|ThreatClaw

New ThreatClaw Detections: Exploited CVEs & Advanced Web Threats

This week’s update expands coverage for 20+ exploited CVEs, critical web vulnerabilities, and 20+ malware families, hardening defenses against initial access and persistence threats.

T1003T1003.001KEVDétection

New ThreatClaw Detections: Exploited CVEs & Advanced Web Threats

This week, ThreatClaw expanded detection coverage with 355 new Sigma rules and 22 YARA files, addressing critical vulnerabilities, web-based exploitation, and advanced malware families. Below is a summary of the most significant updates.

Exploited CVEs: Critical Vulnerabilities Now Detected

ThreatClaw now detects exploitation attempts for two newly added Known Exploited Vulnerabilities (KEVs):

  • CVE-2026-45659 (Microsoft SharePoint Server): This vulnerability enables unauthenticated attackers to execute arbitrary code via crafted requests, leading to initial access (T1190) and potential lateral movement. SharePoint’s widespread enterprise use makes it a prime target for threat actors seeking to compromise internal networks.

  • CVE-2026-48558 (SimpleHelp): A remote code execution flaw in SimpleHelp’s remote support software, allowing attackers to gain footholds in environments where the tool is deployed. Exploitation aligns with T1190 (Exploit Public-Facing Application) and can facilitate persistence (T1505.003) or command-and-control (T1071.001).

Web Exploitation: Hardening Defenses Against Initial Access

A significant portion of this week’s updates focuses on web-based exploitation, a favored tactic for gaining initial access. New detections cover:

  • 20+ exploited CVEs in web applications and frameworks, including:

    • CVE-2024-3400 (Palo Alto Networks PAN-OS): A critical command injection flaw enabling unauthenticated RCE, actively exploited in the wild. Aligns with T1190 and T1059 (Command and Scripting Interpreter).
    • CVE-2023-22515 (Atlassian Confluence): A privilege escalation vulnerability allowing attackers to create admin accounts, facilitating persistence (T1098) and data exfiltration (T1048).
    • CVE-2023-42793 (JetBrains TeamCity): Enables authentication bypass and RCE, often used to deploy backdoors or ransomware. Tied to T1190 and T1505.003 (Server Software Component).
  • Common Web Attack Techniques:

    • Local file inclusion/path traversal (T1083, T1190): Detects attempts to access sensitive files or execute arbitrary code via malicious URI requests.
    • OS command injection (T1190): Identifies exploitation of vulnerable web inputs to execute system commands.
    • Vulnerability scanning (T1592.004, T1595.002): Flags reconnaissance activity, such as probes for exposed endpoints or sensitive files, often preceding exploitation.
  • Vendor-Specific Exploits:

    • Citrix (CVE-2025-5777, CVE-2023-24489): Covers CitrixBleed memory disclosure and ShareFile RCE, both leveraged in recent campaigns for credential theft (T1552.001) and lateral movement (T1021.001).
    • Ivanti (CVE-2023-46805/CVE-2024-21887, CVE-2024-21893): Detects exploitation of Ivanti Connect Secure flaws, including command injection and SSRF, used to bypass authentication and deploy webshells (T1505.003).
    • Adobe ColdFusion (CVE-2023-29298, CVE-2023-26360): Addresses access control bypass and arbitrary file read vulnerabilities, enabling data theft (T1005) and persistence (T1546.003).

Malware Families: Expanding Coverage for Advanced Threats

ThreatClaw added 22 YARA files to detect sophisticated malware families, including:

  • ESET-tracked families:

    • AnimalFarm, Gazer, InvisiMole, Kobalos: Advanced backdoors and spyware used by threat actors for espionage (T1059.001), data exfiltration (T1048), and persistence (T1547.001).
    • Carbon, SparklingGoblin, Turla-Outlook: Modular malware frameworks enabling lateral movement (T1021.002), credential dumping (T1003), and command-and-control (T1071.001).
    • Stantinko, Mozi: Botnets and cryptocurrency miners leveraging T1059.007 (JavaScript) and T1496 (Resource Hijacking) for financial gain or DDoS attacks.
  • Other notable families:

    • RedLine: A prevalent infostealer targeting credentials, browser data, and cryptocurrency wallets, aligning with T1003.001 (LSASS Memory) and T1552.001 (Credentials in Files).
    • SSHDoor: A backdoor targeting SSH services for persistence (T1543.003) and remote access (T1021.004).

MITRE ATT&CK Techniques: Broadened Coverage

This update enhances detection for 80+ MITRE ATT&CK techniques, including:

  • Initial Access (T1190, T1133): Exploiting public-facing applications and external remote services.
  • Persistence (T1546.003, T1547.001): Abusing startup folders, registry keys, and scheduled tasks.
  • Privilege Escalation (T1068, T1548.002): Exploiting vulnerabilities or abusing token manipulation.
  • Defense Evasion (T1027, T1070): Obfuscating files, clearing logs, or using living-off-the-land binaries.
  • Credential Access (T1003, T1552.001): Dumping credentials from memory or files.
  • Lateral Movement (T1021.001, T1570): Using remote services like RDP or SMB to move across networks.
  • Collection (T1005, T1113): Gathering sensitive data from local systems.
  • Command and Control (T1071.001, T1090.001): Communicating with attacker infrastructure via web protocols or proxies.

Call to Action

Stay ahead of emerging threats with ThreatClaw Premium, which delivers real-time rule updates and advanced detection capabilities. Protect your organization from the latest exploits, malware, and attack techniques, before they impact your environment.

Related articles