Skip to content
Threat Feed

Tag

Network-Security

97 briefs RSS
high advisory

Cross-Telemetry Correlation of Endpoint and Network Security Alerts

Detection engineering logic that correlates Elastic Defend endpoint alerts with network security events from PAN-OS, FortiGate, and Suricata to identify potentially compromised hosts based on multi-source telemetry.

Elastic Defend +5 correlation multi-datasource network-security endpoint-security phishing email-security
3t
low advisory

Detection of Potential HTTP Downgrade Attacks

Attackers may force HTTP protocol downgrades from secure versions like HTTP/2 to legacy versions to exploit header parsing inconsistencies and facilitate request smuggling or cache poisoning.

Apache HTTP Server +3 web-application-attack defense-evasion network-security
1r 1t
medium advisory

Detection of Anomalous SOCKS Proxy Traffic via FortiGate Integration

This detection leverages cross-platform correlation between FortiGate network application logs and endpoint telemetry to identify processes acting as SOCKS proxies for potential command and control obfuscation.

FortiGate command-and-control proxy network-security cross-platform
1t updated
medium advisory

Correlation of Palo Alto Networks C2 Alerts with Endpoint Process Activity

This detection capability correlates Palo Alto Networks (PANW) firewall command and control alerts with Elastic Defend endpoint events to identify the specific process responsible for network traffic flagged as malicious.

PAN-OS +1 command-and-control detection-engineering network-security cross-platform
1t
medium advisory

Detection of Suspicious TLD Connections by GenAI and CLI Tools

Detection rule monitors GenAI tools and CLI package managers for network connections to high-risk Top-Level Domains frequently utilized by threat actors for C2 infrastructure.

command-and-control genai network-security
1r 1t
high advisory

Stack-based Buffer Overflow in PLANET IGS-5225-8P2T4S Managed Switches

A stack-based buffer overflow vulnerability in the web server of PLANET IGS-5225-8P2T4S industrial managed switches allows authenticated remote attackers to achieve denial of service or remote code execution via CVE-2026-81944.

IGS-5225-8P2T4S vulnerability industrial-control-systems network-security cve-2026-81944
1t 1c
high advisory

DNSSEC Validation Bypass in hickory-resolver

A vulnerability in hickory-resolver versions prior to 0.26.2 causes the library to ignore bogus DNSSEC proof states, allowing attackers to inject forged DNS records as validated data.

hickory-resolver dnssec vulnerability network-security
1t 1c
critical threat

Critical Vulnerabilities Patched in Cisco FMC, ISE, and Nexus Dashboard

Cisco has released emergency patches for dozens of critical vulnerabilities across Identity Services Engine (ISE), Secure Firewall Management Center (FMC), and Nexus Dashboard, including several flaws currently exploited in the wild.

exploited Secure Firewall Management Center +4 vulnerability cisco network-security patch-management
2t 3c
high advisory

Remote Code Execution Vulnerability in Check Point Management Products

A critical remote code execution vulnerability (CVE-2026-91843) affects multiple Check Point security management servers, allowing unauthenticated attackers to execute arbitrary code.

Log Server +5 vulnerability rce network-security
1c updated
rumour rumour

SilkParasite Campaign Infrastructure Analysis

Analysis of the SilkParasite campaign reveals a 13-server command-and-control cluster facilitating the deployment of SpiceRAT against targets in Central Asia.

spicerat silkparasite command-and-control central-asia network-security threat-intelligence
1t
high advisory

Remote Code Execution Vulnerability in Netgate pfSense

An authenticated remote attacker can exploit a vulnerability in Netgate pfSense to bypass security controls and execute arbitrary PHP code and shell commands.

pfSense vulnerability rce network-security
1t
high advisory

Remote Command Injection in TOTOLINK X5000R

A remote OS command injection vulnerability in the TOTOLINK X5000R router allows unauthenticated attackers to execute arbitrary commands via the exportOvpn function.

