§ Category
Category

AU

AC

Started Chat With Rovo Agent: The Only Rovo Chat Event Atlassian Logs

Varonis’s RovoBlast turned an Atlassian URL parameter into a trusted instruction, and Rovo’s ResearchAgent went and collected Jira, Confluence, and SharePoint data under the clicking user’s own identity. Atlassian fixed that link path in July. The identity and audit gap underneath it is still open.

·
AU

metabase_database.details, the Column Storing Snowflake Credentials in Cleartext

Metabase’s CVE-2026-72898 patch closes an unauthenticated SQL injection in the password-reset endpoint, but it does not remove the admin accounts, API keys, or rotated connected-database credentials an attacker created before you upgraded. Here is what the retro-hunt actually looks like in ingress logs and the Metabase application database.

·
AC

CoreBreak: Tool Execution Without a Model Turn in Three Runtimes

Four CVEs across AWS, Google, and Vercel agent runtimes converge on one authorization failure: tool execution could proceed with no trustworthy binding to a model-authorized event. Here is what the audit record shows, what the detection actually looks like in CloudWatch and Splunk, and why the Strands branch that started it all is still open.

·
AC

Gmail Content Compliance: The Audit Event Retires After August

A PRC-nexus actor exfiltrated years of medical and defense research by creating a single domain-level Gmail content compliance rule that silently BCC’d matching mail to an attacker Gmail account. It produced no endpoint telemetry and no user-visible forwarding setting, and the admin audit event family that authoritatively records it is mid-migration, with the legacy events retiring after August 2026.

·
AU

The Renumber Step Is What Closes the EventRecordID Gap

An attacker who can manipulate the active or offline EVTX can pull a single 4624 out of the Security log without inherently firing Event ID 1102 — and, by renumbering the records that follow, without leaving a hole in the EventRecordID sequence your rule watches. Here is why gap detection misses that, and what actually catches it.

·
AC

CVE-2026-3055: Appliance Logs Are Not Evidence of Non-Exploitation

The NetScaler memory-overread class has a third sequel. CVE-2026-3055 leaks session tokens through an endpoint the appliance barely logs — so its own logs won’t prove you’re clean, and the detection has to move upstream to the response size and downstream to the reused token, while patching does nothing to the sessions already bled.

·
AU

Scratch on a Ramdisk: The ESXi Default That Decides Your Timeline

On an ESXi host without persistent scratch, /var/run/log lives on an in-memory ramdisk and evaporates at the next boot. Ransomware crews get the same effect for free — they power off, kill, or reboot the workloads before encrypting — which means your entire forensic timeline had to be forwarded off-box before the incident or it never existed at all.

·
AC

Entra Logs a Federated Credential Add as Update Application

Most SOCs detect service principal persistence by watching for “Add service principal credentials.” Federated identity credentials reach the same persistence with a different audit operation, on a different object, sometimes in a log source you never ingested.

·