium advisory

WordPress Widgets for Social Photo Feed Plugin Stored XSS Vulnerability

The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'feed_data' parameter, allowing unauthenticated attackers to inject arbitrary web scripts in pages that will execute when a user accesses the injected page.

wordpress xss cve-2026-5425 plugin
2r 1t 1c
medium advisory

Piwigo Unauthenticated History Search Access

Piwigo versions prior to 16.3.0 expose the full browsing history of gallery visitors to unauthenticated users via the pwg.history.search API method due to a missing authorization check.

piwigo vulnerability information-disclosure
2r 1t 1c 1i
medium advisory

Suricata Quadratic Complexity Issue in SMTP URL Searching (CVE-2026-31934)

Suricata versions 8.0.0 to before 8.0.4 exhibit a quadratic complexity vulnerability (CVE-2026-31934) when searching for URLs in MIME-encoded SMTP messages, leading to significant performance degradation and potential denial-of-service conditions; this is fixed in version 8.0.4.

suricata cve-2026-31934 denial-of-service performance network-security
2r 1t 1c 1i
medium advisory

Democratization of Business Email Compromise (BEC) Attacks

Attackers are leveraging AI to rapidly reconnoiter and tailor content for smaller organizations, making it easier to execute business email compromise (BEC) scams and scam smaller sums from many victims, as demonstrated by a recent attack targeting a small community organization.

business-email-compromise bec ai social-engineering credential-harvesting exploitation
2r 2t 1c 6i
medium advisory

ManageEngine Exchange Reporter Plus Stored XSS Vulnerability

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in the Distribution Lists report, allowing attackers to inject malicious scripts.

xss vulnerability manageengine
2r 2t 1c
medium advisory

OpenClaw Arbitrary File Read and Credential Exfiltration Vulnerability

The openclaw package is vulnerable to arbitrary file read and credential exfiltration due to media local roots self-whitelisting in `appendLocalMediaParentRoots`, allowing a model to initiate arbitrary host file reads, potentially leading to credential exfiltration.

arbitrary-file-read credential-exfiltration openclaw npm
2r 1t
medium advisory

OpenSSH scp Insecure File Permission Vulnerability (CVE-2026-35385)

OpenSSH versions before 10.3 allow for the potential installation of setuid or setgid files when using scp to download files as root with the -O option (legacy SCP protocol) and without the -p option (preserve mode), contrary to user expectations.

openssh scp privilege-escalation cve-2026-35385
2r 1t 1c
medium advisory

Rack::Static Information Disclosure Vulnerability (CVE-2026-34785)

Rack versions prior to 2.2.23, 3.1.21, and 3.2.6 are vulnerable to information disclosure due to improper static file serving via a prefix matching issue in Rack::Static.

rack information-disclosure CVE-2026-34785 ruby webserver
2r 1t 1c
medium advisory

Huimeicloud hm_editor Server-Side Request Forgery Vulnerability (CVE-2026-5346)

A server-side request forgery (SSRF) vulnerability exists in huimeicloud hm_editor up to version 2.2.3, allowing remote attackers to manipulate the 'url' argument in the client.get function of src/mcp-server.js to potentially access internal resources.

cve-2026-5346 ssrf huimeicloud
2r 1t 1c
medium advisory

Suricata HTTP2 Continuation Frame Flooding Denial of Service (CVE-2026-31935)

A denial of service vulnerability, CVE-2026-31935, exists in Suricata versions prior to 7.0.15 and 8.0.4, where flooding the system with crafted HTTP2 continuation frames leads to memory exhaustion and process termination.

cve dos http2 suricata
2r 1t 1c
medium advisory

Suricata DCERPC Buffering Inefficiency Vulnerability (CVE-2026-31937)

Suricata versions prior to 7.0.15 are vulnerable to CVE-2026-31937, where inefficient DCERPC buffering can lead to a denial-of-service condition through performance degradation.

vulnerability dos suricata
2r 1t 1c
medium advisory

Suricata NULL Dereference Vulnerability

Suricata versions 8.0.0 to before 8.0.4 are vulnerable to a NULL dereference crash when using the 'tls.alpn' rule keyword, potentially leading to a denial of service.

suricata denial-of-service null-dereference
2r 2t 1c
medium advisory

Suricata KRB5 Buffering Inefficiency Vulnerability (CVE-2026-31932)

An unauthenticated attacker can exploit CVE-2026-31932, a vulnerability in Suricata versions prior to 7.0.15 and 8.0.4, to cause performance degradation due to inefficient KRB5 buffering.

cve-2026-31932 suricata krb5 performance-degradation denial-of-service
2r 1t 1c
medium advisory

Suricata DoS Vulnerability (CVE-2026-31933)

Specially crafted network traffic can cause Suricata to slow down, leading to a denial-of-service condition in versions prior to 7.0.15 and 8.0.4, as identified by CVE-2026-31933.

dos suricata cve-2026-31933 network
2r 1t 1c
medium advisory

Keycloak Redirect URI Bypass Vulnerability (CVE-2026-3872)

CVE-2026-3872 is a vulnerability in Keycloak that allows an attacker controlling a path on the same web server to bypass URI redirect validation using a wildcard, potentially leading to access token theft and information disclosure.

keycloak redirect-uri-bypass cve-2026-3872 authentication authorization
2r 1t 1c
medium advisory

SSH Authorized Key File Modification Inside a Container

The rule detects the creation or modification of an authorized_keys file inside a container, a technique used by adversaries to maintain persistence on a victim host by adding their own public key(s) to enable unauthorized SSH access for lateral movement or privilege escalation.

container persistence lateral-movement privilege-escalation ssh
2r 4t
medium advisory

V-SFT Out-of-Bounds Read Vulnerability (CVE-2026-32929)

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability (CVE-2026-32929) in VS6ComFile!get_macro_mem_COM, where opening a crafted V7 file may lead to information disclosure.

cve-2026-32929 out-of-bounds read information disclosure v-sft
2r 1t 1c
medium advisory

V-SFT Out-of-Bounds Read Vulnerability (CVE-2026-32926)

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in the VS6ComFile!load_link_inf function, allowing for potential information disclosure when opening a crafted V7 file.

cve-2026-32926 out-of-bounds read information disclosure
2r 6t 1c 2i
medium advisory

File Browser EPUB Preview Stored XSS Vulnerability (CVE-2026-34529)

File Browser versions prior to 2.62.2 are vulnerable to stored cross-site scripting (XSS) via the EPUB preview function, allowing attackers to execute arbitrary JavaScript in a user's browser by embedding malicious code in a crafted EPUB file.

xss filebrowser cve-2026-34529
2r
medium advisory

Payload CMS Stored XSS Vulnerability (CVE-2026-34748)

A stored Cross-Site Scripting (XSS) vulnerability exists in Payload CMS versions prior to 3.78.0, allowing authenticated users with write access to inject malicious scripts that execute in the browsers of other users.

xss cve-2026-34748 payloadcms
2r 1t 1c
medium advisory

Payload CMS SSRF Vulnerability (CVE-2026-34746)

Payload CMS versions before 3.79.1 are vulnerable to Server-Side Request Forgery (SSRF) allowing authenticated users with upload access to trigger outbound HTTP requests to arbitrary URLs.

cve-2026-34746 ssrf payload-cms
2r 1t 1c
medium advisory

Open WebUI Broken Access Control Vulnerability (CVE-2026-34222)

A broken access control vulnerability in Open WebUI versions prior to 0.8.11 (CVE-2026-34222) allows authenticated users to potentially access or modify tool values they should not be authorized to, leading to privilege escalation and unauthorized configuration changes.

broken-access-control web-application privilege-escalation
2r 3t 1c
medium advisory

Unsecured Zoom Meeting Creation

The creation of Zoom meetings without passcodes allows unauthorized access and disruption, known as Zoombombing, potentially leading to the exposure of sensitive information or reputational damage.

zoom zoombombing initial-access
2r 2t
medium advisory

Corosync Integer Overflow Vulnerability (CVE-2026-35092) Leads to DoS

CVE-2026-35092 is an integer overflow vulnerability in Corosync's join message sanity validation, allowing a remote, unauthenticated attacker to send crafted UDP packets, resulting in a denial of service condition.

cve-2026-35092 denial-of-service corosync
2r 2t 1c
medium advisory

WebServer Access Logs Deleted

Detection of web server access log deletion across Windows, Linux, and macOS systems indicates potential defense evasion and destruction of forensic evidence by threat actors.

defense-evasion indicator-removal file-deletion
2r 1t
medium advisory

Dell AppSync 4.6.0 UNIX Symbolic Link Following Vulnerability (CVE-2026-22767)

Dell AppSync version 4.6.0 is vulnerable to a UNIX Symbolic Link (Symlink) Following vulnerability (CVE-2026-22767) that allows a low-privileged local attacker to tamper with information.

symlink dell appsync privilege-escalation
2r 1t 1c
medium advisory

HTTP/2 Implementations Vulnerability Enables Denial of Service

A remote, anonymous attacker can exploit a vulnerability in various HTTP/2 implementations to perform a denial-of-service attack.

http/2 denial-of-service webserver
2r 1t
medium advisory

7-Zip Vulnerability Allows File Manipulation

A remote, anonymous attacker can exploit a vulnerability in 7-Zip to manipulate files, leading to potential data integrity issues.

7-zip file-manipulation vulnerability
2r 2t
medium advisory

XenForo Path Disclosure via Open-Basedir Restrictions (CVE-2025-71282)

XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions, allowing attackers to gain sensitive information about the server's directory structure.

path-disclosure cve-2025-71282 xenforo
2r 1t 1c
medium advisory

MPPX TypeScript Interface Vulnerability (CVE-2026-34209)

A vulnerability exists in mppx TypeScript interface before version 0.4.11, allowing attackers to close or grief channels for free by submitting close vouchers equal to the settled amount due to incorrect validation.

vulnerability payment-channel typescript
1r 1t 1c
medium advisory

Query Monitor WordPress Plugin Vulnerable to Reflected XSS (CVE-2026-4267)

The Query Monitor WordPress plugin is vulnerable to reflected cross-site scripting (XSS) due to insufficient input sanitization and output escaping of the '$_SERVER['REQUEST_URI']' parameter, allowing unauthenticated attackers to inject arbitrary web scripts.

wordpress xss reflected-xss cve-2026-4267
2r 1t 1c
medium advisory

OpenClaw Microsoft Teams Plugin Sender Allowlist Bypass (CVE-2026-34506)

OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin, allowing unauthorized senders to bypass intended authorization checks due to improper handling of empty groupAllowFrom parameters, potentially leading to information disclosure.

cve-2026-34506 openclaw microsoft teams allowlist bypass
2r 2t 1c
medium advisory

OpenClaw Information Disclosure via Telegram Bot Token Exposure

OpenClaw before version 2026.3.13 exposes Telegram bot tokens in error messages due to the fetchRemoteMedia function embedding these tokens in MediaFetchError strings when media downloads fail.

information-disclosure vulnerability telegram
2r 1c
medium advisory

baserCMS DOM-Based Cross-Site Scripting Vulnerability (CVE-2026-32734)

baserCMS versions prior to 5.2.3 are vulnerable to DOM-based Cross-Site Scripting (XSS) due to improper neutralization of input during web page generation, potentially allowing a remote attacker to execute arbitrary JavaScript in a user's browser.

xss vulnerability basercms
2r 1t 1c
medium advisory

FreeRDP Heap-Buffer-Overflow Vulnerability (CVE-2026-33982)

A heap-buffer-overflow read vulnerability exists in FreeRDP versions prior to 3.24.2, specifically in the winpr_aligned_offset_recalloc() function, potentially leading to denial of service or information disclosure.

freerdp heap-buffer-overflow cve-2026-33982 rdp
2r 3t 1c
medium advisory

Symantec DLP Windows Endpoint Elevation of Privilege Vulnerability (CVE-2026-3991)

CVE-2026-3991 is an elevation of privilege vulnerability in Symantec Data Loss Prevention (DLP) Windows Endpoint that could allow a local attacker to gain elevated access to resources.

vulnerability privilege-escalation symantec dlp windows
2r 1t
medium advisory

Potential Abuse of msDS-ManagedAccountPrecededByLink for Privilege Escalation

Detection of PowerShell scripts modifying the msDS-ManagedAccountPrecededByLink attribute, potentially indicating exploitation of the BadSuccessor privilege escalation vulnerability in Windows Server 2025.

privilege-escalation defense-evasion persistence initial-access active-directory
2r 4t
medium advisory

CrowdStrike Falcon Cloud Security Advances CNAPP with Adversary-Informed Risk Prioritization

CrowdStrike Falcon Cloud Security enhances its CNAPP capabilities, incorporating adversary intelligence to prioritize cloud risks based on threat actor behavior, particularly focusing on groups like LABYRINTH CHOLLIMA and SCATTERED SPIDER, to enable security teams to understand and remediate cloud exposures more effectively.

Lazarus Group +10 cloud-security cnapp threat-intelligence
2r 5t
medium advisory

CrowdStrike Falcon Next-Gen SIEM Supports Third-Party EDR Tools

CrowdStrike's Falcon Next-Gen SIEM now supports third-party EDR solutions, starting with Microsoft Defender, to extend AI-native SOC capabilities without replacing existing endpoint agents.

siem edr threat-intelligence
2r 2t
medium advisory

OpenClaw Insufficient File Permissions Vulnerability (CVE-2026-33572)

OpenClaw before 2026.2.17 creates session transcript JSONL files with overly broad default permissions, allowing local users to read transcript contents and extract sensitive information.

cve-2026-33572 file-permissions credential-access
2r 1t
medium advisory

CrowdStrike CNAPP Adds Adversary-Informed Risk Prioritization

CrowdStrike's CNAPP enhancements prioritize cloud risks based on adversary behavior, application context, and configuration change tracking to reduce breach likelihood.

Lazarus Group +10 cnapp cloud-security risk-prioritization
2r 1t
medium advisory

Securing AI Agents with Falcon AIDR and NVIDIA NeMo Guardrails

CrowdStrike Falcon AIDR now supports NVIDIA NeMo Guardrails to protect AI agents by blocking prompt injection attacks, redacting sensitive data, defanging malicious content, and moderating unwanted topics, ensuring compliance and preventing abuse.

ai-security prompt-injection data-protection
3r 4t
medium advisory

CrowdStrike Falcon Next-Gen SIEM Integrates with Microsoft Defender EDR

CrowdStrike Falcon Next-Gen SIEM now supports third-party EDR solutions like Microsoft Defender, enabling unified detection and response across diverse environments, addressing the challenges of cross-domain attacks and fragmented security systems.

siem edr threat-intelligence
2r 2t
medium advisory

CrowdStrike CNAPP Enhanced with Adversary-Informed Risk Prioritization

CrowdStrike enhances its CNAPP capabilities by incorporating adversary intelligence for improved risk prioritization, addressing limitations in infrastructure visibility, threat actor behavior analysis, and alert triage.

Lazarus Group +10 cloud-security cnapp risk-prioritization
2r 3t
medium advisory

elecV2 elecV2P Server-Side Request Forgery Vulnerability (CVE-2026-5016)

A server-side request forgery vulnerability exists in elecV2 elecV2P up to 3.8.3, affecting the eAxios function within the /mock URL handler, allowing remote attackers to manipulate the req argument and potentially conduct internal reconnaissance or other malicious activities.

cve-2026-5016 ssrf elecv2 web-application
2r 2t
medium advisory

CrowdStrike Falcon SIEM Integration with Microsoft Defender

CrowdStrike's Falcon Next-Gen SIEM expands to support third-party EDR solutions, beginning with Microsoft Defender, to unify detection, investigation, and response without requiring the Falcon sensor and modernize security operations.

siem edr integration microsoft-defender
2r 10t
medium advisory

CrowdStrike Innovations Secure AI Agents and Govern Shadow AI

CrowdStrike is introducing innovations to secure AI agents and govern shadow AI across endpoints, SaaS, and cloud environments by extending AI detection and response (AIDR) capabilities to cover desktop AI applications and provide visibility into AI-related components, helping to prevent prompt attacks, data leaks, and policy violations.

AI AI-Security Shadow-AI Endpoint-Security SaaS Cloud
2r 2t
medium advisory

CrowdStrike Falcon SIEM Integrates with Microsoft Defender EDR

CrowdStrike Falcon Next-Gen SIEM is expanding its capabilities to integrate with third-party EDR solutions, starting with Microsoft Defender, to enable organizations to extend their AI-native SOC across heterogeneous environments without replacing existing endpoint agents.

siem edr microsoft-defender crowdstrike-falcon
2r 1t
medium advisory

Securing AI Agents with CrowdStrike Falcon AIDR and NVIDIA NeMo Guardrails

CrowdStrike Falcon AIDR integrates with NVIDIA NeMo Guardrails to provide comprehensive protection for AI agents against prompt injection, data leaks, and malicious content.

ai security agentic-soc
2r 2t
medium advisory

CrowdStrike CNAPP Enhanced with Adversary-Informed Risk Prioritization

CrowdStrike has enhanced its CNAPP capabilities by adding application-layer visibility and prioritizing risks based on known adversary tactics, techniques, and procedures (TTPs).

Lazarus Group +10 cloud-security cnapp threat-intelligence risk-prioritization
2r 2t
medium advisory

CrowdStrike Falcon Enhancements for Securing AI Environments

CrowdStrike is enhancing its Falcon platform with new features focusing on AI Detection and Response (AIDR) capabilities across endpoints, SaaS, and cloud environments to mitigate risks such as prompt injection attacks, data leaks, and policy violations related to AI agents and shadow AI.

ai security falcon agentic-soc prompt-injection
2r 2t
medium advisory

CrowdStrike Falcon Cloud Security CNAPP with Adversary-Informed Risk Prioritization

CrowdStrike Falcon Cloud Security enhances CNAPP capabilities with application-layer visibility and adversary-informed risk prioritization, enabling security teams to focus on attacker-aligned risks and known threat actors.

Lazarus Group +10 cloud-security cnaap risk-prioritization
2r 3t
medium advisory

CrowdStrike Falcon Cloud Security Introduces Adversary-Informed Risk Prioritization

CrowdStrike's Falcon Cloud Security enhances CNAPP capabilities by introducing adversary-informed risk prioritization, application layer visibility, and root cause analysis of configuration changes, enabling security teams to better understand and remediate cloud risks.

Lazarus Group +10 cloud cnapp risk-prioritization
2r 8t
medium advisory

CrowdStrike Agentic MDR and SOC Transformation Services

CrowdStrike introduces agentic MDR and SOC Transformation Services to enhance breach prevention through machine-speed execution and expert oversight, while SOC Transformation Services aim to modernize security operations by focusing on SIEM, data pipelines, workflows, talent models, and governance.

agentic-soc mdr soc ai
2r 2t
medium advisory

CrowdStrike Charlotte AI AgentWorks and Agentic SOAR for Automated Security Operations

CrowdStrike introduces Charlotte AI AgentWorks and Agentic SOAR to enhance security operations through AI-driven automation and orchestration, reducing manual workloads and improving decision accuracy.

ai automation security operations soar
2r
medium advisory

CrowdStrike Falcon Next-Gen SIEM Supports Third-Party EDR Tools

CrowdStrike Falcon Next-Gen SIEM is expanding to support third-party EDR solutions, starting with Microsoft Defender, enabling organizations to extend their AI-native SOC across their ecosystem by unifying detection, investigation, and response.

SIEM EDR Microsoft Defender
2r
medium advisory

CrowdStrike Charlotte AI AgentWorks for Agentic SOC Transformation

CrowdStrike's Charlotte AI AgentWorks facilitates the development and deployment of AI-driven security agents within the SOC, aiming to enhance analyst capabilities through automated and orchestrated responses to threats.

agentic-soc ai-security automation
2r 2t
medium advisory

CrowdStrike Charlotte AI AgentWorks and Agentic SOAR for Agentic Security Operations

CrowdStrike's Charlotte AI AgentWorks and Agentic SOAR aim to revolutionize security operations by enabling the creation and orchestration of AI-powered agents, enhancing analyst capabilities and automating tasks to combat AI-accelerated adversaries.

agentic-soc ai security-automation
2r
medium advisory

CrowdStrike Agentic MDR and SOC Transformation Services

CrowdStrike's Agentic MDR combines machine-speed execution with expert oversight, leveraging deterministic automation and adaptive AI agents to enhance breach prevention and SOC modernization.

agentic-soc mdr soc-transformation ai
2r 2t
medium advisory

CrowdStrike Flex for Services Expands Access to Incident Response Expertise

CrowdStrike is expanding its Falcon Flex model to its services offering, providing flexible access to incident response, proactive security services, advisory, platform services, and training.

incident-response security-services
2r 2t
medium advisory

CrowdStrike Falcon Cloud Security CNAPP with Adversary-Informed Risk Prioritization

CrowdStrike's new CNAPP capabilities in Falcon Cloud Security focus on adversary-informed risk prioritization by correlating application-layer visibility with threat actor profiles and techniques, enabling security teams to understand cloud risk, prioritize remediation, and accelerate response.

Lazarus Group +10 cloud-security cnapp threat-intelligence risk-prioritization
3r 2t
medium advisory

CrowdStrike Falcon Next-Gen SIEM Integrates with Microsoft Defender

CrowdStrike Falcon Next-Gen SIEM now supports third-party EDR solutions, beginning with Microsoft Defender, enabling organizations to extend their AI-native SOC and unify detection across heterogeneous environments.

siem edr microsoft defender crowdstrike falcon
2r 1t
medium advisory

CrowdStrike Falcon Enhancements for Securing AI Agents and Governing Shadow AI

CrowdStrike is enhancing its Falcon platform with new AI detection and response capabilities to secure AI agents and govern shadow AI across endpoints, SaaS, and cloud environments, addressing threats like prompt injection and data leaks.

AI-Security Shadow-AI Endpoint-Security
2r
medium advisory

CrowdStrike Falcon Data Security Introduction

CrowdStrike's Falcon Data Security aims to protect sensitive data by providing visibility into data movement across various environments and preventing data theft.

data-security data-loss-prevention crowdstrike
2r 2t
medium advisory

CrowdStrike Agentic MDR and SOC Transformation Services

CrowdStrike's agentic MDR combines automation, AI agents, and human oversight for rapid breach response, while SOC Transformation Services modernize security operations for an agentic SOC approach.

agentic-soc mdr soc-transformation
3r
medium advisory

Incus Image Cache Poisoning Vulnerability

A vulnerability exists in Incus where it does not properly verify the combined fingerprint when downloading images from simplestreams servers, allowing an attacker to perform image cache poisoning and potentially expose other tenants to running attacker-controlled images.

incus image-poisoning simplestreams
2r 1t 3i
medium advisory

ManageSieve AUTHENTICATE Command Denial-of-Service Vulnerability (CVE-2025-59032)

CVE-2025-59032 describes a vulnerability in ManageSieve's AUTHENTICATE command, where using a literal as a SASL initial response can crash the ManageSieve service, leading to a denial-of-service condition.

denial-of-service managesieve cve-2025-59032 mail-service
2r 1t
medium advisory

EVerest EV Charging Stack Data Race Vulnerability (CVE-2026-26074)

EVerest versions prior to 2026.02.0 exhibit a data race vulnerability (CVE-2026-26074) where concurrent network requests and physical events can corrupt the event queue, leading to potential denial of service or other undefined behavior.

cve-2026-26074 data-race ev-charging everest
2r
medium advisory

GitLab Improper HTML Sanitization Vulnerability (CVE-2026-2995)

CVE-2026-2995 is a vulnerability in GitLab EE versions 15.4 to 18.10.1 where an authenticated user can add email addresses to other user accounts due to improper HTML sanitization, potentially leading to account takeover or information disclosure.

gitlab html-injection cve-2026-2995
2r 2t
medium advisory

GitLab GraphQL Denial of Service Vulnerability (CVE-2026-3988)

CVE-2026-3988 is a denial of service vulnerability in GitLab CE/EE allowing unauthenticated users to crash instances by sending malformed GraphQL requests, affecting versions 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1.

denial-of-service graphql gitlab cve-2026-3988
2r 1t
medium advisory

Blackhole for Bad Bots WordPress Plugin Stored XSS Vulnerability

The Blackhole for Bad Bots WordPress plugin through version 3.8 is vulnerable to stored cross-site scripting (XSS) via the User-Agent HTTP header, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the plugin's admin page.

wordpress xss plugin cve-2026-4329
2r 1t
medium advisory

IBM InfoSphere Information Server Plaintext Credential Storage Vulnerability

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 stores user credentials in plaintext, allowing local users to read sensitive information.

cve-2025-36258 credential-access plaintext-storage infosphere
2r 1t
medium advisory

CPython Zipfile Module Vulnerability Allows File Manipulation

A remote, anonymous attacker can exploit a vulnerability in the zipfile module of CPython to manipulate files on affected systems.

cpython zipfile file-manipulation vulnerability
2r 1t
medium advisory

Red Hat OpenShift GitOps Multiple Vulnerabilities

An anonymous remote attacker can exploit multiple vulnerabilities in Red Hat OpenShift GitOps to manipulate data, misrepresent information, or cause a denial of service.

openshift gitops vulnerability cloud
2r 1t
medium advisory

Mozilla Firefox and Thunderbird Graphics Text Component Vulnerability (CVE-2026-4719)

CVE-2026-4719 describes an incorrect boundary condition in the Graphics: Text component of Mozilla Firefox and Thunderbird, potentially leading to a denial-of-service condition in vulnerable versions.

cve vulnerability firefox thunderbird
2r 2t
medium advisory

WebRTC Signaling Denial-of-Service Vulnerability (CVE-2026-4704)

CVE-2026-4704 is a denial-of-service vulnerability in the WebRTC Signaling component affecting Firefox, Firefox ESR, and Thunderbird, potentially disrupting service availability.

webrtc denial-of-service firefox thunderbird
2r 1t
medium advisory

Mozilla Firefox and Thunderbird WebCodecs Boundary Condition Vulnerability (CVE-2026-4695)

An incorrect boundary condition in the Audio/Video Web Codecs component in Mozilla Firefox and Thunderbird (CVE-2026-4695) could lead to a denial-of-service (DoS) condition due to a vulnerability that affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

cve-2026-4695 firefox thunderbird webcodecs denial-of-service
2r 1t
medium advisory

Mozilla Firefox and Thunderbird Web Codecs Denial-of-Service Vulnerability (CVE-2026-4697)

CVE-2026-4697 is a denial-of-service vulnerability due to incorrect boundary conditions in the Audio/Video Web Codecs component of Mozilla Firefox and Thunderbird, potentially leading to application crashes.

cve-2026-4697 denial-of-service mozilla firefox thunderbird
2r 1t
medium advisory

Mozilla Firefox and Thunderbird Audio/Video Playback Denial-of-Service Vulnerability (CVE-2026-4693)

CVE-2026-4693 is a vulnerability due to incorrect boundary conditions in the Audio/Video: Playback component of Mozilla Firefox and Thunderbird, potentially leading to a denial-of-service condition.

cve denial-of-service firefox thunderbird
2r 1t
medium advisory

Mozilla Firefox Canvas2D Improper Boundary Condition Vulnerability (CVE-2026-4685)

An improper boundary condition vulnerability in the Canvas2D component of Mozilla Firefox, Firefox ESR, and Thunderbird (CVE-2026-4685) could allow for a denial-of-service condition.

cve-2026-4685 firefox thunderbird denial-of-service canvas2d
2r 2t
medium advisory

OwnTone Server DAAP Request NULL Pointer Dereference Denial-of-Service (CVE-2026-26828)

A NULL pointer dereference vulnerability in the daap_reply_playlists function of owntone-server allows attackers to cause a Denial of Service (DoS) by sending a crafted DAAP request.

cve-2026-26828 denial-of-service owntone-server
2r 2t
medium advisory

Easy Chat Server 3.1 Denial of Service Vulnerability (CVE-2019-25613)

Easy Chat Server 3.1 is vulnerable to a denial-of-service attack where a remote attacker can crash the application by sending oversized data in the message parameter via a POST request to the body2.ghp endpoint after establishing a session, leading to service unavailability.

dos cve-2019-25613 easy-chat-server
2r 1t
medium advisory

DNS Queries to RMM Domains from Non-Browser Processes

Detection of DNS queries to known remote monitoring and management (RMM) domains originating from non-browser processes on Windows systems indicates potential abuse of legitimate software for command and control.

rmm command-and-control windows
2r 74i
medium advisory

CrowdStrike Falcon Flex for Services Expansion

CrowdStrike is expanding the Falcon Flex model to its services offering to provide organizations with more flexible access to incident response and proactive security services.

incident response security services MDR
2r 2t
medium advisory

VMware Tanzu Spring Framework and Spring Security Vulnerabilities Allow Security Bypass

An anonymous, remote attacker can exploit multiple vulnerabilities in VMware Tanzu Spring Security and VMware Tanzu Spring Framework to bypass security measures.

vmware spring security-bypass web-application
2r 1t
medium advisory

Znuny Cross-Site Scripting Vulnerability

An anonymous remote attacker can exploit a vulnerability in Znuny to perform a cross-site scripting attack, potentially leading to information disclosure or session hijacking.

znuny xss cross-site scripting web application
2r 1t
medium advisory

cURL Vulnerability Allows File Manipulation

A remote, anonymous attacker can exploit a vulnerability in cURL to manipulate files on a vulnerable system.

curl vulnerability file-manipulation
2r 2t
medium advisory

Apache Commons FileUpload Denial of Service Vulnerability

A remote, anonymous attacker can exploit a vulnerability in Apache Commons FileUpload to perform a denial of service attack.

apache commons-fileupload denial-of-service vulnerability
2r 1t
medium advisory

Apache Commons BeanUtils Security Bypass Vulnerability

An authenticated remote attacker can exploit a vulnerability in Apache Commons BeanUtils to bypass security measures, potentially leading to unauthorized access or privilege escalation.

apache-commons-beanutils vulnerability security-bypass
1r 1t
medium advisory

MIT Kerberos Security Bypass Vulnerability

An anonymous, remote attacker can exploit a vulnerability in MIT Kerberos to bypass security measures.

kerberos authentication security-bypass
2r 1t
medium advisory

Android-ImageMagick7 Memory Leak Vulnerability (CVE-2026-33852)

A missing release of memory vulnerability (CVE-2026-33852) in MolotovCherry Android-ImageMagick7 before version 7.1.2-11 can lead to a denial-of-service condition due to memory exhaustion.

cve memory leak denial of service android
2r 1t
medium advisory

Ruby on Rails Active Storage DoS Vulnerability (CVE-2026-33174)

A denial-of-service vulnerability (CVE-2026-33174) exists in Ruby on Rails Active Storage versions prior to 8.1.2.1, 8.0.4.1, and 7.2.3.1 due to unbounded memory allocation when handling large or unbounded Range headers in proxy delivery mode.

rails active-storage dos cve-2026-33174
2r 1t
medium advisory

Citrix NetScaler ADC and Gateway Vulnerabilities

Citrix has released a security advisory addressing multiple vulnerabilities in NetScaler ADC and NetScaler Gateway that could lead to sensitive information disclosure and user session mix-up under specific configurations.

citrix netscaler vulnerability information-disclosure
2r
medium advisory

Inner Warden Security Agent Capabilities

The open-source Inner Warden project is a security agent leveraging eBPF for kernel-level monitoring and autonomous response actions like IP blocking and process termination, aiming to create a distributed security mesh.

ebpf security-agent autonomous-response privilege-escalation c2-blocking linux
2r 1t
medium advisory

RagaSerpent 'Tax Audit' Campaign Targeting Multiple Countries

The RagaSerpent cluster, also known as SideWinder-Adjacent, is conducting targeted attacks across multiple countries between 2025 and 2026, associated with a 'Tax Audit' themed campaign.

RagaSerpent SideWinder Tax Audit Spearphishing
2r 1t
medium advisory

StoatWaffle Malware Used by WaterPlum Actor

StoatWaffle is malware employed by the WaterPlum threat actor, used for an unknown purpose.

WaterPlum stoatwaffle malware
2r 1t
medium advisory

NetNTLM Hash Phishing via Archive Extraction (CVE-2025-59284)

A phishing technique, potentially still viable due to incomplete patching, allows attackers to obtain NetNTLM hashes from archive extraction on Windows systems (CVE-2025-59284).

credential-access netntlm phishing windows
2r 1t
medium advisory

Self-Hosted Email Threat Detection Tool

A user created a self-hosted email threat detection tool, named VerdictMail, employing IMAP IDLE for real-time monitoring and multi-stage enrichment via SPF, DKIM, DMARC, DNSBL, WHOIS, URLhaus, and VirusTotal, coupled with an LLM for threat assessment.

email-security threat-detection imap
2r
medium advisory

Iranian Botnet Operation Exposed via Open Directory

An Iranian botnet operation utilizing a 15-node relay network and active C2 infrastructure was exposed through an open directory.

botnet iran C2
1r 1t 1i
medium advisory

Azure Service Principal Sign-In Followed by Arc Cluster Credential Access

Detects a service principal authenticating to Microsoft Entra ID and then listing credentials for an Azure Arc-connected Kubernetes cluster within a short time window, indicating potential unauthorized access to Kubernetes clusters via stolen service principal secrets.

azure azure-arc credential-access initial-access
2r 2t
medium advisory

Persistnux - Linux Persistence Detection Tool

Persistnux is a bash-based tool designed to identify known Linux persistence mechanisms used by attackers to maintain access to compromised systems, generating detailed reports for DFIR analysis.

persistence linux dfir
3r 3t
medium advisory

HushSpec: Security Policy Specification for AI Agent Action Boundaries

HushSpec is an open specification under development to standardize security policies at the action boundary of AI agents, focusing on actions such as file access, network egress, and shell execution, aiming to create a portable and engine-agnostic policy layer.

AI-Agent security-policy action-boundary
2r 1t 1i
medium advisory

Stealthy WMI Lateral Movement via StealthyWMIExec.py

The StealthyWMIExec.py script facilitates lateral movement via WMI, potentially evading standard detection mechanisms by employing stealthy techniques.

lateral-movement wmi windows
2r 1t
medium advisory

GlassWorm Campaign Deploying Wave 3 Windows Payload

The GlassWorm campaign has been observed deploying a Wave 3 Windows payload, indicating ongoing malicious activity targeting Windows systems.

glassworm malware windows
2r 2t
medium advisory

Maltrail IOC Feed Update for Multiple Threats

This brief summarizes IOCs extracted from the Maltrail feed on March 15, 2026, covering domains and URLs associated with threats targeting macOS and Android platforms, including OSX_Atomic, FakeApp, Android_Joker, Lummack2, APT_Sidewinder, APT_Kimsuky, and Hak5Cloud_C2.

maltrail ioc osx android apt
3r 6t 40i
medium advisory

GlassWorm V2 Infrastructure Rotation and GitHub Injection Analysis

Analysis of GlassWorm V2 reveals infrastructure rotation and GitHub injection techniques.

malware github infrastructure
2r 2t
medium advisory

KRVTZ-NET IDS Alerts Analysis: Network Scanning and Exploitation Attempts

Multiple IDS alerts indicate potential network reconnaissance, vulnerability exploitation attempts targeting Fortigate VPN (CVE-2023-27997), and ColdFusion servers originating from various IP addresses on March 13, 2026.

network-scanning vulnerability-exploitation fortigate coldfusion cve-2023-27997
3r 4t
medium advisory

Kubernetes Sensitive Role Creation or Modification

This rule detects the creation or modification of Kubernetes Roles or ClusterRoles that grant high-risk permissions, such as wildcard access or RBAC escalation verbs (e.g., bind, escalate, impersonate), potentially leading to privilege escalation or unauthorized access within the cluster.

kubernetes rbac privilege-escalation persistence
2r 2t
medium advisory

Kubernetes Endpoint Permission Enumeration

A single user and source IP attempts to enumerate Kubernetes endpoints, issuing API requests across multiple endpoints to identify accessible resources for further exploitation.

kubernetes enumeration discovery
2r 1t
medium advisory

Maltrail IOCs Report: Tracking Multiple Threat Actors

This brief analyzes IOCs aggregated by Maltrail on February 27, 2026, highlighting network activity associated with diverse threat actors including APT_UNC2465, Lazarus Group, Gorat, APT_Bitter, Android_Joker, PowerShell Injector, SmokeLoader, and FakeApp campaigns targeting various sectors.

maltrail threat-intelligence apt malware
3r 5t 27i
medium advisory

Suspicious AWS EC2 Key Pair Import Activity

The import of SSH key pairs into AWS EC2, as detected by CloudTrail logs, may indicate unauthorized access attempts, persistence establishment, or privilege escalation by an attacker.

Elastic Compute Cloud aws cloudtrail ec2 keypair initial-access persistence privilege-escalation
2r 1t
medium advisory

AWS SAML Provider Deletion Activity

An adversary may delete an AWS SAML provider to disrupt administrative access, hindering incident response and potentially escalating privileges within the AWS environment.

aws cloudtrail saml iam deletion impact
2r 2t
medium advisory

AWS S3 Unauthenticated Bucket Access by Rare Source

This rule detects AWS CloudTrail events indicative of unauthenticated sources attempting to access an S3 bucket, potentially exposing sensitive data due to misconfigured bucket policies.

Amazon S3 aws s3 unauthenticated-access cloudtrail collection
2r 4t
medium threat

Potential Web Shell ASPX File Creation

The creation of ASPX files in web server directories, excluding legitimate processes, indicates potential web shell deployment for persistence on Windows systems.

exploited SharePoint web-shell persistence windows
2r 1t
medium advisory

Azure Entra ID MFA TOTP Brute Force Attempted

Identifies brute force attempts against Azure Entra multi-factor authentication (MFA) Time-based One-Time Password (TOTP) verification codes, characterized by high-frequency failed attempts for a single user across numerous distinct sessions, potentially indicating programmatic attempts to bypass MFA.

Azure Entra ID azure entra_id mfa totp brute_force credential_access
3r 1t
medium advisory

AWS STS AssumeRoot by Rare User and Member Account

The rule detects when the STS AssumeRoot action is performed by a rare user in AWS, potentially indicating privilege escalation.

AWS Security Token Service aws privilege-escalation cloud
2r 3t
medium advisory

Entra ID Sign-in Brute Force Attempt Against Microsoft 365

A high volume of failed Microsoft Entra ID sign-in attempts against Microsoft 365 services within a short time period indicates a potential brute-force attack, which could lead to unauthorized access to Microsoft 365 services.

Microsoft 365 +4 azure entra-id microsoft-365 brute-force credential-access
2r 1t
medium advisory

Windows SIP Provider Modification for Defense Evasion

This brief covers the modification of Subject Interface Package (SIP) providers on Windows systems, a technique used by attackers to bypass signature validation checks and inject malicious code into critical processes, ultimately leading to defense evasion.

Windows defense-evasion registry
1r 1t
medium advisory

M365 Identity Login from Atypical Travel Location

This rule detects successful Microsoft 365 portal logins from rare locations, potentially indicating an adversary attempting to access an account from an unusual location or behind a VPN.

