Vendor
Critical Vulnerabilities in Spring Tools IDE Extensions
5 CVEsMultiple vulnerabilities in Spring Tools for Eclipse and VSCode/Cursor/Theia allow for remote code execution, unauthorized service access, credential exposure, and cross-site scripting.
Toy Ghouls Deploying Custom GenieLocker Ransomware
1 rule 4 TTPs 1 IOCThe Toy Ghouls threat actor is deploying a custom ransomware family called GenieLocker against manufacturing organizations, utilizing compromised VPN credentials and legitimate system tools for lateral movement and encryption.
Critical Vulnerabilities in VMware vCenter and ESX Products
5 TTPs 4 CVEsMultiple critical vulnerabilities, including CVE-2026-59309 and CVE-2026-59310 with CVSS 9.8, affect VMware vCenter and ESX/ESXi products, enabling unauthorized access without credentials, arbitrary code execution, virtualization escape, information disclosure, and defense evasion, which could lead to full system compromise and data breaches.
VMware Cloud Foundation, vSphere, Aria Operations, and Tools: Multiple Vulnerabilities
1 TTPMultiple vulnerabilities exist in VMware Cloud Foundation, vSphere, Aria Operations, and VMware Tools, allowing an attacker to exploit these weaknesses to gain elevated privileges, including administrative access, and disclose confidential information within affected environments.
Potential CVE-2025-41244 vmtoolsd Local Privilege Escalation Attempt
1 rule 3 TTPs 1 CVEAttackers can exploit CVE-2025-41244, a local privilege escalation vulnerability in VMware Tools' `vmtoolsd` service and its `get-versions.sh` script on Linux, by manipulating the `PATH` environment variable to execute malicious binaries with elevated privileges when the service attempts to retrieve version information, potentially leading to a root shell.
Unusual Child Process Execution by Web Servers on Linux
2 rules 5 TTPs 13 IOCsThis detection rule identifies suspicious child process executions originating from web server processes on Linux systems, indicating that attackers may have exploited web application vulnerabilities such as command injection or remote file inclusion to establish persistence or execute malicious commands.
Qilin Ransomware Claims New Victim in Agriculture and Food Production Sector
2 rules 13 TTPs 156 IOCsThe Qilin ransomware group, active since July 2022 and utilizing Golang, has claimed a new victim, Danone (International Delights) in the US Agriculture and Food Production sector, employing double extortion tactics involving data encryption and threatened data release.
RabbitMQ Management UI UNC SSRF Vulnerability (CVE-2026-57211) on Windows
1 CVECVE-2026-57211 details a Server-Side Request Forgery (SSRF) vulnerability within the RabbitMQ management UI when deployed on Windows, enabling an attacker to coerce the server into making requests to arbitrary UNC paths, potentially leading to NTLM credential disclosure or internal network reconnaissance.
Adobe Security Updates — July 2026
5 CVEs 15 IOCsRoundup of Adobe security advisories published in July 2026.
Potential Proxy Execution via Systemd-run on Linux
1 rule 3 TTPsThis brief details how attackers may leverage the `systemd-run` utility on Linux systems for defense evasion and execution by running commands as detached, transient services or scopes to obscure their activities and parent-child process chains.
Mozilla Security Updates — July 2026
Roundup of Mozilla security advisories published in July 2026.
Microsoft Security Updates — July 2026
11 CVEs 354 IOCsRoundup of Microsoft security advisories published in July 2026.
Multiple Vulnerabilities in NetApp Products
2 rules 5 CVEsMultiple vulnerabilities in NetApp products, including CVE-2023-0482, CVE-2023-20863, CVE-2024-22257, CVE-2025-23367, CVE-2025-48976, CVE-2025-53816, and CVE-2025-53817, could lead to remote denial of service, data confidentiality breaches, and data integrity breaches.
ESXi External Root Login Detection
2 rules 1 TTPThis detection identifies instances where the ESXi UI is accessed using the root account instead of a delegated administrative user, which bypasses role-based access controls and may indicate risky behavior or unauthorized activity.