X5000R remote-code-execution cve-2026-91853 network-security
1r 1t 1c
high advisory

Remote Command Injection in D-Link DSL-3782

An unauthenticated remote command injection vulnerability in the D-Link DSL-3782 router allows attackers to execute arbitrary system commands via the Diagnostics component.

DSL-3782 cve-2026-90880 command-injection network-security
1c
medium advisory

HAProxy Security Bypass Vulnerability

A vulnerability in HAProxy (CVE-2023-45538) allows remote, unauthenticated attackers to bypass security restrictions, manipulate data, and trigger denial-of-service conditions.

HAProxy security-bypass denial-of-service network-security
1t
critical advisory

Command Injection Vulnerability in D-Link DWR-M921

A remote command injection vulnerability in the D-Link DWR-M921 router allows unauthenticated attackers to execute arbitrary OS commands by manipulating the partition argument in the formDiskFormat function.

DWR-M921 cve command-injection network-security
2t 1c
high advisory

Remote Stack-Based Buffer Overflow in Tenda W20E

A stack-based buffer overflow in the Tenda W20E formDelWebAuthWhiteUser function allows remote unauthenticated attackers to execute arbitrary code or cause a denial of service via manipulation of the webAuthWhiteUserIndex argument.

W20E cve-2026-90689 network-security buffer-overflow
1t 1c
high advisory

Correlation of First Seen Network Flow Exporters with Suspicious Source Activity

This detection identifies potential defense evasion where a newly observed network flow exporter subsequently acts as the source of suspicious security alerts within a 30-minute window.

defense-evasion network-security netflow monitoring
1t
critical advisory

Unauthenticated Arbitrary File Write in WAVLINK Routers

WAVLINK WN535M1 and WN535M3 routers are vulnerable to unauthenticated arbitrary file writes via the sync_server daemon, enabling attackers to gain root-level persistence.

WN535M1 +1 network-security remote-code-execution cve-2026-89009
2t 1c
low advisory

Detection of SYN-Based Port Scanning Reconnaissance

Detection logic identifies internal reconnaissance activity characterized by a single source IP probing a large volume of unique destination ports using SYN packets.

reconnaissance discovery network-security port-scan
1r 2t
low advisory

Detection of Newly Observed IPSEC NAT Traversal Peers

Detection of potentially unauthorized IPSEC NAT Traversal (NAT-T) tunnels indicates potential command and control (C2) or exfiltration activity masked by encrypted traffic.

command-and-control network-security vpn detection-engineering
1r 3t
medium advisory

Cross-Platform C2 Detection via Suricata and Elastic Defend Correlation

This detection capability correlates network-layer Suricata alerts with host-based process telemetry from Elastic Defend to identify malicious outbound command and control communication.

command-and-control detection-engineering network-security
3t
high advisory

Multiple Vulnerabilities in Arista EOS

Multiple vulnerabilities in Arista EOS allow an attacker to achieve privilege escalation, arbitrary code execution, security bypass, and denial-of-service.

EOS network-security vulnerability arista
3t
high advisory

Critical Vulnerabilities in Check Point Security Appliances

Check Point has disclosed critical vulnerabilities, including CVE-2026-85102 and CVE-2026-85103, affecting various Security Gateway, Management Server, and Spark Firewall deployments.

Security Gateway +2 vulnerability network-security rce high-confidence-source
2t 2c
high threat

CVE-2026-0308 Stored XSS in PAN-OS Web Interface

A stored cross-site scripting (XSS) vulnerability in the PAN-OS web interface allows an authenticated administrator to execute arbitrary JavaScript within the context of the management interface.

PAN-OS +12 xss web-vulnerability cve rce network-security vulnerability panos
4t
medium advisory

OpenVPN Reliability Layer Vulnerability CVE-2026-84732

OpenVPN versions 2.6.22 and 2.7.6 and earlier contain a vulnerability in the reliability layer that can be triggered by unbounded TLS timeouts and acknowledgments for non-outstanding packets, potentially leading to denial-of-service.

