|ThreatClaw

New ThreatClaw Detections: Linux & Windows Persistence, 4 Exploited CVEs

This week, ThreatClaw expands coverage with 51 new Sigma rules targeting Linux/macOS/Windows persistence, plus 4 actively exploited CVEs in Cisco, Microsoft, Metabase, and Progress LoadMaster.

T1003.002T1003.004KEVDétection

New ThreatClaw Detections: Linux & Windows Persistence, 4 Exploited CVEs

This week, ThreatClaw enhanced detection coverage with 51 new Sigma rules, focusing on persistence mechanisms across Linux, macOS, and Windows environments. Additionally, we now detect exploitation of four newly added Known Exploited Vulnerabilities (KEVs), reinforcing defenses against advanced threats targeting enterprise infrastructure.

New Detection Coverage: Persistence Techniques

Persistence remains a critical phase in the attack lifecycle, enabling threat actors to maintain access, evade detection, and escalate privileges. This week’s updates address 28 distinct persistence techniques, spanning 14 MITRE ATT&CK techniques, including:

  • Linux Persistence

    • Cron jobs (T1053.003): Attackers leverage cron directories to execute malicious payloads at scheduled intervals, ensuring long-term access.
    • Systemd services (T1543.002): Modification of systemd unit files or timers (T1053.006) allows adversaries to survive reboots and blend with legitimate services.
    • Dynamic linker hijacking (T1574.006): Tampering with /etc/ld.so.preload enables code injection into every executed process, a stealthy method for privilege escalation.
    • Shell initialization files (T1546.004): Appending malicious commands to .bashrc or .bash_profile ensures persistence across user sessions.
  • macOS Persistence

    • LaunchAgents/LaunchDaemons (T1543.001, T1543.004): Property list (plist) modifications in system or user directories enable automatic execution of malware.
    • Dock modifications (T1647): Altering persistent-apps via defaults commands allows adversaries to hijack user interactions.
    • Kernel extensions (T1547.006): Loading malicious kexts via kextload grants deep system access, often used by advanced threats.
  • Windows Persistence

    • DLL side-loading (T1574.001, T1574.002): Exploiting writable paths to load malicious DLLs (e.g., aadauthhelper.dll, wwlib.dll) alongside legitimate applications like Office or DCOM components.
    • Registry hijacking (T1112): Manipulating UserChoice associations or FileExts to redirect file execution to attacker-controlled binaries.
    • Startup approval tampering (T1547.001): Modifying StartupApproved keys to bypass security controls and ensure malware launches at boot.
    • Credential dumping (T1003.002, T1003.004): Using reg.exe to export SAM or SECURITY hives, a precursor to lateral movement and privilege escalation.

Exploited CVEs: Immediate Threats to Enterprise Security

ThreatClaw now detects exploitation of four CVEs recently added to CISA’s Known Exploited Vulnerabilities Catalog. These flaws are actively targeted by threat actors to gain initial access, escalate privileges, or deploy ransomware:

  • CVE-2026-20349 (Cisco Secure Firewall ASA/FTD): A vulnerability in Cisco’s firewall platforms could allow unauthenticated remote code execution, posing a severe risk to perimeter defenses.
  • CVE-2026-68820 (Microsoft Windows Ancillary Function Driver): A privilege escalation flaw in the Windows kernel, enabling attackers to bypass security boundaries and execute code with elevated privileges.
  • CVE-2026-72898 (Metabase): A critical flaw in the Metabase analytics platform, potentially allowing remote attackers to execute arbitrary code on vulnerable servers.
  • CVE-2026-8037 (Progress LoadMaster): A vulnerability in Progress LoadMaster load balancers, which could be exploited to gain control over critical network infrastructure.

Why This Matters

Persistence techniques are a hallmark of advanced threat actors, enabling them to maintain footholds in compromised environments for extended periods. By blending with legitimate system processes (e.g., cron jobs, systemd, or registry keys), attackers evade traditional security controls and complicate incident response. The exploited CVEs in this update highlight the urgency of patching high-risk vulnerabilities, particularly in firewalls, load balancers, and analytics platforms, which are prime targets for initial access.

Enhance Your Defenses with ThreatClaw Premium

Stay ahead of evolving threats with ThreatClaw Premium, which provides real-time detection updates, exclusive threat intelligence, and enterprise-grade support. Access the latest detection rules and protect your organization from advanced attacks: https://threatclaw.io/en/feeds.

Related articles