Tag
Detection of Unauthorized External MQTT Broker Connections
1 rule 1 TTPThis brief describes the detection of anomalous MQTT traffic to external brokers, a communication channel leveraged by malware like BambooToken and WailingCrab for command and control.
Multiple Security Vulnerabilities in Moquette MQTT Broker
1 CVEMoquette-broker versions <= 0.18.0 are susceptible to cross-tenant ACL bypass, remote unauthenticated denial-of-service, and cross-session durable storage corruption.
Toy Ghouls Deploying Custom HiveMQ and Matrix-Based Backdoors
1 rule 3 TTPs 1 IOCThe threat actor Toy Ghouls is using WinRM to deploy custom 'Bird' backdoors that utilize HiveMQ MQTT brokers and the Matrix protocol for C2, featuring machine-bound encrypted configurations.
Unauthenticated Remote Access to Phoenix Contact CHARX SEC MQTT Broker
2 rules 5 TTPs 12 CVEsA critical vulnerability (CVE-2026-44090) in Phoenix Contact CHARX SEC controllers allows unauthenticated remote attackers to gain full device control by bypassing authentication on the MQTT broker.
NATS Server Authorization Bypass Vulnerability (CVE-2026-58252)
2 TTPs 1 CVECVE-2026-58252 identifies an authorization bypass vulnerability in NATS Server, described as a 'Subscribe Authz Bypass via Wildcard-Overlap', which allows unauthorized access or actions by exploiting how wildcard subscriptions are handled.
NATS.io MQTT ACL Bypass Vulnerability
2 rules 1 TTPA vulnerability in NATS.io versions before v2.12.6 or v2.11.15 allows MQTT clients to bypass ACL checks for MQTT subjects due to ACLs not being applied in the `$MQTT.>` namespace, potentially allowing unauthorized access and control of MQTT communications.
NATS Server MQTT Password Disclosure Vulnerability
3 rules 1 TTPThe NATS server exposes MQTT passwords in plaintext via monitoring endpoints due to incorrect classification as JWTs, affecting versions before v2.12.6 or v2.11.15.