What is CWE-311?
The product does not encrypt sensitive or critical information before storage or transmission.
CWE-311 is a class-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of High. Applicable platforms: Language: Not Language-Specific.
Source: MITRE CWE (CWE-311 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Confidentiality — Read Application Data. If the application does not use a secure channel, such as SSL, to exchange sensitive information, it is possible for an attacker with access to the network traffic to sniff packets from the connection and uncover the data. This attack is not technically difficult, but does require physical access to some portion of the network over which the sensitive data travels. This access is usually somewhere near where the user is connected to the network (such as a colleague on the company network) but…
- Confidentiality, Integrity — Modify Application Data. Omitting the use of encryption in any program which transfers data over a network of any kind should be considered on par with delivering the data sent to each user on the local networks of both the sender and receiver. Worse, this omission allows for the injection of data into a stream of communication between two parties -- with no means for the victims to separate valid data from invalid. In this day of widespread network attacks and password collection sniffers, it is an unnecessary risk to…
Source: MITRE CWE, common consequences.
How CWE-311 is exploited in the wild
Threadlinqs maps 3 CVEs to CWE-311, published between 2026-04-09 and 2026-07-15. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 3 high. The highest EPSS score in the set is 42.6% (CVE-2026-34486), the modelled probability of exploitation in the next 30 days. 45 tracked threats reference CWE-311 directly or through a CVE it covers; the most recent is “Iran Exploits SS7 Cellular Interconnect Infrastructure to Track US Military Personnel” (2026-09-21). Affected products concentrate in Apache Software Foundation (1), Cisco (1), CoreWCF (1).
Vulnerabilities (CVEs)
All 3 CVEs mapped to CWE-311, CISA KEV first, then by CVSS score.
- CVE-2026-34486 — CISA KEV · CVSS 7.5 high · EPSS 42.6% · published 2026-04-09
- CVE-2026-20157 — CVSS 7.5 high · EPSS 0.1% · published 2026-07-15
- CVE-2026-54784 — CVSS 7.4 high · EPSS 0.1% · published 2026-07-08
Affected vendors
- Apache Software Foundation — 1 CVE
- Cisco — 1 CVE
- CoreWCF — 1 CVE
Threat activity
45 tracked threats cite CWE-311; the 25 most recent are listed.
- Iran Exploits SS7 Cellular Interconnect Infrastructure to Track US Military PersonnelHIGH
- CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively Exploited in SnowLight and AI-Assisted CampaignsHIGH
- ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting 444+ PackagesCRITICAL
- XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram TrojanizationHIGH
- ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome App-Bound Encryption via ChromEggscalator to Steal Browser CredentialsHIGH
- BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell Loaders, and Crypto Wallet/iCloud Keychain TheftHIGH
- GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to Steal Chrome Credentials and MetaMask Data (Famous Chollima / ClickFake Interview)HIGH
- Dolphin X Stealer — MaaS Credential/Crypto Infostealer with AI-Driven Victim Profiler (thedolphinx[.]top)HIGH
- ASEC June 2026 Financial Sector Threat Roundup: Phishing-to-Infostealer Chains and Ransomware Dark Web Sales (LAPSUS$, MORPHEUS, Qilin)MEDIUM
- HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern Manticore / Iran MOIS-Nexus)HIGH
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to Cavern Manticore/Lyceum (Low Confidence)HIGH
- FakeGit Campaign Uses 7,600 GitHub Repositories with AgentBaiting to Spread SmartLoader & StealC MalwareHIGH
- HOLLOWGRAPH: Microsoft 365 Calendar-Based C2 Malware Targeting Israeli Organizations (Cavern Manticore)HIGH
- GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' AI-Enabled Malware (PROMPTFLUX, PROMPTSTEAL/LAMEHUG, PROMPTLOCK, FRUITSHELL, QUIETVAULT) Deployed by State ActorsHIGH
- CrashStealer: Novel macOS Information Stealer Disguised as Apple Crash Reporter (Jamf Threat Labs)MEDIUM
- Multiple Vulnerabilities in Cisco Identity Services Engine, ISE Passive Identity Connector, and RoomOS (GovCERT.HK A26-07-32)MEDIUM
- UAT-11795 (Russian) Trojanizes WebEx, Zoom, MobaXterm, DBeaver, FaceIT Installers to Deploy Starland RAT and Bespoke WLDR C2 ImplantHIGH
- GoSerpent Backdoor Campaign Targets Southeast Asian Government and Diplomatic EntitiesHIGH
- macOS Infostealer Hijacks Telegram Desktop Sessions via tdata Theft to Bypass 2FA, Harvests Keychain, Browser Credentials, Apple Notes, and 16 Crypto WalletsHIGH
- OkoBot: Multi-Stage Malware Framework Targeting Cryptocurrency Wallets (TookPS/HDUtil/Volume2/SeedHunter)CRITICAL
- Compromised @injectivelabs/sdk-ts npm Package (v1.20.21) Exfiltrates Cryptocurrency Wallet Mnemonics and Private Keys via Fake TelemetryHIGH
- OkoBot Malware Framework Injects Seed-Phrase Phishing Pages Into Ledger and Trezor Wallet AppsHIGH
- ModHeader Chrome/Edge Extension (v7.0.17-7.0.18, 1.6M Installs) Contains Dormant AES-GCM Browsing-History Exfiltration Pipeline to api.stanfordstudies.comHIGH
- LabubaRAT: Rust-Based RAT Masquerades as NVIDIA Container Runtime to Backdoor Windows HostsHIGH
- Krybit Ransomware — Babuk-Derived RaaS Operation Emerges with Double ExtortionHIGH
Mitigations
- Requirements: Clearly specify which data or resources are valuable enough that they should be protected by encryption. Require that any transmission or storage of this data/resource should use well-vetted encryption algorithms.