Microsoft 365 +1 cloud identity o365 initial-access
2r 1t
medium advisory

Bitbucket Secret Scanning Rule Deleted

Attackers may delete secret scanning rules in Bitbucket to impair defenses and introduce secrets into the code repository undetected, potentially leading to unauthorized access or data breaches.

Bitbucket attack.defense-impairment attack.t1685
2r 1t
medium advisory

ROT Encoded Python Script Execution

This analytic detects the execution of Python scripts employing ROT encoding for letter substitution, a technique used by adversaries to obfuscate malicious code within legitimate Python packages on Windows and macOS systems.

Python defense-evasion encoding obfuscation
2r 2t
medium advisory

Entra ID Device Code Authentication Abuse via Malicious Broker Client

Adversaries are abusing Entra ID device code authentication using a malicious broker client to bypass MFA and gain unauthorized access to Azure resources by compromising Primary Refresh Tokens (PRTs).

Azure +1 entra-id device-code-authentication prt
2r 2t 4i
medium advisory

Microsoft 365 Identity Login from Impossible Travel Location

Detects successful Microsoft 365 portal logins from impossible travel locations, defined as logins originating from two different countries within a short time frame, potentially indicating account compromise or unauthorized access.

Microsoft 365 cloud identity azure active directory initial access
2r 1t
medium advisory

AWS RDS DB Snapshot Shared with Another Account

An AWS RDS DB snapshot is shared with another AWS account or made public, potentially enabling unauthorized access, offline analysis, or data exfiltration by allowing adversaries to restore the snapshot in their controlled infrastructure.

AWS RDS aws rds snapshot exfiltration
2r 1t
medium advisory

VScode Remote Tunnel Abuse for Command and Control

Adversaries are leveraging the VScode remote tunnel feature to establish unauthorized access and control over Windows systems, potentially enabling command and control activities via disguised legitimate software.

Visual Studio Code vscode remote-access command-and-control windows
2r 1t
medium advisory

Potential Persistence via Linux File Modification

This rule detects potential persistence attempts on Linux systems by monitoring file modifications of files commonly used for persistence, such as cron jobs, systemd services, message-of-the-day (MOTD), SSH configurations, shell configurations, runtime control, init daemon, passwd/sudoers/shadow files, Systemd udevd, and XDG/KDE autostart entries.

Linux persistence file_integrity_monitoring
3r 6t
medium advisory

Suspicious Pod Creation in Kubernetes System Namespace

An attacker may deploy a pod within the kube-system namespace in Kubernetes to mimic legitimate system pods and evade detection.

Kubernetes pod kube-system container
2r 1t
medium advisory

Powercat PowerShell Implementation Detection

Adversaries may leverage Powercat, a PowerShell implementation of Netcat, to establish command and control channels or perform lateral movement within a compromised network.

Windows command-and-control execution lateral-movement powershell
2r 2t
medium advisory

Active Directory Group Modification by SYSTEM Account

Detection of a user being added to an Active Directory group by the SYSTEM account (S-1-5-18) can indicate an attacker with SYSTEM privileges attempting to pivot to a domain account.

Active Directory persistence privilege-escalation windows
2r 2t
medium advisory

First Time AWS CloudFormation Stack Creation

This rule detects the first time a principal calls AWS CloudFormation CreateStack or CreateStackInstances API, potentially indicating malicious resource deployment by an attacker with elevated privileges.

AWS CloudFormation cloudformation aws execution
2r 2t
medium threat

Potential Web Shell ASPX File Creation

This rule identifies the creation of ASPX files in web server directories, commonly targeted by attackers to deploy web shells for persistence, by monitoring file creation events and excluding known legitimate processes.

exploited SharePoint web-shell aspx persistence windows
2r 1t
medium advisory

GitHub SSH Certificate Configuration Changed

Attackers can modify SSH certificate configurations in GitHub organizations to gain unauthorized access, persist in the environment, escalate privileges, and operate stealthily.

Github ssh certificate initial-access persistence privilege-escalation stealth t1078.004
2r 4t
medium advisory

Potential Privilege Escalation via SUID/SGID on Linux

Attackers may leverage misconfigured SUID/SGID permissions on Linux systems to escalate privileges to root or establish persistence by executing processes with root privileges initiated by non-root users.

Elastic Defend privilege-escalation persistence defense-evasion suid sgid
2r 2t
medium advisory

Phoenix Long-Poll Transport Denial-of-Service Vulnerability

An unauthenticated denial-of-service vulnerability in Phoenix's long-poll transport allows a remote client to exhaust server memory by sending a series of crafted HTTP requests, affecting LiveView apps with a public Longpoll socket or Phoenix.Socket with longpoll option.

Phoenix dos webserver
2r 2t 1c
medium advisory

Microsoft Management Console File Execution from Unusual Path

This rule identifies the execution of Microsoft Management Console (MMC) files from unusual paths, a technique adversaries may use to bypass security controls and execute malicious code.

Microsoft Management Console execution defense-evasion windows
2r 5t
medium advisory

Micronaut TimeConverterRegistrar Memory Exhaustion via Accept-Language Header

Micronaut's `TimeConverterRegistrar` has an unbounded `formattersCache` that allows memory exhaustion via a crafted `Accept-Language` header, where an unauthenticated attacker can crash the JVM by sending requests with novel locale tags to `@Format`-annotated endpoints, growing the cache until heap memory is exhausted, affecting Micronaut applications with `micronaut-context` versions 4.3.0 and above, up to but not including 4.10.22.

micronaut-context dos memory-exhaustion micronaut
3r 2t
medium advisory

Local SxS Shared Module DLL Hijacking

Adversaries may abuse shared modules in local Side-by-Side (SxS) folders to execute malicious payloads by instructing the Windows module loader to load DLLs from arbitrary local paths, potentially bypassing security controls.

Windows dll-hijacking execution defense-evasion
2r 2t
medium advisory

Kubernetes Admission Controller Modification

An adversary modifies Kubernetes admission controller configurations to achieve persistence, escalate privileges, or gain unauthorized access to credentials within the cluster.

Kubernetes admission-controller privilege-escalation persistence credential-access
2r 2t
medium advisory

go-zserio Unbounded Memory Allocation Vulnerability

go-zserio versions prior to 0.9.1 are vulnerable to unbounded memory allocation when deserializing data, potentially leading to denial of service.

go-zserio memory-allocation denial-of-service
2r 1t
medium advisory

Detect AWS Route Table Modification via CloudTrail

An attacker may add a new route to an AWS route table, potentially redirecting network traffic for malicious purposes such as defense impairment or data exfiltration.

AWS EC2 +1 cloud aws network-routing
2r
medium advisory

Bitbucket Global SSH Settings Changed

An attacker modifies Bitbucket global SSH settings to potentially enable unauthorized access and lateral movement.

Bitbucket lateral-movement defense-impairment
2r 2t
medium advisory

M365 Identity Login from Atypical Region

Detects successful Microsoft 365 portal logins from a country and region the user has not previously authenticated from in a specific time window, potentially indicating unauthorized access attempts by analyzing login events and user location patterns.

Microsoft 365 cloud identity microsoft365
2r 1t
medium advisory

Exchange Mailbox Export via PowerShell

Adversaries may use the `New-MailboxExportRequest` PowerShell cmdlet to export mailboxes to PST files for sensitive data collection.

Exchange email-collection powershell
2r 4t
medium advisory

Detection of Suspicious PowerShell Arguments

This rule detects suspicious PowerShell arguments often used during malware installation, including encoded commands, file downloads, and obfuscation techniques.

PowerShell +1 malware execution obfuscation
2r 4t
medium advisory

MsiExec Child Process Spawning Network Connections for Defense Evasion

Detection of MsiExec spawning child processes that initiate network connections, potentially indicating abuse of Windows Installers for malware delivery and defense evasion.

Elastic Defend +3 defense-evasion windows msiexec
2r 1t
medium advisory

Entra ID OAuth Device Code Grant by Unusual User

An attacker uses device code authentication in Entra ID to phish users and steal access tokens, leading to unauthorized access and potential defense evasion.

Entra ID azure entra-id device-code phishing
2r 3t
medium advisory

Cryptographic Admission Control Framework for Autonomous Agents

A security framework called ACP employs cryptographic measures, including Ed25519 identities, capability tokens, delegation chains, anti-replay mechanisms, and an immutable audit ledger, to govern autonomous agents and prevent unauthorized system state changes.

Autonomous Agent Control Protocol +2 autonomous-agents cryptographic-control privilege-escalation audit-logging
2r 2t 3i
medium advisory

Bitbucket Audit Log Configuration Modified

An attacker may modify the Bitbucket audit log configuration to impair security monitoring and evade detection.

Bitbucket attack.defense-impairment attack.t1562.004
2r 1t
medium advisory

AWS STS GetFederationToken Request for Defense Evasion and Persistence

Detection of the first AWS Security Token Service (STS) GetFederationToken request by a user, which adversaries can abuse to obtain temporary credentials for persistence and to bypass IAM API call limitations by gaining console access.

AWS Security Token Service aws cloud defense-evasion persistence
2r 2t
medium advisory

AWS STS Role Chaining for Privilege Escalation and Persistence

AWS STS role chaining, where one assumed role is used to assume another, can lead to privilege escalation or persistence by refreshing session tokens, triggering alerts on the first observed role assumption based on CloudTrail logs.

AWS Security Token Service +1 aws sts role-chaining privilege-escalation persistence
2r 3t
medium advisory

AWS Secrets Manager Rapid Secrets Retrieval Attempts

Compromised AWS credentials may be used to rapidly retrieve multiple secrets from AWS Secrets Manager in order to escalate privileges or move laterally within the environment.

AWS Secrets Manager aws credential-access secrets-manager
2r 1t
medium advisory

Detection of Suspicious VScode Remote Tunnel Usage

This brief details the detection of potential command and control activity through the suspicious use of the VScode remote tunnel feature, which allows attackers to establish unauthorized remote access to systems.

Visual Studio Code command-and-control vscode remote-access windows
2r 1t
medium advisory

Persistence via Windows Installer (Msiexec)

Adversaries may establish persistence by abusing the Windows Installer (msiexec.exe) to create scheduled tasks or modify registry run keys, allowing for malicious code execution upon system startup or user logon.

Windows +21 persistence defense-evasion
3r 3t
medium advisory

M365 Identity Login from Impossible Travel Location

Detects successful Microsoft 365 portal logins from impossible travel locations, defined as logins originating from two different countries within a short timeframe, potentially indicating account compromise or unauthorized access.

Microsoft 365 cloud identity initial access
2r 1t
medium advisory

AWS Federated User Console Login without MFA Enforcement

Detection of successful AWS Management Console logins by federated users, which pose a security risk due to potential lack of enforced MFA as CloudTrail does not reliably record MFA status for federated users.

Amazon Web Services +1 aws cloudtrail federated-user initial-access
2r 1t
medium advisory

Service DACL Modification via sc.exe

Adversaries modify a service's DACL (Discretionary Access Control List) via `sc.exe` to deny access to key user groups, potentially making the service unstoppable or hiding it from users and the system, in order to evade defenses and persist.

Windows defense-evasion persistence
2r 2t
medium advisory

Suspicious Execution via Windows Command Debugging Utility (cdb.exe)

Adversaries can abuse the Windows command line debugging utility cdb.exe, specifically when executed from non-standard paths with specific command-line arguments (-cf, -c, -pd), to execute commands or shellcode for defense evasion.

Windows defense-evasion lolbas
2r 2t
medium advisory

Potential WSUS Abuse for Lateral Movement via PsExec

This rule detects potential abuse of Windows Server Update Services (WSUS) for lateral movement by identifying suspicious processes, specifically PsExec, initiated by WSUS (wuauclt.exe).

Windows Server Update Services lateral-movement windows wsus psexec
2r 2t
medium advisory

AWS S3 Object Versioning Suspended

Detection of S3 bucket versioning suspension via PutBucketVersioning API call, potentially indicating an attempt to inhibit system recovery by making restoration of deleted or overwritten objects impossible.

S3 aws versioning impact
2r 1t
medium advisory

AWS S3 Bucket Server Access Logging Disabled

An adversary may disable server access logging for an Amazon S3 bucket in order to impair defenses by removing logs that contain evidence of malicious activity.

S3 cloud aws defense-evasion
2r 1t
medium advisory

AWS S3 Bucket Replicated to Another Account

Detection of S3 bucket replication configurations sending data to a different AWS account, potentially indicating unauthorized data exfiltration by adversaries abusing replication rules.

Amazon S3 aws s3 exfiltration cloudtrail
2r 2t
medium advisory

Alternate Data Stream Creation/Execution at Volume Root Directory

Detection of Alternate Data Stream (ADS) creation at a volume root directory, a technique used to hide malware and tools by exploiting how ADSs in root directories are not readily visible to standard system utilities, indicating a defense evasion attempt.

Microsoft Defender XDR +2 defense-evasion hide-artifacts alternate-data-stream
2r 1t
medium advisory

AWS RDS DB Instance or Cluster Deletion Protection Disabled

An adversary may disable deletion protection on an AWS RDS DB instance or cluster as a precursor to destructive actions, such as deleting databases containing sensitive data.

AWS RDS cloud aws rds datadestruction
2r 2t
medium advisory

First Time Python Created a LaunchAgent or LaunchDaemon

Detection of the first-time a Python process creates or modifies a LaunchAgent or LaunchDaemon plist file on a given macOS host, which is indicative of persistence attempts via malicious scripts, compromised dependencies, or model file deserialization.

macOS +2 persistence python launchagent launchdaemon
2r 1t
medium advisory

VMware Tanzu Spring Framework Multiple Vulnerabilities

An anonymous, remote attacker can exploit multiple vulnerabilities in VMware Tanzu Spring Framework to disclose information or circumvent security measures.

Tanzu Spring Framework spring-framework vulnerability information-disclosure
2r 2t
medium advisory

Unsigned DLL Loaded by DNS Service

The rule identifies the loading of unusual or unsigned DLLs by the DNS Server process, which can indicate exploitation of the ServerLevelPluginDll functionality, potentially leading to privilege escalation and remote code execution with SYSTEM privileges.

Elastic Defend privilege-escalation execution persistence windows
2r 3t
medium advisory

russh Keyboard-Interactive Authentication Denial-of-Service

A denial-of-service vulnerability exists in the russh crate, where a malicious client can crash any russh-based server implementing keyboard-interactive authentication by sending a crafted SSH_MSG_USERAUTH_INFO_RESPONSE message with a large response count, leading to excessive memory allocation and an out-of-memory crash without requiring any credentials.

russh denial-of-service keyboard-interactive
2r 2t
medium advisory

Python .pth File Creation for Persistence

Attackers can establish persistence on Linux systems by creating malicious .pth files in Python package directories, causing arbitrary code execution on interpreter startup.

Copilot Studio +5 persistence python linux pth file_creation
2r 3t 2i updated
medium advisory

Potential Veeam Credential Access via SQL Commands

Attackers can leverage sqlcmd.exe or PowerShell commands like Invoke-Sqlcmd to access Veeam credentials stored in MSSQL databases, potentially targeting backups for destructive operations such as ransomware attacks.

Microsoft Defender XDR +1 veeam credential-access mssql windows ransomware
2r 5t
medium advisory

First Time Python Accessed Sensitive Credential Files on macOS

This alert triggers on the first instance of a Python process accessing sensitive credential files on macOS, potentially indicating post-exploitation credential theft.

Python +1 credential-access macos endpoint
2r 1t
medium advisory

AWS RDS Snapshot Deletion Detected

The deletion of AWS RDS DB snapshots or disabling backups via configuration changes can inhibit recovery, destroy forensic evidence, and prepare for destructive actions by adversaries.

Amazon RDS aws rds snapshot backup datadestruction
3r 2t
medium advisory

AWS RDS DB Instance Made Public

An attacker with compromised AWS credentials may modify an Amazon RDS DB instance or cluster to be publicly accessible for persistence, data exfiltration, or to bypass network restrictions.

AWS RDS cloud aws rds persistence defense_evasion
2r 3t
medium advisory

Potential Windows Session Hijacking via CcmExec

Adversaries may exploit Microsoft's System Center Configuration Manager by loading malicious DLLs into SCNotification.exe, a process associated with user notifications, potentially leading to Windows session hijacking.

System Center Configuration Manager defense-evasion dll-hijacking sccm
2r 1t
medium advisory

NTDS Dump via Wbadmin

Attackers with Backup Operator privileges may abuse wbadmin.exe to access the NTDS.dit file, enabling credential dumping and domain compromise.

Microsoft Defender XDR +4 credential-access windows wbadmin ntds.dit
2r 2t
medium advisory

Microsoft Management Console File Execution from Unusual Path

Adversaries may use Microsoft Management Console (MMC) files from untrusted paths to bypass security controls for initial access and execution on Windows systems.

Microsoft Management Console File +2 execution defense-evasion windows
2r 4t
medium advisory

DNS Global Query Block List Modified or Disabled

Attackers with DNSAdmin privileges can modify or disable the DNS Global Query Block List (GQBL) in Windows, allowing exploitation of hosts running WPAD with default settings for privilege escalation and lateral movement.

Elastic Defend +4 defense-evasion registry-modification windows
2r 3t
medium advisory

AWS RDS DB Instance or Cluster Password Modification

The modification of the master password for an AWS RDS DB instance or cluster can indicate malicious activity used for persistence, privilege escalation, or defense evasion.

RDS cloud aws persistence
2r 3t
medium advisory

First Time Python Spawned a Shell on macOS Host

This rule detects the first time a Python process spawns a shell on a given macOS host using the `-c` flag, indicating potential malicious activity stemming from compromised Python environments.

macOS +2 execution python
2r 1t
medium advisory

Roundcube Vulnerabilities Leading to Cross-Site Scripting and Information Disclosure

Multiple vulnerabilities in Roundcube allow an attacker to perform a cross-site scripting attack and disclose confidential information.

Roundcube xss vulnerability
2r 1t 3c
medium advisory

AWS IAM AdministratorAccess Policy Attached to Role

An adversary with compromised AWS credentials may escalate privileges or persist in the environment by attaching the AdministratorAccess AWS managed policy to an existing IAM role.

AWS IAM cloud aws iam privilege-escalation persistence
2r 2t
medium advisory

Unauthorized Modification of Azure Conditional Access Policy

An unauthorized actor modifies an Azure Conditional Access policy, potentially leading to privilege escalation, credential access, persistence, or defense impairment.

Azure Active Directory azure conditional-access policy-modification attack.privilege-escalation attack.credential-access attack.persistence attack.defense-impairment attack.t1548 +1
2r 2t
medium advisory

Suspicious ScreenConnect Client Child Process Activity

This rule identifies suspicious child processes spawned by ScreenConnect client processes, potentially indicating unauthorized access and command execution abusing ScreenConnect remote access software to perform malicious activities such as data exfiltration or establishing persistence.

Elastic Defend +3 command-and-control defense-evasion execution persistence screenconnect
2r 11t 2c
medium advisory

AWS Bedrock Model Invocation Logging Deletion

Detection of AWS Bedrock model invocation logging configuration deletion via the DeleteModelInvocationLogging API in CloudTrail logs, potentially indicating an adversary attempting to evade detection of malicious AI model usage.

Bedrock aws cloudtrail defense-evasion
2r 1t
medium advisory

Suspicious Sensitive Key and Password Searches within Linux Containers

Adversaries may search for sensitive credentials, such as SSH keys and passwords, within Linux containers using utilities like grep and find, potentially leading to unauthorized access or container escape.

container credential-access linux
2r 4t updated
medium advisory

Suspicious Child Processes Spawned by JetBrains TeamCity

Detection of suspicious processes spawned by JetBrains TeamCity indicates potential exploitation of remote code execution vulnerabilities, with attackers using command interpreters and system binaries for malicious purposes.

TeamCity supply-chain initial-access
2r 17t 1c
medium advisory

AWS Route 53 Resolver Query Log Configuration Deleted

Detection of the deletion of an Amazon Route 53 Resolver Query Log Configuration, potentially stopping DNS query and response logging for associated VPCs, which can be used by adversaries to evade detection and suppress forensic evidence.

AWS Route 53 Resolver aws cloudtrail route53 defense_evasion
2r 1t
medium advisory

AWS EC2 EBS Snapshot Shared or Made Public

An AWS Elastic Block Store (EBS) snapshot is shared with another AWS account or made public, potentially leading to data exfiltration and persistence operations.

Amazon EC2 +1 cloud aws exfiltration
2r 1t
medium advisory

Google Workspace Object Copied from External Drive Followed by OAuth Consent

Detects a sequence of events where a user copies a Google Workspace object (spreadsheet, form, document, or script) from an external drive and subsequently grants OAuth permissions to a custom application, potentially indicating a phishing attack leveraging container-bound scripts.

Google Workspace +5 google-workspace oauth phishing initial-access persistence
1r 3t
medium advisory

Azure AD Root Certificate Authority Added for Passwordless Authentication

An attacker may add a new root certificate authority to an Azure AD tenant to support certificate-based authentication for persistence, privilege escalation, or defense evasion.

Azure Active Directory attack.credential-access attack.persistence attack.privilege-escalation attack.defense-impairment attack.t1556
2r 4t
medium advisory

Suspicious JetBrains TeamCity Child Process Activity

Detection of suspicious processes spawned by JetBrains TeamCity indicates potential exploitation of remote code execution vulnerabilities.

TeamCity jetbrains rce supply-chain
2r 17t 1c
medium advisory

OpenSSL Vulnerability Allows Denial of Service and Information Disclosure

A remote, authenticated attacker can exploit a vulnerability in OpenSSL to perform a denial-of-service attack and disclose information.

OpenSSL denial-of-service information-disclosure
2r 2t
medium advisory

phpseclib OID Amplification DoS Vulnerability

A vulnerability exists in phpseclib when loading untrusted ASN1 files, potentially leading to an OID amplification denial-of-service (DoS) in the ASN1::decodeOID() function.

phpseclib +2 denial-of-service asn1
2r 1t
medium advisory

AWS EC2 Instance Connect SSH Public Key Upload

This rule detects the uploading of new SSH public keys to AWS EC2 instances using the EC2 Instance Connect service, which could indicate an adversary attempting to maintain access, escalate privileges, or move laterally within the cloud environment.

EC2 +1 cloud aws ssh lateral-movement privilege-escalation persistence
2r 3t
medium advisory

Microsoft Defender Tampering via Registry Modification

Adversaries may disable or tamper with Microsoft Defender features to evade detection and conceal malicious behavior by modifying specific registry keys and values.

Microsoft Defender defense-evasion registry-modification windows
3r 2t
medium advisory

Veeam Backup Library Loaded by Unusual Process

Detects potential credential decryption operations by PowerShell or unsigned processes using the Veeam.Backup.Common.dll library, indicating potential credential access attempts to target backups as part of destructive operations.

Veeam Backup credential-access veeam powershell
2r 3t
medium advisory

AWS EC2 AMI Shared with Another Account for Potential Exfiltration

An AWS Amazon Machine Image (AMI) being shared with another AWS account could indicate data exfiltration, as AMIs may contain sensitive data, and unauthorized sharing can lead to exposure.

AWS EC2 aws ami exfiltration
2r 1t
medium advisory

Logback Denial of Service Vulnerability

A remote, anonymous attacker can exploit a vulnerability in Logback to perform a denial-of-service (DoS) attack.

Logback denial-of-service java
2r 3t
medium advisory

Insecure AWS EC2 VPC Security Group Ingress Rule Added

An AWS EC2 VPC security group ingress rule was added to allow traffic from any IP address (0.0.0.0/0 or ::/0) to common remote access ports, potentially exposing instances to unauthorized access and defense evasion.

EC2 +1 aws security-group defense-evasion
2r 2t
medium advisory

Potential AWS S3 Bucket Ransomware Note Upload

An adversary may upload a ransomware note to an AWS S3 bucket by abusing compromised credentials or overly permissive bucket policies, potentially leading to data encryption or exfiltration.

S3 aws ransomware impact
3r 3t
medium advisory

GenAI Process Connection to Unusual Domain on macOS

This rule detects GenAI tools on macOS connecting to unusual domains, potentially indicating command and control activity, data exfiltration, or malicious payload retrieval following compromise via prompt injection, malicious MCP servers, or poisoned plugins.

Copilot +22 genai command and control macos network connection
2r 1t
medium advisory

AWS EC2 Unauthorized Admin Credential Fetch via Assumed Role

The rule detects the first occurrence of an unauthorized attempt by an AWS role to use `GetPasswordData` to access the administrator password of an EC2 instance, potentially indicating privilege escalation or lateral movement.

EC2 cloud aws credential-access
2r 2t
medium advisory

Zserio Runtime Unbounded Memory Allocation Vulnerability

A crafted payload can force memory allocations of up to 16 GB, leading to a denial-of-service condition in applications using the Zserio serialization framework, including those within the automotive Navigation Data Standard (NDS).

Navigation Data Standard +1 zserio denial-of-service memory-allocation nds
2r 1t
medium advisory

Monetr Lunch Flow SSRF Vulnerability

A server-side request forgery (SSRF) vulnerability in Monetr's Lunch Flow integration allows authenticated users on self-hosted instances to send HTTP GET requests to arbitrary URLs, potentially exposing sensitive information.

Monetr ssrf monitr github-advisory
2r 1t 1i
medium advisory

Kubernetes Event Deletion for Defense Evasion

An adversary may delete Kubernetes events to evade detection and hide malicious activity within a Kubernetes environment by removing audit logs.

Kubernetes stealth defense-evasion
2r 1t
medium advisory

AWS Systems Manager SecureString Parameter Request with Decryption Flag

This rule detects when an AWS resource accesses SecureString parameters within AWS Systems Manager (SSM) with the decryption flag set to true, potentially indicating credential access.

AWS Systems Manager aws credential-access cloud
2r 1t
medium advisory

AWS S3 Bucket Policy Modified to Share with External Account

An attacker modifies an Amazon S3 bucket policy to grant access to an external AWS account, potentially leading to unauthorized data access and exfiltration.

S3 aws bucket_policy exfiltration
2r 3t
medium advisory

AWS IAM Roles Anywhere Trust Anchor Created with External CA

The creation of an AWS IAM Roles Anywhere Trust Anchor using an external Certificate Authority (CA) instead of an AWS-managed CA allows adversaries to establish persistent access by using their own CA to sign certificates for authentication.

IAM Roles Anywhere aws iam rolesanywhere persistence
2r 2t
medium advisory

Azure AD Certificate-Based Authentication Enabled

Enabling certificate-based authentication (CBA) in Azure Active Directory can be abused by attackers to establish persistence, escalate privileges, and impair defenses.

Azure Active Directory azure certificate-based-authentication persistence privilege-escalation
2r 1t
medium advisory

Bitbucket Global Secret Scanning Rule Deletion

An adversary with administrative privileges may delete global secret scanning rules in Bitbucket to impair defenses and exfiltrate sensitive data without detection.

Bitbucket attack.defense-impairment attack.t1685
2r 1t
medium advisory

Potential Abuse of AWS Console GetSigninToken

Adversaries may abuse the AWS GetSigninToken API to create temporary federated credentials for obfuscating compromised AWS access keys and pivoting to console sessions without MFA, potentially leading to lateral movement within the AWS environment.

AWS CloudTrail aws cloud lateral-movement credential-access
2r 2t
medium advisory

Bitbucket Repository Exempted from Secret Scanning

An attacker may attempt to disable or bypass secret scanning on a Bitbucket repository to avoid detection of committed secrets, potentially leading to credential compromise and subsequent unauthorized access.

Bitbucket Server attack.defense-impairment attack.t1685 bitbucket
2r 1t
medium advisory

AWS SSM Session Started to EC2 Instance for Lateral Movement

An AWS user or role establishing a session via SSM to an EC2 instance may indicate lateral movement, and this rule detects the first occurrence of such an event.

AWS Systems Manager +1 aws lateral-movement ssm
2r 1t
medium advisory

AWS EC2 User Data Retrieval for EC2 Instance

Detection of the AWS EC2 DescribeInstanceAttribute API call to retrieve the userData attribute, potentially exposing sensitive information like credentials or configuration details.

EC2 +1 aws cloudtrail userdata discovery credential-access
2r 2t
medium advisory

Bitbucket User Login Failure Detection

Detection of Bitbucket user login failures, potentially indicating credential access attempts, initial access attempts, or other malicious activity.

Bitbucket authentication brute-force credential-access initial-access
2r 3t
medium advisory

GitHub Repository Deletion Detection

Detection of unauthorized GitHub repository deletion within an organization, potentially leading to irreversible data loss and indicating compromise.

GitHub repository deletion impact
2r 1t
medium advisory

Autodesk Fusion Stored XSS Vulnerability via Maliciously Crafted Design Name

A stored cross-site scripting (XSS) vulnerability exists in the Autodesk Fusion desktop application, where a maliciously crafted HTML payload stored in a design name and exported to CSV can be triggered, potentially leading to local file reads or arbitrary code execution.

Autodesk Fusion xss autodesk cve-2026-4345 application
2r 2t 1c 2i
medium advisory

Algolia Admin Keys Exposed in Open Source Documentation

A security researcher discovered 39 Algolia admin keys exposed across various open source documentation websites, potentially allowing unauthorized access and modification of search indices.

Algolia DocSearch algolia api-key data-breach information-disclosure
2r 2t 1i
medium advisory

Google Workspace Application Removed from Blocklist

An adversary with Google Workspace administrative privileges may remove an application from the explicit blocklist to enable its distribution and usage, potentially indicating unauthorized activity and defense evasion.

Google Workspace google_workspace defense_evasion cloud
2r 2t
medium advisory

Remote File Copy to a Hidden Share

Detects remote file copy attempts to hidden network shares, indicative of lateral movement or data staging, by monitoring command-line tools like cmd.exe and powershell.exe for hidden share patterns.

Windows lateral-movement collection
2r 3t
medium advisory

Suspicious Child Processes from Communication Applications

The detection rule identifies suspicious child processes spawned from communication applications on Windows systems, potentially indicating masquerading or exploitation of vulnerabilities within these applications.

Elastic Defend +12 defense-evasion persistence windows
3r 3t
medium advisory

Potential Account Takeover via Mixed Logon Types

Atypical logon patterns, where a high-volume account (e.g., service account) exhibits successful logons using an unusual logon type with low frequency, may indicate account takeover or stolen credentials.

Windows account-takeover privilege-escalation
2r 1t
medium advisory

Kubernetes Secret or ConfigMap Access via Azure Arc Proxy

Detection of unauthorized access to Kubernetes secrets or configmaps via the Azure Arc AAD proxy service account, indicating potential abuse of stolen service principal credentials to read, exfiltrate, or modify sensitive data.

Azure Arc +2 kubernetes azure-arc credential-access collection
2r 2t
medium advisory

Azure Firewall Rule Collection Modification or Deletion

An attacker may modify or delete Azure Firewall rule collections (Application, NAT, and Network) to impair defenses and potentially enable malicious traffic.

Azure Firewall azure firewall defense-impairment
2r 2t
medium advisory

AWS Console Login by User from New Region

An AWS account may be compromised if a user logs into the AWS console from a geographic region they have never accessed before, potentially indicating unauthorized access or account takeover.

AWS Management Console cloud aws iam account_compromise
2r 1t
medium advisory

Suspicious Svchost.exe Spawning Cmd.exe

Detects suspicious activity where svchost.exe spawns cmd.exe, potentially indicating malware masquerading or privilege escalation on Windows systems.

Windows execution svchost cmd
2r 2t
medium advisory

Potential Enumeration via Active Directory Web Service

Adversaries may abuse the Active Directory Web Service (ADWS) to enumerate network resources and user accounts, by loading AD-related modules followed by a network connection to the ADWS dedicated TCP port.

Active Directory Web Service active-directory enumeration adws discovery windows
2r 3t
medium advisory

WinRAR and 7-Zip Encryption Abuse for Data Exfiltration Preparation

Adversaries use WinRAR or 7-Zip to create encrypted archives in preparation for data exfiltration, using command-line arguments to enable encryption functionality.

WinRAR +1 data-exfiltration archive encryption windows
3r 2t
medium advisory

Windows Defender Disabled via Registry Modification

Attackers modify Windows Defender registry settings to disable the service or set the service to manual start, evading defenses to operate undetected.

Windows Defender defense-evasion windows registry-modification
3r 3t
medium advisory

Windows Console History Clearing

Adversaries may clear the command history of a compromised account to conceal the actions undertaken during an intrusion on a Windows system.

M365 Defender +1 defense-evasion powershell windows
2r 2t
medium advisory

System Information Discovery Detection

This detection identifies system information discovery techniques by monitoring process execution logs for commands like `wmic qfe`, `systeminfo`, and `hostname`, often used by attackers to gather system configuration details for further exploitation, potentially leading to privilege escalation, persistence, or data exfiltration.

Windows discovery endpoint
2r 1t
medium advisory

Suspicious Windows Process Cluster from Parent Process via Machine Learning

A machine learning model detected a parent process spawning a cluster of suspicious Windows processes with high malicious probability scores, potentially indicating LOLBins usage and defense evasion.

Windows defense-evasion lolbin
2r 2t
medium advisory

Suspicious Explorer Child Process via DCOM

A suspicious Windows Explorer child process is detected, indicating potential exploitation of explorer.exe to launch malicious scripts or executables from a trusted parent process via DCOM.

Windows explorer.exe dcom initial-access defense-evasion execution
3r 9t
medium advisory

Suspicious AWS ECR Container Upload by Unknown User

This alert detects a container image upload to an AWS Elastic Container Registry (ECR) repository by a user that is not typically associated with such actions, potentially indicating account compromise or insider threat activity.

Elastic Container Registry aws ecr cloud container
2r 1t
medium advisory

Service Reconnaissance via WMIC.exe

Adversaries use WMIC.exe to enumerate running services on remote devices, potentially identifying valuable targets or misconfigured systems.

Windows attack.execution attack.t1047
2r 1t
medium advisory

Remote Management Software Launch After MSI Install

Attackers are leveraging MSI installers to deploy remote management software (RMM) such as ScreenConnect, Syncro, and VNC, potentially indicating unauthorized access and control over compromised systems.

ConnectWise ScreenConnect +3 remote-access rmm msi command-and-control
3r
medium advisory

Keitaro Tracker Abused in AI-Driven Investment Scams

The Keitaro Tracker advertising platform is being exploited by malicious actors to facilitate AI-driven investment scams.

Keitaro Tracker keitaro tds traffic-direction investment-scam ai
2r 2t 1i
medium advisory

Fortigate SSL VPN Login Followed by SIEM Alert

Detection of initial access via Fortigate SSL VPN login, followed by a SIEM alert, indicating potential malicious activity post-VPN access.

Fortigate SSL VPN fortigate sslvpn initial-access siem
2r
medium advisory

Expired or Revoked Driver Loaded

An expired or revoked driver being loaded on a Windows system may indicate an attempt to gain code execution in kernel mode or abuse revoked certificates for malicious purposes, potentially leading to privilege escalation or defense evasion.

Elastic Defend privilege-escalation defense-evasion windows
2r 3t
medium advisory

DiceBear SVG Size Capping Bypass Leads to Denial of Service

A denial-of-service vulnerability exists in DiceBear versions prior to 9.4.2 due to a bypassable regex in the `ensureSize()` function, allowing attackers to craft SVGs that cause out-of-memory crashes during rendering on Node.js.

DiceBear +1 dos svg vulnerability
2r 1t
medium advisory

Detection of Unauthorized GitHub Actions Runner Registration

The configuration of a GitHub Actions self-hosted runner using the Runner.Listener binary can indicate malicious activity aimed at establishing remote code execution via malicious GitHub workflows.

GitHub Actions Runner github-actions supply-chain remote-code-execution
3r 3t
medium advisory

Cisco IOS and IOS XE HTTP Server Denial-of-Service Vulnerability (CVE-2026-20125)

CVE-2026-20125 allows an authenticated, remote attacker to cause a denial of service by sending malformed HTTP requests to a Cisco IOS or IOS XE device, triggering a device reload.

Cisco IOS +1 cisco ios ios-xe dos CVE-2026-20125
3r 1t
medium advisory

AWS CreateLoginProfile Activity Detection

Detects the creation of AWS IAM login profiles, which can be indicative of new user creation or modifications by potentially malicious actors for privilege escalation or persistence.

AWS Identity and Access Management aws cloud iam privilege_escalation persistence
2r 2t
medium advisory

Apple's App Translocation Security Mechanism

Apple's App Translocation in macOS v10.12 mitigates Gatekeeper bypasses (CVE-2015-3715, CVE-2015-7024) by creating a read-only DMG, impacting applications accessing external resources.

ictool app-translocation gatekeeper macos security-mitigation
2r 2c
medium advisory

AdFind.exe Execution with Reconnaissance Arguments

This rule detects the execution of AdFind.exe with specific command-line arguments used for reconnaissance, often associated with threat actors like Wizard Spider, FIN6, and groups linked to SUNBURST, who use it to enumerate domain controllers.

AdFind +2 Conti +3 active-directory reconnaissance discovery
2r 1t 1i
medium advisory

Office Test Registry Persistence for Malicious DLL Execution

Attackers can modify the Microsoft Office 'Office Test' Registry key to establish persistence by loading a malicious DLL that executes every time an MS Office application starts.

Microsoft Office persistence registry modification office test
2r 2t
medium advisory

Node.js Spawning Curl or Wget for Command and Control

Detection of Node.js directly or via a shell spawning curl or wget, potentially indicating command and control behavior where adversaries download tools or payloads onto the system.

Node.js command_and_control nodejs curl wget initial_access
2r 2t
medium advisory

Encoded Executable Stored in the Registry

This rule detects registry modifications used to hide encoded portable executables, indicating a defense evasion technique where adversaries avoid storing malicious content directly on disk by writing encoded executables to the Windows Registry.

Windows defense-evasion registry-modification encoded-executable
2r 3t 1i
medium advisory

Azure AD Authentication from Unexpected Geo-locations

Detection of successful authentications originating from geographic locations outside of an organization's expected operational footprint, potentially indicating compromised credentials or unauthorized access.

Azure Active Directory azuread authentication geo-location unauthorized-access credential-compromise privilege-escalation
2r 1t
medium advisory

free5GC PCF Nil Pointer Dereference Vulnerability

A nil-pointer dereference vulnerability exists in free5GC's PCF when handling POST requests to `/npcf-smpolicycontrol/v1/sm-policies`. When a downstream UDR lookup returns a 404 error, the handler continues execution instead of returning, leading to a nil response struct dereference and a panic. This results in an HTTP 500 error for the request, but the PCF process continues running. The vulnerability is triggered by sending a POST request with input that causes the downstream UDR lookup to fail, such as an unknown DNN. This issue affects free5GC versions v4.1.0 and v4.2.1.

