New ThreatClaw Detections: Exploited CVEs & Advanced Web Threats
This week’s update expands coverage for 20+ exploited CVEs, critical web vulnerabilities, and 20+ malware families, hardening defenses against initial access and persistence threats.
New ThreatClaw Detections: Exploited CVEs & Advanced Web Threats
This week, ThreatClaw expanded detection coverage with 355 new Sigma rules and 22 YARA files, addressing critical vulnerabilities, web-based exploitation, and advanced malware families. Below is a summary of the most significant updates.
Exploited CVEs: Critical Vulnerabilities Now Detected
ThreatClaw now detects exploitation attempts for two newly added Known Exploited Vulnerabilities (KEVs):
-
CVE-2026-45659 (Microsoft SharePoint Server): This vulnerability enables unauthenticated attackers to execute arbitrary code via crafted requests, leading to initial access (T1190) and potential lateral movement. SharePoint’s widespread enterprise use makes it a prime target for threat actors seeking to compromise internal networks.
-
CVE-2026-48558 (SimpleHelp): A remote code execution flaw in SimpleHelp’s remote support software, allowing attackers to gain footholds in environments where the tool is deployed. Exploitation aligns with T1190 (Exploit Public-Facing Application) and can facilitate persistence (T1505.003) or command-and-control (T1071.001).
Web Exploitation: Hardening Defenses Against Initial Access
A significant portion of this week’s updates focuses on web-based exploitation, a favored tactic for gaining initial access. New detections cover:
-
20+ exploited CVEs in web applications and frameworks, including:
- CVE-2024-3400 (Palo Alto Networks PAN-OS): A critical command injection flaw enabling unauthenticated RCE, actively exploited in the wild. Aligns with T1190 and T1059 (Command and Scripting Interpreter).
- CVE-2023-22515 (Atlassian Confluence): A privilege escalation vulnerability allowing attackers to create admin accounts, facilitating persistence (T1098) and data exfiltration (T1048).
- CVE-2023-42793 (JetBrains TeamCity): Enables authentication bypass and RCE, often used to deploy backdoors or ransomware. Tied to T1190 and T1505.003 (Server Software Component).
-
Common Web Attack Techniques:
- Local file inclusion/path traversal (T1083, T1190): Detects attempts to access sensitive files or execute arbitrary code via malicious URI requests.
- OS command injection (T1190): Identifies exploitation of vulnerable web inputs to execute system commands.
- Vulnerability scanning (T1592.004, T1595.002): Flags reconnaissance activity, such as probes for exposed endpoints or sensitive files, often preceding exploitation.
-
Vendor-Specific Exploits:
- Citrix (CVE-2025-5777, CVE-2023-24489): Covers CitrixBleed memory disclosure and ShareFile RCE, both leveraged in recent campaigns for credential theft (T1552.001) and lateral movement (T1021.001).
- Ivanti (CVE-2023-46805/CVE-2024-21887, CVE-2024-21893): Detects exploitation of Ivanti Connect Secure flaws, including command injection and SSRF, used to bypass authentication and deploy webshells (T1505.003).
- Adobe ColdFusion (CVE-2023-29298, CVE-2023-26360): Addresses access control bypass and arbitrary file read vulnerabilities, enabling data theft (T1005) and persistence (T1546.003).
Malware Families: Expanding Coverage for Advanced Threats
ThreatClaw added 22 YARA files to detect sophisticated malware families, including:
-
ESET-tracked families:
- AnimalFarm, Gazer, InvisiMole, Kobalos: Advanced backdoors and spyware used by threat actors for espionage (T1059.001), data exfiltration (T1048), and persistence (T1547.001).
- Carbon, SparklingGoblin, Turla-Outlook: Modular malware frameworks enabling lateral movement (T1021.002), credential dumping (T1003), and command-and-control (T1071.001).
- Stantinko, Mozi: Botnets and cryptocurrency miners leveraging T1059.007 (JavaScript) and T1496 (Resource Hijacking) for financial gain or DDoS attacks.
-
Other notable families:
- RedLine: A prevalent infostealer targeting credentials, browser data, and cryptocurrency wallets, aligning with T1003.001 (LSASS Memory) and T1552.001 (Credentials in Files).
- SSHDoor: A backdoor targeting SSH services for persistence (T1543.003) and remote access (T1021.004).
MITRE ATT&CK Techniques: Broadened Coverage
This update enhances detection for 80+ MITRE ATT&CK techniques, including:
- Initial Access (T1190, T1133): Exploiting public-facing applications and external remote services.
- Persistence (T1546.003, T1547.001): Abusing startup folders, registry keys, and scheduled tasks.
- Privilege Escalation (T1068, T1548.002): Exploiting vulnerabilities or abusing token manipulation.
- Defense Evasion (T1027, T1070): Obfuscating files, clearing logs, or using living-off-the-land binaries.
- Credential Access (T1003, T1552.001): Dumping credentials from memory or files.
- Lateral Movement (T1021.001, T1570): Using remote services like RDP or SMB to move across networks.
- Collection (T1005, T1113): Gathering sensitive data from local systems.
- Command and Control (T1071.001, T1090.001): Communicating with attacker infrastructure via web protocols or proxies.
Call to Action
Stay ahead of emerging threats with ThreatClaw Premium, which delivers real-time rule updates and advanced detection capabilities. Protect your organization from the latest exploits, malware, and attack techniques, before they impact your environment.
Related articles
This week’s ThreatClaw update expands detection for 4 exploited CVEs, ransomware staging techniques, BYOVD attacks, and 258 new Sigma rules targeting enterprise threats.
This week, ThreatClaw expands coverage for 8 newly exploited CVEs, including critical flaws in VMware vCenter, Microsoft SharePoint, and MLflow. Learn why these matter.
This week, ThreatClaw expands coverage with 51 new Sigma rules targeting Linux/macOS/Windows persistence, plus 4 actively exploited CVEs in Cisco, Microsoft, Metabase, and Progress LoadMaster.
ThreatClaw expands coverage with 67 new rules targeting brand impersonation (T1566.002) and 6 actively exploited CVEs in Check Point, SharePoint, and WordPress.