Tag
Detection of SSH Reverse Port Forwarding on Windows
1 rule 3 TTPsAdversaries are abusing native Windows OpenSSH and Plink binaries to establish unauthorized reverse SSH tunnels, bypassing inbound connectivity controls for C2 and lateral movement.
Artica Proxy Session Fixation Vulnerability CVE-2026-66745
1 TTP 1 CVE 1 IOCA session fixation vulnerability, CVE-2026-66745, in Artica Proxy before version 4.50.000000 Service Pack 7 allows unauthenticated attackers to hijack administrative sessions by pre-setting a PHPSESSID on a victim's browser, leading to full administrative control upon victim authentication.
CVE-2026-63770: Glance IP Address Spoofing Vulnerability Bypasses Brute-Force Lockout
1 rule 2 TTPs 1 CVEA vulnerability in Glance through version 0.8.5 allows unauthenticated attackers to bypass brute-force lockout protections by manipulating the X-Forwarded-For HTTP header with arbitrary values, making each login attempt appear to originate from a distinct IP address when the server's proxied option is enabled, thereby enabling unlimited credential guessing against the authentication endpoint.
HelloNet Campaign Uses ViPNet Update System for Malicious Module Delivery
3 rules 11 TTPs 1 IOCAn unknown sophisticated threat actor is leveraging DLL sideloading within the ViPNet update system to deploy a multi-stage malware suite, including HelloInjector, HelloProxy, HelloExecutor, HelloCleaner, and HelloBackdoor, to establish persistence, exfiltrate data, and maintain covert access to large Russian organizations in government, energy, and other critical sectors.
CVE-2026-12382 - AAP Gateway Envoy Proxy Authentication Bypass
2 TTPs 1 CVEA critical authentication bypass vulnerability (CVE-2026-12382) exists in the AAP Gateway Envoy proxy configuration within Red Hat Ansible Automation Platform 2 where the non-mTLS route to EDA event streams fails to remove the Subject HTTP header from client requests, allowing an unauthenticated remote attacker to inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams.
OpenClaw Vulnerability Allows Local Forged Identity Headers
2 TTPsA vulnerability (GHSA-rggc-m335-3wvj) in OpenClaw's trusted-proxy deployments allows a local attacker on the same host to forge identity headers, bypassing intended security controls and potentially leading to unauthorized access or privilege escalation if the affected feature is enabled and reachable.
Multiple Vulnerabilities in Squid Proxy (CVE-2026-47729, CVE-2026-50012)
3 TTPs 2 CVEsMultiple vulnerabilities, including CVE-2026-47729 and CVE-2026-50012, have been identified in Squid proxy versions prior to 7.6, allowing an attacker to compromise data confidentiality and cause other unspecified security issues.
CVE-2026-55203 HAProxy Integer Overflow in FastCGI Handling
2 rules 3 TTPsAn integer overflow vulnerability (CVE-2026-55203) in HAProxy through version 3.4.0 allows malicious FastCGI backends to desynchronize the FCGI framing parser, leading to request routing errors, response smuggling, or memory safety issues.
Heimdall Proxy Forwarded Header Injection via Unsanitized Host Header
1 rule 1 TTPAttackers can exploit Heimdall proxy versions <= 0.17.16 operating in proxy mode by injecting malicious values into the `Host` HTTP header, leading to the construction of a manipulated `Forwarded` header that can spoof client IP addresses for upstream services, potentially bypassing IP-based access controls.
Squid Vulnerability Allows Security Bypass and Information Disclosure
2 rules 2 TTPsA remote, anonymous attacker can exploit a vulnerability in Squid to bypass security precautions and disclose information, potentially leading to unauthorized access or data leakage.
Caddy Defender Client IP Bypass Vulnerability (CVE-2026-46415)
2 rules 1 TTPCaddy Defender versions before v0.10.1 are vulnerable to a client IP bypass (CVE-2026-46415) when deployed behind a trusted proxy, allowing blocked clients to bypass Defender's IP-based restrictions.
CVE-2026-7168 Cross-Proxy Digest Authentication State Leak
2 rules 1 CVEMicrosoft published information regarding CVE-2026-7168, a cross-proxy Digest authentication state leak.
Goobi Viewer Unauthenticated Solr Streaming Expression Proxy Vulnerability
2 rules 1 TTPThe Goobi viewer REST endpoint accepted an arbitrary Solr streaming expression from unauthenticated network clients, enabling attackers to read, modify, or delete the complete Solr index; this was resolved by removing the affected API endpoint.
Potential Protocol Tunneling via Cloudflared
2 rules 2 TTPs 1 IOCAdversaries may abuse Cloudflare Tunnel (cloudflared) on Windows systems to proxy command and control traffic or exfiltrate data through Cloudflare's edge, evading direct connection blocking.
Mirax RAT Targeting Android Users in Europe
2 rules 4 TTPsMirax RAT, a new Android RAT distributed as MaaS, is targeting European users by turning infected devices into residential proxy nodes and enabling credential theft via overlay and notification injection.
Okta Initial Access via Proxy
2 rules 1 TTPDetection of a first-time user session started via a proxy, potentially indicating unauthorized initial access.
Windows TOR Client Execution Detection
2 rules 1 TTPDetects the execution of the TOR Browser and related components on Windows endpoints, indicating potential anonymization of traffic for command and control, data exfiltration, or policy evasion by adversaries or insider threats.
Okta User Session Start via Anonymizing Proxy Service
2 rules 1 TTPDetection of Okta user sessions initiated through anonymizing proxy services, potentially indicating malicious activity or attempts to evade security controls.