PCF denial-of-service vulnerability web-application
2r 1t 2i
medium advisory

Zoom Meetings Created Without Passcodes

Detection of Zoom meetings created without a passcode, which are susceptible to Zoombombing and potential disruption or exposure of sensitive information.

Zoom Meetings zoom initial-access configuration-audit zoombombing
2r 2t
medium advisory

Web Server Local File Inclusion Activity Detected

Detection of potential Local File Inclusion (LFI) activity on web servers through HTTP GET requests attempting to access sensitive local files via directory traversal or known file paths, potentially leading to information disclosure and system compromise.

Nginx +4 web-server lfi file-inclusion discovery credential-access initial-access
3r 4t
medium advisory

VaultCmd Usage for Listing Windows Credentials

Adversaries may use vaultcmd.exe to list credentials stored in the Windows Credential Manager to gain unauthorized access to saved usernames and passwords, potentially in preparation for lateral movement.

Microsoft Defender XDR +1 credential-access windows vaultcmd
2r 2t
medium advisory

Suspicious Registry Modifications by Scripting Engines

The use of scripting engines like WScript and CScript to modify the Windows registry can indicate an attempt to bypass standard tools and evade defenses, potentially for persistence or other malicious activities.

Windows defense-evasion persistence execution registry-modification
2r 3t
medium advisory

Scheduled Task Created or Deleted via Command Line

Detection of scheduled task creation or deletion via command-line, often used for persistence and privilege escalation by threat actors.

Windows persistence privilege_escalation scheduled_task
2r 2t
medium advisory

Program Files Directory Masquerading

Adversaries may masquerade malicious executables within directories mimicking the legitimate Windows Program Files directory to evade defenses and execute untrusted code.

Elastic Defend +2 defense-evasion masquerading windows
2r 1t
medium advisory

Prismatic WordPress Plugin Stored XSS Vulnerability

The Prismatic plugin for WordPress versions 3.7.3 and earlier is vulnerable to stored cross-site scripting (XSS) via the 'prismatic_encoded' pseudo-shortcode, allowing unauthenticated attackers to inject arbitrary web scripts into pages.

Prismatic plugin +1 wordpress xss plugin prismatic
2r 1t 1c
medium advisory

Potential LSASS Memory Dump Activity

This brief covers the potential for credential access via LSASS memory dumping, a technique used to steal credentials from memory, though specific details are absent from the provided source.

Windows credential-access lsass memory-dump
2r 1t
medium advisory

Potential Evasion via Filter Manager

Adversaries may abuse the Filter Manager Control Program (fltMC.exe) to unload filter drivers, evading defenses like EDR and antivirus.

Windows defense-evasion filter-manager
2r 1t
medium advisory

Okta Policy Rule Modification or Deletion

An Okta policy rule was modified or deleted, potentially weakening security controls.

Okta identity policy attack.impact
2r 1t
medium advisory

Okta Initial Access via Proxy

Detection of a first-time user session started via a proxy, potentially indicating unauthorized initial access.

Okta initial-access proxy
2r 1t
medium advisory

Newly Observed Fortigate Alert

This brief covers a newly observed Fortigate alert rule added to the Elastic detection rules repository, potentially indicating emerging threat activity targeting Fortigate devices.

Fortigate intrusion-detection network-security
2r 7t
medium advisory

Kubernetes Cluster Enumeration via Audit Logs

Attackers attempt to enumerate and discover sensitive information within a Kubernetes cluster by leveraging common shells, utilities, and specialized tools, as reflected in audit logs.

Kubernetes enumeration cloud
3r 2t
medium advisory

GCP Storage Bucket Deletion for Impact

An adversary may delete a Google Cloud Platform (GCP) storage bucket to disrupt business operations, detected via GCP audit logs.

Google Cloud Platform +1 cloud gcp impact
2r 1t
medium advisory

Enhancing Detection Capabilities Through PowerShell Script Logging

This brief highlights the importance of PowerShell and script logging to improve threat detection capabilities within an organization's environment, focusing on increased visibility into malicious activities.

PowerShell script-logging threat-detection
2r 6t
medium advisory

Discussion of EDR Killers on Reddit

A Reddit post on r/blueteamsec references an ESET WeLiveSecurity article discussing EDR killer techniques that extend beyond driver manipulation.

Endpoint Detection and Response edr-evasion defense-evasion red-team
2r 2t
medium advisory

AWS SAML Identity Provider Modification

An adversary may attempt to modify the AWS SAML Identity Provider configuration to potentially escalate privileges or disrupt federated access.

AWS Identity and Access Management aws saml identity-provider privilege-escalation
2r 1t
medium advisory

AWS KMS Key User Performing S3 Encryption

Detection of AWS users employing KMS keys for S3 encryption, potentially indicating suspicious data handling within cloud environments.

AWS Identity and Access Management +2 aws kms s3 cloud encryption
2r 1t
medium advisory

AWS IAM Group Deletion Failure

Detection of a failed attempt to delete an AWS IAM group, which could indicate an attempt to remove audit trails or disrupt security policies.

AWS Identity and Access Management aws iam cloud deletion
2r 1t
medium advisory

AWS Console Login by User from New City

Detection of AWS console logins by a user from a previously unseen city, potentially indicating compromised credentials or account takeover.

AWS Management Console aws cloud account-takeover credential-compromise
2r 1t
medium advisory

Admidio SAML Assertion Consumer Service (ACS) URL Validation Bypass

Admidio's SAML IdP implementation in its SSO module is vulnerable to sending SAML responses to unvalidated Assertion Consumer Service URLs, allowing an attacker to craft a SAML AuthnRequest with an arbitrary AssertionConsumerServiceURL, causing the IdP to send the signed SAML response, containing user identity attributes, to an attacker-controlled URL, enabling impersonation of the victim user on the legitimate SP by replaying the SAML assertion.

admidio saml sso acs-bypass cve-2026-41670
2r 2t 2i
medium advisory

Local Account TokenFilter Policy Modification for Defense Evasion

Modification of the LocalAccountTokenFilterPolicy registry key to enable high-integrity tokens for local administrator accounts is detected, potentially allowing attackers to bypass User Account Control (UAC) and facilitate lateral movement.

Windows defense-evasion lateral-movement registry-modification
2r 3t
medium advisory

AWS IAM AdministratorAccess Policy Attached to User

An adversary with compromised AWS credentials may attempt to escalate privileges or persist access by attaching the AdministratorAccess AWS managed policy to an existing IAM user via the AttachUserPolicy API, granting full access to all AWS services and resources.

AWS IAM aws iam privilege-escalation persistence
2r 2t
medium advisory

Windows Registry Classes Autorun Keys Modification for Persistence

Adversaries modify Windows Registry Classes keys to establish persistence by executing malicious code when specific file types are opened or actions are performed, potentially leading to privilege escalation and persistent access.

Windows attack.privilege-escalation attack.persistence attack.t1547.001
3r 1t
medium advisory

Remote File Download via Script Interpreter

Attackers are using Windows script interpreters (cscript.exe or wscript.exe) to download executable files from remote locations to deliver second-stage payloads or download tools.

Windows Script Host command-and-control execution windows script_interpreter
2r 3t
medium advisory

Kerberos Pre-authentication Disabled for User Account

Detection of Kerberos pre-authentication being disabled for a user account, potentially leading to AS-REP roasting and offline password cracking by attackers with GenericWrite or GenericAll rights over the account.

Active Directory kerberos credential-access as-rep-roasting active-directory windows
3r 4t
medium advisory

CircleCI Security Step Disabled Detection

Detection of disabling security steps in CircleCI, potentially indicating an attempt to bypass security controls during the CI/CD process.

CircleCI ci/cd devops security-bypass
2r 1t
medium advisory

Detection of Obfuscated IP Address Usage in Download Commands

This brief details the use of obfuscated IP addresses within download commands, often employed to evade detection by hiding the true destination of malicious downloads.

Windows discovery evasion obfuscation
2r 2t
medium advisory

Suspicious Zoom Child Process Activity

The spawning of command interpreters (cmd.exe, powershell.exe, pwsh.exe) as child processes of Zoom.exe is indicative of potential exploitation or malicious masquerading, allowing attackers to execute arbitrary commands within the context of the Zoom application.

Zoom masquerading process-injection defense-evasion
2r 5t
medium advisory

M365 Copilot Impersonation Jailbreak Attempt Detection

This detection identifies M365 Copilot impersonation and roleplay jailbreak attempts by analyzing exported eDiscovery prompt logs, searching for users manipulating the AI into adopting alternate personas or bypassing safety controls via roleplay keywords, categorizing specific impersonation types to identify persona injection attacks.

Microsoft 365 Copilot copilot jailbreak ai persona-injection
2r 1t
medium advisory

Mozilla Firefox and Thunderbird GMP Component Denial-of-Service Vulnerability (CVE-2026-4709)

A vulnerability exists in the Audio/Video: GMP component of Mozilla Firefox and Thunderbird due to incorrect boundary conditions, potentially leading to a denial-of-service condition.

Firefox +1 cve-2026-4709 denial-of-service thunderbird
2r 1t
medium advisory

Kyverno Controller Denial of Service via forEach Mutation Panic

An unchecked type assertion in Kyverno versions v1.13.0 to v1.17.1 allows a user with permission to create a Policy or ClusterPolicy to crash the cluster-wide background controller into a persistent CrashLoopBackOff, leading to a denial of service, by crafting a malicious policy that triggers a nil pointer dereference in the forEach mutation handler.

Kyverno denial-of-service kubernetes policy-engine
2r 2t
medium advisory

CI4MS Improper Sanitization of User Input Leading to XSS

CI4MS versions prior to 0.31.2.0 are vulnerable to stored cross-site scripting due to improper sanitization of user-controlled input within the System Settings – Company Information, allowing attackers to inject arbitrary JavaScript into public-facing pages.

CI4MS xss codeigniter cms
2r 1t 1c
medium advisory

Application Compatibility Shim Database Installation for Persistence

Attackers abuse Application Compatibility Shims to establish persistence by installing custom shim databases, allowing for stealthy code execution within legitimate Windows processes.

Windows persistence app-compat
2r 1t
medium advisory

Active Directory msPKIAccountCredentials Modification

Attackers can modify the msPKIAccountCredentials attribute in Active Directory user objects to abuse credential roaming, potentially overwriting files for privilege escalation, by injecting malicious credential objects.

Active Directory privilege-escalation credential-roaming active-directory windows
2r 2t
medium advisory

Kaspersky Anti-Virus Reverse Engineering for Document Detection

A blog post details the reverse engineering of the Kaspersky anti-virus engine on macOS to demonstrate the potential for crafting signatures capable of detecting and flagging classified documents, leveraging the product's scanning capabilities and dynamic signature updates, without implying any malicious activity by Kaspersky.

Kaspersky Internet Security anti-virus reverse-engineering signature-analysis macos
2r 1t
medium advisory

XSL Script Execution via COM Interface in Microsoft Office

Adversaries may exploit Microsoft Office applications to execute malicious JScript or VBScript by leveraging the Microsoft.XMLDOM COM interface to process and transform XML documents using XSL scripts, potentially leading to initial access or defense evasion.

Microsoft Office +3 xsl-script com-interface office-macro
2r 5t
medium advisory

System Language Discovery via Reg.Exe

Adversaries use reg.exe to query system language settings in order to determine the geographic location of victims, customize payloads, or evade detection by avoiding certain locales.

Windows discovery system-language reg.exe
2r 1t
medium advisory

Okta Network Zone Deactivation or Deletion

An Okta network zone was deactivated or deleted, potentially indicating malicious activity aimed at bypassing security controls.

Okta Identity Engine okta network-zone impact
2r 1t
medium advisory

Mozilla Firefox and Thunderbird Information Disclosure Vulnerability (CVE-2026-4712)

CVE-2026-4712 is an information disclosure vulnerability in the Widget: Cocoa component affecting Firefox versions less than 149, Firefox ESR versions less than 140.9, Thunderbird versions less than 149, and Thunderbird versions less than 140.9, potentially allowing a remote attacker to access sensitive information.

Firefox +1 information disclosure thunderbird cve-2026-4712
2r 1t
medium advisory

macOS Mojave Sandbox Distributed Notification Bypass

A vulnerability in macOS Mojave allows sandboxed applications to bypass sandbox restrictions and surreptitiously monitor user activities by registering for distributed notifications by name, circumventing intended privacy protections.

macOS sandbox-escape privacy
2r 1t
medium advisory

Simple Social Media Share Buttons CSRF Vulnerability (CVE-2026-34904)

A cross-site request forgery (CSRF) vulnerability exists in the Simple Social Media Share Buttons WordPress plugin (versions through 6.2.0), potentially allowing attackers to perform unauthorized actions on behalf of authenticated users.

Simple Social Media Share Buttons csrf wordpress plugin vulnerability
2r 1t 1c
medium advisory

Potential NetNTLMv1 Downgrade Attack via Registry Modification

Attackers modify the Windows registry to weaken NTLM authentication, forcing a downgrade to the less secure NTLMv1 protocol, potentially leading to credential compromise.

Windows ntlm downgrade registry defense-evasion credential-access
2r 2t
medium advisory

WP Statistics Plugin Stored XSS Vulnerability (CVE-2026-5231)

The WP Statistics WordPress plugin is vulnerable to stored cross-site scripting (XSS) via the 'utm_source' parameter, allowing unauthenticated attackers to inject arbitrary web scripts into admin pages.

WP Statistics wordpress xss cve-2026-5231 wp-statistics
2r 1t 1c
medium advisory

Windows Scheduled Tasks AT Command Enabled via Registry Modification

Attackers may enable the deprecated Windows scheduled tasks AT command via registry modification to achieve local persistence or lateral movement on a compromised system.

Windows defense_evasion execution
2r 2t
medium advisory

LSASS Credential Dumping via Windows Error Reporting (WER) Abuse

Attackers can enable full user-mode dumps system-wide via registry modification to facilitate LSASS credential dumping, allowing extraction of credentials from process memory without deploying malware.

Elastic Defend +2 credential-access windows lsass wepw
2r 2t
medium advisory

Langflow Unauthenticated Image Retrieval Vulnerability (CVE-2026-33484)

Langflow versions 1.0.0 through 1.8.1 are vulnerable to an unauthenticated image retrieval vulnerability (CVE-2026-33484) that allows attackers to download any user's uploaded images without credentials in multi-tenant deployments by accessing the `/api/v1/files/images/{flow_id}/{file_name}` endpoint.

Langflow unauthenticated-access image-retrieval vulnerability
2r 1t
medium advisory

GCP Logging Sink Deletion for Defense Evasion

Detection of Google Cloud Platform (GCP) Logging sink deletion, a technique used by adversaries to impair defenses and evade detection by preventing log entries from being exported to designated destinations.

Google Cloud Platform +1 gcp logging defense-evasion
2r 1t
medium advisory

Unusual Network Connection via RunDLL32

The rule detects unusual outbound network connections made by rundll32.exe, specifically when executed with minimal arguments, which may indicate command and control activity or defense evasion tactics on Windows systems.

Elastic Defend +1 defense-evasion command-and-control windows
2r 2t
medium advisory

Persistence via BITS Job Notify Cmdline

Adversaries can achieve persistence by abusing the Background Intelligent Transfer Service (BITS) SetNotifyCmdLine method to execute a program after a job finishes, leading to arbitrary code execution and system compromise.

Defender XDR +2 persistence bits windows
2r 1t
medium advisory

Google Workspace Suspicious Login Activity

Detect Google Workspace login activity that Google has classified as suspicious, potentially indicating initial access, privilege escalation, defense evasion, or persistence attempts.

Google Workspace initial-access privilege-escalation defense-evasion persistence gworkspace
3r 1t
medium advisory

Network-Level Authentication (NLA) Disabled via Registry Modification

Detection of attempts to disable Network-Level Authentication (NLA) by modifying the registry on Windows systems, potentially enabling persistence methods and unauthorized access.

Windows defense-evasion lateral-movement registry-modification
2r 3t
medium advisory

Okta Password Spray Attempt Detection

Detection of Okta password spraying attempts by identifying multiple failed login attempts from different source IPs targeting the same user account.

Okta credential-access password-spraying
2r 1t
medium advisory

Okta Identity Provider Creation Detected

An adversary may create a rogue identity provider within Okta to establish persistence and potentially escalate privileges by impersonating legitimate users or bypassing multi-factor authentication.

Okta identityprovider persistence
3r 2t
medium advisory

Cloud Compute Instance Created with Previously Unseen Image

A cloud compute instance was created with a previously unseen image, potentially indicating malicious activity such as unauthorized deployment or image compromise.

Amazon Web Services +2 cloud compute-instance image-compromise
2r 1t
medium advisory

NTDS Dump via Wbadmin Execution

Adversaries with Backup Operator privileges can abuse the legitimate Windows utility `wbadmin.exe` to dump the NTDS.dit file, enabling credential access and domain compromise.

Windows +1 credential-access defense-evasion
2r 3t
medium advisory

Windows Script Execution from Archive File

This rule identifies attempts to execute Jscript/Vbscript files from an archive file, a common delivery method for malicious scripts on Windows systems.

M365 Defender +2 execution windows scripting archive
2r 3t
medium advisory

Unusual Process Performing NewCredentials Logon

Anomalous NewCredentials logon events triggered by uncommon processes may indicate access token manipulation for privilege escalation.

Windows privilege-escalation token-manipulation
2r 1t
medium advisory

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability in Synacor Zimbra Collaboration Suite (ZCS) could allow attackers to execute arbitrary JavaScript within a user's session, potentially leading to unauthorized access to sensitive information.

Zimbra Collaboration Suite xss vulnerability zimbra
2r 1t 1c
medium advisory

Suspicious File Creation via OpenEDR ITSMService

OpenEDR's ITSMService process, used for remote management, is being abused to create suspicious files on compromised systems, potentially leading to unauthorized file uploads, data staging, or malicious file deployment.

OpenEDR itsmservice file-creation lateral-movement
3r 4t
medium advisory

Rare SMB Connection to the Internet

This rule detects rare network connections via the SMB protocol to external networks, where SMB is commonly abused to exfiltrate data or leak NTLM credentials via UNC path injection.

Windows exfiltration credential-access smb
2r 2t
medium advisory

Potential Privilege Escalation via SUID/SGID Abuse on Linux

This rule detects potential privilege escalation attempts on Linux systems by identifying processes running with root privileges but initiated by non-root users, indicative of SUID/SGID abuse.

Elastic Defend privilege-escalation persistence suid sgid
2r 3t
medium advisory

Potential Account Takeover via Logon from New Source IP

Atypical login activity where a user account, normally logging in from a high-volume, single source IP, suddenly authenticates from a different IP address, potentially indicating account takeover or stolen credentials.

Windows account-takeover credential-access
2r 1t
medium advisory

OpenEDR ssh-shellhost.exe Spawning Command Shell or PowerShell with PTY

OpenEDR's ssh-shellhost.exe spawning a command shell (cmd.exe) or PowerShell with PTY capabilities may indicate remote command execution and potential abuse of OpenEDR's remote management features by threat actors for lateral movement or command-and-control.

OpenEDR remote-access-tool lateral-movement
2r 3t
medium advisory

Nimiq Node Panic due to Invalid BLS Key

An unauthenticated peer can crash a Nimiq node by sending a malformed election macro block containing an invalid BLS voting key, leading to a denial of service.

nimiq-primitives denial-of-service nimiq bls
2r 3t
medium advisory

First Time Seen Remote Monitoring and Management Tool Execution

Detects the execution of previously unseen remote monitoring and management (RMM) tools or remote access software on compromised Windows endpoints, often leveraged for command-and-control, persistence, and execution of malicious commands.

Elastic Defend +101 remote-access rmm command-and-control persistence
3r
medium advisory

Executable File Creation with Multiple Extensions

Detection of executable files created with multiple extensions, a masquerading technique to evade defenses.

Elastic Defend +3 defense-evasion execution masquerading windows
2r 2t
medium advisory

EntraFalcon Security Posture Assessment Tool

EntraFalcon is a security tool designed to enumerate and assess the security posture of Entra ID tenants, identifying misconfigurations and vulnerabilities related to users, groups, applications, roles, PIM settings, and Conditional Access policies.

Entra ID entra-id azure-ad security-assessment misconfiguration cloud-security
2r 3t 2i
medium advisory

Azure Compute VM Command Execution Detected

Successful execution of commands on Azure Virtual Machines, specifically the MICROSOFT.COMPUTE/VIRTUALMACHINES/RUNCOMMAND/ACTION operation, may indicate unauthorized activity or lateral movement attempts.

Azure Virtual Machines +1 azure execution cloud vm
2r 1t
medium advisory

Apache Tomcat Security Bypass Vulnerability

A remote, anonymous attacker can exploit an unspecified vulnerability in Apache Tomcat to bypass security measures, potentially leading to unauthorized access or modification of data.

Apache Tomcat apache-tomcat security-bypass defense-evasion
2r 1t
medium advisory

UAC Bypass via Windows Firewall MMC Snap-In Hijack

Attackers bypass User Account Control (UAC) by hijacking the Microsoft Management Console (MMC) Windows Firewall snap-in to execute code with elevated permissions, potentially leading to system compromise.

Windows uac-bypass privilege-escalation windows-firewall mmc
2r 2t
medium advisory

Process Execution from Unusual Windows Directories

Adversaries may execute processes from unusual Windows directories to masquerade malware as legitimate software and evade defenses.

Windows defense-evasion masquerading
1r 1t
medium advisory

Suspicious Microsoft Outlook Child Processes

Detects suspicious child processes spawned by Microsoft Outlook, commonly associated with spear phishing attacks and the execution of malicious payloads.

Outlook initial-access execution defense-evasion phishing windows
2r 10t
medium advisory

Spoofing AD FS Signing Logs via Azure AD Hybrid Health Service

A threat actor can create a new, rogue AD Health ADFS service within Azure and then create a fake server instance, which can be leveraged to spoof AD FS signing logs without compromising on-prem AD FS servers.

Azure Active Directory +1 cloud azure adfs defense-impairment
2r 1t
medium advisory

Okta Security Threat Detected

This alert detects when Okta's ThreatInsight identifies a security threat within an Okta environment, potentially indicating command and control activity.

Okta identity threat-detection attack.command-and-control
2r 1t
medium advisory

Okta Admin Role Assignment Creation

Detection of new admin role assignments in Okta, potentially indicating privilege escalation or persistence attempts by malicious actors.

Okta identity privilege-escalation persistence
2r 1t
medium advisory

Local Account TokenFilter Policy Modification

An adversary modifies the LocalAccountTokenFilterPolicy registry key to weaken security controls and enable privilege escalation, allowing them to bypass User Account Control (UAC) and gain elevated privileges remotely.

Windows defense-evasion lateral-movement
2r 4t
medium advisory

Ech0 OAuth Redirect URI Validation Bypass Vulnerability

Ech0's OAuth redirect URI validation ignores the path component, allowing attackers to craft malicious redirect URIs for exchange-code theft and potential account takeover.

github.com/lin-snow/Ech0 oauth redirect_bypass account_takeover web_application
2r 1t
medium advisory

Detection of Persistent Scripts in the Startup Directory

This rule identifies script engines creating files in the Startup folder, or the creation of script files in the Startup folder, enabling adversaries to maintain persistence by placing malicious scripts or shortcuts in the Windows Startup folder, which are then executed during account logon.

Windows persistence startup-folder malware
2r 2t
medium advisory

Curl or Wget Execution from Container Context

This rule detects the execution of curl or wget from within runc-backed containers on Linux systems monitored by Auditd Manager, indicating potential ingress tool transfer or data exfiltration by attackers who have compromised the container.

Auditd Manager command-and-control execution container auditd linux
2r 2t
medium advisory

Azure Blob Storage Permissions Modified for Defense Evasion

An adversary may modify Azure Blob Storage permissions to weaken security controls, leading to potential data exposure or loss; this rule detects such modifications by monitoring Azure activity logs for specific operations related to permission changes on blobs.

Azure Blob Storage azure cloud defense_evasion
2r 1t
medium advisory

Azure Authentication Method Change Detection

An attacker may add an authentication method to a compromised Azure account for persistent access, which can be detected by monitoring changes to authentication methods in Azure audit logs.

Azure persistence privilege-escalation
2r 3t
medium advisory

AWS CloudTrail Logging Disabled or Modified

Detection of AWS CloudTrail being disabled, deleted, or updated by an adversary to impair defenses and evade detection.

AWS CloudTrail defense-impairment cloud
3r 1t
medium advisory

AWS IAM User Creates Access Keys For Another User

An adversary with access to compromised AWS credentials may attempt to persist or escalate privileges by creating a new set of access keys for an existing IAM user, potentially leading to unauthorized access to resources and data.

AWS Identity and Access Management cloud aws iam persistence privilege-escalation
2r 2t
medium advisory

AWS KMS Key Policy Updated via PutKeyPolicy

Detection of successful PutKeyPolicy calls on AWS KMS keys to identify potential privilege escalation or unauthorized access by adversaries modifying key policies to decrypt or exfiltrate data.

KMS cloud aws privilege-escalation defense-evasion
2r 2t
medium advisory

CVE-2026-34293: Unspecified Vulnerability in Microsoft Product

CVE-2026-34293 is an unspecified vulnerability affecting a Microsoft product, for which details are currently unavailable, posing a potential risk to affected systems.

cve vulnerability microsoft
2r 1c
medium advisory

Suspicious WMIC XSL Script Execution

This rule detects suspicious execution of scripts via WMIC, potentially used for allowlist bypass, by identifying WMIC executions with atypical arguments and the loading of specific libraries like jscript.dll or vbscript.dll for defense evasion and execution.

Elastic Defend defense-evasion execution windows
2r 3t
medium advisory

ProblemChild ML Detection of Suspicious Windows Processes

The ProblemChild machine learning model has detected a user with suspicious Windows processes exhibiting unusually high malicious probability scores, potentially indicating defense evasion via masquerading or LOLbins.

Windows defense-evasion machine-learning
2r 2t
medium advisory

Potential Ransomware Behavior - Note Files Dropped via SMB

This rule detects potential ransomware behavior by identifying the creation of multiple files with the same name over SMB by the SYSTEM account, potentially indicating remote execution of ransomware dropping note files.

Elastic Defend ransomware impact lateral-movement windows
2r 4t
medium advisory

Detection of User-Reported Phishing or Malware in Office 365

This detection identifies potentially malicious emails reported by users within an Office 365 environment through Security & Compliance policies, indicating possible phishing or malware attacks targeting the organization.

Office 365 +2 office365 phishing user-reporting
2r 1t
medium advisory

CVE-2026-31613 SMB Client Out-of-Bounds Read Vulnerability

CVE-2026-31613 is an out-of-bounds read vulnerability in the SMB client when parsing symlink error responses, requiring patching to prevent potential information disclosure or denial-of-service.

cve-2026-31613 smb out-of-bounds read vulnerability
2r 1t 1c
medium advisory

Detection of Sensitive LDAP Attribute Access

This rule detects unauthorized access to sensitive Active Directory object attributes such as unixUserPassword, ms-PKI-AccountCredentials, and msPKI-CredentialRoamingTokens, potentially leading to credential theft and privilege escalation.

Active Directory +1 credential-access privilege-escalation collection windows
2r 5t
medium advisory

Okta End-User Reports Suspicious Account Activity

An Okta end-user reports potentially suspicious activity on their account, indicating possible compromise or unauthorized access.

Okta identity suspicious-activity
2r 1t
medium threat

Entra ID Unusual ROPC Login Attempt

Detects unusual resource owner password credential (ROPC) login attempts by a user principal in Microsoft Entra ID, potentially indicating account compromise or password spraying.

exploited Microsoft Entra ID azure entra-id ropc initial-access
2r 2t
medium advisory

Detect Suspicious Windows Service Installation

This detection identifies the creation of new Windows services with suspicious command values, often used for privilege escalation and persistence by malicious actors.

Windows persistence privilege_escalation service_creation
2r 1t
medium advisory

Azure VNet Full Network Packet Capture Enabled

Detection of Azure Network Watcher's Packet Capture feature being enabled, potentially indicating malicious network sniffing for credential access and discovery of sensitive data in unencrypted traffic.

Azure +1 network-sniffing credential-access
3r 2t
medium advisory

GCP Logging Bucket Deletion for Defense Evasion

Detection of a Google Cloud Platform (GCP) logging bucket deletion, which can be used by adversaries to impair defenses and evade detection by removing or modifying cloud logs.

Google Cloud Platform gcp cloud defense_evasion
2r 1t
medium advisory

Windows Sandbox Abuse with Sensitive Configuration

This rule detects the abuse of Windows Sandbox with sensitive configurations to evade detection, where malware may abuse the sandbox feature to gain write access to the host file system, enable network connections, and automatically execute commands via logon, identifying the start of a new container with these sensitive configurations.

Microsoft Defender XDR +4 defense-evasion windows-sandbox windows
3r 1t
medium advisory

PhpSpreadsheet XML Reader Denial of Service via Unbounded Row Index

PhpSpreadsheet is vulnerable to a denial-of-service attack by crafting a SpreadsheetML XML file with an excessively large row index, which exhausts server CPU resources due to unbounded iteration.

PhpSpreadsheet denial-of-service xml
2r 1t
medium advisory

Unsigned DLL Loaded by Svchost for Persistence and Privilege Escalation

Adversaries may load unsigned DLLs into svchost.exe to establish persistence or escalate privileges, leveraging a shared Windows service to execute malicious code with elevated permissions.

Elastic Defend persistence defense-evasion execution windows dll-injection
2r 4t 5i
medium advisory

Azure Kubernetes Events Deleted

Adversaries may delete events in Azure Kubernetes to evade detection, which this rule detects via the MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/EVENTS.K8S.IO/EVENTS/DELETE operation.

Azure Kubernetes Service azure kubernetes defense-evasion
2r 1t
medium advisory

AWS EBS Encryption Disabled

Detects when Amazon Elastic Block Store (EBS) encryption by default is disabled in an AWS region, potentially leading to data exposure and weakening data protection against exfiltration or ransomware.

Elastic Block Store aws ebs encryption cloudtrail
2r 2t
medium advisory

Suspicious Process Execution via Renamed PsExec Executable

The rule identifies suspicious PsExec activity where the psexec service is executed from a renamed executable, possibly to evade detection and enable lateral movement.

PsExec +1 lateral-movement defense-evasion windows
2r 3t
medium advisory

AWS ECR Container Upload Outside Business Hours

This analytic detects the upload of a new container image to AWS Elastic Container Registry (ECR) outside of standard business hours, indicating potential unauthorized activity and leveraging AWS CloudTrail logs to identify `PutImage` events during non-business hours.

Elastic Container Registry cloud aws ecr container
2r 1t
medium advisory

Web Server Potential Remote File Inclusion Activity

This rule detects potential Remote File Inclusion (RFI) activity on web servers by identifying HTTP GET requests that attempt to access sensitive remote files through directory traversal techniques or known file paths, potentially leading to information disclosure or further compromise.

Nginx +4 rfi webserver vulnerability
2r 2t
medium advisory

Windows Subsystem for Linux Distribution Installation via Registry Modification

Detects the installation of a new Windows Subsystem for Linux (WSL) distribution through registry modifications, which can be leveraged by attackers to evade security measures and execute malicious activities on Windows systems.

Windows Subsystem for Linux defense-evasion execution windows wsl
2r 3t
medium advisory

Netsh Used to Enable Remote Desktop Protocol (RDP) in Windows Firewall

Adversaries use the `netsh.exe` utility to enable inbound Remote Desktop Protocol (RDP) connections through the Windows Firewall, potentially for unauthorized remote access and lateral movement.

Windows +1 defense-evasion lateral-movement rdp
2r 2t
medium advisory

ESXi System Information Discovery via ESXCLI

Adversaries may use ESXCLI system-level commands to retrieve configuration details on VMware ESXi hosts for reconnaissance purposes, potentially leading to further compromise.

ESXi reconnaissance vmware
2r 1t
medium advisory

Azure Storage Account Deletion Detection

This brief detects the deletion of Azure Storage Accounts which can indicate malicious activity like data destruction, denial of service, or covering tracks after data exfiltration by adversaries.

Azure Storage Account azure storage deletion impact
2r 2t
medium advisory

macOS Mojave Beta Webcam and Microphone Access Bypass

macOS Mojave beta's new privacy controls can be bypassed by exploiting the entitlements of trusted applications like QuickTime Player via AppleScript to access the webcam and microphone without user consent.

macOS Mojave +2 macos webcam microphone applescript tcc
2r 1t
medium advisory

Twisted DNS Server Denial of Service via Crafted Compression Pointers

A denial-of-service vulnerability exists in the twisted.names module, where an unauthenticated attacker can send a crafted TCP DNS packet with deeply chained compression pointers, causing the Twisted reactor to hang while processing recursive lookups and effectively freezing the server.

Twisted denial-of-service dns
2r 1t
medium advisory

Microsoft Graph API Email Access by Unusual Client and User

Detects anomalous access to email resources via Microsoft Graph API, potentially indicating a compromised OAuth refresh token or Primary Refresh Token (PRT) being used by an attacker.

Microsoft 365 +1 azure graphapi email oauth credentialtheft
2r 1t
medium advisory

GoBGP Remote Denial of Service via Malformed BGP Update Message

GoBGP version 4.4.0 is vulnerable to a remote denial-of-service attack where a malformed BGP UPDATE message triggers a nil pointer dereference, crashing the GoBGP process.

gobgp/v4 bgp denial-of-service networking
2r 1t
medium advisory

Entra ID Service Principal Federated Credential Authentication by Unusual Client

Detection of initial Entra ID service principal authentication using a federated identity credential, potentially indicating a rogue identity provider abusing compromised applications.

Entra ID entra-id federated-credentials byoidp initial-access
2r 3t
medium advisory

Entra ID OAuth PRT Issuance to Non-Managed Device Detected

Detection of Entra ID OAuth Primary Refresh Token (PRT) issuance to a non-managed device following a refresh token sign-in via Microsoft Authentication Broker (MAB), potentially indicating device registration abuse (ROADtx) for persistent access.

Entra ID +1 cloud entra_id persistence initial_access credential_access defense_evasion
2r 4t
medium advisory

BloodHound Suite User-Agent Detected in Entra ID Sign-ins

Detection of BloodHound tools like AzureHound and SharpHound being used to enumerate Microsoft Entra ID and Microsoft 365 environments, potentially indicating reconnaissance activity by red teams or malicious actors.

Microsoft Azure +2 azuread bloodhound enumeration discovery
3r 6t
medium advisory

M365 Copilot Impersonation Jailbreak Attack

This detection identifies attempts to jailbreak M365 Copilot by impersonating roles, adopting unrestricted personas, or mimicking malicious AI systems to bypass safety controls, searching exported eDiscovery prompt logs for roleplay keywords and categorizing prompts into impersonation types to detect persona injection attacks.

M365 Copilot ai_jailbreak prompt_injection m365_copilot
3r
medium advisory

CustomLoadImage .NET Assembly Loading Technique

CustomLoadImage enables stealthy reflective loading of .NET assemblies by directly calling AssemblyNative::LoadFromBuffer, bypassing hooks on RuntimeAssembly.nLoadImage for defense evasion.

.NET Framework defense-evasion .net reflective-loading
2r 1t 1i
medium threat

Unusual Azure Storage Account Key Access by Privileged User

Detects unusual access to Azure Storage Account keys by users with Owner, Contributor, Storage Account Contributor, or User Access Administrator roles, potentially indicating compromised identities as seen in STORM-0501 ransomware campaigns.

Microsoft Azure +1 Storm-0501 azure storage account credential access ransomware
2r 2t
medium advisory

Windows Persistence via Scheduled Job Creation

Adversaries can abuse the Windows Task Scheduler to establish persistence by creating malicious scheduled jobs, which are detected by monitoring for the creation of '.job' files in the 'Windows\Tasks' directory while excluding known legitimate software.

Windows persistence scheduled-task
2r 1t
medium advisory

Unauthorized Removal of Azure Conditional Access Policy

An unauthorized actor removes a Conditional Access policy in Azure, potentially weakening the organization's security posture and enabling privilege escalation or credential access.

Azure Active Directory azure conditional-access privilege-escalation credential-access persistence defense-impairment
2r 3t
medium advisory

Successful AWS Console Login Without MFA

Successful AWS console logins without multi-factor authentication can indicate compromised credentials, misconfigured security settings, or unauthorized access attempts.

AWS Management Console aws cloudtrail mfa initial-access
2r 1t
medium advisory

Multiple Remote Management Tool Vendors on Same Host

The presence of multiple remote monitoring and management (RMM) tools from different vendors on a single Windows host within a short time frame may indicate compromise, shadow IT, or attacker staging for redundant access.

TeamViewer +3 remote-access-tools command-and-control windows
3r
medium advisory

GCP Virtual Private Cloud Route Deletion for Defense Evasion

An adversary may delete a Virtual Private Cloud (VPC) route in Google Cloud Platform (GCP) to disrupt network traffic flow and evade defenses.

Virtual Private Cloud gcp vpc route defense-evasion cloud
2r 2t
medium advisory

Execution of Downloaded Windows Script

This rule identifies the creation and execution of a Windows script downloaded from the internet, which adversaries may leverage for initial access and execution by exploiting unusual parent-child process relationships and script attributes.

Windows execution scripting
2r 5t
medium advisory

Entra ID Service Principal Sign-in from Unusual ASN

Detection of Entra ID service principal sign-ins originating from a previously unseen combination of workload identity and source autonomous system number (ASN), potentially indicating compromised credentials or malicious activity.

Entra ID azure entra-id service-principal initial-access
2r 2t
medium advisory

AWS EC2 EBS Snapshot Access Permissions Removed

Detection of AWS EC2 EBS snapshot access permissions removal can indicate malicious attempts to disrupt data recovery, evade detection, or maintain exclusive backup access, leading to increased attack impact and incident response complexity.

EC2 +1 aws ebs snapshot impact
2r 4t
medium advisory

Werfault ReflectDebugger Persistence Abuse

Attackers can achieve persistence by modifying the ReflectDebugger registry key associated with Windows Error Reporting (Werfault) to execute arbitrary code when Werfault is invoked with the `-pr` parameter.

Windows persistence registry
2r 2t
medium advisory

Suspicious Remote File Copy via TeamViewer

Attackers may abuse TeamViewer, a legitimate remote access tool, to transfer malware or tools into a compromised environment by creating executable or script files with suspicious extensions.

TeamViewer command-and-control remote-access
2r 2t
medium advisory

Potential PowerShell Obfuscated Script via High Entropy

This rule detects potential PowerShell obfuscated scripts by identifying script blocks with high entropy and non-uniform character distributions, which attackers use to evade signature-based detections.

Microsoft Windows +1 powershell obfuscation defense_evasion windows
2r 3t
medium advisory

Office 365 User Restricted from Sending Email

An Office 365 user account is restricted from sending email, potentially indicating account compromise, policy violation, or administrative action following suspicious activity.