NetApp Active IQ Unified Manager and OnCommand Insight Remote Code Execution Vulnerability
2 rules 1 TTP 1 CVECVE-2023-22102 describes a vulnerability in NetApp Active IQ Unified Manager and OnCommand Insight that allows a remote attacker to execute arbitrary code.
VMware Tanzu Spring Framework Denial of Service Vulnerability
1 rule 1 TTPA remote, anonymous attacker can exploit a vulnerability in VMware Tanzu Spring Framework to perform a denial of service attack.
VMware Tanzu Spring Security Vulnerability Allows File Manipulation
2 rules 1 TTPA local attacker can exploit a vulnerability in VMware Tanzu Spring Security to manipulate files, potentially leading to privilege escalation.
VMware Tanzu Spring Framework Security Bypass Vulnerability
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in VMware Tanzu Spring Framework to bypass security measures.
Suspicious Kerberos Authentication Ticket Request
2 rules 2 TTPsThis rule detects suspicious Kerberos authentication ticket requests by correlating network connections to the standard Kerberos port (88) from a source machine with a Kerberos authentication ticket request from the target domain controller, which could indicate lateral movement or credential access attempts within a Windows domain.
VMware Tanzu Spring Cloud Config Multiple Vulnerabilities
2 rules 2 TTPsMultiple vulnerabilities in VMware Tanzu Spring Cloud Config could allow an attacker to disclose sensitive information or manipulate data.
VECT Ransomware Destroys Files Due to Encryption Flaw
2 rules 1 TTPVECT 2.0 ransomware, a RaaS offering, permanently destroys large files due to an encryption flaw, discarding decryption nonces for files above 128 KB, rendering them unrecoverable and effectively acting as a wiper; it uses raw ChaCha20-IETF with no authentication.
Broadcom Addresses Critical Vulnerabilities in VMware Tanzu Products
2 rulesBroadcom released a security advisory addressing critical vulnerabilities in VMware Tanzu Data Lake (versions prior to 4.0.0) and VMware Tanzu Greenplum Platform Extension Framework (versions prior to 8.0.0), requiring immediate patching to prevent potential exploitation.
VMware Tanzu Spring Boot Multiple Vulnerabilities
2 rules 4 TTPsMultiple vulnerabilities in VMware Tanzu Spring Boot allow attackers to execute arbitrary code, bypass security measures, manipulate or disclose sensitive data, or hijack authenticated users.
Persistence via Windows Installer (Msiexec)
3 rules 3 TTPsAdversaries may establish persistence by abusing the Windows Installer (msiexec.exe) to create scheduled tasks or modify registry run keys, allowing for malicious code execution upon system startup or user logon.
VMware Tanzu Spring Framework Multiple Vulnerabilities
2 rules 2 TTPsAn anonymous, remote attacker can exploit multiple vulnerabilities in VMware Tanzu Spring Framework to disclose information or circumvent security measures.
VMware Tanzu Spring Framework Vulnerability Allows File Manipulation
2 rules 1 TTPAn anonymous remote attacker can exploit a vulnerability in VMware Tanzu Spring Framework to manipulate files or disclose information.
VMkatz Tool for Extracting Windows Credentials from VM Memory Snapshots
2 rules 1 TTPVMkatz is a tool designed to extract Windows credentials directly from virtual machine memory snapshots and virtual disks, enabling unauthorized credential access.
ESXi System Information Discovery via ESXCLI
2 rules 1 TTPAdversaries may use ESXCLI system-level commands to retrieve configuration details on VMware ESXi hosts for reconnaissance purposes, potentially leading to further compromise.
ESXi System Clock Manipulation for Evasion
2 rules 1 TTPAn attacker manipulates the system clock on an ESXi host to potentially evade detection, disrupt logging, or invalidate security controls, as seen in ESXi Post Compromise scenarios and Black Basta ransomware incidents.
