Security content from Elastic and Splunk highlights two Linux behaviors that defenders should monitor closely: unauthorized privilege escalation through setuid execution and deletion of web server access logs. Splunk published an anomaly detection for Linux auditd that flags execve syscall 59 events where a non-root user gains effective UID 0 without a matching successful PAM authentication event in the same audit session, a pattern associated with privilege escalation and mapped to MITRE ATT&CK T1068; the rule also references CVE-2026-46331 and notes that some scheduled tasks can produce false positives.
Elastic separately documented a prebuilt rule for detecting deleted web server access logs, while ThreatBear provided tuning guidance showing how legitimate activity on Mitel MiCollab systems can create noisy process trees and trigger alerts such as suspicious Java child processes and logfile deletion detections. The combined guidance underscores that Linux monitoring programs should pair coverage for high-risk behaviors with environment-specific exceptions so defenders can preserve visibility into real attacks without overwhelming analysts with benign alerts.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
ThreatBear published guidance on reducing false positives when monitoring Mitel MiCollab systems, including recommendations to tune suspicious Java child process and logfile deletion detections for known Mitel-specific activity.
Splunk published the 'Linux Auditd Possible Setuid Execve Privesc' detection, which flags execve events where a non-root user gains effective UID 0 without a corresponding PAM authentication event. The detection is mapped to ATT&CK T1068 and references CVE-2026-46331.
Elastic published documentation for its prebuilt detection rule 'WebServer Access Logs Deleted,' describing detection logic for deletion of web server access logs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceelastic.co
Open sourcethreatbear.co
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.