Office 365 o365 email account-compromise
2r 1t
medium advisory

Linux Service Stop and Disable Detection

Attackers may halt or disable security services on Linux systems to evade defenses, maintain persistence, or disrupt operations, detected through the use of utilities like 'systemctl', 'service', and 'chkconfig'.

attack.defense-evasion attack.t1562 attack.impact attack.t1489
3r 2t
medium advisory

Execution via GitHub Actions Runner

Compromised GitHub Actions workflows allow attackers to execute arbitrary commands on self-hosted runners, leading to code execution, file manipulation, and potential data exfiltration.

GitHub Actions Runner github-actions supply-chain execution
2r 8t
medium advisory

Azure Resource Group Deletion Detected

This rule detects the deletion of a resource group in Azure. Deleting a resource group permanently removes all resources within it, which adversaries may use to evade defenses or destroy data.

Microsoft Azure azure resource-group deletion impact
2r 5t
medium advisory

Signed Proxy Execution via MS Work Folders

Adversaries may misuse Windows Work Folders to execute a masqueraded 'control.exe' file from a non-standard location, bypassing application controls and potentially escalating privileges.

Windows Work Folders defense-evasion masquerading workfolders windows
2r 3t 1i
medium threat

Microsoft Exchange Server UM Spawning Suspicious Processes

This rule detects suspicious processes spawned by the Microsoft Exchange Server Unified Messaging (UM) service, potentially indicating exploitation of CVE-2021-26857 and leading to unauthorized process execution and system compromise.

exploited Exchange Server exchange initial-access lateral-movement cve-2021-26857 windows
2r 2t 1c
medium advisory

Multiple Logon Failure Followed by Logon Success

This rule identifies potential password guessing/brute force activity from a single address, followed by a successful logon, indicating that an attacker may have compromised an account by brute-forcing login attempts across multiple users.

Windows Security Event Logs credential-access brute-force windows
2r 1t
medium advisory

Unusual Persistence via Services Registry Modification

Adversaries may modify the Windows services registry keys directly to stealthily persist through abnormal service creation or modification of an existing service, bypassing standard APIs, detected by monitoring registry changes related to service DLLs and image paths.

Windows persistence registry services
2r 3t
medium advisory

Suspicious WMI Image Load from MS Office

Adversaries may exploit Windows Management Instrumentation (WMI) to execute code stealthily, bypassing traditional security measures by loading `wmiutils.dll` from Microsoft Office applications, potentially indicating malicious execution.

WINWORD.EXE +4 wmi image load office execution
2r 1t
medium advisory

SUSE Harvester Rancher Integration Vulnerable to MITM and DOS

SUSE Harvester's Rancher integration mechanism is vulnerable to a man-in-the-middle attack due to insecure TLS options, potentially leading to denial of service.

Harvester mitm denial-of-service virtualization
3r 2t
medium advisory

rustls-webpki Denial-of-Service Vulnerability via Malformed CRL BIT STRING

A denial-of-service vulnerability exists in rustls-webpki versions prior to 0.103.13 and between 0.104.0-alpha.1 and 0.104.0-alpha.7 due to a panic in `bit_string_flags()` when processing a malformed CRL BIT STRING, triggered when CRL checking is enabled and an attacker provides a crafted CRL.

rustls-webpki denial-of-service crl
2r 1t
medium advisory

rust-zserio Unbounded Memory Allocation Vulnerability

The rust-zserio package is vulnerable to unbounded memory allocation when deserializing arrays, strings, or bytes (blob) types, allowing an attacker to cause a denial-of-service by providing a crafted data file with a large size value.

rust-zserio denial-of-service memory-allocation
2r 1t
medium advisory

Potential Reverse Shell via Java on Linux

The execution of a Linux shell process from a Java JAR application following an incoming network connection may indicate reverse shell activity.

Elastic Defend reverse-shell java linux execution
2r 2t
medium advisory

Potential Application Shimming via Sdbinst

This brief covers the abuse of application shimming in Windows via `sdbinst.exe` to achieve persistence and privilege escalation by executing arbitrary code within legitimate processes.

Windows persistence privilege-escalation application-shimming
3r 2t
medium advisory

Persistence via Scheduled Job Creation

This detection rule identifies attempts to establish persistence on Windows systems by creating scheduled jobs in the Windows Tasks directory, excluding known legitimate jobs.

Microsoft Defender XDR +5 persistence windows
2r 1t
medium advisory

Pachno 1.0.6 Stored Cross-Site Scripting Vulnerability

Pachno 1.0.6 is vulnerable to stored cross-site scripting (XSS), allowing attackers to inject malicious HTML or scripts into POST parameters, which are then stored and executed in user browser sessions due to improper sanitization.

Pachno xss web-application
2r 1t 1c
medium advisory

Ollama Abnormal Network Connectivity Detected

This detection identifies unusual network patterns and connection problems within Ollama, encompassing unauthorized API access attempts beyond localhost and warning-level network errors like DNS lookup failures, TCP connection issues, or host resolution problems, which can signal network-based attacks, unauthorized access, or infrastructure reconnaissance.

Ollama network-connectivity anomaly
2r 1t
medium advisory

MSBuild Making Network Connections Indicating Potential Defense Evasion

MsBuild.exe making outbound network connections may indicate adversarial activity as attackers leverage MsBuild to execute code and evade detection.

MSBuild defense-evasion command-and-control
2r 2t
medium advisory

Linux Log Clearing Attempts via Common Utilities

Adversaries attempt to clear Linux system logs using utilities like rm, rmdir, shred, and unlink to conceal malicious activity and evade detection.

defense-evasion log-clearing linux
3r 1t
medium advisory

Kubernetes Service Account Token Access Followed by API Request

Detection of interactive access to a Kubernetes service account token or certificate followed by a Kubernetes API request, potentially indicating credential theft and lateral movement within the cluster.

Kubernetes credential-access lateral-movement container
2r 5t
medium advisory

Kubernetes Potential Endpoint Permission Enumeration by Anonymous User

An anonymous user attempts to enumerate Kubernetes API endpoints, resulting in a series of failed API requests across multiple endpoints, potentially revealing the cluster's exposed surface.

Kubernetes discovery enumeration cloud
2r 1t
medium advisory

Granian WebSocket Subprotocol Header Denial of Service

Granian versions 1.2.0 through 2.7.3 are vulnerable to an unauthenticated denial of service. Sending a WebSocket upgrade request with a `Sec-WebSocket-Protocol` header containing non-ASCII bytes causes a worker process to abort, leading to a denial of service.

granian denial-of-service websocket
2r 1t
medium advisory

Google Workspace BitLocker Setting Disabled

Detection of Google Workspace administrators disabling the BitLocker setting, potentially allowing adversaries with valid account access to decrypt sensitive data on managed Windows devices.

Google Workspace +2 google_workspace bitlocker defense_evasion
2r 2t
medium advisory

FreeScout Unauthorized Attachment Deletion Vulnerability (CVE-2026-41192)

FreeScout versions prior to 1.8.215 are vulnerable to unauthorized attachment deletion, allowing a malicious mailbox peer to delete attachments by replaying encrypted attachment IDs in the `save_draft` flow.

FreeScout attachment-deletion cve-2026-41192
2r 1c
medium advisory

Direct Interactive Kubernetes API Request by Common Utilities

This rule detects direct interactive Kubernetes API requests by common utilities from within a container, potentially indicating lateral movement or discovery activities within the cluster.

Kubernetes container execution discovery
2r 3t
medium advisory

Defense Evasion via Exchange DLP Policy Removal

Attackers may remove or modify Exchange Data Loss Prevention (DLP) policies in Microsoft 365 to evade detection and exfiltrate sensitive data without triggering alerts.

Microsoft 365 +1 o365 dlp defense_evasion data_exfiltration
2r 1t
medium advisory

Azure Diagnostic Settings Deletion for Defense Evasion

Adversaries may delete Azure diagnostic settings to evade defenses by hindering detection and analysis, which this detection identifies by monitoring Azure activity logs for successful deletion operations.

Azure defense_evasion cloud
2r 2t
medium advisory

Azure AD Service Principal Enumeration via Microsoft Graph API

An attacker uses Microsoft Graph API to enumerate multiple Azure AD service principals, potentially using tools like AzureHound or ROADtools, to gather information for privilege escalation or lateral movement.

Azure Active Directory +1 azuread serviceprincipal enumeration
2r 2t
medium advisory

AWS WAF Rule or Rule Group Deletion

Detection of AWS WAF rule or rule group deletions, which can weaken web application security and expose applications to various attacks.

AWS WAF aws waf defense-evasion cloud
2r 1t
medium advisory

AWS RDS DB Instance Restored for Defense Evasion or Data Collection

Detection of AWS RDS database instance restoration from a snapshot or S3 backup, potentially indicating unauthorized data access, defense evasion, or data collection by adversaries recreating database environments to bypass controls or exfiltrate sensitive data.

RDS cloud aws defense-evasion data-collection
3r 3t
medium advisory

AWS KMS Key User Performing S3 Encryption Detection

Detection of AWS users utilizing KMS keys to perform encryption operations on S3 buckets, indicating potential misuse or malicious activity within the cloud environment.

AWS Key Management Service +3 cloud aws kms s3 encryption
2r 1t
medium advisory

AWS IAM Long-Term Access Key First Seen from Source IP

The rule identifies the first time a long-term IAM access key ID (prefix AKIA) is used successfully from a given source.ip in AWS CloudTrail, indicating potential credential compromise.

AWS IAM aws cloudtrail iam credential-access
2r 2t
medium advisory

AWS EC2 Security Group Configuration Change Detection

Detection of unauthorized changes to AWS EC2 Security Group configurations, potentially leading to persistence, data exfiltration, or lateral movement within the AWS environment.

Elastic Compute Cloud cloud aws security-group persistence
3r 4t
medium advisory

AWS CLI Activity Detection for Open S3 Bucket Creation

Detection of S3 bucket creation via AWS CLI which might lead to data exposure and unauthorized access.

Amazon S3 +1 aws s3 cloud data-breach
2r 1t
medium advisory

AWS Account Login Profile Update

An AWS account's login profile has been modified, potentially indicating account compromise, privilege escalation, or malicious user activity.

AWS cloud iam account-takeover
3r 1t
medium advisory

Windows Subsystem for Linux Enabled via Dism Utility

Adversaries may enable Windows Subsystem for Linux (WSL) via the Dism utility to evade detection by running Linux tools on Windows.

Windows +1 defense-evasion wsl
2r 1t
medium advisory

Suspicious WerFault Child Process Abuse

This rule detects suspicious child processes of WerFault.exe, a Windows error reporting tool, indicating potential abuse of the SilentProcessExit registry key to execute malicious processes stealthily for defense evasion, persistence, and privilege escalation.

Microsoft Defender XDR +2 defense-evasion persistence privilege-escalation masquerading
2r 3t
medium advisory

Remote Management Access Launch After MSI Install

Detects a suspicious sequence of an MSI installer execution immediately followed by the execution of commonly abused Remote Management Software, potentially indicating unauthorized remote access.

ScreenConnect +3 remote-access command-and-control rmm msi
2r
medium advisory

PowerShell Script Block Logging Disabled via Registry Modification

Attackers may disable PowerShell Script Block Logging by modifying the registry to conceal their activities on the host and evade detection by setting the `EnableScriptBlockLogging` registry value to 0, impacting security monitoring and incident response capabilities.

Defender XDR +2 defense-evasion powershell registry
2r 2t
medium advisory

Potential Timestomping of Executable Files on Windows

This rule identifies potential timestomping behavior on Windows systems where the creation time of executable files in sensitive system directories is modified, potentially to blend malicious executables with legitimate system files and evade detection.

Windows defense-evasion timestomp
2r 1t
medium advisory

Potential Data Exfiltration via Wget on Linux Systems

This rule detects the use of wget on Linux systems to upload files to an external server, a tactic commonly used for data exfiltration.

Linux exfiltration wget data-theft
2r 1t
medium advisory

MSBuild Making Network Connections

Detection of MsBuild.exe making outbound network connections which may indicate adversarial activity used to execute code and evade detection.

MSBuild defense-evasion windows
2r 2t
medium advisory

Ingress Transfer via Windows BITS

Adversaries leverage the Windows Background Intelligent Transfer Service (BITS) to download executable and archive files, potentially delivering malicious payloads while evading traditional security measures.

Windows bits file-transfer command-and-control defense-evasion
2r 2t
medium advisory

IIS AppCmd Tool Used to Dump Service Account Credentials

Attackers with access to IIS web servers may use the AppCmd command-line tool to dump sensitive configuration data, including application pool credentials, potentially leading to lateral movement and privilege escalation.

IIS credential-access appcmd windows
2r 2t
medium advisory

Entra ID OAuth Phishing via First-Party Microsoft Application

Attackers are leveraging first-party Microsoft applications in Entra ID to conduct OAuth phishing attacks, bypassing traditional consent prompts and accessing sensitive resources like Microsoft Graph and legacy Azure AD.

Entra ID +3 entra_id oauth phishing initial_access
2r 5t
medium advisory

Entra ID MFA Disabled for User

Detection of multi-factor authentication (MFA) being disabled for an Entra ID user account, potentially weakening account security and leading to compromise.

Entra ID azure entra_id mfa persistence credential_access defense_evasion
2r 3t
medium advisory

Disabling Windows Defender Security Settings via PowerShell

Attackers use PowerShell commands, including base64-encoded variants, to disable or weaken Windows Defender settings, impairing defenses on compromised systems.

Windows Defender defense-evasion powershell windows
2r 2t
medium advisory

Detection of Custom Shim Database Installation for Persistence

Attackers abuse the Application Compatibility Shim functionality in Windows to establish persistence and achieve arbitrary code execution by installing malicious shim databases, which this detection identifies through monitoring registry changes.

Windows +7 persistence app-compat shim
2r 1t
medium advisory

Cisco ASA Device File Copy Activity

Adversaries may copy device files, including configurations and packet captures, from Cisco ASA devices via CLI or ASDM for reconnaissance, credential extraction, or data exfiltration, which can be detected via command execution logs.

Cisco ASA +1 cisco asa file_copy reconnaissance credential_access exfiltration
2r 2t
medium advisory

Azure Event Hub Deletion for Defense Evasion

Detection of Azure Event Hub deletion, indicative of defense evasion by adversaries seeking to disrupt data flow and evade detection by erasing log evidence.

Azure Event Hub cloud azure defense-evasion
2r 2t
medium advisory

AWS EC2 Network Access Control List Deletion

The deletion of an Amazon EC2 network access control list (ACL) or its entries can indicate an attacker attempting to disable security controls for unauthorized access or data exfiltration.

AWS EC2 cloud aws ec2 network-security defense-evasion
2r 1t
medium advisory

AWS CloudTrail Logging Suspended via StopLogging API

An attacker may suspend AWS CloudTrail logging via the StopLogging API (StopLogging) to eliminate audit visibility and evade defenses.

CloudTrail aws defense_evasion
3r 2t
medium advisory

AppArmor Policy Interface Tampering

Detection of unauthorized access to AppArmor kernel policy control interfaces, specifically the `.load`, `.replace`, or `.remove` files, indicating potential defense evasion or policy tampering on Linux systems.

AppArmor defense-evasion linux
3r 1t
medium advisory

Creation of New DMSA Service Account Potentially Exploiting BadSuccessor Vulnerability

The creation of a new Delegated Managed Service Account (DMSA) within specific Organizational Units (OUs) using the New-ADServiceAccount cmdlet is indicative of potential BadSuccessor privilege escalation attempts in Windows Server 2025 Active Directory environments.

Windows Server +1 privilege-escalation active-directory bad-successor dmsa
2r 2t
medium advisory

AWS EC2 Traffic Mirroring Abuse for Data Exfiltration

An attacker creates an Amazon EC2 Traffic Mirroring session to capture and exfiltrate sensitive network traffic from EC2 instances, potentially including unencrypted data.

EC2 Traffic Mirroring aws ec2 traffic-mirroring exfiltration
2r 5t
medium advisory

CoreDNS DoH GET Query Denial-of-Service

CoreDNS is vulnerable to a denial-of-service attack where processing oversized DNS-over-HTTPS GET requests exhausts resources prior to returning an error.

CoreDNS cve dos
2r 1t
medium advisory

AWS IAM Access Denied Discovery Events

This detection identifies potential reconnaissance activity by an attacker attempting to discover AWS IAM permissions and configurations by generating a high volume of access denied events.

AWS IAM cloud aws iam reconnaissance
2r 1t
medium advisory

Google Drive Ownership Transferred via Google Workspace

Adversaries may transfer files to an adversary account for potential exfiltration by abusing Google Workspace administration permissions to transfer file ownership within Google Drive.

Google Drive +2 google-workspace data-exfiltration cloud
2r 2t
medium advisory

AWS CloudWatch Log Group Deletion

Detection of Amazon CloudWatch Log Group deletion via the 'DeleteLogGroup' API by non-AWS Internal user agents, potentially indicating defense evasion or disruption of logging pipelines.

Amazon CloudWatch cloudwatch aws logging
2r 3t
medium advisory

Detection of Downloaded URL Files Used in Phishing Campaigns

This detection rule identifies downloaded .url shortcut files on Windows systems, often used in phishing campaigns, by monitoring their creation events and flagging those from non-local sources, enabling early threat detection.

Elastic Defend phishing execution url-file windows
2r 3t
medium advisory

Suspicious Azure Automation Account Creation

An adversary may create an Azure Automation account to maintain persistence in the target environment by automating malicious tasks.

Azure Automation azure persistence cloud
2r 2t
medium advisory

Kubectl Secrets Enumeration Across All Namespaces

The use of `kubectl get secrets --all-namespaces` command is detected, which enumerates secret resources across the entire Kubernetes cluster, potentially aiding credential discovery, privilege escalation, or lateral movement.

Kubernetes discovery credential-access kubectl
2r 2t
medium advisory

Process Execution from Suspicious Windows Directories

Adversaries may execute processes from unusual default Windows directories to masquerade malware and evade defenses by blending in with trusted paths, making malicious activity harder to detect.

Windows +2 defense-evasion masquerading
2r 1t
medium advisory

Persistence via Malicious Microsoft Outlook VBA Template

Attackers establish persistence by installing a malicious VBA template in Microsoft Outlook, triggering scripts upon application startup by modifying the VBAProject.OTM file, detected by monitoring for unauthorized file modifications.

Outlook persistence vba windows
2r 1t
medium advisory

Kubernetes Sensitive Role Creation or Modification

Detects the creation or modification of Kubernetes Roles or ClusterRoles that grant high-risk permissions, such as wildcard access or RBAC escalation verbs, potentially leading to privilege escalation or unauthorized access within the cluster.

Kubernetes rbac privilege-escalation persistence
2r 2t
medium advisory

GitHub Enterprise Audit Log Streaming Paused

Detection of a user pausing audit log event streaming in GitHub Enterprise, potentially indicating an attempt to evade detection by disabling the audit trail.

GitHub Enterprise +3 github audit-log defense-evasion
2r 2t
medium advisory

GCP Virtual Private Cloud Network Deletion

Detection of Virtual Private Cloud (VPC) network deletion in Google Cloud Platform (GCP), which can be used by an adversary to disrupt a target's network and business operations.

Virtual Private Cloud cloud gcp defense-evasion impact
2r 2t
medium advisory

GCP Service Account Disabled

Detection of a Google Cloud Platform (GCP) service account being disabled, potentially indicating malicious activity aimed at disrupting business operations by an adversary.

Google Cloud Platform gcp cloud iam impact
2r 1t
medium advisory

Detection of Command and Control Activity via Commonly Abused Web Services

This rule detects command and control activity using common web services by identifying Windows hosts making DNS requests to a list of commonly abused web services from processes outside of known program locations, potentially indicating adversaries attempting to blend malicious traffic with legitimate network activity.

OneDrive +7 command-and-control windows threat-detection
2r 2t
medium advisory

DCOM Lateral Movement via ShellWindows/ShellBrowserWindow

This analytic identifies the use of Distributed Component Object Model (DCOM) to execute commands on a remote host, specifically when launched via ShellBrowserWindow or ShellWindows Application COM objects, indicating potential lateral movement by an attacker.

Windows lateral-movement dcom
2r 2t
medium advisory

Cisco ASA - New Local User Account Creation

Detection of new user account creations on Cisco ASA devices, potentially indicating unauthorized access or persistence attempts by adversaries.

Cisco ASA cisco-asa account-creation persistence
2r 2t
medium advisory

AzureHound Reconnaissance Activity in Azure AD

Detection of the AzureHound User-Agent in Azure AD logs indicates potential reconnaissance activity by adversaries mapping the Azure AD infrastructure for vulnerabilities.

Azure Active Directory +1 azuread reconnaissance azurehound
2r 2t
medium advisory

AWS CloudTrail Trail Deletion Detected

Detection of AWS CloudTrail trail deletion via the DeleteTrail API indicates potential defense evasion and destruction of audit logging.

AWS CloudTrail cloudtrail aws defense-evasion
2r 2t
medium advisory

Executable File Creation with Multiple Extensions

This rule detects the creation of executable files with multiple extensions, a masquerading technique used to evade defenses by disguising malicious executables as benign files to trick users into executing them.

Windows defense-evasion masquerading file-extension
2r 2t
medium advisory

Disable Windows Event and Security Logs Using Built-in Tools

Attackers attempt to disable Windows Event and Security Logs using logman, PowerShell, or auditpol to evade detection and cover their tracks.

Microsoft Defender XDR +2 defense-evasion windows eventlog
3r 3t
medium advisory

Incoming Execution via PowerShell Remoting

This rule identifies remote execution via Windows PowerShell remoting, which allows a user to run any Windows PowerShell command on one or more remote computers, potentially indicating lateral movement.

Elastic Defend +2 lateral-movement powershell remoting
2r 2t
medium advisory

Suspicious Container Runtime CLI Execution

The rule detects execution of container runtime CLI tools (ctr, crictl, nerdctl) with arguments indicating container creation, command execution inside existing containers, image manipulation, or host filesystem mounting, potentially leading to container escape and privilege escalation.

Elastic Defend for Containers container execution privilege_escalation linux
3r 2t
medium advisory

Okta Session Hijacking via Multiple Device Token Hashes

Detection of multiple device token hashes and source IPs for a single Okta session, indicating potential session hijacking and unauthorized access to Okta resources.

Okta session-hijacking credential-access
2r 2t
medium advisory

Linux Clipboard Activity Monitoring

This brief provides detection strategies for monitoring clipboard activity on Linux systems, potentially identifying malicious data exfiltration or command execution attempts.

Linux clipboard data exfiltration collection
3r 1t
medium advisory

Azure Firewall Modification or Deletion Detected

An Azure firewall was created, modified, or deleted, potentially indicating malicious activity aimed at impairing network defenses.

Azure firewall defense-evasion
2r 1t
medium advisory

Azure AD Bitlocker Key Retrieval

An adversary with sufficient privileges in Azure Active Directory may attempt to retrieve BitLocker keys to decrypt drives for lateral movement or data exfiltration.

Azure Active Directory azure bitlocker key-retrieval persistence privilege-escalation
2r 3t
medium advisory

Cloud Instance Modified by Previously Unseen User

This analytic identifies cloud instances being modified by users who have not previously modified them, specifically focusing on successful modifications of EC2 instances, potentially indicating unauthorized access and configuration changes.

EC2 +1 cloud aws anomaly
2r 2t
medium advisory

Suspicious File Download via Headless Browser

Attackers are leveraging Chromium-based browsers in headless mode with the `--dump-dom` argument to download files from file-sharing services and direct IPs, potentially indicative of reconnaissance or malware delivery.

Chrome +2 headless-browser file-download cisco-nvm
2r 2t 26i
medium advisory

Potential Port Monitor or Print Processor Registration Abuse

This rule detects potential abuse of port monitors and print processors for privilege escalation and persistence on Windows systems by identifying registry modifications to load malicious DLLs that execute with SYSTEM privileges during system boot, focusing on modifications made by non-SYSTEM users.

Windows privilege-escalation persistence
2r 4t
medium advisory

External User Added to Google Workspace Group

Detection of an external Google Workspace user account being added to an existing group, potentially indicating an adversary attempting to intercept shared files or emails by adding accounts where the domain name of the target doesn't match the Google Workspace domain.

Google Workspace google_workspace initial_access account_manipulation
2r 2t
medium advisory

Entra ID Illicit Consent Grant via Registered Application

Attackers register malicious applications within Entra ID and deceive users into granting extensive permissions through OAuth consent, enabling unauthorized access to sensitive data like emails and files.

Microsoft Entra ID azure entra-id oauth illicit-consent
2r 3t
medium advisory

Cisco ASA Logging Message Suppression

Detection of 'no logging message' command usage on Cisco ASA devices, potentially indicating an adversary suppressing security-critical log events to evade detection.

ASA +3 defense-evasion impair-defenses network
2r 1t
medium advisory

Cisco 802.1X (dot1x) Disabled on Network Interface

Detection of manual disablement of IEEE 802.1X (dot1x) on a Cisco network device interface, potentially allowing unauthorized network access and lateral movement.

IOS attack.defense-evasion attack.persistence attack.credential-access attack.t1562.001 attack.t1556.004
2r 2t
medium advisory

GenAI Process Performing Encoding/Chunking Prior to Network Activity

This rule detects GenAI processes performing encoding or chunking (base64, gzip, tar, zip) followed by outbound network activity, indicating data preparation for exfiltration.

Ollama +2 genai exfiltration defense-evasion
2r 4t
medium advisory

Kubernetes Admission Webhook Manipulation for Persistence and Defense Evasion

The rule detects creation, modification, or deletion of Kubernetes MutatingWebhookConfigurations or ValidatingWebhookConfigurations by non-system identities, allowing attackers to inject malicious sidecars, block security tooling, or exfiltrate pod specifications.

kubernetes persistence defense-evasion
2r 2t
medium advisory

Detection of Downloaded Shortcut Files

This rule detects potentially malicious .lnk shortcut files downloaded from outside the local network on Windows systems, which are commonly used in phishing campaigns.

Elastic Defend phishing lnk execution windows
2r 3t
medium advisory

Suspicious AWS SAML Activity Detection

This rule identifies suspicious SAML activity in AWS, such as AssumeRoleWithSAML and UpdateSAMLProvider events, which could indicate an attacker gaining backdoor access, escalating privileges, or establishing persistence.

AWS IAM +1 aws saml cloudtrail initial-access lateral-movement persistence privilege-escalation stealth
2r 3t
medium advisory

User Added to Group with Conditional Access Policy Modification Access

An attacker adds a user to a privileged Azure Active Directory group with permissions to modify Conditional Access policies, potentially leading to privilege escalation, credential access, persistence, and defense impairment.

Azure Active Directory attack.privilege-escalation attack.credential-access attack.persistence attack.defense-impairment attack.t1548 attack.t1556
3r 4t
medium advisory

Netsh Used to Enable Network Discovery

Adversaries may use the `netsh.exe` command-line tool to enable Network Discovery via the Windows firewall, weakening host defenses and facilitating lateral movement by identifying other systems on the network.

Windows defense-evasion firewall lateral-movement
2r 1t
medium advisory

Kubernetes Secret Access by Node or Pod Service Account

This rule detects Kubernetes audit events where a node or pod service account attempts to read secrets directly, which is often a sign of credential access.

kubernetes credential-access cloud
2r 1t
medium threat

Calendar 2 Mac App Store Application Mines Cryptocurrency

The 'Calendar 2' application, available on the official Mac App Store, was found to surreptitiously mine cryptocurrency on users' Macs, utilizing the 'xmr-stak' miner to mine Monero (XMR) and report mining operations to calendar.qbix.com.

Calendar 2 +1 cryptocurrency miner macos appstore
3r 1t
medium advisory

Outlook Security Settings Registry Modification

Attackers modify Outlook security settings via registry changes to enable malicious mail rules and bypass security controls, potentially leading to persistence and data compromise.

Microsoft Outlook persistence registry_modification outlook email
2r 1t
medium advisory

InstallUtil Process Making Network Connections for Defense Evasion

Detection of InstallUtil.exe making outbound network connections, which can indicate adversaries leveraging it to execute code and evade detection by proxying execution through a trusted system binary.

Elastic Defend +1 defense-evasion proxy-execution windows
2r 1t
medium advisory

Windows Downdate Attack Registry Modification

The Windows Downdate attack involves modifying specific registry keys to force a Windows downgrade, enabling exploitation of older, vulnerable versions, which this detection identifies through monitoring for the creation or modification of the pending.xml file in unusual locations.

Splunk Enterprise +2 defense-evasion privilege-escalation windows registry-modification
2r 1t
medium advisory

Third-party Backup Files Deleted via Unexpected Process

This detection identifies the deletion of backup files by processes outside of the backup suite, specifically targeting Veritas and Veeam backups, which may indicate an attempt to prevent recovery from ransomware.

Elastic Defend +5 impact backup deletion ransomware
2r 2t
medium threat

Suspicious File Creation by Microsoft Exchange Unified Messaging Service

This rule detects suspicious file creations by the Microsoft Exchange Server Unified Messaging service, potentially indicative of exploitation of CVE-2021-26858, leading to web shell deployment for initial access, lateral movement, and persistence.

exploited Microsoft Exchange Server exchange webshell cve-2021-26858 initial-access
2r 3t 1c
medium advisory

Suspicious Execution via Microsoft Office Add-Ins

This rule identifies suspicious execution patterns where Microsoft Office applications launch add-ins from unusual paths or with atypical parent processes, potentially indicating initial access via a malicious phishing MS Office Add-In.

Microsoft Word +3 office-addins initial-access phishing
3r 4t
medium threat

Potential Command and Control via Internet Explorer COM Abuse

This rule detects potential command and control activity where Internet Explorer (iexplore.exe) is started via the Component Object Model (COM) and makes unusual network connections, indicating adversaries might exploit Internet Explorer via COM to evade detection and bypass host-based firewall restrictions.

Internet Explorer command-and-control com iexplore windows
2r 4t
medium advisory

Azure Network Firewall Policy Modification or Deletion

An adversary may modify or delete Azure Network Firewall Policies to impair defenses and potentially impact network security.

Azure Network Firewall attack.impact attack.defense-impairment attack.t1686.001
3r
medium advisory

Suspicious Execution via Scheduled Task

This rule identifies execution of suspicious programs via scheduled tasks by looking at process lineage and command line usage, detecting processes such as cscript.exe, powershell.exe, and cmd.exe when executed from suspicious paths like C:\Users\ and C:\ProgramData\.

Windows persistence execution
2r 2t
medium advisory

AWS RDS Snapshot Export to S3 for Potential Data Exfiltration

An adversary may export RDS snapshots to Amazon S3 to exfiltrate sensitive data outside of RDS-managed storage, potentially bypassing database access controls and leading to unauthorized data theft.

RDS +1 aws s3 exfiltration cloudtrail
2r 1t
medium advisory

Mac Malware of 2018 Retrospective

This brief analyzes Mac malware discovered in 2018, including OSX.Mami, a DNS hijacker distributed via browser popups, and CrossRAT, a cross-platform Java-based backdoor likely spread through phishing, highlighting infection vectors, persistence mechanisms, and capabilities.

MacUpdate.com +2 macos malware dns-hijacking backdoor
3r 1t 4i
medium advisory

Potential Credential Access via LSASS Handle Duplication

Detection of suspicious LSASS handle access via DuplicateHandle from an unknown call trace module, indicating a potential attempt to bypass the NtOpenProcess API to evade detection and dump LSASS memory for credential access.

Windows credential-access lsass duplicatehandle mirrordump
2r 1t
medium advisory

AWS Bedrock Knowledge Base Deletion Attempt

An adversary may delete AWS Bedrock Knowledge Bases, which are resources that store and manage domain-specific information for AI models, to disrupt business operations or remove traces of data access by using the DeleteKnowledgeBase API call.

AWS Bedrock +1 aws bedrock knowledge_base deletion cloudtrail
2r 2t
medium advisory

Nginx-UI Unauthenticated Initial Admin Claim Vulnerability

An unauthenticated network attacker can claim the initial administrator account on a fresh Nginx-UI instance during the first-run setup window by exploiting the publicly accessible /api/install endpoint.

Nginx-UI initial-access authentication-bypass
2r 1t
medium advisory

Suspicious PowerShell TabExpansion Direct Call

This detection identifies PowerShell scripts that directly call the TabExpansion internal function, which is uncommon and may indicate malicious activity, such as TabShell, potentially bypassing sandboxes by loading PowerShell functions via directory traversal.

Splunk Enterprise +2 powershell tabexpansion bypass endpoint
2r 2t
medium advisory

Network Connection via Compiled HTML File

This rule detects network connections initiated by hh.exe, the HTML Help executable, which may indicate the execution of malicious code embedded in compiled HTML files (.chm) to deliver malicious payloads, bypass security controls, and gain initial access via social engineering.

HTML Help execution defense-evasion command-and-control malicious-file html-help
2r 3t
medium advisory

Windows Subsystem for Linux Distribution Installed via Registry Modification

This rule detects registry modifications indicative of a new Windows Subsystem for Linux (WSL) distribution installation, a technique adversaries may leverage to evade detection by utilizing Linux environments within Windows.

Windows Subsystem for Linux +4 wsl defense-evasion windows
2r 3t
medium advisory

AWS IAM OIDC Provider Created by Rare User

An uncommon user or role creating an OpenID Connect (OIDC) Identity Provider in AWS IAM can indicate an attacker establishing persistent, federated access by creating rogue OIDC providers to assume roles using attacker-controlled IdP tokens.

IAM aws oidc persistence cloud
2r 3t
medium advisory

Zoom High Video Latency Potentially Indicating Remote Employment Fraud

This analytic identifies Zoom users exhibiting high video latency, a potential indicator of Remote Employment Fraud (REF), by analyzing Zoom logs for average and overall latency and highlighting users with latency exceeding 300ms.

Zoom remote-employment-fraud identity
2r 1t 1i
medium advisory

Windows Hosts Querying Abused Web Services

Adversaries may use abused web services such as paste sites, VoIP, and file hosting to host malicious payloads or facilitate command and control, detected via DNS queries from Windows hosts to these services.

githubusercontent.com +34 abused-web-service command-and-control initial-access windows
2r 1t 34i
medium advisory

Potential Data Exfiltration via Rclone

The rule detects the abuse of rclone, a legitimate file synchronization tool, potentially renamed to evade detection, to exfiltrate data to cloud storage or remote endpoints, using copy/sync commands and specific file filters.

rclone exfiltration cloud storage windows
3r 1t
medium advisory

OpenSSL Data Encryption Detection

This brief documents detection of OpenSSL being used to encrypt data using command-line arguments specifying input and output files, potentially indicating data exfiltration preparation or ransomware activity by threat actors.

OpenSSL defense-evasion collection data-encryption
2r 2t
medium advisory

Multiple Logon Failures from Single Source Indicate Brute Force Attempt

Detection of multiple consecutive logon failures from a single source IP within a short time interval indicates a potential brute force or password guessing attack targeting Windows systems.

Windows credential-access brute-force
2r 2t
medium advisory

MSBuild запускает необычные процессы

Adversaries may exploit MSBuild to execute malicious scripts or compile code, bypassing security controls; this rule detects unusual processes initiated by MSBuild, such as PowerShell or C# compiler, signaling potential misuse for executing unauthorized or harmful actions.

MSBuild +3 defense-evasion execution
2r 3t
medium advisory

Malicious Azure Kubernetes Admission Controller Configuration

An adversary can exploit Kubernetes Admission Controllers in Azure to achieve persistence, privilege escalation, or credential access by manipulating webhook configurations.

Azure Kubernetes Service +1 azure kubernetes admission-controller persistence privilege-escalation credential-access
2r 4t
medium advisory

Detection of Bcdedit Boot Configuration Modification

This rule identifies the use of bcdedit.exe to modify boot configuration data, which may be indicative of a destructive attack or ransomware activity aimed at inhibiting system recovery by disabling error recovery or ignoring boot failures.

Microsoft Defender XDR +2 boot-configuration bcdedit impact windows
2r 1t
medium advisory

Azure AD Authentication to Important Apps Using Single-Factor Authentication

Detection of successful Azure AD authentications to critical applications that only required single-factor authentication, potentially indicating a security lapse or policy violation leading to unauthorized access.

Azure Active Directory attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078
2r 3t
medium advisory

AWS ECR Container Scanning Reveals Low Severity Vulnerabilities

This analytic identifies low, informational, or unknown severity findings from AWS Elastic Container Registry (ECR) image scans using AWS CloudTrail logs, indicating potential vulnerabilities or misconfigurations in container images that could lead to unauthorized access or data breaches.

Elastic Container Registry aws ecr container vulnerability
2r 1t 1c
medium advisory

Detection of Azure Application Deletion

This alert identifies when an application is deleted within an Azure environment, which could indicate malicious activity or unintended misconfiguration leading to service disruption.

Azure application deletion impact t1489
2r 1t
medium advisory

Gsuite Email with Suspicious Subject and Attachments

Detection of Gsuite emails with suspicious subjects and attachments (e.g., DHL, UPS, invoice, DOC, ZIP) indicative of spear phishing, excluding internal test domains, which could lead to initial compromise and further malicious activity.

Gsuite spear-phishing initial-access
2r 1t 1i
medium advisory

Windows TOR Client Execution Detection

Detects the execution of the TOR Browser and related components on Windows endpoints, indicating potential anonymization of traffic for command and control, data exfiltration, or policy evasion by adversaries or insider threats.

TOR Browser +1 tor proxy anonymization command-and-control data-exfiltration windows
2r 1t
medium advisory

Windows Time-Based Evasion via Choice Exec

Detection of choice.exe used in batch files for time-based evasion, a technique observed in SnakeKeylogger malware, indicating potential stealthy code execution and persistence.

Windows +3 time-based-evasion malware persistence defense-evasion
2r 1t
medium threat

Windows Theme File Creation in Unusual Location

Detects the creation of Windows theme files in unusual locations, such as Desktop, Documents, Downloads, or Temp directories, which can be indicative of remote code execution or NTLM coercion attacks.

exploited Splunk Enterprise +2 windows theme-file code-execution credential-theft
2r 3t
medium advisory

Windows Processes Gathering Network Information via IP Check Web Services

Detection of Windows processes using IP check web services for reconnaissance, a behavior commonly associated with malware like Trickbot, by monitoring DNS queries.

Windows network-reconnaissance malware-behavior
2r 1t 26i
medium advisory

Windows Folder Options Disabled via Registry Modification

Attackers modify the Windows registry to disable the Folder Options feature, preventing users from showing hidden files and file extensions, commonly used by malware to conceal malicious files and deceive users with fake file extensions.

Splunk Enterprise +3 defense-evasion registry-modification windows
2r
medium advisory

Windows EventLog Reconnaissance Activity Detection

This detection identifies potential reconnaissance activities on Windows systems by adversaries using tools like `wevtutil.exe`, `wmic.exe`, and PowerShell cmdlets to query event logs for sensitive information.