OpenVPN +1 vulnerability denial-of-service network-security
1c
high advisory

Multiple Vulnerabilities in strongSwan

Multiple vulnerabilities, including remote code execution and security policy bypass, have been disclosed in strongSwan versions prior to 6.1.0.

strongSwan +1 vulnerability network-security patch-management
critical threat

Active Exploitation of MikroTik RouterOS via SSH

Multiple vulnerabilities in MikroTik RouterOS are being actively exploited in the wild, targeting internet-exposed SSH services to achieve full system compromise.

exploited PoC RouterOS +4 active-exploitation network-security
1t 3c updated
high advisory

Authentication Bypass in Tenda AC9 Web Management

A critical authentication bypass vulnerability, CVE-2026-86300, exists in the Tenda AC9 firmware version 15.03.05.14, allowing remote attackers to circumvent security controls via the Web Management interface.

AC9 network-security authentication-bypass cve-2026-86300
1t
critical threat

OS Command Injection in Linksys RE7000 Range Extender

An OS command injection vulnerability (CVE-2026-86299) in the Linksys RE7000 version 2.0.15 allows unauthenticated remote code execution via the PingTest Handler component.

exploited RE7000 vulnerability rce network-security
1r 1t 1c
high advisory

Multiple Vulnerabilities in Netgate pfSense Plus and CE

Multiple vulnerabilities in Netgate pfSense Plus and CE allow remote attackers to execute arbitrary code or conduct cross-site scripting attacks, posing a high risk to network perimeter security.

pfSense Plus +1 vulnerability network-security firewall
2t
critical advisory

Critical Command Injection Vulnerability in Advantech WISE-6610 Gateways (CVE-2026-79697)

Advantech WISE-6610 series gateways are vulnerable to unauthenticated remote command injection via the Basic Station Certificate-Deletion Handler, potentially leading to full system compromise.

WISE-6610-NB +12 iot vulnerability cve network-security
2t 1c
high advisory

Heap Buffer Overflow in ntop nDPI

Versions of ntop nDPI before 6.0 are vulnerable to a heap-based buffer overflow in the ndpi_json_string_escape function, allowing attackers to trigger memory corruption via crafted network traffic.

nDPI vulnerability remote-code-execution network-security
1t 1c
medium advisory

Detection of Anomalous Network Activity from LOLBAS Binaries

This brief details a detection strategy for identifying unauthorized outbound network connections initiated by native Windows Living Off the Land Binaries and Scripts (LOLBAS) often used for C2 and payload delivery.

Windows lolbas defense-evasion network-security
1r 3t
high advisory

IBM ContextForge MCP Gateway SSRF via DNS Rebinding

IBM ContextForge MCP Gateway is susceptible to server-side request forgery (SSRF) via DNS rebinding, allowing a remote authenticated attacker to access sensitive internal network information.

ContextForge MCP Gateway cve-2026-77822 ssrf network-security
1t 1c
high advisory

Ted Backdoor Implant in Trojanized HAProxy Binaries

North Korean state-sponsored actors are deploying a sophisticated Linux backdoor named 'ted' by replacing legitimate HAProxy binaries with trojanized versions to intercept web traffic and execute malicious commands.

HAProxy linux backdoor malware network-security
3t 8i
high advisory

Remote Code Execution in MOOS essential-moos pAntler

The pAntler component in essential-moos versions 10.0.1 and earlier allows unauthenticated attackers to achieve remote code execution by publishing a crafted MISSION_FILE message to the MOOSDB.

essential-moos remote-code-execution vulnerability cve network-security
4t 1c
critical advisory

CVE-2026-85440: Heap Overflow in MOOS core-moos

A pre-authentication heap overflow vulnerability in the MOOSCommPkt packet handling of MOOS core-moos versions up to 10.4.0 allows remote unauthenticated attackers to perform arbitrary memory writes via crafted packets.

core-moos cve authentication-bypass middleware denial-of-service network-vulnerability vulnerability network-security remote-access
5t 1c
critical advisory

Authentication Bypass and Message Injection in MOOS pShare

The pShare component in MOOS essential-moos versions up to 10.0.1 is vulnerable to unauthenticated UDP message injection and denial-of-service.

