August 3, 2026

    July 2026 Product Releases

    Two new Windows detections landed this month, both aimed at persistence techniques: one flags Node.js-based malware writing Registry Run keys to survive reboots, the other catches suspicious javaw.exe and regedit.exe execution from ProgramData paths — a location attackers favor because it’s writable without elevation and rarely watched as closely as Program Files. We also wrapped up the phased retirement of the older indicator-based Connection from Public IP conditions now that the replacement method has cleared its soak period. On the integration side, four new log sources are now parsed: Cisco Secure Endpoint, Untangle firewalls, Barracuda CloudGen firewalls, and HP/Aruba AOS-CX switches. Webhooks for finding event forwarding are now available to all customers on an active paid license. 

    Detection Updates

    Log Type Details
    Windows
    NEW - Node.js Spawning Command Processor to Add Registry Run Key

    This detection identifies a node.exe process spawning cmd.exe to add a Windows Registry Run key. Node.js-based remote access trojans use this technique to establish persistence, re-executing their payload every time the user logs in as part of a paste-and-run initial access chain that can lead to ransomware. While node.exe can legitimately spawn cmd.exe, creating a Run key from that process tree is not expected behavior and warrants immediate investigation.

    Default state: Disabled
    Windows
    NEW - Suspicious Process Execution from ProgramData

    This detection identifies javaw.exe or regedit.exe launching from ProgramData paths, a pattern seen in a real customer incident involving a Java-based dropper disguised as mail server setup software. Attackers favor ProgramData because it’s writable without elevated privileges and rarely monitored as closely as Program Files. Execution from this location by these processes is unusual and worth investigating.

    Default state: Disabled
    Multiple
    UPDATE - Connection from Public IP

    We retired the older indicator-based Connection from Public IP conditions now that the replacement detection method has cleared its testing period, reducing noise while preserving coverage.

    Bug Fixes and Improvements

    Bug Fixes

    • JUNOS Parser - Data Plane Logs: We fixed an issue where JUNOS data plane logs weren’t being parsed, so those events weren’t reaching detections and search.

    Improvements 

    • Cisco Secure Endpoint Log Parsing: Cisco Secure Endpoint (formerly Cisco AMP) logs sent via HTTP Ingest are now parsed, making their events available for detections and search.
    • Untangle Firewall Log Parsing: Untangle firewall logs are now parsed, making their events available for detections and search.
    • Barracuda CloudGen Firewall Log Parsing: Barracuda CloudGen Firewall logs are now parsed, making their events available for detections and search.
    • HP/Aruba AOS-CX Switch Log Parsing: HP and Aruba AOS-CX switch logs are now parsed, making their events available for detections and search.
    • Webhooks - Expanded Access: Webhooks for finding event forwarding are now available to all customers on an active paid license, expanding beyond the limited early rollout.

    June 2026 Release Notes

    In case you missed the June updates, you can find and review those notes here.

    Amanda Berlin

    Amanda Berlin is the Senior Product Manager of Cybersecurity at Blumira, bringing nearly two decades of experience to her position. At Blumira she leads a team of incident detection engineers who are responsible for creating new detections based on threat intelligence and research for the Blumira platform. An...

    More from the blog

    View All Posts