Windows eventlog reconnaissance
3r 1t
medium advisory

Unusual Network Activity from Windows System Binaries

Detection of network connections initiated by unusual Windows system binaries, often leveraged by adversaries to proxy execution of malicious code and evade detection, indicating potential defense evasion and command and control activity.

Windows defense-evasion proxy-execution
3r 5t
medium advisory

Unusual Modification of GenAI Tool Configuration File

This rule detects unusual modifications to GenAI tool configuration files, potentially indicating an attacker injecting malicious MCP server configurations to hijack AI agents for persistence, command and control, or data exfiltration.

Claude +3 genai configuration-modification defense-evasion
3r 4t
medium advisory

System Shells Launched via Windows Services

Attackers may configure existing Windows services or create new ones to execute system shells (cmd.exe, powershell.exe) to elevate privileges from administrator to SYSTEM for persistence and further malicious activity.

Windows persistence execution privilege-escalation
2r 4t
medium advisory

Suspicious WMI Reconnaissance via PowerShell

This analytic detects suspicious PowerShell activity leveraging WMI to gather system information, potentially indicating reconnaissance by an attacker.

Windows reconnaissance powershell wmi
2r 2t
medium advisory

Suspicious Modification of Sensitive Linux Files

This threat brief covers the detection of suspicious processes modifying sensitive files on Linux systems, potentially indicating malicious attempts to persist, escalate privileges, or disrupt system operations.

file-integrity privilege-escalation persistence linux
3r 1t
medium advisory

Suspicious .NET Code Compilation via Unusual Parent Processes

The execution of .NET compilers (csc.exe, vbc.exe) with suspicious parent processes (wscript.exe, mshta.exe, etc.) indicates potential attempts to compile code after delivery for defense evasion and execution.

Windows defense-evasion execution dotnet compiler
2r 9t
medium advisory

Remote File Download via PowerShell

Detects PowerShell being used to download executable files from untrusted remote destinations, often used by attackers to transfer malware into a compromised environment.

PowerShell +1 command-and-control file-download windows
2r 2t
medium advisory

Rare Connection to WebDAV Target for Credential Access

Adversaries may inject WebDAV paths into files or features opened by a user to leak NTLM credentials via forced authentication, and this detection identifies rare connections to WebDAV resources using rundll32.exe.

Windows credential-access webdav
2r 2t
medium advisory

Potential Lateral Tool Transfer via SMB Share

This rule identifies the creation or change of a Windows executable file over network shares (SMB), indicating adversaries may transfer tools or other files between systems in a compromised environment.

Windows lateral-movement smb file-creation
3r 2t
medium advisory

Mounting Hidden or WebDav Remote Shares via Net.exe

Adversaries may use net.exe to mount WebDav or hidden remote shares, indicating lateral movement or preparation for data exfiltration within a Windows environment.

Windows lateral-movement net.exe webdav
2r 4t
medium advisory

Malware Leveraging Large Language Model Endpoints for Command and Control

This rule detects DNS queries to known Large Language Model (LLM) domains originating from unsigned binaries or common Windows scripting utilities, indicating potential malware command and control activity.

Large Language Model services command_and_control llm malware windows macos
3r 1t 35i
medium advisory

Generic Ransomware Detection on macOS

This brief outlines a method for generically detecting ransomware on macOS by monitoring file I/O events and identifying the rapid creation of encrypted files by untrusted processes, as proposed by Objective-See.

Transmission +1 ransomware malware macos
2r 1t
medium advisory

Execution of Persistent Suspicious Programs via Run Keys

This analytic identifies suspicious programs such as script interpreters, rundll32, or MSBuild being executed shortly after user logon, indicating potential persistence mechanisms abusing the registry run keys.

Elastic Defend persistence windows threat-detection
2r 8t
medium advisory

Entra ID User Sign-in with Unusual Client Application

Adversaries with stolen credentials or OAuth tokens may abuse Entra ID-managed or first-party client IDs to perform on-behalf-of (OBO) authentication, blending into legitimate cloud traffic and evading detection by using a rare application ID for principal authentication.

Entra ID +1 azure entra-id initial-access oauth
2r 3t
medium advisory

Detect Windows Entra User Management Via Azure CLI

This analytic detects the usage of the Azure CLI to interact with user accounts, such as creating or deleting a user, potentially indicating malicious activity aimed at maintaining persistence and evading detection within an Entra ID environment.

Azure CLI +3 azure entra-id user-management persistence windows
2r 3t
medium advisory

Bandit WebSocket Memory Exhaustion Vulnerability

An unauthenticated attacker can exhaust server memory by sending unbounded WebSocket continuation frames in Bandit-fronted applications, leading to a denial of service.

Phoenix Channels +1 denial-of-service websocket memory-exhaustion
2r 2t
medium advisory

Azure Network Watcher Deletion for Defense Evasion

An adversary may delete an Azure Network Watcher to impair defenses by disabling network monitoring and logging capabilities, as detected by monitoring Azure activity logs for Network Watcher deletion events.

Azure Network Watcher cloud azure defense-evasion
2r 2t
medium advisory

Azure Key Vault Excessive Secret or Key Retrieval

Detects excessive secret or key retrieval operations from Azure Key Vault, indicating potential unauthorized access attempts or credential harvesting.

Azure Key Vault azure keyvault credential-access threat-detection
2r 2t
medium advisory

Azure AD User Password Reset Detection

Detects when a user successfully resets their own password in Azure Active Directory, which may indicate malicious activity or account compromise.

Azure Active Directory azure password-reset privilege-escalation initial-access persistence credential-access stealth
2r 1t
medium advisory

Azure AD Guest to Member User Type Conversion

An adversary may convert a guest user account to a member account in Azure Active Directory to elevate privileges and gain persistent access to resources.

Azure Active Directory privilege-escalation azure entra guest-account
2r 1t
medium advisory

AWS User Login Profile Update by Different User

A user updating the login profile of another user in AWS CloudTrail logs may indicate privilege escalation attempts.

AWS Identity and Access Management aws cloudtrail iam privilege-escalation
2r 1t
medium advisory

AWS STS Role Assumption by Service for Privilege Escalation

Detection of AWS services assuming roles within AWS Security Token Service (STS) to gain temporary credentials and potentially escalate privileges or move laterally within the AWS environment.

AWS Security Token Service aws sts privilege-escalation lateral-movement
2r 2t
medium advisory

AWS SES Identity Deletion

Detection of an AWS Simple Email Service (SES) identity deletion event, potentially indicating an adversary attempting to cover their tracks after malicious activity.

Simple Email Service attack.stealth attack.t1070 cloud
2r 1t
medium advisory

AWS KMS Customer Managed Key Disabled or Scheduled for Deletion

An adversary may disable or schedule the deletion of an AWS customer-managed KMS Key to cause irreversible data loss, disrupt business operations, impede incident response, or hide evidence of prior activity.

AWS Key Management Service cloud aws kms datadestruction
2r 1t
medium advisory

AWS IAM SAML Provider Updated Detection

Detection of unauthorized updates to AWS IAM SAML providers, potentially leading to privilege escalation and persistent access via trust manipulation.

AWS IAM aws iam saml privilege-escalation defense-evasion
2r 2t
medium advisory

AWS GuardDuty Member Account Manipulation

Adversaries may attempt to disassociate or manipulate Amazon GuardDuty member accounts within an AWS organization to break centralized visibility, allowing them to operate undetected in member accounts.

GuardDuty aws defense_evasion
2r 1t
medium advisory

AWS Console Login from New Country

Detects AWS console logins by a user from a previously unseen country, potentially indicating compromised credentials.

AWS Console aws cloud credential-access initial-access
2r 3t
medium advisory

Attrib.exe Used to Hide Files and Directories

Detection of attrib.exe being used with the +h flag to hide files and directories on Windows systems, a technique used by attackers for defense evasion and persistence.

Splunk Enterprise +2 defense-evasion persistence windows
2r 1t
medium advisory

Apple Security Framework Crash due to Uninitialized Pointer

A crash was identified in Apple's Security framework due to an uninitialized pointer in the SecError function, leading to the dereference of an invalid memory address.

Security Framework security-framework crash uninitialized-pointer macos
2r
medium advisory

Entra ID User Reported Suspicious Activity

This rule detects suspicious activity reported by users in Microsoft Entra ID, indicating potential account compromise or unauthorized access attempts via social engineering during authentication.

Entra ID +1 entra-id suspicious-activity initial-access credential-access
2r 2t
medium advisory

Windows Netsh Tool Used for Firewall Discovery

The native Windows `netsh.exe` tool is being abused to discover firewall configurations, potentially to weaken defenses before lateral movement and data exfiltration.

Windows network-discovery firewall netsh
2r 1t
medium advisory

Windows Firewall Disabled via Netsh

Detection of adversaries disabling Windows Firewall rules using the `netsh.exe` command-line tool to weaken defenses and facilitate unauthorized network activity.

Microsoft Defender XDR +1 defense-evasion windows firewall
2r 1t
medium advisory

Symbolic Link Creation to Shadow Copies for Credential Access

The creation of symbolic links to shadow copies on Windows systems by processes such as cmd.exe or powershell.exe can indicate an attempt to access sensitive files for credential theft.

Windows +1 credential-access defense-evasion
2r 3t
medium advisory

Suspicious PowerShell Execution via Windows Script Host

Detection of PowerShell processes launched by cscript.exe or wscript.exe, indicative of potential malicious initial access or execution attempts.

Microsoft Defender XDR +2 initial-access execution windows powershell script
2r 4t
medium advisory

Suspicious MS Office Child Process

This rule detects suspicious child processes spawned by Microsoft Office applications, indicating potential exploitation or malicious macros used for initial access, command execution, defense evasion, and discovery activities.

Microsoft Office +3 initial-access execution defense-evasion discovery windows
2r 18t 1c
medium advisory

Suspicious Module Loaded by LSASS for Credential Access

Detection of unsigned or untrusted DLLs being loaded into the LSASS process, which is indicative of credential access attempts by adversaries aiming to steal sensitive information such as user passwords.

credential-access lsass windows
2r 2t
medium advisory

RDP (Remote Desktop Protocol) from the Internet

This rule detects network events indicative of RDP traffic originating from the internet, which poses a significant security risk due to its frequent exploitation as an initial access or backdoor vector.

Remote Desktop Services command-and-control lateral-movement initial-access rdp
2r 3t 1c
medium advisory

Python Site or User Customize File Creation for Persistence

Attackers can exploit Python's sitecustomize.py and usercustomize.py files for persistence by injecting malicious code, allowing them to execute arbitrary commands upon Python startup.

Python persistence startup-hook linux
2r 2t
medium advisory

Potential Defense Evasion via Symbolic Link of Common Linux Binaries to Writable Directories

An adversary may create symbolic links of legitimate system binaries in world-writable directories to potentially bypass security restrictions or execute malicious code with elevated privileges by masquerading as a trusted process.

Linux Operating System defense_evasion symlink linux
2r 1t
medium advisory

MSSQL xp_cmdshell Stored Procedure Abuse for Persistence and Execution

Attackers leverage the MSSQL xp_cmdshell stored procedure to execute arbitrary commands, escalating privileges and establishing persistence on Windows systems.

SQL Server mssql xp_cmdshell persistence execution
2r 2t
medium advisory

MSIExec Spawning Discovery Commands

Detection of msiexec.exe spawning discovery commands indicating potential reconnaissance activity by attackers for system information gathering and lateral movement.

Splunk Enterprise +2 msiexec discovery windows
2r 1t
medium advisory

MpCmdRun Used for Remote File Download

Attackers are abusing the Windows Defender command-line utility, MpCmdRun.exe, to download malicious files from remote URLs, enabling them to introduce malware or offensive tooling into compromised environments.

Windows Defender Antivirus living-off-the-land file-download windows
2r 1t
medium advisory

Linux Cron File Creation for Persistence

An attacker may create new cron files in cron directories to establish persistence on a Linux system, potentially leading to privilege escalation and arbitrary code execution.

cron persistence privilege-escalation linux
2r 1t
medium advisory

Kubelet API Connection Attempt to Internal IP

The rule detects network connection attempts to the Kubernetes Kubelet API ports 10250 and 10255 on internal IP ranges from Linux hosts, indicating potential lateral movement within container and cluster environments.

kubelet +2 kubernetes lateral-movement linux container
2r 2t
medium advisory

Entra ID Service Principal Sign-in from Unusual Source ASN

Detects Entra ID service principal sign-ins from a source ASN that is unusual based on a history window, potentially indicating compromised credentials or a rogue application.

Microsoft Entra ID azure entra_id service_principal initial_access
2r 2t
medium advisory

Entra ID OAuth User Impersonation to Microsoft Graph

Detects potential session hijacking or token replay in Microsoft Entra ID, where a user signs in and subsequently accesses Microsoft Graph from a different IP address using the same session ID, indicating a successful OAuth phishing attack, session hijacking, or token replay attack.

Microsoft Entra ID +2 azure entra_id oauth graph_api token_replay session_hijacking initial_access defense_evasion
2r 2t
medium advisory

Detection of Azure Service Principal Creation

Detects the creation of a service principal in Azure, which could indicate potential attacker activity for lateral movement or persistence.

Azure cloud service principal persistence lateral movement
3r 1t
medium advisory

Azure AD Successful Authentication Increase

This detection identifies a statistically significant (10% or greater) increase in successful sign-ins to Azure Active Directory, potentially indicating credential compromise or account takeover attempts.

Azure Active Directory attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078
2r 1t
medium advisory

Azure AD Hybrid Health AD FS Service Deletion for Defense Evasion

Threat actors may delete Azure AD Hybrid Health AD FS service instances after using them to spoof AD FS signing logs for defense evasion.

Azure Active Directory attack.defense-impairment attack.t1578.003 azure
2r 1t
medium advisory

UAC Bypass via DiskCleanup Scheduled Task Hijack

Attackers bypass User Account Control (UAC) to stealthily execute code with elevated permissions by hijacking the DiskCleanup Scheduled Task, leveraging specific arguments with non-standard executables.

Windows uac-bypass privilege-escalation
2r 3t
medium advisory

Container Runtime CLI Execution with Suspicious Arguments

Detects execution of container runtime CLI tools (ctr, crictl, nerdctl) with arguments indicating container creation, command execution inside existing containers, image manipulation, or host filesystem mounting, potentially leading to privileged container creation and unauthorized access to sensitive data.

Elastic Defend +1 container execution privilege-escalation linux
2r 2t
medium advisory

Azure Service Principal Removal Detection

Detection of a service principal removal in Azure, potentially indicating malicious activity or an attempt to remove evidence of a compromise.

Azure service principal stealth cloud
2r 1t
medium advisory

Unsecured Elasticsearch Node Inbound Connection

This rule identifies potentially unsecured Elasticsearch nodes that lack TLS and/or authentication and are accepting inbound network connections, which could allow adversaries to gain initial access, exfiltrate data, or disrupt services.

Elasticsearch initial-access reconnaissance network
2r 2t
medium advisory

Potential Database Dumping Activity on Linux

This rule detects the use of database dumping utilities to exfiltrate data from a database on Linux systems, where attackers may attempt to dump the database to a file and then exfiltrate the file to a remote server.

PostgreSQL +3 exfiltration database linux
2r 1t
medium advisory

Suspicious Non-Interactive PowerShell Process Creation

Detects PowerShell processes spawned by non-interactive parent processes, potentially indicating malicious script execution or automation bypassing user interaction.

Windows +3 powershell execution non-interactive
2r 1t
medium advisory

Registry Persistence via AppCert DLL

Detection of Registry Persistence via AppCert DLL, which involves modifying registry keys to load malicious DLLs upon process creation, enabling persistence and potential privilege escalation.

Windows persistence privilege-escalation
2r 2t
medium advisory

Kubernetes Multi-Resource Discovery Reconnaissance

Adversaries may perform reconnaissance in a Kubernetes environment by rapidly querying multiple resource types to map the environment and identify potential privilege escalation paths.

Kubernetes discovery reconnaissance
2r 1t
medium advisory

Unusual Network Connection via DllHost

The rule identifies unusual instances of dllhost.exe making outbound network connections to non-local IPs, which may indicate adversarial Command and Control activity and defense evasion.

Elastic Defend +2 defense-evasion command-and-control windows
2r 2t
medium advisory

Unsigned DLL Side-Loading from Suspicious Folders by Trusted Processes

This detection identifies a Windows trusted program running from locations often abused by adversaries to masquerade as a trusted program and loading a recently dropped unsigned DLL, which indicates an attempt to evade defenses via side-loading a malicious DLL within the memory space of a signed process.

Elastic Defend defense-evasion dll-sideloading windows
2r 2t
medium advisory

Suspicious PowerShell Engine ImageLoad

This rule identifies instances where the PowerShell engine is loaded by processes other than powershell.exe, potentially indicating attackers attempting to use PowerShell functionality stealthily by using the underlying System.Management.Automation namespace and bypassing PowerShell security features.

Elastic Defend powershell execution windows
2r 1t
medium advisory

Suspicious MSBuild Execution from Scripting Processes

Adversaries may use MSBuild, a legitimate Microsoft tool, to execute malicious code through script interpreters for defense evasion and execution on Windows systems.

MSBuild defense-evasion execution proxy-execution
2r 6t
medium advisory

Suspicious Execution from a Mounted Device

Attackers may use mounted devices as a non-standard working directory to execute signed binaries or script interpreters, evading traditional defense mechanisms, particularly when launched via explorer.exe.

Windows defense-evasion execution mounted-device
2r 9t
medium advisory

Suspicious CertUtil Commands Used for Defense Evasion

Attackers abuse certutil.exe, a native Windows utility, to download/deobfuscate malware for command and control or data exfiltration, evading defenses.

Windows defense-evasion command-and-control credential-access
2r 3t
medium advisory

Remote Execution via File Shares

This rule identifies the execution of a file that was created by the virtual system process, potentially indicating lateral movement via network file shares in Windows environments.

lateral-movement file-share windows
2r 2t
medium advisory

Potential RemoteMonologue Attack via Registry Modification

This rule detects potential RemoteMonologue attacks by identifying attempts to perform session hijacking via COM object registry modification, specifically when the RunAs value is set to Interactive User.

MsMpEng.exe +4 remotemonologue defense-evasion persistence windows
2r 4t
medium advisory

Potential Defense Evasion via Filter Manager (fltMC.exe)

Adversaries may abuse the Filter Manager Control Program (fltMC.exe) to unload filter drivers, thereby evading security software defenses such as malware detection and file system monitoring.

Defender XDR +3 defense-evasion filter-driver fltMC.exe windows
2r 1t
medium threat

Kerberos Traffic from Unusual Process

Detects network connections to the standard Kerberos port from an unusual process other than lsass.exe, potentially indicating Kerberoasting or Pass-the-Ticket activity on Windows systems.

Elastic Defend +22 kerberoasting credential-access lateral-movement windows
2r 2t
medium advisory

Execution from Unusual Directory - Command Line

This rule identifies process execution from suspicious default Windows directories, which adversaries may abuse to hide malware in trusted paths to evade defenses.

Microsoft Defender XDR +1 execution defense-evasion windows process-execution
2r 2t
medium advisory

Detecting Remote Windows Service Installation for Lateral Movement

This rule detects a network logon followed by Windows service creation with the same LogonId on a Windows host, which could indicate lateral movement or persistence by adversaries.

Windows +4 lateral-movement persistence
2r 3t
medium advisory

WMI Incoming Lateral Movement

Detection of processes executed via Windows Management Instrumentation (WMI) on a remote host indicating potential adversary lateral movement.

HPWBEM +3 lateral-movement wmi windows
3r 2t
medium advisory

WinPEAS PowerShell Script Execution Detection

This brief documents the detection of the WinPEAS PowerShell script execution on Windows systems, a tool commonly used for identifying privilege escalation paths by identifying specific function names used within the script.

Splunk Enterprise +2 privilege-escalation post-exploitation windows
2r 8t
medium advisory

Windows System Restore Disabled via Registry Modification

Attackers disable Windows System Restore by modifying specific registry keys to hinder recovery efforts after malicious activity.

Windows impact t1490 persistence
2r 1t
medium advisory

Windows System File Ownership Change via Takeown or Icacls

Adversaries may modify file or directory ownership to evade access control lists (ACLs) and access protected files by using takeown.exe or icacls.exe to grant excessive permissions to system files.

Windows defense-evasion persistence
2r 2t
medium advisory

Windows Subsystem for Linux Enabled via Dism Utility

Adversaries may enable and use Windows Subsystem for Linux (WSL) using the Microsoft Dism utility to evade detection on Windows systems by running Linux applications and tools.

Microsoft Defender XDR +2 defense-evasion wsl windows
2r 1t
medium advisory

Windows Software Discovery via PowerShell Registry Queries

Attackers use PowerShell to query the Windows registry's Uninstall key to discover installed software and identify potential vulnerabilities for exploitation.

Splunk Enterprise +2 software-discovery powershell registry reconnaissance
2r 3t
medium advisory

Windows Script Interpreter Executing Process via WMI

The rule identifies the use of Windows script interpreters (cscript.exe or wscript.exe) executing a process via Windows Management Instrumentation (WMI), which may indicate malicious activity, especially when initiated by non-system accounts.

Sysmon windows wmi script_execution initial_access execution
2r 4t
medium advisory

Windows Root Certificate Modification Detection

The modification of root certificates on Windows systems by unauthorized processes can allow attackers to masquerade malicious files as valid signed components and intercept/decrypt SSL traffic, leading to defense evasion and data collection.

Elastic Defend +2 defense-evasion persistence root certificate mitm
2r 2t
medium advisory

Windows Host Network Discovery Enabled via Netsh

Attackers can enable host network discovery via netsh.exe to weaken host firewall settings, facilitating lateral movement by identifying other systems on the network.

Microsoft Defender XDR +3 defense-evasion windows firewall
2r 1t
medium advisory

Windows Guest Account Enabled via net.exe

The Windows guest account, typically restricted, can be enabled via `net.exe` for malicious activities like malware installation or data theft, potentially indicating persistence, defense evasion, privilege escalation or initial access.

Splunk Enterprise +2 guest-account persistence windows
2r 1t
medium advisory

Windows Firewall Rule Modification Detection

This detection identifies instances where a Windows Firewall rule has been modified, potentially indicating an attempt to weaken security policies and allow malicious traffic or prevent legitimate communications.

Windows +3 firewall anomaly
2r
medium advisory

Windows Firewall Rule Deletion Detection

Detection of Windows Firewall rule deletion events (Event ID 4948) indicating potential attacker attempts to bypass security controls or malware disabling protections for persistence and command-and-control.

Windows +3 firewall endpoint
2r 1t
medium advisory

Windows Firewall Rule Added via Event ID 4946

This detection identifies instances where a Windows Firewall rule is added by monitoring Event ID 4946 in the Windows Security Event Log, potentially indicating unauthorized changes or malicious activity such as attackers allowing traffic for backdoors or persistence mechanisms.

Splunk Enterprise +2 firewall persistence windows
2r
medium advisory

Windows Firewall Disabled via PowerShell

Attackers may disable the Windows firewall or its rules using the `Set-NetFirewallProfile` PowerShell cmdlet to enable lateral movement and command and control activity.

Microsoft Defender XDR +3 defense-evasion powershell firewall windows
2r 2t
medium advisory

Windows Firewall Disabled via Netsh

Attackers use the `netsh.exe` command-line tool to disable or weaken the local Windows firewall, facilitating lateral movement and command and control by bypassing host-based network traffic filtering.

Windows defense-evasion firewall
2r 1t
medium advisory

Windows Defender Tracing Level Modification

The following analytic detects modifications to the Windows registry specifically targeting the 'WppTracingLevel' setting within Windows Defender, potentially impairing its diagnostic capabilities and allowing attackers to evade detection.

Windows Defender +3 defense-evasion registry-modification windows
2r
medium advisory

Windows Defender Throttle Rate Modification

An attacker modifies the Windows Defender ThrottleDetectionEventsRate registry setting to reduce the frequency of logged detection events, potentially evading detection.

Splunk Enterprise +2 windows defender registry defense-evasion
2r 1t
medium advisory

Windows Defender Signature Retirement Disabled via Registry Modification

An attacker disables Windows Defender's signature retirement feature by modifying a registry key, potentially reducing its effectiveness in detecting threats by allowing older, less relevant signatures to persist.

Windows Defender +3 defense-evasion windows-registry windows-defender
2r 1t
medium advisory

Windows Defender Scan On Update Disabled via Registry Modification

An attacker modifies the Windows registry to disable the Windows Defender Scan On Update feature, potentially evading detection and establishing persistence.

Windows Defender +3 defense-evasion registry-modification windows-defender
2r 1t
medium advisory

Windows Defender Reporting Disabled via Registry Modification

Attackers modify the Windows registry to disable Windows Defender generic reports, preventing error reports and potentially hiding malicious activity.

Windows Defender defense-evasion windows registry
2r 1t
medium advisory

Windows Defender Exclusions Added via PowerShell

Adversaries may attempt to bypass Windows Defender's capabilities by using PowerShell to add exclusions for folders or processes, and this activity can be detected by monitoring PowerShell command lines that use `Add-MpPreference` or `Set-MpPreference` with exclusion parameters.

Microsoft Defender XDR +3 defense-evasion powershell windows
2r 3t
medium advisory

Windows Auditpol ResourceSACL Clearing for Defense Evasion

Adversaries may clear the global object access auditing policy using `auditpol.exe` with the `/resourceSACL` flag and either `/clear` or `/remove` arguments to evade detection by removing audit configurations.

Splunk Enterprise +3 defense-evasion windows
2r
medium advisory

Windows Audit Policy Sub-Category Disabled

This rule detects attempts to disable auditing for security-sensitive audit policy sub-categories on Windows systems, often done by attackers to evade detection and forensic analysis.

Windows defense_evasion audit_policy
2r 3t
medium advisory

Windows Application Hotkey Disablement via Registry Modification

Attackers disable Windows application hotkeys by modifying specific registry entries to hinder incident response and evade detection.

Splunk Enterprise +2 registry-modification defense-evasion persistence hotkey-disablement
2r 1t
medium advisory

Windows AD GPO Disabled

Detection of Active Directory Group Policy being disabled using the Group Policy Management Console, potentially indicating malicious attempts to weaken security controls.

Splunk Enterprise +3 active_directory group_policy persistence
3r 1t
medium advisory

Web Server Request Command Injection Attempt

Detection of potential command injection attempts via web server requests by identifying URLs containing suspicious patterns associated with command execution payloads, which attackers exploit to execute arbitrary commands on the server.

Apache +4 command-injection web-server persistence
2r 5t
medium advisory

User Removed from Group with Conditional Access Policy Modification Access

An attacker removes a user from a privileged Azure Active Directory group with permissions to modify Conditional Access policies, potentially leading to privilege escalation, persistence, or defense evasion.

Azure Active Directory azure conditional-access privilege-escalation
2r 3t
medium advisory

User Added to Privileged Group in Active Directory

Adversaries may add a user to a privileged group in Active Directory, such as Domain Admins, to maintain persistent access and elevate privileges within the domain.

Active Directory persistence privilege_escalation active_directory
2r 1t
medium advisory

Unusual Volume of File Deletion in Microsoft 365

An attacker may delete an unusual volume of files in Microsoft 365 to cause disruption or hide malicious activity.

Microsoft 365 +3 microsoft365 file_deletion data_loss impact
2r 1t
medium advisory

Unusual Source IP for Azure Arc Cluster Credential Access

Detects when a service principal or user performs an Azure Arc cluster credential listing operation from a source IP not previously associated with that identity, potentially indicating compromised credentials.

Azure Arc +1 azure azure-arc credential-access
2r 2t
medium advisory

Unusual Process Connecting to Docker or Containerd Socket

An unusual process connecting to a container runtime Unix socket like Docker or Containerd can indicate an attacker attempting to bypass Kubernetes security measures for container manipulation.

Auditbeat +4 container privilege-escalation lateral-movement linux
2r 3t
medium advisory

Unused Privileged Identity Management (PIM) Roles in Azure

Detection of assigned but unused privileged roles in Azure's Privileged Identity Management (PIM) service, indicating potential misconfiguration, license overuse, or dormant privileged access that could be exploited.

Azure pim privileged-identity-management role-based-access-control initial-access privilege-escalation
2r 1t
medium advisory

Uncommon Registry Persistence Change Detection

This rule detects changes to uncommon registry persistence keys on Windows systems that are not commonly used or modified by legitimate programs, which could indicate an adversary's attempt to persist in a stealthy manner by modifying registry keys for persistence, ensuring malicious code executes on startup or during specific events.

Windows persistence registry
2r 2t
medium advisory

Unauthorized Guest User Invitation Attempt in Azure

Detection of a failed attempt to invite an external guest user by an Azure user lacking the necessary permissions, potentially indicating privilege escalation or malicious insider activity.

Azure privilege-escalation initial-access persistence stealth
2r 1t
medium advisory

Unauthorized Conditional Access Policy Creation in Azure AD

An unauthorized actor created a new Conditional Access policy in Azure AD, potentially leading to privilege escalation and unauthorized access.

Azure Active Directory azure conditional-access privilege-escalation attack.privilege-escalation attack.t1548
2r 1t
medium advisory

UAC Bypass Attempt via Elevated COM Internet Explorer Add-On Installer

This threat brief details a UAC bypass technique leveraging the Internet Explorer Add-On Installer (ieinstal.exe) and Component Object Model (COM) to execute arbitrary code with elevated privileges.

Microsoft Defender XDR +2 uac-bypass privilege-escalation com ieinstal
2r 3t
medium advisory

TeamFiltration Tool User-Agent Detected in Entra ID Sign-ins

The TeamFiltration tool, used for Entra ID and Microsoft 365 enumeration and password spraying, is detected via specific user-agent strings in sign-in logs.

Microsoft Entra ID +2 azure o365 teamfiltration credential-access
2r 7t 1i
medium advisory

System Process Executables Created in Unusual Locations

The creation of executable files masquerading as legitimate Windows system processes in non-standard directories indicates potential malware installation or defense evasion tactics by threat actors.

Windows defense-evasion file-creation masquerading
3r 1t
medium advisory

Suspicious SolarWinds Child Process Execution

Detection of unusual child processes spawned by SolarWinds processes may indicate malicious program execution, potentially bypassing security controls.

Elastic Defend +3 supply-chain execution solarwinds
2r 2t
medium advisory

Suspicious SMB Connections via LOLBin or Untrusted Process

This rule identifies potentially suspicious processes, excluding those signed by Microsoft, making Server Message Block (SMB) network connections over port 445, which could indicate lateral movement attempts.

Elastic Defend lateral-movement smb windows
3r 1t
medium advisory

Suspicious Script Object Execution via scrobj.dll

Detection of scrobj.dll loaded into unusual Microsoft processes indicates potential malicious scriptlet execution for defense evasion and execution by abusing legitimate system binaries.

Elastic Defend +3 defense-evasion execution windows
2r 2t
medium advisory

Suspicious PowerShell Module DLL Creation

The creation of a DLL file within PowerShell module directories can indicate malicious PowerShell activity, such as installing new modules or attempts at ScriptBlock smuggling, and this activity is detected using Sysmon Event ID 11.

Splunk Enterprise +2 powershell module dll filecreation scriptblocksmuggling
2r 3t
medium advisory

Suspicious PDF Reader Child Process Execution

Adversaries may exploit vulnerabilities in PDF reader applications or use social engineering to execute malicious commands, often spawning system utilities for discovery or defense evasion purposes.

Adobe Acrobat Reader +3 exploitation pdf initial-access
3r 4t
medium advisory

Suspicious Network Connection via Registration Utility

The native Windows tools regsvr32.exe, regsvr64.exe, RegSvcs.exe, or RegAsm.exe making a network connection may indicate an attacker bypassing allowlists or running arbitrary scripts via a signed Microsoft binary.

Windows execution defense evasion regsvr32
2r 4t
medium advisory

Suspicious MS Office Child Process

Detects suspicious child processes of Microsoft Office applications, indicating potential exploitation or malicious macros for initial access, defense evasion, and execution.

Microsoft Office +4 initial-access defense-evasion execution discovery windows
2r 18t
medium advisory

Suspicious Mofcomp Activity Leading to WMI Abuse

Attackers may leverage the mofcomp.exe utility to compile malicious MOF files, enabling them to manipulate the Windows Management Instrumentation (WMI) repository for persistence or execution of arbitrary code.

Windows execution persistence wmi mofcomp
2r 3t
medium advisory

Suspicious Modifications to Windows Security Support Provider (SSP) Registry

Adversaries may modify the Windows Security Support Provider (SSP) configuration in the registry to establish persistence or evade defenses.

Microsoft Defender XDR +4 persistence defense-evasion registry-modification ssp
2r 2t
medium advisory

Suspicious Microsoft Workflow Compiler Usage

The use of Microsoft Workflow Compiler (microsoft.workflow.compiler.exe), a rarely utilized executable typically found in C:\Windows\Microsoft.NET\Framework64\v4.0.30319, can indicate malicious intent such as code execution or persistence mechanisms, potentially leading to unauthorized access.

Splunk Enterprise +2 living-off-the-land proxy-execution endpoint
2r 1t
medium advisory

Suspicious LSASS Process Access

This rule identifies suspicious access attempts to the LSASS process, potentially indicating credential dumping attempts by filtering out legitimate processes and access patterns to focus on anomalies.

Windows Defender +3 credential-access lsass windows
3r 1t
medium advisory

Suspicious HTML File Creation Leading to Potential Payload Delivery

This detection identifies the creation of HTML files with high entropy and large size, followed by execution via a browser process, indicating potential HTML smuggling and malicious payload delivery on Windows systems.

Elastic Defend html-smuggling phishing initial-access windows evasion
3r 3t
medium advisory

Suspicious Execution from VS Code Extension

Malicious VS Code extensions can execute arbitrary commands, leading to initial access and subsequent payload deployment on Windows systems.

VS Code initial-access execution supply-chain-compromise vscode
2r 9t
medium advisory

Suspicious Endpoint Security Parent Process Detected

This rule detects suspicious parent processes of endpoint security solutions such as Elastic Defend, Microsoft Defender, and SentinelOne, indicating potential process hollowing or code injection attempts to evade detection.

Elastic Defend +2 defense-evasion process-injection windows
2r 2t
medium advisory

Suspicious Dynamic .NET Compilation via Csc.exe

Attackers may use csc.exe to compile .NET code on the fly to evade detection, often placing the compiler and source code in suspicious locations, which can be detected by monitoring process creation events.

.NET Framework defense-evasion dynamic-compilation csc.exe
2r 1t
medium advisory

Suspicious DNS Queries to RMM Domains from Non-Browser Processes

Detection of DNS queries to remote monitoring and management (RMM) domains from non-browser processes indicating potential misuse of legitimate remote access tools for command and control.

Elastic Endpoint +1 command-and-control remote-access windows
2r
medium advisory

Suspicious Copy from or to System Directory

This threat involves the suspicious copying of files from or to Windows system directories (System32, SysWOW64, WinSxS) using command-line tools, often employed by attackers to relocate LOLBINs for defense evasion.

Windows defense-evasion lolbin
3r 1t
medium advisory

Suspicious AWS STS GetSessionToken Usage

The AWS STS GetSessionToken API is being misused to create temporary tokens for lateral movement and privilege escalation within AWS environments by potentially compromised IAM users.

AWS CloudTrail aws cloud lateral-movement privilege-escalation sts GetSessionToken
2r 2t
medium advisory

Suspicious AWS EC2 Key Pair Creation from Non-Cloud AS

An AWS EC2 CreateKeyPair event triggered by a new principal originating from a network autonomous system (AS) organization not associated with major cloud providers, indicating potential unauthorized access or persistence activity.

Amazon EC2 aws ec2 keypair persistence credential_access lateral_movement
2r 3t
medium advisory

Suspicious Access to Windows Product Key Registry

Detection of processes attempting to access the Windows registry to recover product keys, potentially indicating malware activity, unauthorized security bypass, or data exfiltration.

Windows registry product-key malware
2r 1t
medium advisory

Successful AWS IAM Group Deletion Detection

Successful deletion of an AWS IAM group, while not inherently malicious, can indicate insider threat activity, account compromise, or attempts to remove audit trails, and should be monitored.

IAM aws cloud deletion
2r 1t
medium advisory

Spike in AWS Security Hub Alerts for EC2 Instance

Detects a sudden increase in security alerts generated by AWS Security Hub related to a specific EC2 instance, potentially indicating active compromise or misconfiguration.

EC2 cloud aws securityhub alert-spike
2r 6t
medium advisory

SolarWinds Process Disabling Services via Registry Modification

A SolarWinds binary is modifying the start type of a service to be disabled via registry modification, potentially to disable or impair security services.

Microsoft Defender XDR +1 solarwinds defense-evasion registry-modification supply-chain
2r 3t
medium advisory

Signed Proxy Execution via MS Work Folders

Attackers can abuse Windows Work Folders to execute a masqueraded control.exe file from untrusted locations, potentially bypassing application controls for defense evasion and privilege escalation.

Windows Work Folders +3 defense-evasion masquerading windows
2r 3t
medium advisory

SharePoint Sensitive Term Discovery via O365 Logs

Adversaries may search for sensitive terms within SharePoint to identify valuable data for exfiltration or further compromise, leaving traces in O365 audit logs.

SharePoint +1 discovery sensitive-data o365
2r 1t
medium advisory

Service Startup Type Modification via WMIC

Adversaries use the Windows Management Instrumentation Command-line (WMIC) utility to modify the startup type of services, setting them to 'Manual' or 'Disabled' to impair defenses or disrupt system operations.

Windows attack.execution attack.t1047 attack.defense-evasion attack.t1562.001
2r 2t
medium advisory

SeDebugPrivilege Enabled by a Suspicious Process

The rule identifies a process running with a non-SYSTEM account that enables the SeDebugPrivilege privilege, which can be used by adversaries to debug and modify other processes to escalate privileges and bypass access controls.

Windows privilege-escalation token-manipulation
2r 1t
medium advisory

Schtasks Run Task On Demand

Detection of on-demand execution of Windows Scheduled Tasks via the schtasks.exe command-line utility, a common technique for persistence and lateral movement.

Splunk Enterprise +2 schtasks scheduled-task persistence execution
2r 1t
medium advisory

Scheduled Task Creation via Scripting

Detection of scheduled task creation by Windows scripting engines like cscript.exe, wscript.exe, or powershell.exe, used by adversaries to establish persistence on compromised systems.

Elastic Defend +1 persistence scheduled-task windows
3r 3t
medium advisory

Scheduled Task Creation via Group Policy Object

Detects the creation of scheduled tasks within a Group Policy Object (GPO) by monitoring for the creation of the ScheduledTasks.xml file in the SYSVOL share, potentially indicating malicious persistence.

Splunk Enterprise +3 scheduled-task gpo persistence windows
2r 2t
medium advisory

RMM Domain DNS Queries from Non-Browser Processes

Detects DNS queries to commonly abused remote monitoring and management (RMM) or remote access software domains from non-browser processes, potentially indicating unauthorized remote access or command and control activity.