essential-moos vulnerability remote-code-execution network-security cve authorization-bypass robotics
2t 1c
high threat

Cisco Releases Patches for Critical Infrastructure Vulnerabilities

Cisco has issued security advisories for unpatched S/MIME vulnerabilities in Secure Email and critical RCE and authentication bypass flaws across its IOS XR, Nexus, and VoIP phone product lines.

exploited Secure Email +6 vulnerability network-security patch-management informational
2t 5c
high advisory

Privilege Escalation in F5 BIG-IP TMUI via CVE-2026-66842

An authenticated user with any role can exploit a vulnerability in the F5 BIG-IP Traffic Management User Interface to create arbitrary administrative accounts.

BIG-IP privilege-escalation network-security f5
1t 1c
high advisory

Multiple Vulnerabilities in WatchGuard Fireware OS

Multiple vulnerabilities in WatchGuard Fireware OS, including the Mobile Security component, allow unauthenticated remote attackers to execute arbitrary code via specially crafted network traffic.

Fireware OS vulnerability network-security remote-code-execution watchguard
2t
medium advisory

Samba Denial of Service Vulnerability

A vulnerability in Samba tracked as CVE-2024-4323 allows a remote, authenticated attacker to trigger a Denial of Service condition through specific request handling.

Samba +1 denial-of-service vulnerability linux network-security
1t 1c
critical advisory

Command Injection in Cobham SATCOM VSAT7090 Maritime Satellite Router

An unauthenticated remote command injection vulnerability in the mail-report.sh script of Cobham SATCOM VSAT7090 devices allows attackers to execute arbitrary system commands via crafted JSON input.

VSAT7090 Maritime Satellite Router network-security remote-code-execution cve-2026-83772
1r 2t 1c
critical advisory

Critical Authentication Bypass in Tenda AC18 Telnet Handler

A critical authentication bypass vulnerability in the Tenda AC18 router allows remote, unauthenticated attackers to gain unauthorized access via the Telnet service.

AC18 critical-infrastructure network-security authentication-bypass
1t 1c
critical advisory

Authentication Bypass in Tenda AC1206 Web UI

Tenda AC1206 firmware version 15.03.06.23 contains an authentication bypass vulnerability in the /goform/telnet handler, allowing remote attackers to gain unauthorized access.

AC1206 vulnerability network-security web-application
1r 1t 1c
high advisory

Detection of Unauthorized RPC Traffic to the Internet

This brief details detection logic for identifying potentially malicious RPC traffic originating from internal segments toward external networks, a common vector for initial access and lateral movement.

network-security rpc initial-access lateral-movement
1r 2t
high advisory

Exposure of Remote Procedure Call Services to the Internet

Publicly accessible Remote Procedure Call (RPC) services on TCP port 135 facilitate initial access and backdoor establishment by threat actors.

initial-access network-security rpc exposure
1r 2t
medium advisory

Unauthorized VNC Exposure to the Internet

The exposure of VNC services to the public internet enables unauthorized remote access, providing adversaries a vector for initial access or persistent backdoors.

vnc c2 network-security remote-access
1r 2t
medium threat

Adversary Use of RAR and PowerShell Downloads for Tooling Delivery

Adversaries, including FIN7, utilize the downloading of RAR archives and PowerShell scripts from external sources to retrieve encoded or encrypted payloads to facilitate initial access and lateral movement.

PAN-OS +1 FIN7 +2 command-and-control ingress-tool-transfer network-security
1r 1t
critical advisory

Remote Stack-Based Buffer Overflow in D-Link DIR-825M

A critical stack-based buffer overflow vulnerability in D-Link DIR-825M firmware allows unauthenticated remote attackers to achieve code execution via the /boafrm/formDiskFormat endpoint.

PoC DIR-825M remote-code-execution buffer-overflow network-security
1r 2t 2c updated
high advisory

Authenticated OS Command Injection in PLANET GS-4210-16P2S

PLANET GS-4210-16P2S switches running firmware older than 3.441b260626 are vulnerable to authenticated OS command injection via the memberTags parameter.

