Rule Update
23-007 (February 14, 2023)
Publish date: February 14, 2023
DESCRIPTION
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
Atlassian Bitbucket
1011658* - Atlassian Bitbucket Server and Data Center Command Injection Vulnerability (CVE-2022-43781)
Intel Data Center Manager
1011672 - Intel Data Center Manager SQL Injection Vulnerability (CVE-2022-21225)
SolarWinds Information Service
1011552* - SolarWinds Network Performance Monitor 'UpdateActionsDescriptions' SQL Injection Vulnerability (CVE-2022-36961)
Suspicious Client Application Activity
1010307* - Identified Reverse Shell Communication Over HTTPS (ATT&CK T1071.001)
1010364* - Identified Reverse Shell Communication Over HTTPS - 2 (ATT&CK T1071.001)
1010365* - Identified Reverse Shell Communication Over HTTPS - 3 (ATT&CK T1071.001)
1010370* - Identified Reverse Shell Communication Over HTTPS - 4 (ATT&CK T1071.001)
Web Application PHP Based
1011299* - WordPress 'Download Monitor' Plugin SQL Injection Vulnerability (CVE-2021-24786)
1011283* - WordPress 'Wp-Stats-Manager' Plugin SQL Injection Vulnerability (CVE-2021-24750)
Web Application Ruby Based
1011243* - Grafana Path Traversal Vulnerability (CVE-2021-43798)
Web Server Adobe ColdFusion
1011558* - Adobe ColdFusion Directory Traversal Vulnerability (CVE-2022-38418)
1011556* - Adobe ColdFusion Directory Traversal Vulnerability (CVE-2022-38423)
1011563* - Adobe ColdFusion Information Disclosure Vulnerability (CVE-2022-38422)
Web Server Adobe ColdFusion AddOns
1011560* - Adobe ColdFusion Information Disclosure Vulnerability (CVE-2022-38419)
Web Server Common
1011227* - Apache Druid Arbitrary File Read Vulnerability (CVE-2021-36749)
Web Server HTTPS
1011566* - Centreon 'Contact Group' SQL Injection Vulnerability (CVE-2022-42427)
1011235* - Microsoft Exchange Server Reflected Cross-Site Scripting Vulnerability (CVE-2021-41349)
Web Server Miscellaneous
1011179* - Atlassian Jira Path Traversal Vulnerability (CVE-2021-26086)
1011677 - Contec CONPROSYS HMI System Command Injection Vulnerability (CVE-2022-44456)
1011598* - XWiki Cross-Site Scripting Vulnerability (CVE-2022-36097)
Web Server SharePoint
1011554* - Microsoft SharePoint Server Remote Code Execution Vulnerability (CVE-2022-38053)
1011678 - Microsoft SharePoint Server Remote Code Execution Vulnerability (CVE-2022-44690)
Zoho ManageEngine
1011662 - Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability (CVE-2022-47966)
Integrity Monitoring Rules:
1002775* - Microsoft Windows - Network configuration files modified
1002778* - Microsoft Windows - System .dll or .exe files modified (ATT&CK T1036.003, T1222.001)
1002779* - Microsoft Windows - System File Modified
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
Atlassian Bitbucket
1011658* - Atlassian Bitbucket Server and Data Center Command Injection Vulnerability (CVE-2022-43781)
Intel Data Center Manager
1011672 - Intel Data Center Manager SQL Injection Vulnerability (CVE-2022-21225)
SolarWinds Information Service
1011552* - SolarWinds Network Performance Monitor 'UpdateActionsDescriptions' SQL Injection Vulnerability (CVE-2022-36961)
Suspicious Client Application Activity
1010307* - Identified Reverse Shell Communication Over HTTPS (ATT&CK T1071.001)
1010364* - Identified Reverse Shell Communication Over HTTPS - 2 (ATT&CK T1071.001)
1010365* - Identified Reverse Shell Communication Over HTTPS - 3 (ATT&CK T1071.001)
1010370* - Identified Reverse Shell Communication Over HTTPS - 4 (ATT&CK T1071.001)
Web Application PHP Based
1011299* - WordPress 'Download Monitor' Plugin SQL Injection Vulnerability (CVE-2021-24786)
1011283* - WordPress 'Wp-Stats-Manager' Plugin SQL Injection Vulnerability (CVE-2021-24750)
Web Application Ruby Based
1011243* - Grafana Path Traversal Vulnerability (CVE-2021-43798)
Web Server Adobe ColdFusion
1011558* - Adobe ColdFusion Directory Traversal Vulnerability (CVE-2022-38418)
1011556* - Adobe ColdFusion Directory Traversal Vulnerability (CVE-2022-38423)
1011563* - Adobe ColdFusion Information Disclosure Vulnerability (CVE-2022-38422)
Web Server Adobe ColdFusion AddOns
1011560* - Adobe ColdFusion Information Disclosure Vulnerability (CVE-2022-38419)
Web Server Common
1011227* - Apache Druid Arbitrary File Read Vulnerability (CVE-2021-36749)
Web Server HTTPS
1011566* - Centreon 'Contact Group' SQL Injection Vulnerability (CVE-2022-42427)
1011235* - Microsoft Exchange Server Reflected Cross-Site Scripting Vulnerability (CVE-2021-41349)
Web Server Miscellaneous
1011179* - Atlassian Jira Path Traversal Vulnerability (CVE-2021-26086)
1011677 - Contec CONPROSYS HMI System Command Injection Vulnerability (CVE-2022-44456)
1011598* - XWiki Cross-Site Scripting Vulnerability (CVE-2022-36097)
Web Server SharePoint
1011554* - Microsoft SharePoint Server Remote Code Execution Vulnerability (CVE-2022-38053)
1011678 - Microsoft SharePoint Server Remote Code Execution Vulnerability (CVE-2022-44690)
Zoho ManageEngine
1011662 - Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability (CVE-2022-47966)
Integrity Monitoring Rules:
1002775* - Microsoft Windows - Network configuration files modified
1002778* - Microsoft Windows - System .dll or .exe files modified (ATT&CK T1036.003, T1222.001)
1002779* - Microsoft Windows - System File Modified
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Featured Stories
When AI Becomes a Zero-Day Machine: What Public Sector Organizations Need to KnowClaude Mythos Preview shows how AI can rapidly discover and weaponize zero-day vulnerabilities—transforming once human-scale threats into machine-speed attacks. As these capabilities spread, public sector organizations must rely on trusted, proactive defenders like TrendAI™ ZDI to stay ahead of an AI-driven threat landscape.Read more
Hunt Them All: An AI-Powered Vulnerability Sweep of 19,000 MCP ServersIn this research, we analyzed over 19,000 open-source MCP server repositories to uncover how much AI-generated code they contain and how many harbor exploitable vulnerabilities.Read more
Update on Exposed MCP Servers: The Threat Widens to the CloudExposed Model Context Protocol (MCP) servers have become powerful vectors for cloud attacks, enabling threat actors to not only access sensitive data but also take control of the cloud services themselves.Read more
Old Vulnerabilities, New AI Era, Amplified Risk: How Outdated Flaws Continue to Fuel the N-Day Exploit MarketEven as AI adoption accelerates, old exploits remain overlooked weaknesses. Underground trends show a renewed demand for exploits, with cybercriminals relying on aging but still effective vulnerabilities. We examine this blind spot and why long-standing issues need to be addressed.Read more