Elastic Defend +9 command-and-control rmm dns
2r 75i
medium advisory

Right-to-Left Override (RTLO) Masquerading

Adversaries use the Right-to-Left Override (RTLO) character in filenames to disguise malicious files and trick users into executing them, leading to potential malware infection and system compromise.

Windows defense-evasion masquerading rtlo
3r 2t
medium advisory

Renamed Utility Executed with Short Program Name

This rule detects the execution of renamed utilities with a single-character process name, differing from the original filename, a common technique used by adversaries for staging, executing temporary utilities, or bypassing security detections.

Elastic Defend +1 defense-evasion masquerading windows
2r 1t
medium advisory

Remote Scheduled Task Creation via RPC

The creation of scheduled tasks from a remote source via RPC, where the RpcCallClientLocality and ClientProcessId are 0, indicates potential adversary lateral movement within a Windows environment.

Windows lateral-movement execution
2r 2t
medium advisory

Remote File Download via Desktopimgdownldr Utility

The desktopimgdownldr utility can be abused to download remote files, potentially bypassing standard download restrictions and acting as an alternative to certutil for malware or tool deployment.

Microsoft Defender XDR +1 command-and-control file-download windows desktopimgdownldr
3r 1t
medium advisory

Remote File Copy to a Hidden Share

This rule detects remote file copy attempts to hidden network shares, which may indicate lateral movement or data staging activity, by identifying suspicious file copy operations using command-line tools like cmd.exe and powershell.exe focused on hidden share patterns.

Elastic Defend +2 lateral-movement data-staging windows hidden-share
2r 3t
medium advisory

Registry Persistence via AppInit DLL Modification

Modification of the AppInit DLLs registry keys on Windows systems allows attackers to execute code in every process that loads user32.dll, establishing persistence and potentially escalating privileges.

Microsoft Windows +6 persistence defense-evasion appinit-dlls registry windows
2r 2t
medium advisory

Regasm.exe Making External Network Connection

The detection of regasm.exe, a Microsoft-signed binary, establishing a network connection to a public IP address (excluding private ranges) may indicate command and control activity or attempts to bypass application control.

Microsoft .NET Framework regasm application-control-bypass command-and-control lolbin
2r 2t
medium advisory

RDP Enabled via Registry Modification

An adversary may enable Remote Desktop Protocol (RDP) access by modifying the `fDenyTSConnections` registry key, potentially indicating lateral movement preparation or defense evasion.

Microsoft Defender XDR +1 lateral-movement defense-evasion rdp registry-modification
2r 2t
medium advisory

Process Created with a Duplicated Token

This rule identifies the creation of a process impersonating the token of another user logon session on Windows, potentially indicating privilege escalation.

Windows privilege-escalation token-impersonation
2r 2t
medium advisory

Privileged Account Brute Force Detection

Multiple consecutive logon failures targeting admin accounts from the same source IP address within a short timeframe indicates potential brute-force activity targeting privileged accounts on Windows systems.

Windows brute-force credential-access
2r 2t
medium advisory

PowerShell Script with Encryption/Decryption Capabilities

PowerShell scripts employing .NET cryptography APIs are used to encrypt data for impact or decrypt payloads for defense evasion.

Elastic Endpoint Security +1 powershell encryption defense-evasion windows
2r 3t
medium advisory

PowerShell Get-DomainPolicy Usage for Reconnaissance

Adversaries use the PowerShell `Get-DomainPolicy` commandlet to enumerate domain password policies for situational awareness and Active Directory discovery, logged via PowerShell Script Block Logging.

Active Directory +1 active-directory discovery powershell
2r 1t
medium advisory

Potential Windows Error Manager Masquerading

Adversaries may masquerade malicious processes as legitimate Windows Error Reporting processes (WerFault.exe or Wermgr.exe) to evade detection by establishing network connections without arguments, thus blending into normal system activity.

Windows Error Reporting defense-evasion masquerading windows
2r 1t
medium advisory

Potential Protocol Tunneling via Yuze

This brief describes the detection of Yuze, an open-source tunneling tool often executed via rundll32 to proxy C2 or pivot traffic within a compromised network.

Yuze tunneling command-and-control windows
2r 3t
medium advisory

Potential PowerShell Obfuscation via Special Character Overuse

This rule detects PowerShell scripts heavily obfuscated with whitespace and special characters, often used to evade static analysis and AMSI, by identifying scripts with low symbol diversity and a high proportion of whitespace and special characters.

powershell obfuscation defense-evasion windows
2r 3t
medium advisory

Potential Persistence via Time Provider Modification

The rule detects potential persistence via modification of the Time Provider in Windows by adversaries who register and enable a malicious DLL as a time provider, allowing for persistent code execution.

Windows persistence privilege-escalation
2r 2t
medium advisory

Potential Persistence via Mandatory User Profile Modification

Adversaries may abuse Windows mandatory profiles by dropping a malicious NTUSER.MAN file containing pre-populated persistence-related registry keys to establish persistence, which can evade traditional registry-based monitoring.

Elastic Defend persistence windows mandatory-profile file-modification
2r 2t
medium advisory

Potential Masquerading as Communication Apps

Attackers may attempt to evade defenses by masquerading malicious processes as legitimate communication applications such as Slack, WebEx, Teams, Discord, RocketChat, Mattermost, WhatsApp, Zoom, Outlook and Thunderbird.

Slack +9 defense-evasion masquerading windows
2r 3t
medium advisory

Potential LSA Authentication Package Abuse

Adversaries can abuse the Local Security Authority (LSA) authentication packages by modifying the Windows registry to achieve privilege escalation or persistence by executing binaries with SYSTEM privileges.

Microsoft Defender XDR +1 privilege-escalation persistence windows
2r 2t
medium advisory

Potential DNS Tunneling via NsLookup

Detection of multiple nslookup.exe executions with explicit query types from a single host, potentially indicating command and control activity via DNS tunneling, where attackers abuse DNS for data infiltration or exfiltration.

M365 Defender +2 dns-tunneling command-and-control windows
2r 2t
medium advisory

Potential DLL Side-Loading via Trusted Microsoft Programs

This rule detects potential DLL side-loading attempts by identifying trusted Microsoft programs (WinWord.exe, EXPLORER.EXE, w3wp.exe, DISM.EXE) running from non-standard paths or after being renamed to evade defenses.

Microsoft Word +2 defense-evasion execution windows dll side-loading
2r 2t
medium advisory

Potential Defense Evasion via WSL Child Processes

Adversaries may attempt to evade detection by executing malicious commands or scripts through child processes spawned from the Windows Subsystem for Linux (WSL), potentially bypassing traditional Windows-based security monitoring.

Windows wsl defense-evasion child-process
2r 2t
medium advisory

Potential Cloudflared Network Tunnel Detection

This brief detects network connection events associated with the Cloudflared tool, used to create tunnels via Cloudflare, potentially for unauthorized access or exfiltration, by establishing outbound connections to Cloudflare Edge Servers.

Cloudflared +3 reverse-proxy tunneling network-tunnel
2r 1t
medium advisory

Potential Adobe Hijack Persistence Mechanism

This brief outlines a potential persistence mechanism involving hijacking Adobe-related processes or components, which could allow attackers to maintain unauthorized access to a system.

Adobe Acrobat Reader +1 persistence process-injection adobe
2r 1t
medium advisory

PhpSpreadsheet CPU Denial of Service via Unbounded Row Number

A vulnerability in PhpSpreadsheet exists where a crafted XLSX file containing a large row number can cause excessive CPU consumption due to unbounded loop iterations, leading to a denial of service.

PhpSpreadsheet denial-of-service xlsx php
2r 1t
medium advisory

phpMyFAQ Unauthenticated FAQ Permission Bypass via Solution ID Enumeration

phpMyFAQ version 4.1.1 and earlier is vulnerable to an unauthenticated FAQ permission bypass, allowing attackers to enumerate solution IDs and discover restricted FAQ titles due to missing permission filters in key functions.

phpmyfaq unauthenticated access information disclosure web server
2r 1t
medium advisory

Persistence via Visual Studio Tools for Office (VSTO) Add-ins

The Visual Studio Tools for Office (VSTO) add-ins can be abused by attackers to establish persistence in Microsoft Office applications by modifying registry keys.

Microsoft Office +1 persistence office vsto
2r 1t
medium advisory

OpenEMR Stored XSS Vulnerability in CCDA Document Preview (CVE-2026-33932)

A stored cross-site scripting (XSS) vulnerability in OpenEMR's CCDA document preview (CVE-2026-33932) allows an attacker to execute arbitrary JavaScript in a clinician's browser session by uploading a malicious CCDA document.

OpenEMR xss cve-2026-33932 health-records
2r 1t
medium advisory

OpenEMR Authentication Brute Force Vulnerability (CVE-2023-54347)

OpenEMR version 7.0.1 is vulnerable to an authentication brute force attack where attackers can bypass rate limiting by sending repeated login attempts, leading to potential unauthorized access.

OpenEMR 7.0.1 authentication brute-force openemr
2r 1t 1c
medium advisory

OneDrive Share Mounted via Net Utility for Potential Data Exfiltration

Adversaries may mount OneDrive shares as network drives using net.exe or net1.exe to stage, access, or exfiltrate data through cloud-hosted WebDAV paths, potentially bypassing traditional file share monitoring.

OneDrive +3 data-exfiltration net.exe
2r 1t
medium advisory

Ollama API Endpoint Scan Reconnaissance

Detects potential reconnaissance activity against Ollama servers by identifying sources probing multiple API endpoints within short timeframes, indicative of attackers mapping the API surface for vulnerabilities.

Ollama api-reconnaissance web-application
1r 1t
medium advisory

Okta Unauthorized Application Access Attempt

This brief describes a detection for unauthorized application access attempts within an Okta environment, indicating a potential security breach or misconfiguration.

Okta attack.impact threat-type platform
3r
medium advisory

Okta Unauthorized Access to Application

Anomalous activity indicating a user is attempting to access Okta applications they have not been assigned, potentially leading to data exposure or service disruption.

Okta Identity Cloud okta unauthorized-access identity
2r 2t
medium advisory

Okta Successful Single Factor Authentication Attempt

Successful single-factor authentication events against the Okta Dashboard for accounts without Multi-Factor Authentication (MFA) enabled, potentially indicating account takeover attempts.

Okta Identity Cloud okta single-factor authentication account takeover
2r 3t 2i
medium advisory

Okta MFA Reset or Deactivation Attempt

An attacker attempts to disable or reset multi-factor authentication (MFA) for a user account in Okta, potentially leading to unauthorized access and account compromise.

Okta Identity Cloud okta mfa credential-access persistence
2r 1t
medium advisory

Okta Group Privilege Change Spike via ML Detection

A machine learning job has identified an unusual spike in Okta group privilege change events, indicating potential privileged access activity where attackers might be elevating privileges by adding themselves or compromised accounts to high-privilege groups, enabling further access or persistence.

Okta privilege-escalation machine-learning
2r 4t
medium advisory

Okta Authentication Failed During MFA Challenge

Detection of failed authentication attempts during Okta MFA challenges, potentially indicating compromised credentials and attempts to bypass MFA.

Okta Identity Cloud okta mfa authentication account-takeover
2r 3t
medium advisory

Okta Application Sign-On Policy Modified or Deleted

Attackers may modify or delete Okta application sign-on policies to weaken security controls, potentially leading to unauthorized access and data breaches.

Okta identity policy-tampering
2r 1t
medium advisory

Okta Application Modified or Deleted

Detects when an Okta application is modified or deleted, potentially indicating unauthorized changes or removal of critical applications.

Okta application-security identity-management
2r 1t
medium advisory

Okta API Token Revoked

Detection of Okta API token revocation events, indicating potential unauthorized access or compromise.

Okta api token revocation identity
2r 1t
medium advisory

Okta API Token Creation

Detection of Okta API token creation events which can indicate malicious persistence activity.

Okta Identity Cloud persistence okta
2r 1t
medium advisory

Office Application Autorun Registry Key Modification

Adversaries modify Office application autostart extensibility point (ASEP) registry keys to achieve persistence and execute malicious code when Office applications are launched.

Microsoft Office attack.privilege-escalation attack.persistence attack.t1547.001
2r 1t
medium advisory

Office 365 MFA Notification Email Deletion for Defense Evasion

Attackers may delete multi-factor authentication (MFA) notification emails in Office 365 to evade detection and maintain unauthorized access after compromising an account.

Office 365 o365 mfa defense_evasion email
2r 1t
medium advisory

O365 Email Access By Security Administrator

Atypical access to O365 mailboxes is detected when a security administrator uses Threat Explorer features to directly view email, potentially indicating reconnaissance or data exfiltration by a compromised or malicious insider.

Office 365 cloud o365 data exfiltration azure ad
2r 2t
medium advisory

O365 Data Loss Prevention Rule Triggered

Detection of triggered Microsoft Office 365 Data Loss Prevention (DLP) rules, which can indicate potential data exfiltration or policy violations, dependent on upstream DLP configuration.

Office 365 Data Loss Prevention data-exfiltration o365 dlp
2r 2t
medium advisory

O365 Compliance Content Search Activity Detected

Detection of content search initiation within the Office 365 Security and Compliance Center using the SearchCreated operation, which may signal unauthorized access to sensitive organizational data such as emails and documents, potentially leading to data exfiltration and compliance breaches.

Microsoft 365 +1 o365 compliance content search data exfiltration
2r 1t
medium threat

O365 Application Registration Owner Added

A new owner added to an O365 application registration can grant significant control, potentially leading to unauthorized data access, privilege escalation, or malicious behavior.

Azure Active Directory +1 NOBELIUM Group azuread o365 persistence
3r 1t
medium advisory

O365 Advanced Audit Disabled

The O365 Advanced Audit feature provides critical logging and insights into user and administrator activities, and this analytic detects instances where it is disabled for a specific user, potentially blinding security teams to malicious actions.

Microsoft 365 +1 o365 audit defense-evasion persistence
2r 1t
medium advisory

NullSessionPipe Registry Modification for Lateral Movement

Attackers modify the NullSessionPipe registry setting in Windows to enable anonymous access to named pipes, potentially facilitating lateral movement and unauthorized access to network resources.

M365 Defender +3 lateral-movement defense-evasion registry-modification
3r 2t
medium advisory

Notepad++ Updater Querying Uncommon Domains

The Notepad++ updater, gup.exe, makes DNS queries to domains not part of the legitimate update infrastructure, potentially indicating updater mechanism exploitation or suspicious network activity.

Notepad++ supply-chain dns
2r 2t
medium advisory

New ActiveSync Allowed Device Added via PowerShell

The rule detects the use of the Exchange PowerShell cmdlet, Set-CASMailbox, to add a new ActiveSync allowed device, potentially allowing attackers to gain persistent access to sensitive email data by adding unauthorized devices.

Microsoft Defender XDR +4 exchange activesync powershell persistence
2r 3t
medium advisory

Network Logon Provider Registry Modification

Adversaries may modify the network logon provider registry to register a rogue network logon provider module for persistence and credential access by intercepting authentication credentials in clear text during user logon.

Defender XDR +3 credential-access persistence registry-modification
2r 2t
medium advisory

Netty HTTP/3 QPACK Literal Unbounded Allocation Vulnerability

A vulnerability in Netty's HTTP/3 QPACK decoder allows an attacker to cause a denial of service by sending a crafted HTTP/3 header that triggers excessive memory allocation, leading to a server crash.

netty-codec-http3 netty http3 qpack denial-of-service vulnerability
3r 1t
medium threat

Mustang Panda USB-Borne Tool Execution

This brief details detection of executables associated with Mustang Panda being launched from non-standard locations, potentially indicating compromise via USB or other removable media.

Splunk Enterprise +2 Mustang Panda mustang-panda usb-attack dll-sideloading
2r 3t
medium advisory

Multiple Remote Management Tool Vendors on Same Host

This rule identifies Windows hosts where two or more distinct remote monitoring and management (RMM) or remote-access tool vendors are observed starting processes within the same eight-minute window, potentially indicating compromise, shadow IT, or attacker staging of redundant access.

AeroAdmin +60 remote-access-tool command-and-control rmm windows
2r
medium threat

MSSQL xp_cmdshell Stored Procedure Abuse for Persistence

Attackers may leverage the xp_cmdshell stored procedure in Microsoft SQL Server to execute arbitrary commands for privilege escalation and persistence, often bypassing default security configurations.

SQL Server persistence sql-server xp_cmdshell windows
2r 2t
medium advisory

Mshta Making Network Connections Indicative of Defense Evasion

Mshta.exe making outbound network connections may indicate adversarial activity, as it is often used to execute malicious scripts and evade detection by proxying execution of untrusted code.

Amazon Assistant +3 defense-evasion system-binary-proxy-execution windows
2r 1t
medium advisory

Mozilla Firefox and Thunderbird Improper Boundary Condition Vulnerability (CVE-2026-4699)

CVE-2026-4699 describes an improper check for unusual or exceptional conditions in the Layout: Text and Fonts component of Mozilla Firefox and Thunderbird leading to a potential denial-of-service.

Firefox +1 cve-2026-4699 thunderbird denial-of-service
2r 1t
medium advisory

Microsoft Defender Tampering via Registry Modification

Adversaries may disable or tamper with Microsoft Defender features via registry modifications to evade detection and conceal malicious behavior on Windows systems.

Microsoft Defender XDR +4 defense-evasion registry-modification windows
2r 2t
medium advisory

Microsoft Defender 'Block at First Seen' Feature Disabled

An attacker disables the Microsoft Defender 'Block at First Seen' feature to allow potentially malicious files to execute without initial scrutiny, increasing the risk of malware infection and data compromise.

Microsoft Defender defender malware block-at-first-seen registry powershell
2r 1t
medium advisory

Microsoft CVE-2017-3736 Vulnerability

CVE-2017-3736 is a vulnerability tracked by Microsoft, potentially leading to exploitation of affected systems.

vulnerability microsoft
2r
medium advisory

Microsoft Build Engine Executed After Renaming

Attackers may rename the Microsoft Build Engine (MSBuild) executable to evade detection and proxy execution of malicious code.

MSBuild defense-evasion execution masquerading
2r 2t
medium advisory

Microsoft 365 Suspicious Email Delivery

This brief outlines a threat where Microsoft Defender for Office 365 identifies an email as malicious or suspicious but still delivers it to a user's inbox or junk folder, potentially bypassing initial security measures.

Microsoft 365 suspicious-email phishing microsoft365
2r 2t
medium advisory

Microsoft 365 SharePoint Site Administrator Added

Detection of a new SharePoint Site Administrator added in Microsoft 365, which adversaries may leverage after compromising a privileged account to maintain persistent, high-privilege access, as seen in the 0mega ransomware campaign.

Microsoft 365 +1 privilege-escalation persistence cloud
2r 2t
medium advisory

Microsoft 365 Risk-Based Step-Up Consent Disabled

The Microsoft 365 'risk-based step-up consent' security setting is disabled by an adversary to allow users to grant consent to malicious applications, potentially leading to unauthorized access and data breaches.

Splunk Enterprise +4 azuread o365 oauth risk-based consent defense-evasion
2r 1t
medium advisory

Mass Azure Compute Snapshot Deletion

The rule detects mass deletion of Azure disk snapshots, which could indicate an adversary attempting to inhibit system recovery capabilities, destroy backup evidence, or prepare for a ransomware attack.

Azure snapshot data-destruction impact
2r 2t
medium advisory

macOS QuickLook Thumbnail Cache Leak

macOS QuickLook caches thumbnails and file paths of files, even those stored within encrypted containers or on removable USB devices, potentially revealing sensitive data to attackers with access to the running system.

macOS quicklook cache thumbnail privacy
2r 1t
medium advisory

macOS Kernel-to-Userland Process Creation Notification via undocumented kev_msg_post

The kev_msg_post function can be abused by malware to broadcast process creation notifications from a kernel extension (kext) to a user-mode application, potentially bypassing security tools that rely on standard APIs and leading to undetected malicious activity.

BlockBlock kernel-extension kev_msg_post macos process-monitoring
2r
medium advisory

M365 SharePoint/OneDrive File Access via PowerShell

Detects file downloads and access from OneDrive or SharePoint using PowerShell-based user agents, which adversaries leverage with compromised OAuth tokens to exfiltrate data.

Microsoft 365 +2 cloud saas microsoft365 sharepoint onedrive powershell
2r 4t
medium advisory

M365 Identity OAuth Illicit Consent Grant by Rare Client and User

Adversaries may register a malicious application in Microsoft Entra ID and trick users into granting excessive permissions via OAuth consent, allowing the malicious application to access resources in Microsoft 365 on behalf of the user, potentially leading to data exfiltration.

Microsoft 365 +2 o365 oauth consent-grant phishing initial-access
2r 3t
medium advisory

M365 Exchange Inbox Forwarding Rule Creation

Detection of new Microsoft 365 Exchange inbox forwarding rules indicating potential unauthorized email interception and exfiltration by attackers.

Exchange Online +1 o365 exchange inbox-rule email-forwarding data-exfiltration
2r 1t
medium advisory

M365 Copilot Application Usage Pattern Anomalies

This detection identifies anomalous M365 Copilot usage patterns indicative of potential account compromise or automated abuse by flagging users accessing Copilot from multiple locations, generating excessive daily activity, or utilizing multiple Copilot applications.

Microsoft 365 Copilot m365 copilot anomaly detection account compromise
2r 1t
medium advisory

M365 Copilot Access from Non-Compliant Devices

Detects Microsoft 365 (M365) Copilot access from non-compliant or unmanaged devices, potentially indicating shadow IT, BYOD policy violations, or compromised endpoints accessing sensitive data.

M365 Copilot +1 m365 copilot device-compliance byod shadow-it
2r 1t
medium advisory

LSASS Process Access via Windows API

Detects suspicious access to the LSASS process via Windows API calls, potentially indicating credential dumping and subsequent lateral movement.

Windows credential-access lsass process-access
2r 1t
medium advisory

LSA PPL Protection Setting Modification via CommandLine

Attackers modify LSA PPL protection settings via command-line tools like reg.exe and PowerShell to weaken system security and enable credential dumping.

Windows defense-evasion credential-access
2r 1t
medium advisory

Linux System Network Discovery via Multiple Utilities

Adversaries may attempt to enumerate local network configurations on Linux systems using common utilities like arp, ifconfig, ip, netstat, firewall-cmd, ufw, iptables, ss, and route to gather information for reconnaissance and subsequent attacks, leading to network mapping and vulnerability identification.

Linux network-discovery reconnaissance
2r 1t
medium advisory

Linux Auditd Daemon Abort Detection

Detection of abnormal Linux audit daemon (auditd) termination via DAEMON_ABORT events, indicating potential auditing subsystem failure due to resource exhaustion, corruption, or malicious interference.

Splunk Enterprise +3 auditd linux anomaly endpoint
2r 1t
medium advisory

LatePoint WordPress Plugin Stored XSS Vulnerability

The LatePoint WordPress plugin is vulnerable to stored XSS via the booking_form_page_url parameter, allowing unauthenticated attackers to inject arbitrary web scripts in pages that execute when a user accesses the injected page.

LatePoint – Calendar Booking Plugin for Appointments and Events plugin <= 5.5.0 wordpress xss stored-xss cve-2026-7332 plugin
2r 1c
medium advisory

Kubernetes Nginx Ingress Remote File Inclusion Attempt

This analytic detects remote file inclusion (RFI) attacks targeting Kubernetes Nginx ingress controllers by analyzing Kubernetes logs from the Nginx ingress controller and identifying suspicious URL requests, potentially leading to arbitrary code execution or sensitive data access.

Nginx Ingress Controller +1 kubernetes nginx rfi remote file inclusion cloud
2r 1t
medium advisory

Kubernetes Forbidden Request from Unusual User Agent

Detection of forbidden requests originating from unusual user agents within a Kubernetes environment, potentially indicating adversary attempts to exploit vulnerabilities or evade detection by using non-standard user agents to interact with the Kubernetes API.

Kubernetes threat-detection execution
2r 1t
medium advisory

Kubernetes DaemonSet Deployment Detected

The creation of a Kubernetes DaemonSet is detected via Kubernetes Audit logs, indicating a potential attempt to maintain persistent access and control within the cluster by ensuring a specific pod runs on every node.

Kubernetes +1 daemonset persistence
2r 1t 2i
medium advisory

Kiteworks Secure Data Forms Stored XSS Vulnerability (CVE-2026-24750)

An authenticated attacker can exploit a stored XSS vulnerability (CVE-2026-24750) in Kiteworks Secure Data Forms before version 9.2.1 due to improper neutralization of input, leading to arbitrary script execution in the context of other users.

Kiteworks Secure Data Forms xss web-application kiteworks
2r 1t 1i
medium advisory

Keras Model Loader Vulnerable to Denial-of-Service via Malicious HDF5 Shape Bombs

Keras model loader is vulnerable to denial-of-service by loading specially crafted .keras files containing HDF5-based weight files with maliciously oversized dataset metadata, leading to immediate memory exhaustion during model loading.

Keras +2 denial-of-service hdf5 model-loading shape-bomb
2r 1t 1c 1i
medium advisory

Katalyst Koi Session Cookies Replayable After Logout

Katalyst Koi versions before 4.20.0 and between 5.0.0 and 5.6.0 fail to invalidate admin session cookies upon logout, allowing attackers with a valid cookie to maintain unauthorized access.

katalyst-koi +2 session-replay vulnerability authentication
2r 1t
medium advisory

IOBit Unlocker Extension DLL Registration via Regsvr32

The IOBit Unlocker Extension DLL is being registered via regsvr32.exe, a Windows utility used to unlock files or folders by terminating locking processes, which could be abused for malicious purposes.

Unlocker Extension +3 iobit unlocker regsvr32 dll windows threat-detection
2r 1t
medium advisory

Incoming Execution via WinRM Remote Shell

This rule detects incoming execution via Windows Remote Management (WinRM) remote shell on a target host, which could be an indication of lateral movement by monitoring network traffic on ports 5985 or 5986 and processes initiated by WinRM.

Elastic Defend +1 lateral-movement windows winrm remote-execution
2r 1t
medium advisory

i18next-http-middleware HTTP Response Splitting and DoS Vulnerability

i18next-http-middleware versions before 3.9.3 are vulnerable to HTTP response splitting and denial-of-service attacks due to unsanitized Content-Language headers, potentially leading to session fixation, cache poisoning, reflected XSS, or complete service disruption depending on the Node.js version.

i18next-http-middleware crlf-injection http-response-splitting denial-of-service i18next
2r 1t
medium advisory

Host File System Changes via Windows Subsystem for Linux

This rule detects file creation and modification on the host system from the Windows Subsystem for Linux (WSL), potentially indicating defense evasion by adversaries.

Elastic Defend +2 defense-evasion windows wsl
2r 2t
medium advisory

Hickory DNS NSEC3 Validation Vulnerability Leads to DoS

A vulnerability in Hickory DNS's NSEC3 closest-encloser proof validation allows a remote attacker to cause a denial of service by exhausting memory when processing crafted DNS responses with mismatched SOA records.

hickory-proto +1 denial-of-service dnssec memory-exhaustion
2r 1t
medium advisory

GSuite Suspicious File Share with Phishing Filenames

This analytic detects suspicious file sharing activity in Google Workspace where files are shared with names commonly associated with phishing campaigns, such as 'invoice,' 'shipment,' or 'delivery', potentially leading to credential theft or malware infection.

Google Workspace +1 phishing gsuite google_workspace
2r 1t
medium advisory

GSuite Email with Suspicious Attachment

This analytic detects GSuite emails with suspicious file attachments (e.g., .exe, .bat, .js) which may indicate a spear-phishing attack leading to malware deployment and potential system compromise.

GSuite +1 spear-phishing malicious-attachment
2r 1t
medium advisory

GSuite Email with Known Abuse Web Service Links

This analytic detects emails in Gsuite containing links to known abuse web services such as Pastebin, Telegram, and Discord, commonly used by attackers to deliver malicious payloads leading to malware, phishing, or other harmful activities.

GSuite +1 phishing malware pastebin telegram discord
2r 1t 2i
medium advisory

Gravity Forms Plugin Unauthenticated Stored XSS Vulnerability

The Gravity Forms plugin for WordPress is vulnerable to unauthenticated stored cross-site scripting (XSS) in versions up to 2.10.0, allowing attackers to inject arbitrary JavaScript code into the product name field within repeater fields, which executes when an administrator views the affected entry.

Gravity Forms plugin <= 2.10.0 xss wordpress gravityforms
2r 1t 1c
medium advisory

GPO Scheduled Task or Service Creation/Modification

Detection of the creation or modification of new Group Policy based scheduled tasks or services, which can be abused by attackers with domain admin permissions to execute malicious payloads remotely on domain-joined machines, leading to privilege escalation and persistence.

Elastic Defend +2 group-policy privilege-escalation persistence windows
2r 3t
medium advisory

GPO Scheduled Task Abuse for Privilege Escalation and Lateral Movement

Attackers abuse Group Policy Objects by modifying scheduled task attributes to execute malicious commands across objects controlled by the GPO, potentially leading to privilege escalation and lateral movement.

Active Directory +1 group-policy scheduled-task privilege-escalation lateral-movement
2r 3t
medium advisory

GPO Modification to Add Startup/Logon Scripts

This rule detects the modification of Group Policy Objects (GPO) to add a startup or logon script to user or computer objects, enabling attackers to achieve privilege escalation and persistence by executing arbitrary commands at scale.

Active Directory +1 group-policy privilege-escalation persistence windows
2r 3t
medium advisory

Gotenberg Denial of Service via Context Pool Reuse

Gotenberg versions 8.31.0 and earlier are vulnerable to an unauthenticated denial-of-service attack where a race condition in the webhook middleware causes a panic and process termination when handling concurrent requests.

Gotenberg denial-of-service vulnerability
2r 2t
medium advisory

GoBGP Remote Denial of Service via Malformed BGP UPDATE Message

A remote Denial of Service (DoS) vulnerability exists in GoBGP version 4.2.0 and earlier, where a malformed BGP UPDATE message can trigger a runtime error (index out of range panic), crashing the GoBGP process. This occurs during the processing of 4-byte AS attributes when the message structure causes an internal slice index shift that is not properly handled. A single malicious peer or a malformed route propagated through a transit provider can consistently crash the BGP daemon, leading to a complete loss of routing capabilities.

GoBGP denial of service bgp network
2r 1t
medium advisory

GitHub Repository Archived in Organization

This analytic detects the archival of a repository within a GitHub Organization, potentially indicating malicious activity such as attempts to make code inaccessible, insider threats, or account compromise.

GitHub cloud repository archival
2r 2t
medium advisory

GitHub Owner Role Granted to User

Detection of a member being granted the organization owner role in GitHub, potentially indicating unauthorized privilege escalation and persistence by an attacker.

GitHub persistence privilege-escalation
2r 2t
medium advisory

GitHub Organizations 2FA Disabled

The disabling of two-factor authentication (2FA) in GitHub Organizations is detected through audit log monitoring, potentially indicating an attacker's attempt to weaken account security and facilitate unauthorized access.

github.com +3 github 2fa security_controls supply_chain
3r 3t
medium advisory

GitHub Enterprise Self-Hosted Runner Registration

A self-hosted runner was created in GitHub Enterprise, which could be exploited by attackers to execute malicious code, access sensitive data, or pivot to other systems.

github.com github supply_chain self_hosted_runner
2r 1t
medium advisory

GitHub Enterprise Audit Log Streaming Disabled

An attacker disables audit log event streaming in GitHub Enterprise to evade detection by preventing security monitoring platforms from receiving audit events.

github.com github audit-logging defense-evasion
2r 1t
medium advisory

GitHub Classic Branch Protection Rule Disabled

This analytic detects when classic branch protection rules are disabled in GitHub Organizations, potentially allowing malicious actors to bypass code review and security controls.

github.com +4 github branch-protection supply-chain
2r 2t
medium advisory

GCP Storage Bucket Configuration Modification

This rule detects modifications to Google Cloud Platform (GCP) storage bucket configurations, potentially indicating an adversary attempting to weaken security controls for unauthorized access or data exfiltration.

Google Cloud Storage cloud gcp defense_evasion
2r 1t
medium advisory

GCP Service Account Deletion

Detection of Google Cloud Platform (GCP) service account deletion, which adversaries may perform to disrupt business operations.

Google Cloud Platform gcp iam impact
2r 1t
medium advisory

GCP Authentication Failure During MFA Challenge

Detection of failed MFA challenges in Google Cloud Platform (GCP) using Google Workspace login failure events, potentially indicating credential compromise and unauthorized access attempts.

Google Cloud Platform +1 gcp cloud mfa credential-access
2r 2t 1i
medium advisory

FortiGate SSL VPN Login Followed by SIEM Alert

Detects FortiGate SSL VPN logins followed by a SIEM detection alert for the same user within a short timeframe, potentially indicating VPN abuse, credential compromise, or initial access followed by post-compromise activity.

FortiGate SSL VPN fortinet vpn initial-access credential-access
2r 1t
medium advisory

Forbidden Direct Interactive Kubernetes API Request

This rule detects forbidden direct interactive Kubernetes API requests by correlating interactive command execution inside a container with explicitly forbidden Kubernetes API requests, indicating potential enumeration and privilege testing for lateral movement.

Kubernetes container execution discovery
3r 3t
medium threat

Flax Typhoon Masquerading SoftEther VPN as Legitimate Windows Binaries

The Flax Typhoon group uses SoftEther VPN, masquerading the VPN client as legitimate Windows binaries like conhost.exe and dllhost.exe, to obfuscate their network activity within compromised Taiwanese organizations.

SoftEther VPN +3 Flax Typhoon +1 flax-typhoon defense-evasion lateral-movement vpn process-masquerading
2r 2t
medium advisory

First Time Seen Driver Loaded

The rule identifies the load of previously unseen drivers, which may indicate attackers exploiting vulnerable drivers for privilege escalation and persistence.

Elastic Defend privilege-escalation persistence windows
2r 3t
medium advisory

Execution via Windows Subsystem for Linux

This detection identifies attempts to execute programs from the Windows Subsystem for Linux (WSL) to evade detection by flagging suspicious executions initiated by WSL processes and excluding known safe executables.

Microsoft Defender XDR +3 defense-evasion execution windows wsl
2r 2t
medium advisory

Execution via Local SxS Shared Module

This rule detects the creation, modification, or deletion of DLL files within Windows SxS local folders, which could indicate an attempt to execute malicious payloads by abusing shared module loading.

M365 Defender +4 execution defense-evasion dll-hijacking
2r 2t
medium advisory

Exchange Mailbox Export via PowerShell

Adversaries may use the New-MailboxExportRequest PowerShell cmdlet to export mailboxes in Exchange, potentially leading to sensitive information theft.

Microsoft Defender XDR +2 collection execution powershell exchange mailbox
2r 4t
medium advisory

Excessive Usage of SC Service Utility

Detection of anomalous usage of sc.exe, often abused by ransomware and malware to manipulate services for privilege escalation or disabling security measures.

Windows Observed in multiple ransomware families +1 endpoint sc.exe service_control privilege_escalation defense_evasion ransomware
2r 3t
medium advisory

ESXi SSH Enabled Detection

The enabling of SSH on ESXi hosts, as detected in ESXi Syslog, can signal malicious lateral movement by threat actors aiming for persistent access.

ESXi ssh lateral-movement
2r 1t
medium advisory

ESXi Shell Enabled Detection

The ESXi Shell being enabled on a host may indicate malicious activity like preparing to execute commands locally or establishing persistent access.

ESXi vmware shell-access lateral-movement
2r 1t
medium advisory

ESXi Download Error Detection

Detection of failed file download attempts on ESXi hosts, potentially indicating unauthorized or malicious activity such as installing or updating components, including VIBs or scripts.

ESXi +3 vmware syslog anomaly T1601.001 T1685 ESXi Post Compromise Black Basta Ransomware Infrastructure +1
2r 2t
medium advisory

Enumeration of Privileged Local Groups Membership

An unusual process is enumerating built-in Windows privileged local groups membership, such as Administrators or Remote Desktop users, potentially revealing targets for credential compromise and post-exploitation activities.

Windows discovery privileged-access
2r 1t
medium advisory

Entra ID Sharepoint or OneDrive Accessed by Unusual Client

An application accessing SharePoint Online or OneDrive for Business for the first time in a tenant could indicate OAuth phishing, illicit consent grants, or compromised third-party apps accessing file storage.

Entra ID +2 azure sharepoint onedrive oauth phishing illicit-consent
2r 4t
medium advisory

Entra ID Service Principal Credentials Created by Unusual User

Anomalous addition of credentials to an Entra ID service principal by a user not typically performing this action can indicate potential persistence and privilege escalation by an attacker.

Entra ID +1 azure entra_id service_principal persistence privilege_escalation
2r 2t
medium advisory

Entra ID Privileged Identity Management (PIM) Role Modified

Attackers may modify Entra ID Privileged Identity Management (PIM) roles to persist in the environment and weaken security controls, potentially leading to privilege escalation and unauthorized access.

Entra ID Privileged Identity Management azure persistence privileged-identity-management
2r 3t
medium advisory

Entra ID OAuth User Impersonation Scope for Unusual User and Client

Adversaries may abuse the user_impersonation OAuth scope in Entra ID to gain unauthorized access to user accounts, especially when combined with single-factor authentication and unbound sign-in sessions, potentially indicating account compromise for users not seen in the last 10 days.

Entra ID azure oauth user_impersonation initial_access defense_evasion
2r 3t
medium advisory

Entra ID OAuth Authorization Code Grant for Unusual User, App, and Resource

Detects the first-time use of an OAuth 2.0 authorization code grant flow for a specific combination of user, application, and resource in Microsoft Entra ID, potentially indicating OAuth phishing attacks like ConsentFix, where attackers steal authorization codes.

Microsoft Entra ID +2 entra-id oauth phishing initial-access
2r 3t
medium advisory

Entra ID External Authentication Methods (EAM) Modified

Modification of Entra ID external authentication methods (EAM) via the Microsoft Graph API can allow attackers to bypass multi-factor authentication (MFA) and establish persistence or gain unauthorized access via bring-your-own IdP (BYOIDP) methods.

Entra ID azure entra-id persistence authentication
2r 2t
medium advisory

Encoded Executable Stored in the Registry

This rule detects registry write modifications hiding encoded portable executables, indicative of adversary defense evasion by avoiding storing malicious content directly on disk.

Elastic Defend +3 defense-evasion registry windows
2r 3t 1i
medium advisory

DivvyDrive Open Redirect Vulnerability

DivvyDrive versions 4.8.2.9 before 4.8.3.2 are vulnerable to an open redirect vulnerability due to allowing Parameter Injection, potentially leading to phishing attacks.

DivvyDrive open-redirect parameter-injection phishing
2r 1t 1c
medium advisory

Detection of WMI Temporary Event Subscription Creation

Detection of WMI temporary event subscriptions via Windows Event Logs can identify potential attacker command execution, information gathering, or persistence attempts.

