Vendor
Public Exploit for Linux Kernel Use-After-Free Vulnerability CVE-2026-43499
1 TTP 2 CVEs 6 IOCsA public exploit has been published for CVE-2026-43499, a Use-After-Free vulnerability in the Linux Kernel, demonstrated to achieve KASLR bypass and potential privilege escalation on Android 15 devices running Linux Kernel 5.15.149, significantly elevating risk for unpatched systems.
Shai-Hulud Campaign Activity
25 IOCsTracking brief for the Shai-Hulud campaign; individual sightings are folded in as reported.
Adobe Security Updates — July 2026
5 CVEs 15 IOCsRoundup of Adobe security advisories published in July 2026.
Potential Proxy Execution via Systemd-run on Linux
1 rule 3 TTPsThis brief details how attackers may leverage the `systemd-run` utility on Linux systems for defense evasion and execution by running commands as detached, transient services or scopes to obscure their activities and parent-child process chains.
ClickFix Campaign Activity
16 IOCsTracking brief for the ClickFix campaign; individual sightings are folded in as reported.
Mozilla Security Updates — July 2026
Roundup of Mozilla security advisories published in July 2026.
Google Security Updates — July 2026
5 CVEs 41 IOCsRoundup of Google security advisories published in July 2026.
Microsoft Security Updates — July 2026
11 CVEs 354 IOCsRoundup of Microsoft security advisories published in July 2026.
Firefox for iOS Security Policy Bypass Vulnerability
2 rules 1 TTPA vulnerability in Firefox for iOS versions prior to 151.1 allows an attacker to bypass the security policy (CVE-2026-9078).
Multiple Vulnerabilities in Mozilla Products Lead to Potential RCE and Privilege Escalation
2 rules 3 TTPs 4 CVEsMultiple vulnerabilities in Mozilla Firefox ESR, Firefox, Firefox for iOS, and Thunderbird products can lead to arbitrary code execution, privilege escalation, and remote denial of service.
Multiple Vulnerabilities in Mozilla Firefox and Thunderbird
2 rules 5 TTPsMultiple vulnerabilities in Mozilla Firefox, Firefox ESR, and Thunderbird could allow a remote attacker to execute arbitrary code, disclose information, bypass security restrictions, deceive the user, escalate privileges, or cause a denial-of-service condition.
Multiple Vulnerabilities in Mozilla Firefox and Thunderbird
2 rules 2 TTPsMultiple vulnerabilities exist in Mozilla Firefox, Firefox ESR, and Thunderbird that could allow a remote attacker to execute arbitrary code, disclose sensitive information, bypass security measures, or conduct cross-site scripting or spoofing attacks.
Mozilla Firefox Security Updates Released
1 ruleMozilla released security updates on May 19, 2026, addressing vulnerabilities in Firefox versions prior to 151, Firefox ESR versions prior to 115.36, and Firefox ESR versions prior to 140.11.
SHub macOS Infostealer Variant 'Reaper' Spoofing Apple Security Updates
3 rules 5 TTPs 3 IOCsA new variant of the 'SHub' macOS infostealer, dubbed Reaper, uses AppleScript to display a fake security update message and install a backdoor, ultimately stealing browser data, financial documents, and cryptocurrency wallet information while bypassing Terminal-based mitigations in macOS.
Siemens Teamcenter Vulnerability CVE-2026-33862 - Cross-Site Scripting
2 rules 1 TTP 3 CVEs 3 IOCsSiemens Teamcenter versions V2312 (before V2312.0014), V2406 (before V2406.0012), V2412 (before V2412.0009), V2506 (before V2506.0005), and V2512 are vulnerable to cross-site scripting (XSS) due to improper encoding or filtering of user-supplied data, potentially leading to arbitrary code execution by other users.
Mozilla Firefox Multiple Vulnerabilities
2 rules 2 TTPsMozilla released security updates to address vulnerabilities in Firefox and Firefox ESR versions, potentially allowing for exploitation if left unpatched.
Multiple Vulnerabilities in Mozilla Thunderbird Allow for Remote Code Execution and Data Breach
2 rules 4 TTPs 5 CVEsMultiple vulnerabilities in Mozilla Thunderbird prior to versions 150.0.1 and Thunderbird ESR prior to 140.10.1 could allow a remote attacker to achieve arbitrary code execution, data confidentiality breach, and security policy bypass.
Mozilla Firefox Multiple Vulnerabilities
2 rules 3 TTPsMozilla released a security advisory addressing vulnerabilities in Firefox and Firefox ESR versions prior to 150.0.1, 140.10.1, and 115.35.1, potentially leading to arbitrary code execution or information disclosure.