GS-4210-16P2S cve-2026-75121 command-injection network-security
1r 2t 1c
high advisory

Critical Vulnerabilities in Ubiquiti UniFi Product Suite

Multiple high-severity vulnerabilities, including CVE-2026-77533 and CVE-2026-77537, affect Ubiquiti UniFi products, potentially allowing for system compromise.

UniFi Protect +2 vulnerability network-security
2c
medium advisory

Detection of Potential C2 via Recently Issued Self-Signed TLS Certificates

Detection engineers can identify potential C2 activity by flagging outbound TLS connections using recently issued self-signed certificates where issuer and subject distinguished names match.

command-and-control network-security tls threat-detection
2t
medium advisory

Detection of DNS Tunneling via Long and Unique Subdomains

This detection logic identifies potential DNS tunneling activity by monitoring for a high volume of unique, unusually long DNS subdomains directed to the same registered domain within a short timeframe.

command-and-control exfiltration network-security threat-detection
3t
medium advisory

Detection of Anomalous SonicWall Remote Access Logins

This detection logic identifies potentially unauthorized remote or administrative VPN access by monitoring for successful login combinations of user, source IP, and appliance not observed in the previous 14 days.

SonicWall Firewall identity-and-access-audit initial-access network-security
1r 2t
critical advisory

Critical OS Command Injection in DrayTek VigorSwitch

Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability (CVE-2026-71921) in the setget.cgi interface that allows unauthenticated remote attackers to execute arbitrary commands as root.

VigorSwitch G2540xs +10 vulnerability remote-code-execution network-infrastructure cve network-security network hardware
1r 3t 1c
medium advisory

Multiple Vulnerabilities in Cisco Industrial Ethernet 1000 Series Switches

Cisco Industrial Ethernet 1000 Series Switches contain multiple vulnerabilities, including CVE-2024-20412, CVE-2024-20413, and CVE-2024-20414, which allow unauthenticated attackers to cause a denial-of-service or perform cross-site scripting attacks.

Industrial Ethernet 1000 Series Switches vulnerability industrial-control-systems network-security
1t 3c
high advisory

Multiple Vulnerabilities in Cisco Secure Workload

Cisco Secure Workload is affected by multiple vulnerabilities allowing unauthenticated remote attackers to execute arbitrary code, escalate privileges, and cause service disruptions.

Secure Workload vulnerability cisco network-security
2t
medium advisory

Arista EOS and WiFi Access Point Denial of Service Vulnerability

A remote, unauthenticated attacker can exploit a vulnerability in Arista EOS and WiFi Access Point firmware to trigger a denial of service condition by crashing affected network devices.

EOS +1 denial-of-service network-security informational
1t
high advisory

Unauthenticated RCE in Netis NC63 via Stack Buffer Overflow

An unauthenticated stack-based buffer overflow in the Netis NC63 router management interface allows remote code execution via a crafted HTTP request to skk_set.cgi.

NC63 AC1200 Wireless Dual Band Gigabit MU-MIMO Router cve-2026-76071 rce network-security buffer-overflow
1r 2t
critical threat

Stack-based Buffer Overflow in TRENDnet TEW-755AP Access Points

A critical stack-based buffer overflow vulnerability in the /sbin/mycli binary of TRENDnet TEW-755AP access points allows remote unauthenticated attackers to execute arbitrary code via the 'ssid' argument.

exploited TEW-755AP remote-code-execution buffer-overflow iot networking vulnerability network-security cve-2026-76590 cve-2026-76591 +2
2r 3t 1c
critical advisory

Stack-Based Buffer Overflow in UTT HiPER 1250GW

A critical stack-based buffer overflow vulnerability in the UTT HiPER 1250GW HTTP handler allows remote authenticated attackers to execute arbitrary code via a crafted 'pvid' parameter.

HiPER 1250GW vulnerability cve network-security
2r 1t 1c updated
critical advisory

Remote Stack-Based Buffer Overflow in UTT HiPER 1200GW

A stack-based buffer overflow vulnerability in the UTT HiPER 1200GW router allows remote attackers to trigger memory corruption via a malicious 'timestart' parameter, with proof-of-concept exploits publicly available.