Windows wmi persistence execution
2r 2t
medium advisory

Detection of Windows RMM Tool Execution

Detects process creation events indicative of remote management tools, potentially signifying legitimate use or malicious exploitation by threat actors abusing RMM software.

AnyDesk +28 rmm remote-access sysmon
3r 1t
medium advisory

Detection of Suspicious CrowdStrike Agent Registry Key Removal

This detection identifies delete events on CrowdStrike registry keys, which typically occur during agent uninstallation, so any unplanned or unexpected removal of these keys should be investigated for malicious activity such as defense evasion or exploits like CVE-2022-44721.

CrowdStrike Falcon Agent defense-evasion registry-modification endpoint
2r 1t 1c
medium advisory

Detection of PuTTY Suite Utility Execution

This analytic detects the execution of programs associated with the PuTTY SSH client suite, including putty.exe, pscp.exe, plink.exe, psftp.exe, and puttygen.exe, which can be used to establish unauthorized remote connections, transfer files, or execute commands on remote systems potentially leading to network compromise.

Splunk Enterprise +2 putty lateral-movement command-and-control windows
3r 2t
medium advisory

Detection of Privileged Account Creation in Azure

Detects the creation of new privileged accounts in Azure environments, potentially indicating initial access, persistence, privilege escalation, or stealth activities by malicious actors.

Azure privileged-account initial-access persistence privilege-escalation
2r 3t
medium advisory

Detection of Out-of-Domain Email Forwarding in Google Workspace

Detects automatic email forwarding to external domains in Google Workspace, which may indicate data leakage or misuse by malicious insiders or compromised accounts.

Google Workspace data-leakage gworkspace email-forwarding
2r 1t
medium advisory

Detection of Okta Administrator Role Assignment to User or Group

Detects the assignment of an Okta administrator role to a user or group, potentially indicating privilege escalation or persistence attempts by malicious actors.

Okta privilege-escalation persistence
2r 1t
medium advisory

Detection of Obfuscated IP Addresses via Command Line Tools

The use of command-line tools like ping.exe or arp.exe with obfuscated IP addresses (hex, octal, etc.) in the command line can indicate reconnaissance activity or attempts to evade security controls by masking the true destination.

Windows reconnaissance evasion command-line
3r 1t
medium advisory

Detection of Failed ESXi File Downloads

This detection identifies failed file download attempts on ESXi hosts by looking for specific error messages in system logs, potentially indicating unauthorized attempts to install malicious components or scripts.

ESXi vmware download-error anomaly black-basta
2r 2t
medium advisory

Detection of Azure Storage Utility Execution via Command Line Interface

Adversaries may leverage Azure Storage utilities like AzCopy and Storage Explorer post-compromise to stage or extract sensitive data from endpoints, blending malicious activity with legitimate cloud traffic.

AzCopy.exe +1 data-exfiltration azure-storage cli windows
2r 1t
medium advisory

Detection of Abnormally Large DNS Responses Indicative of CVE-2020-1350 Exploitation

This rule detects abnormally large DNS responses indicative of exploitation attempts targeting a known overflow vulnerability (CVE-2020-1350) in Windows DNS servers, potentially leading to Remote Code Execution (RCE) or Denial of Service (DoS).

Windows DNS Server sigred dns-server vulnerability
2r 2t
medium advisory

Detecting WMIC Systeminfo Discovery Activity

This brief covers detection of adversaries using Windows Management Instrumentation Command-line (WMIC) to gather system information, specifically the `computersystem` class, a technique used for reconnaissance.

Windows wmic discovery
2r 1t
medium advisory

Detecting Spikes in Active Directory Object Modifications

This detection identifies a spike in Active Directory group or object modifications, potentially indicating unauthorized access, defense impairment, or persistence establishment by threat actors.

Splunk Enterprise +2 active-directory persistence privilege-escalation windows
2r 1t
medium advisory

Detecting Persistence via Parsing macOS Login Item Files

This brief details a method for parsing macOS login item files to detect persistence mechanisms employed by malware or threat actors.

persistence macos
2r 1t
medium advisory

Detect Windows Netspy Network Scanner Execution

The Netspy network scanner, a tool for internal network discovery, is executed on a Windows endpoint to enumerate active hosts and services, potentially for reconnaissance purposes.

Splunk Enterprise +2 network-discovery windows endpoint
2r 2t
medium advisory

Detect Suspicious WMI Event Subscription Creation for Persistence

This threat brief details the detection of malicious Windows Management Instrumentation (WMI) event subscriptions, a technique used by attackers for persistence and privilege escalation on Windows systems.

Elastic Defend persistence wmi windows event-subscription
2r 1t
medium advisory

Detect AWS Access Key Creation

This brief outlines how to detect the creation of AWS Access Keys, a common tactic used by attackers to establish persistence and escalate privileges within compromised AWS environments.

Amazon Web Services cloud aws iam accesskey persistence
2r 1t
medium advisory

Denial of Service Vulnerability in marked via Infinite Recursion

A denial of service vulnerability exists in marked version 18.0.0 due to infinite recursion when processing a specific 3-byte sequence (tab, vertical tab, and newline), leading to unbounded memory allocation and application crash.

marked denial-of-service javascript vulnerability
2r 1t
medium advisory

CVE-2026-28390 NULL Dereference in CMS KeyTransportRecipientInfo Processing

CVE-2026-28390 is a vulnerability related to a possible NULL pointer dereference when processing CMS KeyTransportRecipientInfo, potentially leading to a denial-of-service condition.

vulnerability denial-of-service
2r 1c
medium advisory

CVE-2019-1547 ECDSA Remote Timing Attack Vulnerability

CVE-2019-1547 is a security vulnerability that could allow a remote timing attack.

cve-2019-1547 timing-attack ecdsa
2r
medium advisory

Command Prompt Network Connection Activity

Detection of command prompt activity initiating network connections can indicate suspicious or malicious behavior, potentially leading to command and control or data exfiltration.

Microsoft Windows command-prompt network-connection execution
2r 2t
medium advisory

Command Execution via ForFiles Utility for Defense Evasion

Adversaries are leveraging the Windows `forfiles` utility to proxy command execution, potentially bypassing security controls by using a trusted process, for defense evasion.

Windows defense-evasion indirect-command-execution
2r 1t
medium advisory

Command Execution via ForFiles Utility

Adversaries may use the Windows forfiles utility to proxy command execution via a trusted parent process, potentially evading detection.

Microsoft Defender XDR +2 defense-evasion indirect-execution windows
2r 1t
medium advisory

Code Signing Policy Modification Through Registry

Attackers modify the Windows Registry to disable code signing enforcement, allowing the execution of unsigned or self-signed malicious code.

Windows defense-evasion registry-modification code-signing
2r 2t
medium advisory

Cloudflare Tunnel (cloudflared) Abuse for Protocol Tunneling

Adversaries are abusing Cloudflare Tunnel (cloudflared) to create outbound tunnels and proxy command and control traffic, or exfiltrate data, evading direct connection blocking by routing traffic through Cloudflare's edge.

Cloudflare Tunnel command-and-control protocol-tunneling windows
3r 2t 1i
medium advisory

Cloud Provisioning Activity From Previously Unseen Region

This analytic detects cloud provisioning activities originating from previously unseen regions by identifying resource creation events and cross-referencing them with a baseline of known regions, potentially indicating unauthorized access or misuse of cloud resources.

AWS cloud provisioning anomaly
2r 1t
medium advisory

Cloud Provisioning Activity From Previously Unseen IP Address

This analytic detects cloud provisioning activities originating from previously unseen IP addresses by leveraging cloud infrastructure logs to identify events where resources are created or started, and cross-references these with a baseline of known IP addresses.

AWS cloud cloudtrail anomaly-detection
2r 1t
medium advisory

Cloud Provisioning Activity From Previously Unseen City

The analytic detects cloud provisioning activities originating from previously unseen cities based on source IP geolocation compared to a learned baseline, which may indicate unauthorized access or misuse of cloud resources leading to resource creation, data exfiltration, or further compromise.

AWS +3 cloud anomaly-detection
2r 1t
medium advisory

Cisco Duo Admin Login from Unusual Browser

Detects Cisco Duo admin logins from browsers other than Chrome, potentially indicating compromised credentials, session hijacking, or unauthorized device usage.

Cisco Duo cisco-duo credential-access anomaly-detection
2r 1t
medium advisory

Cisco ASA User Account Lockout Detection

Detection of user account lockouts on Cisco ASA devices due to excessive failed authentication attempts, potentially indicating brute-force attacks, password spraying, or credential stuffing.

Cisco ASA authentication brute_force password_spraying cisco_asa
2r 2t
medium advisory

Cisco ASA Reconnaissance Command Activity

This analytic detects potential reconnaissance on Cisco ASA devices by identifying execution of multiple information-gathering 'show' commands within a short timeframe, indicating potential enumeration by an attacker.

Cisco ASA cisco reconnaissance network
2r 3t
medium advisory

Cisco ASA Logging Message Suppression

Adversaries may suppress specific log message IDs on Cisco ASA devices using the 'no logging message' command to selectively disable logging of security-critical events and evade detection.

Cisco ASA cisco-asa logging defense-evasion network
2r 2t
medium advisory

Cisco ASA Logging Filters Configuration Tampering

Tampering with logging filter configurations on Cisco ASA devices can allow attackers to evade detection by reducing logging levels or disabling specific log categories.

ASA +3 cisco logging evasion
2r 1t
medium advisory

CircleCI Security Step Disabled

An attacker disables security steps within CircleCI to potentially bypass security controls and introduce malicious code into the build pipeline.

CircleCI ci/cd security-bypass supply-chain
2r 1t
medium advisory

Chmod Activity Targeting Sensitive Linux Directories

Attackers may use chmod to modify file permissions within sensitive Linux directories such as /tmp/, /etc/, and /opt/ to maintain persistence, escalate privileges, or disrupt system operations.

defense-evasion privilege-escalation persistence linux
2r 1t
medium advisory

ChatGPTNextWeb NextChat Improper Authorization Vulnerability (CVE-2026-7644)

CVE-2026-7644 is an improper authorization vulnerability in the addMcpServer function of ChatGPTNextWeb NextChat version 2.16.1 and earlier, allowing for potential remote exploitation following public disclosure of the exploit.

NextChat authorization cve-2026-7644 web-application
1r 1t 1c
medium advisory

changedetection.io Arbitrary Local File Read via Crafted Backup Restore

changedetection.io is vulnerable to arbitrary local file read due to insufficient validation of snapshot paths restored from backup files, allowing attackers to read sensitive files by crafting a malicious backup archive containing a manipulated `history.txt` file.

changedetection.io arbitrary-file-read vulnerability
2r 1t
medium advisory

Certreq HTTP POST Abuse for File Transfer

Adversaries may abuse the Windows Certreq utility to download files or upload data to a remote URL by making an HTTP POST request, potentially for command and control, defense evasion, or exfiltration.

Windows lolbin certreq command-and-control defense-evasion exfiltration
2r 4t
medium advisory

blueprintUE Password Reset Token Vulnerability (CVE-2026-40585)

blueprintUE versions before 4.2.0 generate password reset tokens that remain valid indefinitely due to the absence of a timestamp validation, allowing attackers to potentially gain unauthorized access via token reuse.

blueprintUE cve-2026-40585 password-reset
2r 1t 1c
medium advisory

BITS Job Notify Command Persistence

Adversaries can abuse the Background Intelligent Transfer Service (BITS) SetNotifyCmdLine method to execute arbitrary commands for persistence by configuring a BITS job to execute a program after a transfer completes or enters a specific state.

Windows persistence bits
2r 1t
medium advisory

Azure Storage Account Blob Public Access Enabled

Detection of Azure Storage Account Blob public access being enabled, potentially allowing external access to blob containers for data exfiltration, as abused by threat actors modifying storage account settings.

Azure Storage Account azure storage data_exfiltration cloud_security
2r 1t
medium advisory

Azure Owner Removed from Application or Service Principal

An adversary may remove an owner from an Azure application or service principal to weaken access controls, persist in the environment, or escalate privileges.

Azure attack.stealth
2r 1t
medium advisory

Azure Kubernetes Services (AKS) Kubernetes Events Deleted

Adversaries may delete Kubernetes events in Azure Kubernetes Services (AKS) to evade detection by removing logs of state changes, container creations, image pulls, and pod scheduling.

Azure Kubernetes Service azure kubernetes defense-evasion
2r 2t
medium advisory

Azure Key Vault Unusual Secret Key Usage

Detects unusual secret, key, or certificate retrieval operations from Azure Key Vault by a user principal that has not been seen previously, potentially indicating unauthorized access attempts.

Azure Key Vault azure keyvault credential-access
2r 1t
medium advisory

Azure Event Hub Authorization Rule Created or Updated

Creation or modification of Azure Event Hub authorization rules can indicate unauthorized access or privilege escalation by adversaries using cryptographic keys to manage access to event hubs.

Azure Event Hub cloud azure persistence account-manipulation
2r 2t
medium advisory

Azure Compute Restore Point Collection Deleted by Unusual User

The deletion of Azure Restore Point Collections, which contain recovery points for virtual machines, by a user who has not previously performed this activity, indicates a potential attempt to prevent recovery during ransomware attacks or cover tracks during malicious operations.

Azure Compute cloud azure impact
2r 1t
medium advisory

Azure AD User Consent Blocked for Risky Application

Azure AD blocked a user's attempt to grant consent to a risky application, indicating potential OAuth abuse and requiring investigation of the user and application involved.

Azure Active Directory azuread oauth consent-phishing cloud
2r 1t
medium advisory

Azure AD User Added to Administrator Role

An adversary adds a user to an Azure Active Directory administrative role to gain initial access, persist in the environment, escalate privileges, and potentially operate stealthily.

Azure Active Directory attack.initial-access attack.persistence attack.privilege-escalation attack.stealth attack.t1098.003 attack.t1078
2r 4t
medium advisory

Azure AD Successful Single-Factor Authentication

Successful single-factor authentication events against Azure Active Directory are identified using Azure SignInLogs data, which may indicate misconfiguration, policy violation, or potential account takeover leading to data breaches and privilege escalation.

Azure Active Directory azuread single-factor authentication account takeover
2r 2t
medium advisory

Azure AD Risk-Based Consent Disabled

The analytic detects when the risk-based step-up consent security setting in Azure AD is disabled by monitoring Azure Active Directory logs for the 'Update authorization policy' operation and changes to the 'AllowUserConsentForRiskyApps' setting, potentially exposing organizations to OAuth phishing attacks.

Azure Active Directory azure oauth consent phishing
2r 1t
medium advisory

Azure AD MFA Disabled to Bypass Authentication

An adversary may disable multi-factor authentication (MFA) in Azure Active Directory to weaken an organization's security posture and bypass authentication mechanisms, potentially gaining unauthorized access to sensitive resources and maintaining persistence.

Azure Active Directory azure mfa credential-access persistence defense-impairment
2r 1t
medium advisory

AzuraCast Account Takeover via X-Forwarded-Host Poisoning

AzuraCast is vulnerable to password reset poisoning due to unconditionally trusting the X-Forwarded-Host header, allowing an attacker to inject a malicious host into the password reset URL, exfiltrate the reset token, reset the victim's password, and disable 2FA, leading to account takeover.

azuracast +2 account takeover x-forwarded-host password reset poisoning
2r 3t 2i
medium advisory

AWS User Performing S3 Encryption with KMS Keys

A user with KMS keys is performing encryption operations on S3 buckets, potentially masking exfiltration or tampering efforts by encrypting sensitive data to evade detection or preparing it for exfiltration.

S3 +1 aws encryption ransomware
2r 1t
medium advisory

AWS STS AssumeRole Misuse for Lateral Movement and Privilege Escalation

Abuse of AWS STS AssumeRole can allow attackers to move laterally within an AWS environment and escalate privileges, potentially leading to unauthorized access to sensitive resources and data.

AWS STS attack.lateral-movement attack.privilege-escalation attack.t1548 attack.t1550 attack.t1550.001
1r 2t
medium advisory

AWS SQS Queue Purge Detection

Detection of AWS Simple Queue Service (SQS) queue purging, which adversaries may leverage to disrupt application workflows, destroy operational data, or impair monitoring and alerting systems by removing critical evidence of malicious activity.

Simple Queue Service cloud aws sqs defense-evasion impact
2r 2t
medium advisory

AWS SNS Topic Message Publish by Rare User

This rule identifies when an SNS topic message is published by a rare user in AWS, which may indicate lateral movement, data exfiltration, or phishing campaigns, potentially leading to resource hijacking and impact on cloud services.

Amazon Simple Notification Service aws sns lateral-movement exfiltration impact
2r 4t
medium advisory

AWS RDS DB Instance or Cluster Deleted

An adversary with sufficient permissions may delete RDS resources such as DB instances or clusters to impede recovery, destroy evidence, or inflict operational impact on the environment.

Amazon RDS +1 cloud aws rds datadestruction
2r 1t
medium advisory

AWS Network ACL Deletion Detection

Detection of AWS Network Access Control List (ACL) deletion via CloudTrail logs, potentially indicating malicious attempts to bypass network security controls and gain unauthorized access.

AWS cloudtrail network acl defense-evasion
2r 1t
medium advisory

AWS Login Profile Creation Activity

Monitoring AWS login profile creation events can help identify potentially malicious user or role creation activities within an AWS environment.

AWS Identity and Access Management aws iam cloud privilege-escalation
2r 2t
medium advisory

AWS IAM Virtual MFA Device Registration Attempt with Session Token

An adversary with compromised temporary AWS credentials attempts to establish persistence by creating or enabling a virtual MFA device, bypassing expected session token usage.

IAM cloud aws persistence
2r 3t
medium advisory

AWS IAM Session Token Used From Multiple Addresses

Compromised AWS IAM session tokens are used from multiple IP addresses, networks, cities, and user agents within a short timeframe, indicating potential credential theft and abuse.

IAM aws cloudtrail credential-theft initial-access
2r 1t
medium advisory

AWS IAM Principal Enumeration via UpdateAssumeRolePolicy

Detects repeated failed attempts to update an IAM role's trust policy in an AWS account, consistent with role and user enumeration techniques, potentially indicating attacker-controlled infrastructure or offensive tooling.

AWS IAM aws iam enumeration discovery credential-access
2r 3t
medium advisory

AWS IAM Policy Deletion Detection

Detection of AWS IAM policy deletion events, which could indicate malicious activity by a compromised account or insider threat.

AWS IAM aws iam policy cloudtrail
2r 1t
medium advisory

AWS IAM MFA Device Deactivation

Detection of AWS IAM MFA device deactivation via the `DeactivateMFADevice` API call, which could indicate an attempt to weaken account protections for privilege escalation or persistence.

AWS Identity and Access Management aws iam mfa deactivation cloudtrail
2r 3t
medium advisory

AWS IAM Default Policy Version Modification

An adversary modifies the default version of an AWS IAM policy, potentially downgrading security or disrupting access control.

AWS Identity and Access Management aws iam policy
2r 1t
medium advisory

AWS IAM Customer Managed Policy Version Manipulation for Privilege Escalation

Successful creation of new or setting default versions of customer-managed IAM policies can indicate privilege escalation attempts by attackers modifying policy permissions.

Amazon Web Services privilege-escalation aws iam
2r 2t
medium advisory

AWS IAM AccessDenied Discovery Events

Detection of excessive AccessDenied events within an hour for AWS IAM users, indicating a potential compromised access key used for unauthorized discovery actions.

AWS IAM aws cloudtrail iam accessdenied discovery
2r 1t
medium advisory

AWS Excessive Security Scanning Detection

Detection of excessive AWS API calls indicative of reconnaissance by an attacker attempting to map an AWS environment.

AWS cloudtrail reconnaissance
2r 1t
medium advisory

AWS EFS File System Deletion Detected

An adversary with sufficient permissions deletes an Amazon EFS file system using the 'DeleteFileSystem' API operation to destroy evidence, disrupt workloads, or impede recovery efforts.

Elastic File System aws efs data-destruction impact
2r 1t
medium advisory

AWS ECR Container Upload Anomaly Outside Business Hours

This detection identifies uploads of new containers to AWS Elastic Container Registry (ECR) outside of standard business hours, potentially indicating unauthorized access or malicious deployments.

AWS +1 cloud ecr anomaly
2r 1t
medium advisory

AWS ECR Container Scanning Reveals Medium Severity Vulnerabilities

AWS Elastic Container Registry (ECR) image scans reveal medium-severity vulnerabilities, potentially leading to unauthorized access and data breaches if exploited within containerized applications.

Elastic Container Registry cloud aws ecr container vulnerability
2r 1t 1c
medium advisory

AWS Console Login from New City

A user logging into the AWS console from a previously unseen city could indicate compromised credentials or an insider threat.

AWS Management Console cloud aws credential-access
2r 1t
medium advisory

AWS Console Login Failed During MFA Challenge

Detection of failed AWS console login attempts despite successful MFA usage, indicating potential account compromise attempts.

AWS Management Console +1 aws cloud authentication mfa account-takeover
2r 2t
medium advisory

AWS Console Login by User from New Country

This detection identifies AWS console logins by a user originating from a country not previously associated with that user, potentially indicating account compromise.

AWS Management Console +1 aws cloud identity account-compromise
2r 1t
medium advisory

AWS Console Login by New User

Detects first-time AWS console login, which can indicate compromised credentials or malicious account creation.

AWS cloud initial_access
2r 1t
medium advisory

AWS CloudWatch Log Stream Deletion

Detection of Amazon CloudWatch log stream deletion via the 'DeleteLogStream' API, potentially indicating defense evasion or impact by adversaries aiming to conceal activity and disrupt security monitoring.

CloudWatch Logs aws cloudwatch log-deletion defense-evasion
2r 3t
medium advisory

AWS CloudWatch Alarm Deletion for Defense Evasion

Successful deletion of Amazon CloudWatch alarms via the `DeleteAlarms` API, potentially indicating an adversary attempting to impair visibility, silence alerts, and evade detection after malicious activity within an AWS environment.

CloudWatch defense-evasion aws
2r 2t
medium advisory

AWS Bedrock Invoke Model Access Denied Attempt

Detection of AccessDenied errors when attempting to invoke AWS Bedrock models via the InvokeModel API indicates potential reconnaissance or privilege escalation attempts by an adversary with compromised credentials.

AWS Bedrock aws bedrock access-denied privilege-escalation
2r 2t
medium advisory

AppArmor Profile Compilation via apparmor_parser

Adversaries may abuse `apparmor_parser` to compile custom AppArmor profiles, potentially weakening security controls and facilitating privilege escalation on Linux systems.

AppArmor defense-evasion linux
2r 1t
medium advisory

Active Directory Group Policy Deletion Detected

Detection of Active Directory Group Policy deletion using event ID 5136, indicating potential malicious activity or misconfiguration.

Splunk Enterprise +2 active-directory group-policy gpo deletion t1484.001
2r 2t
medium advisory

Account Configured with Never-Expiring Password

Detects the creation and modification of an account with the 'Don't Expire Password' option enabled, which attackers can abuse to persist in the domain and maintain long-term access.

Active Directory persistence windows account-manipulation
2r 1t
medium advisory

Abnormally High Number of Cloud Infrastructure API Calls

Detection of an abnormally high number of cloud infrastructure API calls, indicating potential malicious activity or misconfiguration in a cloud environment.

Amazon S3 +1 cloud api-abuse anomaly-detection
2r 2t
medium advisory

Windows Universal Data Link File Creation Detection

The creation of Universal Data Link (UDL) files on Windows systems can indicate a phishing technique where attackers bypass email filters and capture user credentials by tricking victims into testing a connection to a malicious server.

Splunk Enterprise +2 phishing credential-theft windows
2r 2t
medium advisory

Windows Port Forwarding Rule Addition via Registry Modification

This alert detects the creation of a new port forwarding rule in the Windows Registry, a technique used by attackers to bypass network segmentation and establish internal proxies for command and control or lateral movement.

Windows port-forwarding registry-modification lateral-movement
2r 3t
medium advisory

Unusual Parent-Child Relationship Detection

This rule identifies Windows programs run from unexpected parent processes, which could indicate masquerading or other strange activity on a system, potentially indicating process injection, masquerading, access token manipulation, or parent PID spoofing.

Microsoft Defender XDR +1 privilege-escalation defense-evasion windows process-injection masquerading access-token-manipulation parent-pid-spoofing
3r 4t
medium advisory

Unusual Microsoft Graph Email Access via OAuth Application

An adversary might use a phished OAuth refresh token or Primary Refresh Token (PRT) with a first-party application to access email resources via Microsoft Graph API, particularly focusing on unusual application and user combinations.

Microsoft Graph API +2 azure graphapi oauth email
2r 2t
medium advisory

Suspicious Process Execution via Renamed PsExec Executable

Detects suspicious PsExec activity where the PsExec service component is executed using a custom name, indicating an attempt to evade detections that look for the default PsExec service component name.

Elastic Defend +2 psexec lateral-movement execution defense-evasion windows
2r 3t
medium advisory

Suspicious Process Creation Followed by Memory Access from Unknown Region

The rule identifies suspicious process creation where a process is created and immediately accessed from an unknown memory code region by the same parent process, indicating a potential code injection attempt, specifically process hollowing, commonly targeting processes spawned by Microsoft Office applications, scripting engines, and command-line tools for defense evasion.

Office +2 defense-evasion process-injection windows
2r 1t
medium advisory

Suspicious Outbound Scheduled Task Activity via PowerShell

This rule detects PowerShell loading the Task Scheduler COM DLL followed by an outbound RPC network connection, potentially indicating lateral movement or remote discovery via scheduled tasks.

Windows execution lateral-movement
2r 3t
medium advisory

Spike in Active Directory User Modification Activity

Detects an increase in modifications to AD user objects, which may indicate unauthorized access, impaired defenses, or persistence establishment.

Splunk Enterprise +2 account-manipulation persistence windows
2r 1t
medium advisory

Remote File Copy via TeamViewer

Attackers may abuse legitimate utilities such as TeamViewer to deploy malware interactively by remotely copying executable or script files during a TeamViewer session.

Elastic Defend +2 command-and-control remote-access teamviewer
2r 2t
medium advisory

Potential Persistence via Time Provider Modification

Adversaries may establish persistence by registering and enabling a malicious DLL as a time provider by modifying registry keys associated with the W32Time service.

Windows +1 persistence privilege-escalation time-provider
2r 2t
medium advisory

Potential Application Shimming via Sdbinst

Attackers abuse the Application Shim functionality in Windows by using `sdbinst.exe` with malicious arguments to achieve persistence and execute arbitrary code within legitimate Windows processes.

Windows +1 persistence privilege-escalation application-shimming
2r 2t
medium advisory

Persistence via LSA Security Support Provider Registry Modification

Adversaries may establish persistence by modifying the Windows Security Support Provider (SSP) configuration in the registry, allowing malicious code to load during system startup.

Windows persistence registry
2r 2t
medium advisory

MpCmdRun.exe Used for Remote File Download

Attackers are abusing the Windows Defender MpCmdRun.exe utility to download remote files, potentially delivering malware or offensive tools into compromised systems.

Windows Defender command-and-control ingress-tool-transfer windows mpcmdrun
2r 1t
medium advisory

LSASS Loading Suspicious DLL

Detection of LSASS loading an unsigned or untrusted DLL, which can indicate credential access attempts by malicious actors targeting sensitive information stored in the LSASS process.

Windows credential-access lsass dll-injection
2r 2t 9i
medium advisory

Linux Stdout Redirection to /dev/null Indicates Potential Malware Activity

The redirection of standard output to /dev/null on Linux systems, particularly when observed in conjunction with other suspicious activities, can indicate attempts to hide malicious command execution, as seen in malware like Cyclops Blink, potentially leading to unauthorized system modifications and persistent access.

Splunk Enterprise +2 linux malware cyclopsblink anomaly endpoint
2r
medium advisory

Kubernetes Scanning by Unauthenticated IP Address

Detects potential scanning activities within a Kubernetes environment by identifying multiple unauthorized access attempts (HTTP 403 responses) from unauthenticated IP addresses in Kubernetes audit logs, potentially indicating vulnerability probing or exploitation attempts.

Kubernetes scanning cloud
2r 1t
medium advisory

Gravity Forms Plugin Unauthenticated Stored XSS Vulnerability

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting (XSS) in versions up to and including 2.10.0, allowing unauthenticated attackers to inject arbitrary web scripts via form submissions that execute when an administrator views the entry detail page.

Gravity Forms plugin xss wordpress gravityforms
2r 1c
medium advisory

Entra ID Application Credential Modification

An adversary may add unauthorized credentials to an Azure application, enabling persistent access, evading defenses, and escalating privileges by modifying certificates or secrets.

Azure +1 persistence entra_id account_manipulation
3r 2t
medium advisory

Detecting Remote Scheduled Task Creation for Lateral Movement

This rule identifies remote scheduled task creations on a target Windows host, potentially indicating lateral movement by adversaries, by monitoring network connections and registry modifications related to task scheduling.

Elastic Defend +2 lateral-movement execution windows scheduled-task
2r 2t
medium advisory

Cisco ASA User Account Deletion

Detection of user account deletion on Cisco ASA devices, potentially indicating adversary attempts to cover tracks, disrupt incident response, or deny administrator access.

Cisco ASA cisco_asa account_deletion defense_evasion
2r 2t
medium advisory

Azure AD User Consent Denied for OAuth Application

This analytic identifies instances where a user has denied consent to an OAuth application seeking permissions within the Azure AD environment, potentially indicating malicious OAuth application activity.

Azure AD azure oauth consent-phishing credential-access
2r 1t
medium threat

Azure AD External Guest User Invitation

Detection of an external guest user invitation in Azure AD through monitoring Azure AD AuditLogs, which, if malicious, can lead to unauthorized access, data breaches, or further exploitation by abusing external identities.

exploited Azure Active Directory azuread cloud persistence
2r 1t
medium advisory

AWS Suspicious User Agent Detected in CloudTrail

Successful AWS API calls with CloudTrail user agents indicating offensive tooling (Kali Linux) or credential verification (TruffleHog) can indicate compromised credentials or unauthorized access.

AWS cloudtrail initial-access credential-access
2r 2t
medium advisory

macOS File Monitoring via Endpoint Security Framework

Objective-See details how to create a file monitor for macOS 10.15 using Apple's Endpoint Security Framework to capture file I/O events and process information.

macOS +6 file-monitoring endpoint-security
2r 1t
medium advisory

Suspicious SUID Binary Execution Sequence on Linux

This rule detects suspicious sequences where a non-root user launches a high-risk parent process and then executes a common privilege elevation helper gaining an effective UID of 0 while the real UID remains non-root, potentially indicating misuse of SUID/SGID helpers or privilege escalation attempts.

auditbeat-* +1 privilege-escalation linux suid
2r 2t
medium advisory

Entra ID User Sign-in with Unusual Authentication Type

Detects rare authentication requirements for Azure Entra ID principal users, potentially indicating an adversary attempting to bypass conditional access policies and MFA using stolen credentials.

Azure Entra ID azure entra_id initial_access credential_access
2r 4t
medium advisory

Remote File Download via Script Interpreter

The rule identifies built-in Windows script interpreters, specifically cscript.exe or wscript.exe, being used to download an executable file from a remote destination, often employed by attackers for initial access or to deploy secondary payloads.

Windows command_and_control execution
2r 2t
medium advisory

Account Password Reset Remotely

The rule detects attempts to reset potentially privileged account passwords remotely, a tactic used by adversaries to maintain access, evade password policies, and preserve compromised credentials.

Windows persistence impact
2r 2t
medium advisory

Unusual Process For a Windows Host via Machine Learning

This rule detects rare processes running on Windows hosts, potentially indicating unauthorized services, malware, or persistence mechanisms by using machine learning to identify processes that run infrequently compared to other processes on the same host.

Windows persistence execution
2r 2t
medium advisory

Startup Folder Persistence by Suspicious Processes

This rule identifies files written to or modified in the startup folder by commonly abused processes on Windows systems, a technique adversaries use to maintain persistence by automatically executing malicious programs upon user login or system startup.

Windows +2 persistence startup-folder
2r 1t
medium advisory

Remote File Download via Desktopimgdownldr Utility

The rule detects the use of desktopimgdownldr.exe to download remote files, which is an abuse of a signed utility often used as an alternative to certutil for transferring malicious tools or malware into a compromised environment.

Windows command-and-control ingress-tool-transfer
2r 1t
medium advisory

Persistence via PowerShell Profile Modification

Attackers can establish persistence by creating or modifying PowerShell profiles to execute malicious code each time PowerShell is launched, customizing the user environment.

PowerShell persistence windows
2r 2t
medium advisory

High Number of AWS Bedrock List Foundation Model Failures

Detection of a high number of AccessDenied errors when attempting to list AWS Bedrock foundation models, indicating potential reconnaissance activity after credential compromise to discover accessible AI models.

Bedrock aws reconnaissance cloudtrail
2r 1t
medium advisory

GCP IAM Custom Role Creation

Detection of Identity and Access Management (IAM) custom role creation in Google Cloud Platform (GCP), which can indicate potential privilege escalation or persistence by adversaries creating roles with excessive permissions.

Google Cloud Platform gcp iam custom-role initial-access persistence privilege-escalation
3r 3t
medium threat

Exchange PowerShell Used to Add New ActiveSync Allowed Device

An adversary may use the Exchange PowerShell cmdlet, Set-CASMailbox, to add a new ActiveSync allowed device, potentially gaining persistent access to a user's email and sensitive information.

exploited Microsoft Exchange Server exchange powershell activesync persistence
2r 3t
medium advisory

Azure Storage Account Data Exfiltration via AzCopy and SAS Token Abuse

Successful GetBlob operations on Azure Storage Accounts using the AzCopy user agent with SAS token authentication can indicate data exfiltration by adversaries abusing compromised SAS tokens.

Azure Storage azure exfiltration cloud-storage azcopy
2r 2t
medium advisory

Azure AD Failed Authentication Increase

Detects a significant increase (10% or greater) in failed Azure AD sign-in attempts, potentially indicating brute-force attacks, credential stuffing, or other unauthorized access attempts.

Azure Active Directory azuread brute-force credential-stuffing authentication
2r 1t
medium advisory

Suspicious dMSA Service Account Creation Attempting BadSuccessor Abuse

The creation of a delegated managed service account (dMSA) in specific Active Directory organizational units (OUs) via PowerShell, especially when the initiating user lacks proper permissions, indicates a potential attempt to exploit the BadSuccessor privilege escalation vulnerability in Windows Server 2025 environments.

Active Directory +1 attack.privilege-escalation attack.initial-access attack.defense-evasion attack.persistence attack.t1078.002 attack.t1098
2r 4t
medium advisory

Detection of New User AWS Console Login

A new AWS user logging into the console could indicate malicious activity, such as an attacker creating a new identity for persistence or lateral movement within the AWS environment.

Amazon Web Services cloud aws iam initial_access
2r 2t
medium advisory

AWS Root Account Usage Detected

The AWS root account, which grants unrestricted access to all resources within an AWS account, was used, potentially indicating unauthorized activity, privilege escalation, or a breach of security best practices.

AWS CloudTrail cloud aws privilege-escalation initial-access persistence stealth
3r 3t
medium advisory

AWS EC2 Instance Export for Potential Exfiltration

An attacker with compromised AWS credentials or EC2 instance access can leverage EC2 export functionalities (CreateInstanceExportTask, ExportImage, or CreateStoreImageTask) to exfiltrate sensitive data by exporting EC2 instances or their images to external storage.

EC2 +2 aws exfiltration cloudtrail
2r 5t
medium advisory

AWS S3 Bucket Deletion Detected via CloudTrail

An AWS S3 bucket deletion event was detected via CloudTrail logs, potentially indicating data loss or unauthorized access attempts.

S3 cloud aws data_loss
3r 1t
medium advisory

Linux Sensitive File Compression for Credential Access

Attackers may use compression utilities like zip, tar, and gzip on Linux systems to collect and archive sensitive files containing credentials and system configurations for credential access and data exfiltration.

Elastic Defend +2 credential-access collection linux
2r 3t
medium advisory

Windows Script Execution from Archive File

This rule detects attempts to execute Jscript/Vbscript files from archive files, a common method for delivering malicious scripts by identifying unusual parent-child process relationships where scripting utilities are launched from archive programs, indicating potential exploitation.

Windows Script Host +2 execution archive scripting windows
2r 3t
medium advisory

Execution via Compiled HTML File

Adversaries may abuse compiled HTML files (.chm) to execute malicious code by proxying execution via hh.exe, often leading to command execution via scripting interpreters.

HTML Help system compiled-html execution defense-evasion windows
2r 6t
medium advisory

SMB (Windows File Sharing) Activity to the Internet

This rule detects network events indicating the use of Windows file sharing (SMB or CIFS) traffic to the Internet, which is commonly exploited for initial access, backdoor deployment, or data exfiltration.

initial-access exfiltration network
2r 2t
medium advisory

MikroTik RouterOS SCEP Endpoint Out-of-Bounds Read Vulnerability (CVE-2026-7668)

MikroTik RouterOS 6.49.8 is vulnerable to an out-of-bounds read in the SCEP endpoint component, triggered by remote manipulation of the transactionID/messageType argument, potentially leading to denial of service or information disclosure.

RouterOS cve out-of-bounds read
2r 1t 1c
medium advisory

Windows WMI Reconnaissance Activity Detection

Detection of Windows Management Instrumentation Command-line (WMIC) usage for reconnaissance by querying common Win32 WMI classes for system information, potentially indicating post-exploitation activity.

Windows wmic reconnaissance post-exploitation
2r 1t
medium advisory

Windows Temporarily Scheduled Task Creation and Deletion

Detection of rapid creation and deletion of scheduled tasks on Windows, indicating potential malicious activity abusing the task scheduler for execution and cleanup.

Windows persistence execution
2r 2t
medium advisory

Windows Script Host Executing PowerShell

Detects PowerShell execution initiated by cscript.exe or wscript.exe, commonly used by attackers for initial access or payload delivery.

Windows Script Host +1 initial-access powershell windows scripting
2r 4t
medium advisory

Windows Sandbox Abuse for Defense Evasion

The execution of Windows Sandbox processes with sensitive configurations (write access to the host file system, network connection, automatic execution via logon command) is identified, as malware may abuse this sandbox feature to evade detection.

Windows Sandbox defense-evasion windows-sandbox windows
3r 1t
medium advisory

Windows Registry Modification to Disable Run Application

The following analytic detects modification of the Windows registry to disable the Run application in the Start menu by monitoring changes to the registry path '*\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun' with a value of '0x00000001', potentially hindering system cleaning and aiding malware persistence.

Splunk Enterprise +2 defense-evasion registry-modification windows
2r 1t
medium advisory

Windows Defender SmartScreen Level Downgrade to 'Warn'

This analytic detects modifications to the Windows Registry to set Windows Defender SmartScreen level to 'Warn', which can reduce user suspicion and increase the risk of malware execution.