ESXi Root Account Compromise Indication
2 rules 2 TTPsThe detection identifies potentially compromised root accounts on ESXi hosts by monitoring the number of unique IP addresses logging in as root within a short time window, indicating credential misuse or lateral movement.
VMware Server-Side Template Injection Attempt (CVE-2022-22954)
2 rules 2 TTPsAn attacker attempts to exploit CVE-2022-22954, a server-side template injection vulnerability in VMware Workspace ONE Access and Identity Manager, by sending a crafted HTTP GET request containing malicious parameters to achieve remote code execution.
ESXi Host Reverse Shell Detection
3 rules 1 TTPThis detection identifies reverse shell string patterns on an ESXi host via syslog, potentially indicating a threat actor attempting to establish remote control over the system, which may lead to further compromise such as ransomware deployment.
ESXi Audit Tampering via esxcli
3 rules 2 TTPsAttackers use esxcli system auditrecords commands on ESXi hosts to tamper with logging, hindering forensic analysis and detection efforts, potentially leading to prolonged compromise and data breaches.
Unusual Process Loading Mozilla NSS/Mozglue Module
2 rules 1 TTPDetection of processes loading Mozilla NSS/Mozglue libraries (mozglue.dll, nss3.dll) outside of known Mozilla applications, potentially indicating malware or unauthorized activity.
Suspicious Module Loaded by LSASS for Credential Access
2 rules 2 TTPsDetection of unsigned or untrusted DLLs being loaded into the LSASS process, which is indicative of credential access attempts by adversaries aiming to steal sensitive information such as user passwords.
Kerberos Traffic from Unusual Process
2 rules 2 TTPsDetects network connections to the standard Kerberos port from an unusual process other than lsass.exe, potentially indicating Kerberoasting or Pass-the-Ticket activity on Windows systems.
ESXi VM Exfiltration via Remote Tool
2 rules 1 TTPAttackers or malicious insiders may leverage remote tools and the NFC protocol to download virtual machine disk files from ESXi datastores, potentially leading to sensitive data exfiltration.
ESXi VIB Acceptance Level Tampering
2 rules 1 TTPAttackers modify the ESXi VIB acceptance level to install unsigned or unverified software, weakening the host's integrity enforcement.
ESXi User Granted Administrator Role
2 rules 2 TTPsA user being granted the Administrator role on an ESXi host is a critical action that can indicate potential malicious behavior, as adversaries may use this to escalate privileges, maintain persistence, or disable security controls.
ESXi Syslog Configuration Changes via esxcli
2 rules 1 TTPDetection of ESXi syslog configuration changes via esxcli command, potentially indicating an attempt to disrupt logging and evade detection.
ESXi Syslog Configuration Change via esxcli
2 rules 1 TTPDetection of ESXi syslog configuration changes using esxcli, potentially indicating an attempt to disrupt logging and evade detection, with known association to Black Basta ransomware.
ESXi SSH Enabled Detection
2 rules 1 TTPThe enabling of SSH on ESXi hosts, as detected in ESXi Syslog, can signal malicious lateral movement by threat actors aiming for persistent access.
ESXi SSH Brute-Force Attack Attempt
2 rules 1 TTPDetection of a potential brute-force attack against an ESXi host via SSH by monitoring for a high number of failed login attempts within a short time frame, indicating an attacker attempting to gain unauthorized access.
ESXi Shell Enabled Detection
2 rules 1 TTPThe ESXi Shell being enabled on a host may indicate malicious activity like preparing to execute commands locally or establishing persistent access.
ESXi Sensitive File Access Attempt
2 rules 2 TTPsAn adversary attempts to access sensitive system and configuration files on an ESXi host, potentially for reconnaissance, credential harvesting, privilege escalation, lateral movement, or persistence.
ESXi Lockdown Mode Disabled
2 rules 1 TTPDetection of ESXi Lockdown Mode being disabled, potentially indicating attacker attempts to weaken host security controls for broader access, data exfiltration, or VM tampering.