- Architecture and Design: Ensure that encryption is properly integrated into the system design, including but not necessarily limited to: Encryption that is needed to store or transmit private data of the users of the system Encryption that is needed to protect the system itself from unauthorized disclosure or tampering Identify the separate needs and contexts for encryption: One-way (i.e., only the user or recipient needs to have the key). This can be achieved using public key cryptography, or other techniques in which the encrypting party (i.e., the product) does not need to have access to a private key. Two-way (i.e., the encryption can be automatically performed on behalf of a user, but the key must be available…
- Architecture and Design / Libraries or Frameworks: When there is a need to store or transmit sensitive data, use strong, up-to-date cryptographic algorithms to encrypt that data. Select a well-vetted algorithm that is currently considered to be strong by experts in the field, and use well-tested implementations. As with all cryptographic mechanisms, the source code should be available for analysis. For example, US government systems require FIPS 140-2 certification. Do not develop custom or private cryptographic algorithms. They will likely be exposed to attacks that are well-understood by cryptographers. Reverse engineering techniques are mature. If the algorithm can be compromised if attackers find out how it works, then it is especially…
- Architecture and Design / Separation of Privilege: Compartmentalize the system to have "safe" areas where trust boundaries can be unambiguously drawn. Do not allow sensitive data to go outside of the trust boundary and always be careful when interfacing with a compartment outside of the safe area. Ensure that appropriate compartmentalization is built into the system design, and the compartmentalization allows for and reinforces privilege separation functionality. Architects and designers should rely on the principle of least privilege to decide the appropriate time to use privileges and the time to drop privileges.
- Implementation, Architecture and Design: When using industry-approved techniques, use them correctly. Don't cut corners by skipping resource-intensive steps (CWE-325). These steps are often essential for preventing common attacks.
- Implementation / Attack Surface Reduction: Use naming conventions and strong types to make it easier to spot when sensitive data is being used. When creating structures, objects, or other complex entities, separate the sensitive and non-sensitive data as much as possible.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Manual Analysis (effectiveness: High): The characterizaton of sensitive data often requires domain-specific understanding, so manual methods are useful. However, manual efforts might not achieve desired code coverage within limited time constraints. Black box methods may produce artifacts (e.g. stored data or unencrypted network transfer) that require manual evaluation.
- Automated Analysis: Automated measurement of the entropy of an input/output source may indicate the use or lack of encryption, but human analysis is still required to distinguish intentionally-unencrypted data (e.g. metadata) from sensitive data.
- Manual Static Analysis - Binary or Bytecode (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Binary / Bytecode disassembler - then use manual analysis for vulnerabilities & anomalies
- Dynamic Analysis with Automated Results Interpretation (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Web Application Scanner Web Services Scanner Database Scanners
- Dynamic Analysis with Manual Results Interpretation (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Network Sniffer Cost effective for partial coverage: Fuzz Tester Framework-based Fuzzer Automated Monitored Execution Man-in-the-middle attack tool
- Manual Static Analysis - Source Code (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Focused Manual Spotcheck - Focused manual analysis of source Manual Source Code Review (not inspections)
- Automated Static Analysis - Source Code (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Context-configured Source Code Weakness Analyzer
- Architecture or Design Review (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Inspection (IEEE 1028 standard) (can apply to requirements, design, source code, etc.) Formal Methods / Correct-By-Construction Cost effective for partial coverage: Attack Modeling
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.