Vendor
medium
advisory
CVE-2026-60109 - Zeek Kerberos Protocol Analyzer Null Pointer Dereference
1 TTP 1 CVEA null pointer dereference vulnerability (CVE-2026-60109) exists in Zeek's Kerberos protocol analyzer before version 8.0.9, allowing unauthenticated remote attackers to crash a Zeek sensor by sending a specially crafted KRB_ERROR message with error-code 25 and specific PA-DATA elements, leading to a denial-of-service condition.
Zeek
vulnerability
network
dos
kerberos
1t
1c
high
advisory
Web Server Potential SQL Injection Attempt Detection
1 rule 6 TTPsThis brief details the detection of potential SQL injection (SQLi) attempts against web servers by identifying common SQLi patterns in URLs and query strings, used by threat actors for reconnaissance, data exfiltration, or command execution, aiming for sensitive information disclosure or system compromise.
Apache +5
sql-injection
web-attack
reconnaissance
initial-access
data-exfiltration
command-execution
persistence
cross-platform
1r
6t