ModSecurity — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
November 18, 2025
Last Seen
July 13, 2026

ModSecurity is a technology platform tracked by ThreatCluster, appearing in 4 threat clusters built from 4 intelligence report mentions.

ModSecurity is a technology platform tracked across 4 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed November 18, 2025; most recent activity July 13, 2026.

Related Threat Clusters

  • Reconnaissance for MCP Servers and AI Credentials Intensifies

    A recent analysis of Apache and ModSecurity logs revealed a surge in internet-wide reconnaissance targeting Model Context Protocol (MCP) servers and AI assistant configuration files. Over a 14-day period, approximately…

    2 articles · Updated July 13, 2026
  • ModSecurity Vulnerabilities Allow WAF Rule Evasion

    ModSecurity, an open-source web application firewall, has multiple vulnerabilities (CVE-2026-52761 and CVE-2026-52747) that enable attackers to bypass security rules through specially crafted HTTP requests. These flaws…

    2 articles · Updated July 6, 2026
  • Critical RCE Vulnerability in Imunify360 Exposes Millions of Linux Servers

    A remote code execution vulnerability in the Imunify360 antivirus system affects millions of Linux servers, allowing attackers to upload malicious files and execute arbitrary code. This flaw impacts versions prior to…

    1 article · Updated November 18, 2025
  • Critical RCE Vulnerability in ImunifyAV Affects Millions of Linux Servers

    A remote code execution vulnerability was found in the AI-Bolit component of ImunifyAV, impacting millions of Linux servers and websites. This flaw allows attackers to execute arbitrary code and escalate privileges to…

    4 articles · Updated November 18, 2025

Recent Intelligence Reports

  • Attackers Combine MCP Recon With Cloud Metadata SSRF to Steal Service Account Tokens — Gbhackers · July 13, 2026
  • Multiple ModSecurity Vulnerabilities Allow Attackers to Bypass Firewall Rules — Cybersecuritynews · July 6, 2026
  • ModSecurity Security Flaws Enable WAF Rule Evasion With Crafted HTTP Requests — Gbhackers · July 6, 2026
  • Imunify AI — Gbhackers · November 18, 2025

Frequently asked questions

What is ModSecurity?

ModSecurity is a technology platform tracked by ThreatCluster, appearing in 4 threat clusters built from 4 intelligence report mentions.

Is ModSecurity still active?

The most recent intelligence report mentioning ModSecurity on ThreatCluster is dated July 13, 2026. Activity was first observed November 18, 2025, giving a tracked span from then to July 13, 2026.

What is ModSecurity associated with?

Across ThreatCluster reporting, ModSecurity most frequently co-occurs with Lazarus APT Group, Unc1549, DDoS, Server-Side Request Forgery (ssrf), Iran, among 12 tracked related entities.

What are the latest developments involving ModSecurity?

The most significant recent cluster is “Reconnaissance for MCP Servers and AI Credentials Intensifies” (2 articles · Updated July 13, 2026). ModSecurity appears across 4 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on ModSecurity?

ModSecurity appears in 4 intelligence report mentions across 4 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown