New Detection: Brand Spoofing Surge & 6 Exploited CVEs in SMB
ThreatClaw expands coverage with 67 new rules targeting brand impersonation (T1566.002) and 6 actively exploited CVEs in Check Point, SharePoint, and WordPress.
Brand Spoofing Surge: 67 New Detections for Phishing Domains
This week, ThreatClaw significantly expanded detection coverage to combat a rising wave of brand impersonation attacks targeting enterprises. We added 67 new Sigma rules to identify domains mimicking trusted brands, including financial institutions, cloud services, and government portals. These attacks leverage MITRE ATT&CK technique T1566.002 (Spearphishing Link), a critical vector for credential theft and malware delivery. By spoofing domains like Adobe, Microsoft, or banking platforms, threat actors exploit user trust to bypass email filters and social-engineer employees into disclosing sensitive data or executing malicious payloads.
Why This Matters
- Financial and operational risk: Spoofed banking or payment portals (e.g., Binance, Credit Agricole) can lead to direct fraud or supply-chain compromise.
- Supply-chain exposure: Fake vendor domains (e.g., DHL, FedEx) enable attackers to intercept invoices or deliver malware to partners.
- Regulatory pressure: Impersonation of government services (e.g., FranceConnect, Impots) may violate compliance mandates like GDPR or NIS2.
6 Newly Exploited CVEs: Critical Patches Required
ThreatClaw now detects exploitation attempts for six CVEs recently added to CISA’s Known Exploited Vulnerabilities (KEV) catalog. These flaws are actively weaponized by advanced threat actors to gain initial access, escalate privileges, or deploy secondary payloads:
- CVE-2026-16232 (Check Point SmartConsole): A vulnerability in this network security management tool could allow attackers to bypass authentication, granting control over firewall policies or VPN configurations. MITRE ATT&CK: T1190 (Exploit Public-Facing Application).
- CVE-2026-50522 (Microsoft SharePoint): A server-side request forgery (SSRF) or remote code execution (RCE) flaw in SharePoint enables attackers to access internal resources or execute arbitrary code on enterprise servers. MITRE ATT&CK: T1210 (Exploitation of Remote Services).
- CVE-2026-60137 & CVE-2026-63030 (WordPress Core): These vulnerabilities in the world’s most widely used CMS could lead to site takeovers, SEO poisoning, or malware distribution via compromised plugins. MITRE ATT&CK: T1190 (Exploit Public-Facing Application).
- CVE-2026-0770 (Langflow): A flaw in this AI workflow tool may allow attackers to manipulate or exfiltrate sensitive data processed by enterprise AI models. MITRE ATT&CK: T1557 (Adversary-in-the-Middle).
- CVE-2021-27137 (DD-WRT): A persistent RCE vulnerability in this open-source router firmware could enable attackers to pivot into corporate networks from compromised edge devices. MITRE ATT&CK: T1190 (Exploit Public-Facing Application).
Enterprise Impact
- Initial access: Exploited CVEs in public-facing applications (e.g., SharePoint, WordPress) are a top vector for ransomware and data exfiltration.
- Lateral movement: Flaws in network tools (e.g., Check Point, DD-WRT) can facilitate deeper infiltration into internal systems.
- Data exposure: Vulnerabilities in AI tools (e.g., Langflow) may lead to unintended data leaks or model poisoning.
Strengthened Defense with ThreatClaw Premium
With 6,400+ Sigma rules and 8,000+ YARA signatures, ThreatClaw provides real-time detection for emerging threats. Upgrade to ThreatClaw Premium for instant access to new rules, prioritized CVE alerts, and expert-guided response playbooks to stay ahead of advanced threat actors.
Related articles
This week, ThreatClaw expands coverage for 8 newly exploited CVEs, including critical flaws in VMware vCenter, Microsoft SharePoint, and MLflow. Learn why these matter.
This week, ThreatClaw expands coverage with 51 new Sigma rules targeting Linux/macOS/Windows persistence, plus 4 actively exploited CVEs in Cisco, Microsoft, Metabase, and Progress LoadMaster.
This week, ThreatClaw expands detection for 12 newly exploited CVEs, including critical flaws in Microsoft SharePoint, Fortinet FortiSandbox, and Oracle E-Business Suite.
This week, ThreatClaw expands coverage for actively exploited CMS vulnerabilities (CVE-2026-48908, CVE-2026-56290) and suspicious firmware updates (T1542.001), hardening defenses against supply-chain attacks.