Unusual Execution via Microsoft Common Console File
2 rules 2 TTPsAdversaries may embed a malicious command in an MSC file in order to trick victims into executing malicious commands, leading to initial access and execution of arbitrary code.
Suspicious Child Processes from Communication Applications
3 rules 3 TTPsThe detection rule identifies suspicious child processes spawned from communication applications on Windows systems, potentially indicating masquerading or exploitation of vulnerabilities within these applications.
Mozilla Firefox Audio/Video Boundary Condition Vulnerability (CVE-2026-4714)
2 rules 3 TTPsCVE-2026-4714 is a high-severity vulnerability affecting Firefox, Firefox ESR, and Thunderbird due to incorrect boundary conditions in the Audio/Video component, potentially leading to denial-of-service.
Firefox 0-day Drops OSX.Mokes.B Backdoor on macOS
2 rules 5 TTPs 1 IOCA Firefox 0-day exploit was used to target Mac users, dropping a second backdoor identified as a new variant of the cross-platform Mokes malware (OSX.Mokes.B) with screen capture, audio capture, and document exfiltration capabilities.
Mozilla Firefox and Thunderbird GMP Component Denial-of-Service Vulnerability (CVE-2026-4709)
2 rules 1 TTPA vulnerability exists in the Audio/Video: GMP component of Mozilla Firefox and Thunderbird due to incorrect boundary conditions, potentially leading to a denial-of-service condition.
OSX/CreativeUpdater Cryptominer Distributed via MacUpdate
3 rules 2 TTPs 7 IOCsOSX/CreativeUpdater is a macOS cryptominer distributed through compromised download links on the MacUpdate website, using a trojanized application bundle to execute a script that downloads and installs a persistent Monero miner using launch agents.
Mozilla Firefox and Thunderbird Information Disclosure Vulnerability (CVE-2026-4712)
2 rules 1 TTPCVE-2026-4712 is an information disclosure vulnerability in the Widget: Cocoa component affecting Firefox versions less than 149, Firefox ESR versions less than 140.9, Thunderbird versions less than 149, and Thunderbird versions less than 140.9, potentially allowing a remote attacker to access sensitive information.
Detection of Malicious Browser Extension Installation
2 rulesThis rule detects the installation of browser extensions, a persistence mechanism where attackers install malicious extensions via app store downloads, social engineering, or compromised systems, focusing on file creation events in extension directories on Windows.
Mozilla Firefox and Thunderbird Canvas2D Improper Boundary Conditions Vulnerability (CVE-2026-4686)
2 rules 1 TTPCVE-2026-4686 is a high-severity vulnerability due to incorrect boundary conditions in the Canvas2D component of Mozilla Firefox and Thunderbird, potentially leading to a denial-of-service condition.
Mozilla Products Graphics Component Boundary Condition Vulnerability (CVE-2026-4713)
2 rules 1 TTPCVE-2026-4713 is a high-severity vulnerability due to incorrect boundary conditions in the Graphics component of Mozilla Firefox, Firefox ESR, and Thunderbird, potentially leading to denial of service.
Mozilla Firefox and Thunderbird Graphics Component Vulnerability (CVE-2026-4708)
2 rules 1 TTPCVE-2026-4708 is a high-severity vulnerability involving incorrect boundary conditions in the Graphics component, impacting Firefox versions earlier than 149, Firefox ESR versions before 140.9, Thunderbird versions before 149, and Thunderbird versions prior to 140.9, potentially leading to a denial-of-service.
Mozilla Firefox WebRender Use-After-Free Vulnerability (CVE-2026-4684)
2 rules 1 TTPCVE-2026-4684 is a race condition and use-after-free vulnerability in the Graphics: WebRender component affecting Firefox versions less than 149, Firefox ESR versions less than 115.34 and 140.9, and Thunderbird versions less than 149 and 140.9, potentially leading to arbitrary code execution.
Mozilla Firefox and Thunderbird JIT Miscompilation Vulnerability (CVE-2026-4702)
3 rules 2 TTPsA critical JIT miscompilation vulnerability (CVE-2026-4702) in the JavaScript Engine affects Firefox and Thunderbird, potentially allowing remote code execution.
Mozilla Firefox and Thunderbird WebRTC Undefined Behavior Vulnerability (CVE-2026-4705)
2 rules 3 TTPs 2 IOCsAn undefined behavior vulnerability in the WebRTC signaling component affects Mozilla Firefox and Thunderbird, potentially leading to arbitrary code execution.
Unusual Process Loading Mozilla NSS/Mozglue Module
2 rules 1 TTPDetection of processes loading Mozilla NSS/Mozglue libraries (mozglue.dll, nss3.dll) outside of known Mozilla applications, potentially indicating malware or unauthorized activity.