Splunk Enterprise +3 defense-evasion registry-modification windows
2r 1t
medium advisory

Windows Defender Quick Scan Interval Modification

Detection of modifications to the Windows registry that change the Windows Defender Quick Scan Interval, potentially impairing its ability to detect malware promptly.

Splunk Enterprise +3 defense-evasion windows-registry windows-defender endpoint
2r 1t
medium advisory

Windows Defender PUA Protection Disabled via Registry Modification

An attacker modifies the Windows Registry to disable Windows Defender Potentially Unwanted Application (PUA) protection, increasing the risk of malware installation and system compromise.

Windows Defender +3 defense-evasion windows registry-modification
2r
medium advisory

Windows Credential Manager Abuse via VaultCmd

Adversaries may abuse VaultCmd to list or dump credentials stored in the Windows Credential Manager to obtain saved usernames and passwords, potentially for lateral movement.

Windows credential-access vaultcmd
2r 2t
medium advisory

Windows Command Obfuscation via Environment Variable Substrings

Attackers obfuscate commands in Windows by dynamically constructing them using substrings extracted from environment variables, a technique observed in malware families such as Cobalt Strike and Meterpreter.

Splunk Enterprise +2 command-obfuscation defense-evasion windows
2r 1t
medium advisory

Windows Admin Account Brute Force Detection

This rule identifies potential password guessing/brute force activity from a single source IP targeting multiple Windows accounts with 'admin' in the username, indicating an attempt to compromise privileged accounts.

Windows Security Event Logs credential-access brute-force windows
2r 2t
medium advisory

Web Server Local File Inclusion Activity

This rule detects potential Local File Inclusion (LFI) exploitation on web servers by identifying HTTP GET requests attempting to access sensitive local files through directory traversal or known file paths, potentially leading to sensitive information disclosure.

Nginx +4 lfi web-server directory-traversal information-disclosure
2r 1t
medium advisory

Wbadmin Backup Catalog Deletion

Adversaries may delete Windows backup catalogs using wbadmin.exe to inhibit system recovery, often as part of ransomware or other destructive attacks.

Windows impact backup-deletion ransomware
2r 2t
medium advisory

User Account ServicePrincipalName Attribute Modified

Detection of modifications to the servicePrincipalName attribute on user accounts, potentially exposing them to Kerberoasting attacks by allowing attackers to request Kerberos tickets for the account.

Active Directory kerberoasting credential-access windows spn
2r 2t
medium advisory

Unusual Service Host Child Process - Childless Service

The rule identifies unusual child processes of Service Host (svchost.exe) instances hosting services that do not traditionally spawn child processes, potentially indicating code injection or exploitation leading to privilege escalation and defense evasion.

Windows process-injection privilege-escalation defense-evasion
2r 2t
medium advisory

Unusual Process Execution via Alternate Data Streams

Adversaries may use Alternate Data Streams (ADS) to hide malicious executables and execute them, evading traditional detection methods by concealing the file's true nature.

Windows defense-evasion malware
2r 1t
medium advisory

Unusual Parent Process for cmd.exe

Atypical parent processes spawning cmd.exe indicate potential malicious command execution on Windows systems, where adversaries leverage cmd.exe from unusual parent processes to execute malicious commands stealthily.

Windows execution process-tree
1r 1t
medium advisory

Unauthorized Guest User Invitations in Azure AD

Detection of unauthorized guest user invitations within an Azure Active Directory tenant, indicating potential privilege escalation, persistence, or initial access attempts.

azure azuread guest-user privilege-escalation persistence initial-access
2r 3t
medium advisory

Suspicious Unshare Usage for Namespace Manipulation

The `unshare` command is used to create new namespaces in Linux, which can be exploited to break out of containers or elevate privileges by creating namespaces that bypass security controls.

Elastic Defend +6 privilege-escalation container-escape linux
2r 2t 1c updated
medium advisory

Suspicious Unshare Usage for Container Escape and Privilege Escalation

The rule identifies suspicious usage of unshare to manipulate system namespaces, which can be utilized to escalate privileges or escape container security boundaries.

Elastic Defend for Containers privilege-escalation container-escape linux
2r 2t
medium advisory

Suspicious Svchost.exe Child Process: cmd.exe

Detection of cmd.exe being spawned by svchost.exe, which is an unusual behavior indicative of potential masquerading or privilege escalation attempts on Windows systems.

execution windows process_injection privilege_escalation
2r 2t
medium advisory

Suspicious Shell Execution via Velociraptor

Attackers are abusing the Velociraptor endpoint visibility and response tool to execute shell commands (cmd, PowerShell, rundll32) on compromised Windows systems, blending in with legitimate system processes.

SolarWinds Web Help Desk velociraptor command-and-control windows
2r 2t
medium advisory

Suspicious Remote Registry Access via SeBackupPrivilege

Detection of remote registry access by an account with SeBackupPrivilege, potentially indicating credential exfiltration attempts via SAM registry hive dumping.

Windows credential-access lateral-movement
2r 3t
medium advisory

Suspicious RDP Client Image Load

The rule detects suspicious loading of the Remote Desktop Services ActiveX Client (mstscax.dll) from unusual locations, potentially indicating RDP lateral movement on Windows systems.

Remote Desktop Client lateral-movement threat-detection windows
2r 1t
medium advisory

Suspicious JavaScript File Upload to AWS S3 Static Website

Detection of a JavaScript file upload to an AWS S3 static website directory by an IAM user or assumed role, potentially indicating malicious web content modification and frontend compromise.

AWS S3 +3 aws s3 static-website javascript web-defacement
2r 2t
medium advisory

Suspicious Inter-Process Communication via Outlook COM

Adversaries may target user email to collect sensitive information or send email on their behalf via API by abusing Outlook's Component Object Model (COM) interface from unusual processes.

Outlook email_collection com_abuse windows
2r 2t
medium advisory

Suspicious Explorer Child Process via DCOM

Adversaries abuse the trusted status of explorer.exe to launch malicious scripts or executables, often using DCOM to start processes like PowerShell or cmd.exe, achieving initial access, defense evasion, and execution.

Microsoft Defender XDR +2 initial-access defense-evasion execution explorer.exe dcom
2r 9t
medium advisory

Suspicious Enumeration Commands Spawned via WMIPrvSE

This rule identifies suspicious activity where enumeration commands are spawned via the Windows Management Instrumentation Provider Service (WMIPrvSE) to gather system and network information.

Windows enumeration wmi reconnaissance
2r 13t
medium advisory

Suspicious Command Execution via SolarWinds Process

This brief covers the detection of suspicious command execution, specifically Cmd.exe or PowerShell.exe, as child processes of legitimate SolarWinds executables, indicative of potential supply chain compromise and unauthorized command execution on Windows systems.

SolarWinds Orion supply-chain solarwinds command-execution powershell cmd
2r 3t
medium advisory

Suspicious AWS ECR Container Upload Outside Business Hours

An AWS Elastic Container Registry (ECR) container image upload occurring outside of normal business hours can indicate suspicious or malicious activity, such as an attacker attempting to deploy compromised containers.

AWS Elastic Container Registry cloud aws ecr container
2r 1t
medium advisory

Suspicious .NET Code Compilation via Unusual Parent Processes

Adversaries may use unusual parent processes to execute .NET compilers for compiling malicious code after delivery, evading security mechanisms, and this activity is detected by monitoring compiler executions initiated by scripting engines or system utilities.

Microsoft Defender XDR +3 defense-evasion compile-after-delivery windows
2r 3t
medium advisory

SMB Registry Hive Exfiltration

Detection of medium-sized registry hive files being created or modified on Server Message Block (SMB) shares, potentially indicating exfiltration of Security Account Manager (SAM) data for credential extraction.

Elastic Defend credential-access lateral-movement exfiltration windows
2r 3t
medium advisory

Signal 'Disappearing' Messages Persist in macOS Notification Center

macOS stores Signal message notifications in an unencrypted SQLite database, potentially exposing 'disappearing' messages even after they are deleted from the Signal application.

Signal macos notification privacy credential-access
2r
medium advisory

Python-Multipart Denial of Service Vulnerability

A denial-of-service vulnerability exists in python-multipart versions prior to 0.0.27 due to unbounded multipart part header parsing, allowing attackers to exhaust CPU resources by sending requests with many repeated headers or a single oversized header value.

python-multipart denial-of-service web-application
2r 1t
medium advisory

PowerShell Script Block Logging Disabled via Registry Modification

Attackers may disable PowerShell Script Block Logging by modifying the registry to evade detection and conceal their activities on the host, detected by monitoring changes to the `EnableScriptBlockLogging` registry value.

PowerShell +1 defense-evasion windows
2r 2t
medium advisory

Potential Kubeletctl Execution on Linux Hosts

This rule detects the execution of kubeletctl, a command-line tool used to interact with the Kubelet API, on Linux hosts, potentially leading to discovery and lateral movement within Kubernetes environments.

Kubernetes kubeletctl container linux
2r 3t
medium advisory

Potential Data Exfiltration Through Curl

This rule detects potential data exfiltration attempts on Linux systems using the curl command-line tool to upload files to external servers, potentially indicating unauthorized data transfer.

curl +1 data-exfiltration linux
2r 1t
medium advisory

Potential Credential Access via DCSync

This rule identifies when a User Account starts the Active Directory Replication Process, potentially indicating a DCSync attack, which allows attackers to steal credential information compromising the entire domain.

Azure AD Connect credential-access privilege-escalation windows active-directory
2r 3t
medium advisory

Okta User Account Lockout Detection

Detection of an Okta user account lockout, which may indicate brute-force attempts or other malicious activity targeting user accounts.

Okta identity account-lockout
2r 1t
medium advisory

Okta New Device Enrollment Detection

Detection of new device enrollments in Okta, potentially indicating account takeover or unauthorized access by an adversary.

Okta Identity Cloud okta account-takeover persistence cloud
2r 1t
medium advisory

Okta Credential Stuffing Attempt Detection

This brief focuses on detecting credential stuffing attacks against Okta, characterized by multiple failed login attempts from a single source, potentially indicating automated attempts to compromise user accounts.

Okta credential-stuffing account-takeover
2r 1t
medium advisory

Nimiq Block Skip Block Quorum Bypass Vulnerability

A vulnerability exists in Nimiq Block's SkipBlockProof verification process, allowing attackers to bypass quorum checks by manipulating MultiSignature signers with out-of-range indices, potentially compromising blockchain integrity, and affecting rust/nimiq-block versions 0.2.0 and earlier.

nimiq-block blockchain quorum bypass nimiq rust
2r 1t
medium advisory

New GitHub App Installation Detection

The installation of a new GitHub application within an organization's account may indicate malicious activity by granting unauthorized access to repositories and organizational data.

GitHub app-installation execution
2r 3t
medium advisory

Netsh Used to Enable Remote Desktop Protocol (RDP) in Windows Firewall

Adversaries may use the `netsh.exe` utility to enable inbound Remote Desktop Protocol (RDP) connections in the Windows Firewall, potentially allowing unauthorized remote access to compromised systems.

Windows Firewall +4 defense-evasion lateral-movement windows netsh rdp
2r 2t
medium advisory

n8n Unauthenticated Denial of Service via MCP Client Registration

n8n is vulnerable to an unauthenticated denial of service (DoS) attack due to missing resource controls in the MCP OAuth client registration endpoint, allowing an attacker to exhaust server memory by sending large registration payloads, leading to service unavailability; this is resolved in versions 1.123.32, 2.17.4, and 2.18.1 and tracked as CVE-2026-42236.

n8n denial-of-service vulnerability
2r 1t
medium advisory

MyBB Recent Threads 17.0 Persistent Cross-Site Scripting Vulnerability (CVE-2018-25309)

MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability (CVE-2018-25309) that allows attackers to inject malicious scripts by creating threads with crafted subject lines, leading to arbitrary JavaScript execution in the browsers of users viewing the index page.

Recent threads 17.0 xss cve-2018-25309 web-application
2r 1t 1c
medium advisory

Multiple Remote Management Tool Vendors on Same Host

This detection identifies a Windows host where two or more distinct remote monitoring and management (RMM) or remote-access tool vendors are observed starting processes within the same eight-minute window, potentially indicating compromise, shadow IT, or attacker staging of redundant access.

AeroAdmin +55 command-and-control rmm windows threat-detection
3r
medium advisory

Msiexec Arbitrary DLL Execution

Adversaries may abuse the msiexec.exe utility to proxy the execution of malicious DLL payloads, bypassing application control and other defenses.

Windows defense-evasion proxy-execution msiexec
2r 1t
medium advisory

MSBuild Started by System Process

Detects instances of MSBuild, the Microsoft Build Engine, started by Explorer or the WMI (Windows Management Instrumentation) subsystem, which is unusual and often used by malicious payloads to evade defenses.

Windows defense-evasion execution
2r 2t
medium advisory

MS Office Macro Security Registry Modifications

Attackers may modify Microsoft Office registry settings related to macro security (AccessVBOM, VbaWarnings) to disable security warnings, enabling malicious macros for persistence and further compromise.

Microsoft Office office macro registry defense-evasion windows
2r 2t
medium advisory

Mounting of Hidden or WebDav Remote Shares via Net Utility

Adversaries may leverage the `net.exe` utility to mount WebDav or hidden remote shares, potentially indicating lateral movement, data exfiltration preparation, or initial access via discovery of accessible shares.

Elastic Defend +2 lateral-movement data-exfiltration windows
2r 4t
medium advisory

Mod_gnutls Certificate Chain Overflow Vulnerability (CVE-2026-33307)

Mod_gnutls versions prior to 0.12.3 and 0.13.0 are vulnerable to a certificate chain overflow when verifying client certificates, potentially leading to a segfault or stack corruption.

Mod_gnutls apache tls certificate-overflow cve-2026-33307 denial-of-service
2r 3t
medium advisory

Microsoft Outlook VBA Template Persistence

Attackers establish persistence by installing a malicious VBA template in Microsoft Outlook, triggering scripts upon application startup by modifying the VBAProject.OTM file.

Outlook persistence vba windows
2r 1t
medium advisory

Microsoft IIS Service Account Password Dump via AppCmd

An attacker with IIS web server access via a web shell can extract service account passwords by requesting full configuration output or targeting credential-related fields using the AppCmd tool.

IIS credential-access appcmd windows
2r 2t
medium advisory

Microsoft Devtunnels Image Load Detection

This detection identifies potential misuse of Microsoft Devtunnels within Visual Studio by detecting image load events, indicating that an attacker could expose a compromised system or service to the internet for covert communication and data exfiltration.

Visual Studio +3 devtunnels reverse-proxy command-and-control data-exfiltration windows
2r 2t
medium advisory

Microsoft Defender ATP Alert Aggregation and Correlation

This analytic aggregates and summarizes alerts from Microsoft Defender ATP, enriching them with MITRE ATT&CK context and risk scoring for improved correlation and risk-based alerting.

Microsoft Defender ATP endpoint alert-correlation risk-based-alerting
2r
medium advisory

Masquerading Business Application Installers

Attackers masquerade malicious executables as legitimate business application installers to trick users into downloading and executing malware, leveraging defense evasion and initial access techniques.

Elastic Defend +22 masquerading defense-evasion initial-access malware windows
2r 4t
medium advisory

macOS DNS Request for IP Lookup Service via Unsigned Binary

An unsigned or untrusted binary on macOS is performing DNS requests for IP lookup services to determine the system's external IP address, which is commonly used by malware for reconnaissance before establishing C2 connections.

macOS discovery dns reconnaissance unsigned_binary
2r 1t 42i
medium advisory

Mac File Opener Adware Persists via Document Handler Registration

The 'Mac File Opener' adware achieves persistence by registering itself as a document handler for numerous file types, leveraging the Launch Services Daemon (lsd) to automatically parse the application's Info.plist and register the handlers.

macOS adware persistence
2r 1t
medium advisory

LSASS Shtinkering Detection via Full User-Mode Dump Configuration

Detection of the enabling of full user-mode dumps system-wide, a setting change leveraged in LSASS Shtinkering attacks to dump LSASS process memory and steal credentials.

Windows credential-access lsass registry
2r 2t
medium advisory

LSASS Memory Dump Creation Detection

This rule identifies the creation of LSASS memory dump files, often indicative of credential access attempts using tools like Task Manager, SQLDumper, Dumpert, or AndrewSpecial, by monitoring for specific filenames and excluding legitimate dump locations.

Elastic Defend +4 credential_access lsass memory_dump windows
2r 1t
medium advisory

Linux Auditd Daemon (Re)Initialization Detection

Detection of Linux audit daemon (auditd) re-initialization events, which can indicate attempts to re-enable audit logging after evasion or restarts with modified rule sets.

Splunk Enterprise +4 linux auditd anomaly
3r 1t
medium advisory

Lanman NullSessionPipe Registry Modification for Lateral Movement

Adversaries may modify the NullSessionPipe registry key to enable anonymous access to named pipes, facilitating lateral movement and defense evasion by allowing unauthorized access to network resources.

Windows lateral-movement defense-evasion
2r 2t
medium advisory

Kubernetes Anonymous Request Authorized by Unusual User Agent

This rule detects when an unauthenticated user request is authorized within a Kubernetes cluster via an unusual user agent, potentially indicating an attacker attempting to gain initial access or avoid attribution by exploiting anonymous accounts.

Kubernetes initial-access defense-evasion
2r 1t
medium advisory

Kubernetes Access Scanning Detection

This analytic detects potential reconnaissance activities within a Kubernetes environment by identifying repeated failed access attempts or unusual API requests from unauthenticated users based on Kubernetes audit logs, indicating a potential attacker's preliminary reconnaissance.

Kubernetes scanning reconnaissance
2r 1t
medium advisory

Image File Execution Options (IFEO) Injection for Persistence and Defense Evasion

Adversaries abuse Image File Execution Options (IFEO) in the Windows Registry by modifying Debugger or MonitorProcess keys to intercept legitimate file executions, enabling persistence and defense evasion.

Windows persistence defense-evasion registry
2r 3t
medium advisory

Hysteria Server Out-of-Memory Vulnerability via Malformed QUIC Packet

A specially constructed QUIC package can crash the Hysteria server due to an out-of-memory (OOM) condition when the 'sniff' option is enabled, leading to a denial of service.

hysteria/core/v2 hysteria quic oom dos
2r 1t
medium advisory

High Number of Process and/or Service Terminations Detected

A high number of process terminations (stop, delete, or suspend) from the same Windows host within a short time period may indicate malicious activity such as an attacker attempting to disable security measures or prepare for ransomware deployment.

Elastic Defend impact defense-evasion windows
2r 2t
medium advisory

Google Workspace MFA Enforcement Disabled

Detection of multi-factor authentication (MFA) enforcement being disabled for Google Workspace users, potentially weakening security controls and leading to account compromise.

Google Workspace google-workspace mfa account-compromise
2r 3t
medium advisory

Google Workspace 2SV Policy Disabled

An adversary may disable 2-Step Verification (2SV) in Google Workspace to weaken account security and facilitate unauthorized access.

Google Workspace google-workspace 2sv persistence
2r 1t
medium advisory

GCP Firewall Rule Deletion for Defense Evasion

The deletion of firewall rules in Google Cloud Platform (GCP) for Virtual Private Cloud (VPC) or App Engine is detected, potentially weakening security controls and enabling unauthorized access or data exfiltration by adversaries.

Google Cloud Platform +2 cloud defense-evasion gcp
2r 1t
medium advisory

First Time Seen AWS Secret Value Accessed in Secrets Manager

This rule detects the first time a specific user identity has programmatically retrieved a secret value from AWS Secrets Manager using the GetSecretValue action, which may indicate a compromised AWS service attempting to access secrets.

AWS Secrets Manager cloud aws credential-access
2r 1t
medium advisory

Firebird Database Server Denial-of-Service Vulnerability (CVE-2026-28212)

An unauthenticated attacker can cause a denial-of-service condition on vulnerable Firebird database servers by sending a specially crafted network packet that triggers a null pointer dereference.

Firebird denial-of-service cve-2026-28212
2r 1t 1c
medium advisory

File with Right-to-Left Override Character (RTLO) Created/Executed

This rule detects the creation or execution of files or processes with names containing the Right-to-Left Override (RTLO) character, which can be used to disguise the file extension and trick users into executing malicious files on Windows systems.

Elastic Defend +2 defense-evasion rtlo masquerading windows
2r 2t
medium advisory

Excessive OneDrive File Downloads Detection

Detection of unusual high-volume file downloads from Microsoft OneDrive, potentially indicating data exfiltration by a compromised account or insider threat.

OneDrive data-exfiltration cloud
2r 1t
medium advisory

ESXi VM Discovery via ESXCLI Commands

Adversaries may use ESXCLI commands to discover virtual machines on an ESXi host, potentially indicating reconnaissance for high-value targets, environment mapping, or preparation for data theft or destructive operations.

VMware ESXi esxi vmware discovery
2r
medium advisory

ericc-ch copilot-api Permissive Cross-Domain Policy Vulnerability (CVE-2026-6662)

CVE-2026-6662 is a vulnerability in ericc-ch copilot-api up to 0.7.0, specifically in the cors function of src/server.ts, leading to a permissive cross-domain policy that can be remotely exploited for cross-domain attacks.

copilot-api CORS Cross-Site Scripting API Vulnerability
2r 1t 1c 2i
medium advisory

Entra ID User Added as Service Principal Owner for Persistence

An adversary may add a user account as an owner for an Azure service principal to define what an application can do in the Azure AD tenant, potentially leading to persistence and privilege escalation.

Entra ID +1 azure service-principal persistence privilege-escalation
2r 4t
medium advisory

Entra ID High Risk User Sign-in Detection

This rule identifies high-risk Azure Active Directory (AD) sign-ins by leveraging Microsoft Identity Protection machine learning and heuristics, specifically focusing on events with a risk state of `confirmedCompromised` or `atRisk`, indicating potential initial access attempts.

Azure Active Directory azure initial-access cloud
2r 1t
medium advisory

Entra ID Conditional Access Policy (CAP) Modified

An adversary may modify existing Conditional Access Policies (CAPs) in Microsoft Entra ID to weaken access controls and maintain persistence in the environment with a compromised identity.

Microsoft Entra ID azure entra_id conditional_access_policy persistence defense_evasion
2r 2t
medium advisory

Elastic Agent Service Termination Attempt

This rule detects attempts to stop the Elastic endpoint agent service, which may indicate a defense evasion tactic employed by adversaries to disable security monitoring and evade detection.

Elastic Agent defense-evasion endpoint elastic-agent
3r 1t
medium advisory

Disabling Windows Defender Security Settings via PowerShell

Attackers use PowerShell commands like Set-MpPreference or Add-MpPreference, often with base64 encoding, to disable or weaken Windows Defender security settings in order to evade detection and execute malicious payloads.

Windows Defender defense-evasion powershell windows
3r 2t
medium advisory

Disabling User Account Control via Registry Modification

Attackers may disable User Account Control (UAC) by modifying specific registry values, allowing them to execute code with elevated privileges, bypass security restrictions, and potentially escalate privileges on Windows systems.

Microsoft Defender XDR +1 privilege-escalation defense-evasion windows
2r 3t
medium advisory

Disable Windows Event and Security Logs Using Built-in Tools

Attackers may attempt to disable Windows event logging to evade detection by using built-in tools like logman, PowerShell, and auditpol.

Windows defense-evasion eventlog
3r 3t
medium advisory

Detection of WMIC System Information Discovery

Adversaries may use Windows Management Instrumentation Command-line (WMIC) to gather system information, specifically using the `computersystem` alias to retrieve details about the system's configuration, which aids in reconnaissance.

Windows discovery wmic
2r 1t
medium advisory

Detection of System Information Discovery Techniques

This brief covers the detection of adversaries using native Windows commands like `wmic qfe`, `systeminfo`, and `hostname` to gather system information for further exploitation.

Windows system-discovery post-exploitation
1r 1t
medium advisory

Detection of Office Macro File Creation

This brief outlines a threat involving the creation of new Office macro files, potentially indicating malicious activity such as phishing or malware distribution, targeting Windows systems.

Microsoft Office initial-access phishing macro
2r 1t
medium advisory

Detection of Level RMM Watchdog Task Creation

The creation of the 'Level Watchdog' task, indicative of the Level remote management tool installation, is detected, highlighting the potential abuse of legitimate RMM tools for persistence and execution by threat actors on Windows systems.

Level remote management tool +3 rmm remote-access persistence
2r 2t
medium advisory

Detection of Level RMM PowerShell Script Installer

This brief details the detection of the Level remote management tool PowerShell installer on Windows endpoints, which can be exploited by threat actors for malicious purposes to maintain persistence and execute commands, although it's a legitimate IT tool.

Splunk Enterprise +2 remote-management powershell rmm
2r 1t 1i
medium advisory

Detecting Execution from Alternate Data Streams

Adversaries may execute malicious code from Alternate Data Streams (ADS) on Windows to evade defenses by hiding malware within legitimate files, which this detection identifies by monitoring process execution paths and arguments.

M365 Defender +1 defense-evasion windows alternate data stream
2r 1t
medium advisory

Decidim Amendment Manipulation Vulnerability (CVE-2026-40869)

CVE-2026-40869 allows authenticated users to manipulate amendments in Decidim versions 0.19.0 prior to 0.30.5 and 0.31.1, potentially hijacking authorship and impacting proposal integrity.

Decidim vulnerability amendment manipulation
2r 1t 1c
medium advisory

CVE-2017-3735 Vulnerability Targeting Microsoft Products

CVE-2017-3735 is a vulnerability impacting Microsoft products, potentially allowing unauthorized access or code execution.

vulnerability microsoft cve-2017-3735
2r 1t 1c
medium advisory

Cloud API Calls From Previously Unseen User Roles

This analytic identifies anomalous cloud API calls executed by user roles that have not previously performed those commands, potentially indicating malicious activity or unauthorized actions leading to unauthorized access or data breaches.

Amazon Web Services cloud aws anomaly assumedrole
2r 2t
medium advisory

Cisco Duo Policy Change to Allow Devices Without Screen Lock

A Splunk detection analytic identifies when a Duo policy is created or updated to allow devices without a screen lock, potentially weakening device security controls and increasing the risk of unauthorized access and data breaches.

Duo cisco-duo screen-lock policy-change
2r 1t
medium advisory

Cisco Duo Policy Allowing Outdated Flash Usage

A Cisco Duo administrator may create or update a policy to allow the use of outdated Flash components, potentially increasing the attack surface by allowing exploitation of Flash vulnerabilities.

Cisco Duo +1 cisco_duo policy_change outdated_software
2r 1t
medium advisory

CircleCI Security Job Disablement Detection

Detection of activity related to disabling security jobs within CircleCI, potentially indicating an attempt to bypass security controls in a CI/CD pipeline.

CircleCI ci/cd supply-chain
2r 1t
medium advisory

Brizy WordPress Plugin Unauthenticated Stored XSS Vulnerability

The Brizy – Page Builder plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting (XSS) in versions up to and including 2.8.11, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the form Leads page due to missing nonce verification and improper handling of file upload fields.

Brizy – Page Builder plugin <= 2.8.11 wordpress xss unauthenticated
2r 1t 1c
medium advisory

BITS Transfer Job With Uncommon or Suspicious Remote TLD

Adversaries abuse Background Intelligent Transfer Service (BITS) to download malicious payloads from unusual top-level domains, bypassing traditional security measures and establishing persistence on compromised systems.

Windows attack.defense-evasion attack.persistence attack.t1197
2r 2t
medium advisory

Azure Kubernetes Services (AKS) Kubernetes Pod Deletion

The deletion of Azure Kubernetes Pods can indicate malicious activity aimed at disrupting the environment's normal behavior.

Azure Kubernetes Services azure kubernetes impact cloud
2r 2t
medium advisory

Azure Domain Federation Settings Modified

An attacker may modify Azure domain federation settings to establish persistence, escalate privileges, or gain unauthorized access to resources.

Azure Active Directory azure federation privilege-escalation persistence initial-access
2r 2t
medium advisory

Azure Blob Storage Container Access Level Modified

The rule identifies modifications to Azure Blob Storage container access levels, which, if unauthorized, may lead to data exposure and exfiltration.

Azure Blob Storage cloud azure asset-visibility discovery
2r 3t
medium threat

AWS SSM Inventory Reconnaissance by Rare User

Detection of a rare user or role accessing AWS Systems Manager (SSM) inventory APIs or running the AWS-GatherSoftwareInventory job, potentially indicating reconnaissance activity by threat actors seeking information about managed EC2 instances.

AWS Systems Manager +1 Scattered Spider (LUCR-3) aws ssm inventory reconnaissance cloudtrail
2r 3t
medium advisory

AWS S3 Data Exfiltration via Uncommon Client Applications

This rule detects AWS API activity originating from uncommon desktop client applications based on the user agent string, specifically S3 Browser and Cyberduck, which provide bulk upload/download capabilities and have been observed in use by threat actors for data exfiltration, warranting validation against authorized data transfer workflows.

Amazon S3 aws s3 exfiltration cloudtrail
3r 2t
medium advisory

AWS S3 Bucket Policy Added to Allow Public Access

An AWS S3 bucket policy was modified to grant public access using a wildcard (Principal:"*") statement, potentially allowing data exfiltration or malicious content hosting.

Amazon S3 aws s3 exfiltration cloud
2r 2t
medium advisory

AWS Route 53 Private Hosted Zone Associated With Unauthorized VPC

An adversary with sufficient permissions may associate unauthorized VPCs to intercept, observe, or reroute internal traffic, establish persistence, or expand their visibility within an AWS environment by associating a Route 53 private hosted zone with a new Virtual Private Cloud (VPC).

Route 53 cloud aws route53 persistence
2r 3t
medium advisory

AWS Network Access Control List Deletion Detected

Detection of AWS Network Access Control List (ACL) deletion using AWS CloudTrail logs, which can remove critical access restrictions, potentially allowing unauthorized access to cloud instances and leading to data exfiltration or further compromise.

Splunk Enterprise +3 cloud aws network
2r 1t
medium advisory

AWS Management Console Root Login Detected

Detection of a successful AWS Management Console login by the Root user, which is an original identity with unrestricted privileges, indicates a potential security breach requiring immediate investigation.

AWS Management Console +2 cloud aws initial-access
2r 2t
medium advisory

AWS IAM SAML Provider Creation for Persistence

Detects the creation of a new SAML Identity Provider (IdP) in AWS IAM, potentially indicating an adversary establishing persistent, federated access to AWS accounts by forging SAML assertions from an IdP they control.

IAM aws saml persistence cloud
3r 3t
medium advisory

AWS IAM Operations via Compromised CloudShell

Compromised AWS console sessions can lead to attackers performing sensitive IAM operations via CloudShell to establish persistence or escalate privileges.

AWS CloudShell +2 cloudshell aws iam persistence privilege-escalation
2r 4t
medium advisory

AWS IAM Key Creation with Encryption Policy but Without MFA

Detection of AWS IAM users creating access keys with encryption policies applied while failing to use multi-factor authentication, potentially indicating compromised accounts or malicious privilege escalation.

Identity and Access Management aws iam access_key encryption mfa
2r 2t
medium advisory

AWS Config Service Disabling Detection

Detection of AWS Config Service disabling, potentially indicating an attempt to impair defenses by stopping configuration recording and delivery.

AWS Config +1 attack.defense-impairment attack.t1562.008 aws
2r 1t
medium advisory

AWS Config Resource Deletion for Defense Evasion

An adversary may delete AWS Config resources to evade detection, hide prior activity, or weaken governance controls, which reduces security visibility and auditability within an AWS environment.

AWS Config cloud defense-evasion aws
2r 2t
medium advisory

AWS CloudTrail Logging Evasion via Oversized IAM Policies

Attackers evade AWS CloudTrail logging by padding IAM policy documents with whitespace, exceeding logging size limits and obscuring unauthorized changes to IAM policies.

CloudTrail +1 aws iam defense-evasion cloud
2r 1t
medium advisory

AppInit DLL Registry Persistence Detected

Modification of the AppInit DLLs registry keys can be used for persistence and defense evasion on Windows systems.

Windows persistence defense-evasion
2r 2t
medium advisory

Android-ImageMagick7 Memory Leak Vulnerability (CVE-2026-33856)

A missing release of memory after effective lifetime vulnerability exists in MolotovCherry Android-ImageMagick7 before version 7.1.2-11, potentially leading to denial of service.

Android-ImageMagick7 cve-2026-33856 memory leak denial of service android
2r 1t
medium advisory

Algovate xhs-mcp Server-Side Request Forgery Vulnerability

A server-side request forgery (SSRF) vulnerability exists in Algovate xhs-mcp 0.8.11 within the xhs_publish_content function, allowing a remote attacker to manipulate the media_paths argument and potentially access internal resources.

xhs-mcp 0.8.11 SSRF algovate xhs-mcp
2r 1t 1c
medium advisory

Abuse of Predefined BIOCs in Palo Alto Cortex XDR

Attackers may decrypt and abuse predefined Behavioral Indicators of Compromise (BIOCs) in Palo Alto Cortex XDR to evade detection or manipulate the system.

Cortex XDR cortex-xdr bioc evasion
2r 1t
medium advisory

Abnormal Cloud Security Group API Call Activity

Detection of an abnormally high number of cloud security group API calls which can indicate malicious activity such as reconnaissance, privilege escalation, or lateral movement within a cloud environment.

Amazon Web Services +2 cloud security-group api-abuse
2r 2t
medium threat

Zebra Block Discovery Denial-of-Service via Gossip Queue Saturation and Syncer Poisoning

A denial-of-service vulnerability exists in Zebra's block discovery pipeline, allowing an unauthenticated remote attacker to permanently halt all new block discovery on a targeted node by exploiting weaknesses in the gossip, syncer, and download subsystems.

zebrad denial-of-service zebra block-discovery gossip syncer
2r 1t 1c
medium advisory

Windows Update Client DLL Loading Abuse

Adversaries abuse the Windows Update Auto Update Client (wuauclt.exe) to load arbitrary DLLs from user-writable locations, achieving defense evasion and execution of malicious code.

Windows defense-evasion execution lolbas
2r 2t
medium advisory

Windows Privilege Escalation via Secondary Logon Service

The rule identifies process creation with alternate credentials, which can be used for privilege escalation, by detecting successful logins via the Secondary Logon service (seclogon) from a local source IP address (::1), followed by process creation using the same TargetLogonId.

Windows privilege-escalation access-token-manipulation
2r 2t
medium advisory

Unusual EC2 Instance Creation with Unseen Instance Type

An attacker may create new EC2 instances with previously unseen instance types, indicating potential unauthorized or suspicious activity such as cryptomining or data exfiltration.

EC2 cloud anomaly cryptomining
2r 1t
medium advisory

Suspicious MS Outlook Child Process

Detection of suspicious child processes spawned by Microsoft Outlook, indicative of spear phishing and malicious file execution leading to potential initial access and further exploitation.

Microsoft Outlook +3 initial-access phishing malware windows
2r 3t
medium advisory

Suspicious Execution via Windows Subsystem for Linux

This rule detects suspicious execution via the Windows Subsystem for Linux (WSL), which adversaries may leverage to execute Linux commands and bypass traditional Windows security measures.

Windows Subsystem for Linux wsl windows-subsystem-for-linux defense-evasion
2r 3t
medium advisory

Suspicious CertUtil Commands for Defense Evasion and Lateral Movement

This rule detects suspicious use of certutil.exe, a native Windows utility often abused by attackers for downloading/deobfuscating malware and exfiltrating data, by identifying commands involving decoding, encoding, URL caching, CTL verification, and PFX exporting, which are frequently used for command and control and defense evasion.

Windows defense-evasion command-and-control credential-access certutil
2r 3t
medium advisory

Remote Execution via File Shares

This rule identifies potential lateral movement via network file shares by detecting the execution of a file that was created by the virtual system process.

Windows lateral-movement file-share
2r 1t
medium advisory

Remote Execution of Windows Services via RPC

Detection of remote execution of Windows services over RPC by correlating `services.exe` network connections and spawned child processes, potentially indicating lateral movement.

SCCM lateral-movement execution windows
2r 2t
medium advisory

Potential Exploitation of Unquoted Service Path Vulnerability

This rule detects potential exploitation of unquoted service paths on Windows systems, which can lead to privilege escalation by identifying suspicious processes starting from common unquoted paths, indicating a potential attempt to execute malicious code.

Windows privilege-escalation unquoted-service-path
2r 1t
medium advisory

Leveraging Apple's Endpoint Security Framework for Process Monitoring

This brief discusses the use of Apple's Endpoint Security Framework in macOS 10.15 and later for user-mode process monitoring, offering improved capabilities over the older OpenBSM subsystem.

macOS endpoint-security process-monitoring defense-evasion discovery
2r 2t
medium advisory

Large ICMP Traffic Detection

This analytic identifies excessive ICMP traffic to external IP addresses exceeding 1,000 bytes, potentially indicating command and control activity, data exfiltration, or covert communication channels.

Splunk Enterprise +4 network-traffic command-and-control data-exfiltration
2r 1t
medium advisory

Impact of Poor Security Operation Center (SOC) Metrics

Poorly chosen performance metrics can significantly impair a SOC's ability to detect and respond to threats, leading to ineffective security operations and potential compromise.

SharePoint soc metrics threat-hunting detection
2r 2t
medium advisory

Google Workspace Marketplace Restrictions Modified to Allow Any App

An adversary may modify Google Workspace Marketplace restrictions to allow installation of any application, potentially enabling the deployment of malicious APKs to end users within the Google Workspace environment, bypassing security restrictions.

Google Workspace google_workspace defense_evasion cloud
2r 2t
medium advisory

Execution via GitHub Actions Runner

Adversaries compromising GitHub Actions workflows can execute arbitrary commands on runner hosts, leading to code execution, reconnaissance, credential harvesting, or network exfiltration.

github-actions supply-chain execution devops
3r 3t
medium advisory

Execution of COM object via Xwizard

Adversaries can abuse the legitimate system binary Xwizard to execute Component Object Model (COM) objects, evading defensive countermeasures by running COM objects created in the registry.

Windows execution defense-evasion com xwizard
2r 2t
medium advisory

Execution from Unusual Directory - Command Line

Adversaries may execute commands and scripts from unusual Windows directories to masquerade malware and evade detection, impacting system integrity and security operations.

Windows execution defense-evasion
2r 3t
medium advisory

Disabling Windows Defender Security Settings via PowerShell

This rule detects the use of the Set-MpPreference PowerShell command to disable or weaken Windows Defender settings, a common defense evasion tactic.

Windows Defender defense-evasion powershell windows
2r 2t
medium advisory

AWS WAF Access Control List Deletion

Detection of AWS Web Application Firewall (WAF) Web ACL deletion, which adversaries may perform to disable security controls, evade detection, and prepare for subsequent attacks, potentially leading to web-application compromise, data theft, or resource abuse.

AWS WAF +3 cloud aws waf defense-evasion
2r 1t