ESXi Firewall Disabled Detection
2 rulesThis detection identifies when the ESXi firewall is disabled or set to permissive mode, potentially exposing the host to unauthorized access and network-based attacks, often preceding lateral movement, data exfiltration, or malware installation.
ESXi Firewall Disabled
2 rules 1 TTPThe ESXi firewall being disabled or set to permissive mode can expose the host to unauthorized access and network-based attacks, often preceding lateral movement, data exfiltration, or malware installation.
ESXi External Root Login Activity Detection
2 rules 1 TTPDetection of ESXi UI access using the root account from external IP addresses, bypassing role-based access controls and potentially indicating unauthorized activity or compromised credentials.
ESXi Encryption Settings Modified
2 rules 2 TTPsAttackers modify ESXi host encryption settings, such as disabling secure boot or executable verification, to weaken hypervisor integrity and enable unauthorized code execution.
ESXi Encryption Settings Modification
2 rulesDetection of modifications to ESXi host encryption settings, such as disabling secure boot or executable verification, which may indicate attempts to weaken hypervisor integrity and allow unauthorized code execution.
ESXi Download Error Detection
2 rules 2 TTPsDetection of failed file download attempts on ESXi hosts, potentially indicating unauthorized or malicious activity such as installing or updating components, including VIBs or scripts.
ESXi Bulk VM Termination Detection
2 rules 2 TTPsDetection of abrupt virtual machine termination on ESXi hosts, potentially indicating denial-of-service, ransomware staging, or destruction of critical workloads.
ESXi Audit Tampering Detection
2 rules 1 TTPDetection identifies the use of the esxcli system auditrecords commands to tamper with logging on an ESXi host, potentially evading detection and hindering forensic analysis.
DNS Kerberos Coercion Attempt Detection
3 rules 3 TTPs 3 IOCsThis brief details the detection of DNS-based Kerberos coercion attacks, where adversaries inject marshaled credential structures into DNS records to spoof SPNs and redirect authentication, as seen in CVE-2025-33073, using Suricata and Sysmon event ID 22.
Detection of Failed ESXi File Downloads
2 rules 2 TTPsThis detection identifies failed file download attempts on ESXi hosts by looking for specific error messages in system logs, potentially indicating unauthorized attempts to install malicious components or scripts.
VMware Aria Operations CVE-2023-20887 Exploitation Attempt
2 rules 1 TTPDetection of potential exploitation attempts against VMware Aria Operations (formerly vRealize Network Insight) by monitoring for HTTP POST requests to the /saas./resttosaasservlet endpoint, indicative of CVE-2023-20887 exploitation leading to arbitrary code execution.
Potential Persistence via Time Provider Modification
2 rules 2 TTPsAdversaries may establish persistence by registering and enabling a malicious DLL as a time provider by modifying registry keys associated with the W32Time service.
LSASS Loading Suspicious DLL
2 rules 2 TTPs 9 IOCsDetection of LSASS loading an unsigned or untrusted DLL, which can indicate credential access attempts by malicious actors targeting sensitive information stored in the LSASS process.
ESXi Loghost Configuration Tampering
2 rules 1 TTPAttackers modify the ESXi host's syslog configuration to disrupt log forwarding, potentially evading detection and hindering incident response efforts after a compromise.
ESXi Account Modification Detection
2 rules 7 TTPsDetection of local user account creation, deletion, or modification on an ESXi host, potentially indicating unauthorized access, persistence attempts, or defense evasion.
ESXi VM Discovery via ESXCLI Commands
2 rulesAdversaries may use ESXCLI commands to discover virtual machines on an ESXi host, potentially indicating reconnaissance for high-value targets, environment mapping, or preparation for data theft or destructive operations.
ESXi Loghost Configuration Tampering
2 rules 1 TTPAn attacker modifies the ESXi host's syslog configuration to disrupt log forwarding, potentially evading detection and hindering incident response.