Palo Alto Networks Unit 42 reported that machine-learning-based traffic analysis identified malicious exploit activity that traditional intrusion prevention signatures can miss, particularly for zero-day and rapidly evolving attacks. The research said signature-based IPS remains effective for known threats but can lag when attackers introduce new payloads, variants, or previously undisclosed vulnerabilities, creating gaps that lead to false negatives and delayed protection.
The cases cited included command injection and SQL injection attempts tied to Atlassian Confluence CVE-2022-26134, Tenda AC18 CVE-2022-31446, Moodle CVE-2022-0332, Django CVE-2022-34265, an unidentified IoT zero-day affecting certain MIPS-based smart devices, and SQL injection payloads generated by sqlmap. Unit 42 said models trained on real-world benign and exploit traffic flagged these attacks with high confidence even where default IPS signature coverage was limited or unavailable, positioning machine learning as a complementary detection layer rather than a replacement for signatures.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
The content describes an HTTP request observed on April 29, 2022 that triggered an alert and was assessed as a possible previously unknown attack targeting certain MIPS-based smart devices. The associated command-and-control server went offline shortly afterward, limiting verification of the suspected zero-day.
The content states that successful exploitation of Atlassian Confluence CVE-2022-26134 was observed in Cerber ransomware attacks. It presents this as a real-world example of command injection activity that its machine learning model could distinguish from benign traffic.
A Palo Alto Networks researcher discovered an exploit in the wild targeting Tenda AC18 CVE-2022-31446, a remote code execution flaw that allows arbitrary command execution on the device. The article says its machine learning model detected the exploitation attempt with high confidence.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.