Skip to main content

All Articles

Security Intelligence

3410 articles · Updated every 8 hours

Severity (this page):

Advertisement

HIGH
Threat Intel

Iranian Actors Target Rockwell PLCs: 4,000 US Devices Exposed

Iranian-linked cyber actors have identified nearly 4,000 exposed US industrial control systems, primarily Rockwell Automation PLCs, raising critical infrastructure…

Runtime Rebel Intel
4 min read · Apr 10, 2026
GlassWorm Campaign: Zig Dropper Infects Developer IDEs via Open VSX
HIGH
Supply Chain

GlassWorm Campaign: Zig Dropper Infects Developer IDEs via Open VSX

The GlassWorm campaign exploits the Open VSX registry with a malicious Zig-based dropper, impersonating WakaTime to compromise multiple developer IDEs.

Runtime Rebel Intel
4 min read · Apr 10, 2026
HIGH
Vulnerabilities

CVE-2024-21825: How Attackers Exploit Orthanc DICOM Servers — Patch Now

Critical vulnerabilities in the Orthanc DICOM server, including CVE-2024-21825, could lead to RCE and DoS. Learn how to patch and protect medical imaging systems.

Runtime Rebel Intel
3 min read · Apr 10, 2026
MEDIUM
Cloud Security

Google Gmail Client-Side Encryption for Android and iOS — Deployment Guide

Google expands Gmail client-side encryption (CSE) to Android and iOS, giving enterprise users full control over encryption keys for mobile email communications.

Runtime Rebel Intel
3 min read · Apr 10, 2026
MEDIUM
Threat Intel

Storm-2755 Targets Canadian Employees in Payroll Pirate Campaigns

Microsoft warns of Storm-2755, a financially motivated threat actor hijacking employee accounts to redirect salary payments via sophisticated phishing.

Runtime Rebel Intel
3 min read · Apr 10, 2026
Securing Enterprise Browser Environments Against AI Extension Risks
HIGH
Threat Intel

Securing Enterprise Browser Environments Against AI Extension Risks

Discover the security blind spots of AI browser extensions and how to mitigate data exfiltration risks in corporate environments via managed policies.

Runtime Rebel Intel
4 min read · Apr 10, 2026

Advertisement

MEDIUM
Malware

Detect Obfuscated JavaScript Phishing Delivered via RAR Archives

Security researchers identify a new phishing campaign using heavily obfuscated JavaScript within RAR archives to bypass traditional endpoint detection.

Runtime Rebel Intel
4 min read · Apr 10, 2026
HIGH
Vulnerabilities

CVE-2026-4436: High-Severity Flaw in GPL Odorizers GPL750

High-severity vulnerability CVE-2026-4436 in GPL Odorizers GPL750 allows remote attackers to manipulate gas odorant levels. Learn how to patch affected systems.

Runtime Rebel Intel
3 min read · Apr 10, 2026
HIGH
Vulnerabilities

CVE-2025-13926: Critical Flaw in Contemporary Controls BASC 20T

CISA warns of a CVSS 9.8 vulnerability in Contemporary Controls BASControl20 3.1. Attackers can forge packets to reconfigure or delete PLC components.

Runtime Rebel Intel
4 min read · Apr 10, 2026
BlueHammer Zero-Day: Windows Local Privilege Escalation Exploit Risks
HIGH
Vulnerabilities

BlueHammer Zero-Day: Windows Local Privilege Escalation Exploit Risks

Researcher Chaotic Eclipse released the BlueHammer zero-day exploit for Windows, enabling local privilege escalation. Learn how to detect and mitigate it.

Runtime Rebel Intel
4 min read · Apr 10, 2026
APT28 Analysis: Mitigation Strategies Against Fancy Bear Campaigns
HIGH
Threat Intel

APT28 Analysis: Mitigation Strategies Against Fancy Bear Campaigns

A technical analysis of APT28's global operations, highlighting the necessity of Zero Trust and rapid patching to counter Fancy Bear threat activity.

Runtime Rebel Intel
3 min read · Apr 10, 2026
HIGH
Supply Chain

CVE-2024-21390: EngageLab SDK Vulnerability Risks Android Crypto Wallets

Microsoft reveals a vulnerability in the EngageLab SDK affecting millions of Android crypto wallet users, potentially allowing for private key theft.