HiPER 1200GW remote-code-execution buffer-overflow network-security
1r 1t 1c
high advisory

Command Injection in TRENDnet Router via /cgi-bin/ping.cgi

A command injection vulnerability in TRENDnet Router 1.1.02b01 allows remote, authenticated attackers to execute arbitrary commands by manipulating the wan_type parameter.

Router cve-2026-75985 command-injection network-security
1r 1t 1c
critical advisory

Critical Stack-Based Buffer Overflow in TRENDnet TEW-WLC100

A critical stack-based buffer overflow in the TRENDnet TEW-WLC100 HTTP Header Handler allows remote attackers to achieve arbitrary code execution via a malformed 'Server' header.

TEW-WLC100 cve-2026-75784 buffer-overflow remote-code-execution network-security
1r 1t 1c
high advisory

Authorization Bypass in GL.iNet WebDAV Service

Multiple GL.iNet router models running firmware versions up to 4.8.x contain an authorization bypass vulnerability in the WebDAV service, allowing remote unauthenticated attackers to manipulate file operations.

A1300 +16 cve-2026-19980 remote-code-execution network-security firmware-vulnerability vulnerability rce network-infrastructure
1r 2t 1c
high advisory

Stack-Based Buffer Overflow in Tenda AC1206 Web Interface

A stack-based buffer overflow in the Tenda AC1206 firmware version 15.03.06.23_multi_TD01 allows remote attackers to trigger memory corruption via the httpd web management interface.

AC1206 vulnerability remote-code-execution network-security buffer-overflow
1r 1t 1c
critical advisory

Path Traversal in luci-app-openvpn via instance_name2 Parameter

An authenticated path traversal vulnerability in the luci-app-openvpn component of OpenWrt allows remote attackers to write arbitrary files to the filesystem and achieve persistent root-level code execution.

luci-app-openvpn path-traversal remote-code-execution openwrt network-security
2t 1c
low threat

CVE-2026-0292: Prisma Access Agent Local Security Inspection Bypass

A local authentication bypass vulnerability in the Palo Alto Networks Prisma Access Agent for Windows enables an administrative user to disable security inspections and manipulate network traffic.

exploited Prisma Access Agent vulnerability windows network-security
1t
high advisory

Multiple Vulnerabilities in SonicWall GMS

SonicWall GMS contains multiple vulnerabilities allowing remote code execution with root privileges, privilege escalation, security bypass, and information disclosure.

GMS vulnerability network-security sonicwall
3t
high advisory

Undertow AJP Authentication Bypass via CVE-2026-15554

The Undertow AJP listener incorrectly trusts ssl_cert and is_ssl attributes within the AJP protocol without validating a shared secret, allowing unauthenticated attackers to bypass CLIENT-CERT authentication.

Undertow vulnerability authentication-bypass network-security
2t 1c
critical advisory

OS Command Injection Vulnerability in Zyxel WAH7601

An OS command injection vulnerability in Zyxel WAH7601 devices (CVE-2026-13206) allows unauthenticated remote attackers to execute arbitrary system commands.

WAH7601 cve-2026-13206 command-injection zyxel network-device rce credential-access vulnerability networking +1
3t 1c
high threat

Remote Command Injection in Tenda CH22

Tenda CH22 firmware version 1.0.0.1 is vulnerable to unauthenticated remote command injection via the formCertListInfo function, allowing for arbitrary system command execution.

exploited CH22 command-injection iot network-security
1r 2t 1c
high advisory

Security Policy Bypass in SonicWall SonicOS

A security policy bypass vulnerability (CVE-2026-0516) in SonicWall SonicOS affects multiple hardware generations and virtual appliances, potentially allowing unauthorized access or configuration subversion.

SonicOS +3 vulnerability network-security firewall
1c
high advisory

ENDLESSDOORS Vulnerability Affecting Zbtlink Routers

Multiple Zbtlink router models are susceptible to the ENDLESSDOORS root implant, which leverages the rctl remote control tool for unauthorized access and persistent phone-home capabilities.

