<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Logsign - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/logsign/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 17 Aug 2026 14:46:56 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/logsign/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Insufficiently Protected Credentials in Logsign SIEM</title><link>https://feed.craftedsignal.io/briefs/2026-08-logsign-siem-credentials/</link><pubDate>Mon, 17 Aug 2026 14:46:56 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-logsign-siem-credentials/</guid><description>Logsign SIEM versions 6.4.97 through 6.4.113 are vulnerable to an insufficiently protected credentials flaw, allowing privileged users to retrieve embedded sensitive data (CVE-2026-14564).</description><content:encoded><![CDATA[<p>CVE-2026-14564 describes a vulnerability in Innotim Software's Logsign SIEM product, specifically affecting versions 6.4.97 up to, but not including, 6.4.114. The flaw is categorized as an Insufficiently Protected Credentials issue (CWE-522). This vulnerability allows an authenticated attacker with administrative privileges to retrieve sensitive data embedded within the application. Given the nature of a SIEM, which centralizes logs, security alerts, and often credentials for managed assets, the ability to extract embedded secrets represents a critical risk to the broader security ecosystem. Organizations running affected versions are urged to upgrade to version 6.4.114 or later to remediate the exposure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability enables an attacker with elevated access to bypass security controls and gain unauthorized access to sensitive information stored or processed by the SIEM. This potentially facilitates lateral movement, credential theft, and access to integrated infrastructure monitoring data, which could impact the entire network environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all Logsign SIEM instances to version 6.4.114 or later to address CVE-2026-14564.</li>
<li>Audit logs for the period prior to patching to identify any anomalous access to sensitive system configurations or configuration export events.</li>
<li>Review administrative access logs for unusual user activity associated with the affected product.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>credential-theft</category><category>logsign</category></item></channel></rss>