Vendor
medium
advisory
OpenVPN Connect MacOS Local Privilege Escalation Vulnerability
2 rules 1 TTPA local attacker can exploit a vulnerability in OpenVPN Connect on MacOS to escalate their privileges.
OpenVPN Connect
privilege-escalation
macos
2r
1t
medium
advisory
BadIIS Malware-as-a-Service Ecosystem Targeting IIS Servers
2 rules 1 TTP 6 IOCsA commodity BadIIS malware variant is fueling a thriving malware-as-a-service (MaaS) ecosystem for Chinese-speaking cybercrime groups, allowing them to execute malicious SEO fraud, hijack server content, and redirect traffic to illicit sites.
Photoshop +3
iis
malware
maas
seo fraud
2r
1t
6i
medium
advisory
Persistence via Windows Installer (Msiexec)
3 rules 3 TTPsAdversaries may establish persistence by abusing the Windows Installer (msiexec.exe) to create scheduled tasks or modify registry run keys, allowing for malicious code execution upon system startup or user logon.
Windows +21
persistence
defense-evasion
3r
3t