CPE2801 Firmware +19 firmware-vulnerability implant router network-security informational
1t
critical advisory

Zbtlink Router Firmware Contains Embedded ENDLESSDOORS Implant

Zbtlink router firmware ships with the ENDLESSDOORS remote-control implant, which runs as root, masquerades as a kernel process, and enables unauthenticated remote command execution.

PoC Router Firmware +20 supply-chain firmware backdoors remote-access-trojan network-security
3t 1c updated
high advisory

Path Traversal Vulnerability in Zyxel Network Appliance CLI

An authenticated path traversal vulnerability in Zyxel ATP and USG series firmware allows administrators to execute arbitrary configuration files, potentially leading to command execution.

ATP series +3 path-traversal network-security firmware
1t 1c
medium advisory

Detection of Destructive NFS File Operations

Detection logic identifies ransomware-like activity on NFS shares by flagging high-frequency bursts of successful WRITE, REMOVE, and RENAME operations from a single client within a one-minute window.

impact nfs ransomware network-security detection-engineering
2t
medium advisory

Unauthorized Memcached Data Manipulation via CVE-2026-29093

Unauthorized actors can leverage the lack of native authentication in Memcached to perform data manipulation or session hijacking, as identified in CVE-2026-29093.

Memcached network-security cve-2026-29093 impact
1r 1t 1c
medium advisory

Detection of SIP REGISTER Brute Force and Credential Spraying

Detection of malicious SIP REGISTER authentication attempts targeting VoIP infrastructure through anomalous 401, 403, and 407 response code patterns.

PBX +1 credential-access voip network-security
1r 2t
medium advisory

Detection of Unauthorized Apache Thrift RPC Invocations from External Networks

Detection logic targeting unauthorized Apache Thrift RPC method invocations from external IP addresses to identify exposed internal microservices or potential exploitation of data platforms.

Thrift network-security initial-access microservices
1r 1t 1c
high advisory

PostgreSQL COPY PROGRAM Command Execution

The PostgreSQL 'COPY ... PROGRAM' feature enables users with elevated privileges to execute arbitrary operating-system commands, a technique frequently abused by attackers to deploy cryptominers or establish persistence.

PostgreSQL execution network-security
1r 1t 1c updated
low advisory

Unusual Process Writing Data to an External Device Detected by Machine Learning

Elastic's Data Exfiltration Detection integration leverages machine learning to identify rare processes writing data to external devices, indicating potential data exfiltration by adversaries using benign-looking processes.

Elastic Defend +15 exfiltration machine-learning elastic-defend endpoint lateral-movement rdp anomaly-detection privilege-escalation +29
22t
low advisory

Potential Data Exfiltration Activity to an Unusual Destination Port

A machine learning job by Elastic detects potential data exfiltration by identifying anomalous network traffic patterns where high bytes are sent to an unusual destination port, suggesting data is being exfiltrated via command and control channels.

data-exfiltration machine-learning network-security elastic-defend network-packet-capture
2t
low advisory

Potential Data Exfiltration Activity to an Unusual IP Address

Elastic's machine learning rule detects potential data exfiltration by identifying anomalous network traffic, specifically large data transfers to unusual geo-locations via IP addresses, indicating possible exfiltration over command and control channels.

Data Exfiltration Detection integration +5 machine-learning network-security exfiltration data-loss-prevention elastic
1t
critical advisory

Progress Software LoadMaster and MOVEit WAF Vulnerabilities Lead to RCE and Root Privileges

Multiple vulnerabilities have been identified in Progress Software LoadMaster and MOVEit WAF products, allowing an attacker from an adjacent network to execute arbitrary program code and gain root privileges on the affected systems.