Runtime Rebel Intel
3 min read · Apr 10, 2026
MEDIUM
Identity & Access

Chrome DBSC: Securing Session Cookies with Device Binding — Analysis

Google introduces Device Bound Session Credentials in Chrome to combat session hijacking by cryptographically linking authentication cookies to local hardware.

Runtime Rebel Intel
4 min read · Apr 10, 2026
Smart Slider 3 Pro 3.5.1.35 Backdoor via Supply Chain Attack
HIGH
Supply Chain

Smart Slider 3 Pro 3.5.1.35 Backdoor via Supply Chain Attack

Nextend's Smart Slider 3 Pro version 3.5.1.35 was compromised via a supply chain attack. Learn how to identify and remediate the backdoor today.

Runtime Rebel Intel
3 min read · Apr 10, 2026
Google Chrome 146 DBSC Implementation Hardens Windows Against Session Hijacking
INFO
Identity & Access

Google Chrome 146 DBSC Implementation Hardens Windows Against Session Hijacking

Google releases Device Bound Session Credentials (DBSC) in Chrome 146 for Windows to mitigate cookie theft and session hijacking via hardware-backed security.

Runtime Rebel Intel
4 min read · Apr 10, 2026
HIGH
Threat Intel

VENOM PhaaS: New Phishing Attacks Target Senior Executives' Microsoft Logins

Analysis of VENOM, a new PhaaS platform targeting C-suite executives with sophisticated phishing attacks to steal Microsoft login credentials across industries.

Runtime Rebel Intel
4 min read · Apr 10, 2026
HIGH
Malware

LucidRook Malware Targets Taiwan NGOs via DLL Side-Loading

Analysis of the Lua-based LucidRook malware targeting Taiwanese NGOs and universities through spear-phishing and sophisticated DLL side-loading techniques.

Runtime Rebel Intel
4 min read · Apr 10, 2026
UAT-10362 Targets Taiwanese NGOs with LucidRook Malware
HIGH
Threat Intel

UAT-10362 Targets Taiwanese NGOs with LucidRook Malware

Runtime Rebel analyzes UAT-10362's sophisticated spear-phishing campaigns deploying new Lua-based LucidRook malware against Taiwanese NGOs and universities.

Runtime Rebel Intel
4 min read · Apr 10, 2026
EngageLab SDK Vulnerability: Protecting Crypto Wallets from Sandbox Bypass
HIGH
Vulnerabilities

EngageLab SDK Vulnerability: Protecting Crypto Wallets from Sandbox Bypass

A flaw in EngageLab SDK exposed 50 million Android users to data theft. Learn how attackers bypass the Android sandbox to access private cryptocurrency keys.

Runtime Rebel Intel
4 min read · Apr 10, 2026
Legacy Apache RCE and Hybrid P2P Botnet Resurgence Analysis
HIGH
Threat Intel

Legacy Apache RCE and Hybrid P2P Botnet Resurgence Analysis

Exploration of a resurrected 13-year-old Apache RCE and the operational shifts of a hybrid P2P botnet architecture targeting enterprise infrastructure.

Runtime Rebel Intel
3 min read · Apr 9, 2026
MEDIUM
Cloud Security

Federal Evaluators Flag Microsoft Cloud Security Documentation

U.S. federal evaluators expressed a 'lack of confidence' in Microsoft's cloud security posture due to insufficient documentation, despite approval.

Runtime Rebel Intel
5 min read · Apr 9, 2026
HIGH
Vulnerabilities

Palo Alto Networks & SonicWall High-Severity Privilege Escalation Patches

Palo Alto Networks and SonicWall have issued patches for high-severity vulnerabilities allowing privilege escalation to administrator. Immediate patching is advised.

Runtime Rebel Intel
5 min read · Apr 9, 2026
HIGH
Vulnerabilities

Exposed Google API Keys in Android Apps Grant Gemini Access

Analysis of Google API keys found in Android apps that enable unauthorized access to Gemini AI endpoints, detailing risks and mitigation for developers.

Runtime Rebel Intel
5 min read · Apr 9, 2026
HIGH
Data Breach

Eurail Data Breach: 300,000 Individuals' Data Compromised

Eurail B.V. disclosed a December 2023 data breach affecting 300,000 individuals, leading to the theft of personal information. Learn about the impact and mitigation.

Runtime Rebel Intel
4 min read · Apr 9, 2026