OSX.NetWire.A Backdoor Dropped via Firefox 0-day
3 rules 2 TTPs 4 IOCsA Firefox zero-day exploit was used to target Mac users, resulting in the installation of the OSX.NetWire.A malware, which establishes persistence and communicates with a command and control server.
Mozilla Firefox Use-After-Free Vulnerability in Widget: Cocoa Component (CVE-2026-4711)
2 rules 1 TTP 1 IOCA use-after-free vulnerability in the Widget: Cocoa component of Mozilla Firefox (versions less than 149), Firefox ESR (less than 140.9), Thunderbird (less than 149), and Thunderbird (less than 140.9) could lead to arbitrary code execution.
Kerberos Traffic from Unusual Process
2 rules 2 TTPsDetects network connections to the standard Kerberos port from an unusual process other than lsass.exe, potentially indicating Kerberoasting or Pass-the-Ticket activity on Windows systems.
Unusual Process Accessing Browser Password Store
2 rules 1 TTPA Windows anomaly detection identifies non-browser processes accessing browser user data profiles, indicative of credential theft by malware such as SnakeKeylogger, which attempts to gather sensitive browser information.
RMM Domain DNS Queries from Non-Browser Processes
2 rules 75 IOCsDetects DNS queries to commonly abused remote monitoring and management (RMM) or remote access software domains from non-browser processes, potentially indicating unauthorized remote access or command and control activity.
Potential Masquerading as Communication Apps
2 rules 3 TTPsAttackers may attempt to evade defenses by masquerading malicious processes as legitimate communication applications such as Slack, WebEx, Teams, Discord, RocketChat, Mattermost, WhatsApp, Zoom, Outlook and Thunderbird.
Mozilla Firefox and Thunderbird Improper Boundary Condition Vulnerability (CVE-2026-4699)
2 rules 1 TTPCVE-2026-4699 describes an improper check for unusual or exceptional conditions in the Layout: Text and Fonts component of Mozilla Firefox and Thunderbird leading to a potential denial-of-service.
Malicious Termination of Browser Processes via Taskkill
2 rules 1 TTPThe use of taskkill to forcibly terminate browser processes such as Chrome, Firefox, and Edge, often associated with credential-stealing malware like Braodo stealer, is detected, allowing it to unlock and steal sensitive browser data.
DNS-over-HTTPS Enabled via Registry Modification
3 rules 2 TTPsDetection of DNS-over-HTTPS (DoH) being enabled via registry modifications on Windows systems, potentially indicating defense evasion and obfuscation of network activity by masking DNS queries.
DNS-over-HTTPS Enabled via Registry Modification
3 rules 2 TTPsDetection of DNS-over-HTTPS (DoH) being enabled via registry modifications on Windows systems, potentially indicating defense evasion by masking network activity and hindering traditional DNS monitoring.
Windows Scheduled Task Creation for Persistence
3 rules 1 TTPAdversaries may create scheduled tasks on Windows systems to establish persistence, move laterally, or escalate privileges, and this detection identifies such activity by monitoring Windows event logs for scheduled task creation events, excluding known benign tasks and those created by system accounts.
Masquerading Business Application Installers
2 rules 4 TTPsAttackers masquerade malicious executables as legitimate business application installers to trick users into downloading and executing malware, leveraging defense evasion and initial access techniques.
CVE-2026-4722 - Mozilla Firefox and Thunderbird Privilege Escalation
2 rules 1 TTP 1 IOCCVE-2026-4722 is a privilege escalation vulnerability in the IPC component of Mozilla Firefox and Thunderbird versions less than 149, potentially allowing an attacker to gain elevated privileges on a compromised system.
Convict NPM Package Prototype Pollution Vulnerability
2 rulesThe `convict` npm package is vulnerable to prototype pollution via the `load()`, `loadFile()`, and schema initialization functions, allowing attackers to overwrite properties on `Object.prototype` by supplying malicious input, potentially leading to unexpected behavior, authentication bypass, or remote code execution, affecting versions 6.2.4 and earlier.
Use-After-Free Vulnerability in Firefox, ESR, and Thunderbird CSS Parsing (CVE-2026-4691)
2 rules 3 TTPsA use-after-free vulnerability (CVE-2026-4691) in the CSS Parsing and Computation component affects Firefox versions prior to 149, Firefox ESR versions prior to 115.34 and 140.9, and Thunderbird versions prior to 149 and 140.9, potentially leading to arbitrary code execution.
Non-Firefox Process Accessing Firefox Profile Directory
2 rules 1 TTPDetection of non-Firefox processes accessing the Firefox profile directory, potentially indicating malware attempting to steal user credentials and data.