LoadMaster +1 progress-software moveit waf rce privilege-escalation network-security
3t
medium advisory

Accepted Default Telnet Port Connection

This threat brief details how threat actors exploit the insecure Telnet protocol on its default port 23 for initial access, lateral movement, and command and control, leveraging its unencrypted nature to compromise systems and exfiltrate data, emphasizing the need for robust detection and mitigation strategies.

telnet network-security remote-access plain-text initial-access lateral-movement command-and-control
1r 4t
medium advisory

Detecting Potential ICMP Tunneling Activity for Covert C2 and Exfiltration

This brief describes a critical network threat where attackers leverage ICMP tunneling, a technique to embed command and control (C2) or exfiltrated data within large ICMP Echo payloads, enabling covert communication channels that bypass traditional firewall rules, posing a significant risk of data theft and unauthorized system control.

network-security command-and-control data-exfiltration icmp-tunneling elastic-detection-rule
1r 2t
high advisory

Suspicious ICMP Redirect Messages from Internal Hosts Indicating MITM Activity

This brief details the detection of ICMP Redirect messages (IPv4 type 5, IPv6 type 137) originating from internal IP addresses, which strongly indicates Adversary-in-the-Middle (MITM) activity designed to manipulate routing, potentially leading to credential access or data exfiltration by directing target host traffic through a compromised internal system.

network-security credential-access mitm icmp
1r 1t
high advisory

Detection of Accepted Default Telnet Port Connection

This brief details the detection of unencrypted Telnet traffic on its default port 23, a legacy protocol commonly used for remote administration but frequently exploited by threat actors for initial access or as a backdoor due to its plain-text nature, which exposes sensitive information and facilitates unauthorized access.

command-and-control lateral-movement initial-access telnet network-security detection elastic-rule
1r 4t
medium advisory

Stormshield Network Security (SNS) Remote Denial-of-Service Vulnerability

A remote denial-of-service vulnerability exists in Stormshield Network Security (SNS) versions 4.3.x before 4.3.43, 4.4.x to 4.8.x before 4.8.16, and 5.x before 5.0.6, allowing an attacker to disrupt service availability.

Network Security +3 denial-of-service network-security cve-2025-9086
2r 1t 1c
critical advisory

free5GC NEF nnef-pfdmanagement API Unauthenticated Access Vulnerability

free5GC's NEF nnef-pfdmanagement API is vulnerable to unauthenticated access, allowing attackers with network access to read PFD data and create/delete PFD subscriptions by using forged bearer tokens due to the absence of inbound OAuth2/bearer-token authorization.

nef free5GC unauthenticated access CVE-2026-44330 PFD management network security
2r 1t 4i
medium advisory

Suricata Quadratic Complexity Issue in SMTP URL Searching (CVE-2026-31934)

Suricata versions 8.0.0 to before 8.0.4 exhibit a quadratic complexity vulnerability (CVE-2026-31934) when searching for URLs in MIME-encoded SMTP messages, leading to significant performance degradation and potential denial-of-service conditions; this is fixed in version 8.0.4.

suricata cve-2026-31934 denial-of-service performance network-security
2r 1t 1c 1i
medium advisory

Newly Observed Fortigate Alert

This brief covers a newly observed Fortigate alert rule added to the Elastic detection rules repository, potentially indicating emerging threat activity targeting Fortigate devices.

Fortigate intrusion-detection network-security
2r 7t
low advisory

AWS EC2 Route Table Created for Persistence or Defense Evasion

An EC2 Route Table creation event in AWS can indicate an attacker attempting to disrupt network traffic, reroute communications, or maintain persistence by creating unauthorized routes.

EC2 cloud aws persistence network-security
2r 2t
medium advisory

AWS EC2 Network Access Control List Deletion

The deletion of an Amazon EC2 network access control list (ACL) or its entries can indicate an attacker attempting to disable security controls for unauthorized access or data exfiltration.

AWS EC2 cloud aws ec2 network-security defense-evasion
2r 1t
high threat

Detection of Suspicious Cisco Configuration Changes via Archive Logging

This analytic detects suspicious configuration changes on Cisco devices by analyzing archive logs for activities such as backdoor account creation, SNMP community string modifications, and TFTP server configurations, potentially indicating attacker presence and lateral movement.

IOS +6 Static Tundra cisco network-security configuration-change
3r 2t 2c 6i updated