Skip to main content

All Articles

Security Intelligence

3410 articles · Updated every 8 hours

Severity (this page):

Advertisement

Managing Shadow AI Risks in Healthcare: Security Governance Guide
MEDIUM
Threat Intel

Managing Shadow AI Risks in Healthcare: Security Governance Guide

Healthcare organizations face rising risks from unsanctioned AI usage. Learn how to secure patient data and implement governance to prevent data leakage.

Runtime Rebel Intel
4 min read · Apr 6, 2026
UAT-10608 Exploits Next.js CVE-2024-34351 via React2Shell Script
HIGH
Threat Intel

UAT-10608 Exploits Next.js CVE-2024-34351 via React2Shell Script

Threat actor UAT-10608 is leveraging an automated script to exploit a Next.js SSRF flaw, exfiltrating credentials and environment secrets from web applications.

Runtime Rebel Intel
3 min read · Apr 6, 2026
INFO
Threat Intel

Google DeepMind Research: Six Web Attack Vectors Against AI Agents

DeepMind researchers reveal how malicious web content can manipulate AI agents, highlighting risks like indirect prompt injection and data exfiltration.

Runtime Rebel Intel
4 min read · Apr 6, 2026
HIGH
Identity & Access

Identity-Based Attacks: Why Breach Monitoring Fails to Stop Infostealers

Infostealers are bypassing MFA by harvesting session cookies. Learn why traditional breach monitoring is insufficient and how to secure identity perimeters.

Runtime Rebel Intel
4 min read · Apr 6, 2026
CRITICAL
Vulnerabilities

FortiClient EMS RCE via CVE-2023-48788 — Patch Guidance

CISA mandates federal agencies patch the critical FortiClient EMS SQL injection flaw, CVE-2023-48788, which allows unauthenticated remote code execution.

Runtime Rebel Intel
3 min read · Apr 6, 2026
Chrome Zero-Day and Fortinet Exploits: Weekly Threat Intelligence
HIGH
Threat Intel

Chrome Zero-Day and Fortinet Exploits: Weekly Threat Intelligence

Intelligence analysis of the latest Chrome zero-day, Fortinet vulnerabilities, and the Axios security breach, including technical remediation for SOC teams.

Runtime Rebel Intel
3 min read · Apr 6, 2026

Advertisement

Multi-OS Attack Defense: Unifying SOC Workflows Across Platforms
MEDIUM
Threat Intel

Multi-OS Attack Defense: Unifying SOC Workflows Across Platforms

Learn how modern threat actors exploit fragmented security silos to move across Windows, Linux, and macOS, and how SOCs can implement unified defenses.

Runtime Rebel Intel
4 min read · Apr 6, 2026
MEDIUM
Threat Intel

Analyzing the Frequency of Open Redirects in Phishing Campaigns

Examine the technical drivers behind the use of open redirects in phishing delivery and learn strategies for detection and vulnerability remediation.

Runtime Rebel Intel
3 min read · Apr 6, 2026
INFO
Threat Intel

Google Accelerates Post-Quantum Cryptography Transition for 2029

Google announces a full migration to post-quantum cryptography by 2029 to ensure crypto-agility and defend against future quantum computing threats.

Runtime Rebel Intel
3 min read · Apr 6, 2026
HIGH
Supply Chain

North Korean Social Engineering Targets Node.js Maintainers

North Korean threat actors use social engineering and malicious npm packages to target high-profile Node.js maintainers in a sophisticated supply chain campaign.

Runtime Rebel Intel
3 min read · Apr 6, 2026
HIGH
Supply Chain

Guardarian Users Targeted via 36 Malicious Strapi npm Packages

Analysis of a supply chain attack involving 36 malicious npm packages posing as Strapi plugins to target Guardarian users and harvest sensitive credentials.

Runtime Rebel Intel
4 min read · Apr 6, 2026
Qilin and Warlock Ransomware Bypass 300+ EDR Tools via BYOVD
HIGH
Malware

Qilin and Warlock Ransomware Bypass 300+ EDR Tools via BYOVD

Threat actors Qilin and Warlock use Bring Your Own Vulnerable Driver (BYOVD) tactics and msimg32.dll to disable security software on compromised endpoints.

Runtime Rebel Intel
3 min read · Apr 6, 2026
BKA Unmasks REvil Leadership Behind 130 German Ransomware Attacks
INFO
Threat Intel

BKA Unmasks REvil Leadership Behind 130 German Ransomware Attacks

Germany's BKA unmasks the leadership of the REvil (Sodinokibi) ransomware group, including the representative UNKN, following a major threat intel investigation.

Runtime Rebel Intel
3 min read · Apr 6, 2026
HIGH
Vulnerabilities

CVE-2024-32113: Apache OFBiz RCE Exploited for Mirai Botnet

Technical analysis of CVE-2024-32113 exploitation in Apache OFBiz. Learn how attackers use path traversal to deploy Mirai botnet malware and how to patch.

Runtime Rebel Intel
3 min read · Apr 6, 2026
HIGH
Threat Intel

Germany Doxes UNKN: Identity of REvil and GandCrab Leader Revealed

German authorities identify Daniil Maksimovich Shchukin as UNKN, the lead operator behind the notorious GandCrab and REvil ransomware operations.

Runtime Rebel Intel
4 min read · Apr 6, 2026
CRITICAL
Vulnerabilities

FortiClient EMS RCE via CVE-2026-35616 — Mitigation Guide

Fortinet releases emergency patches for CVE-2026-35616, a critical SQL injection flaw in FortiClient EMS exploited to achieve unauthenticated RCE.

Runtime Rebel Intel
4 min read · Apr 5, 2026
MEDIUM
Threat Intel

QR Code Phishing: SMS Traffic Violation Scams Bypass Mobile Filters

Scammers are using QR codes in SMS traffic violation scams to bypass security filters and steal financial data. Learn how to identify and block quishing.

Runtime Rebel Intel
4 min read · Apr 5, 2026
DPRK Social Engineering Behind $285 Million Drift Hack: Analysis
HIGH
Threat Intel

DPRK Social Engineering Behind $285 Million Drift Hack: Analysis

A deep dive into the six-month DPRK social engineering operation targeting Drift protocol, resulting in a $285 million Solana-based cryptocurrency theft.

Runtime Rebel Intel
3 min read · Apr 5, 2026
HIGH
Vulnerabilities

CVE-2025-55182: Hackers Exploit React2Shell in Next.js Applications

Security researchers observe automated credential theft campaigns exploiting the React2Shell vulnerability (CVE-2025-55182) in vulnerable Next.js frameworks.

Runtime Rebel Intel
3 min read · Apr 5, 2026
CVE-2026-35616: Critical FortiClient EMS API Bypass Exploited
CRITICAL
Vulnerabilities

CVE-2026-35616: Critical FortiClient EMS API Bypass Exploited

Fortinet releases out-of-band patches for CVE-2026-35616, a critical API access bypass in FortiClient EMS enabling unauthenticated privilege escalation.

Runtime Rebel Intel
3 min read · Apr 5, 2026
36 Malicious npm Packages Target Strapi, Redis, and PostgreSQL
HIGH
Supply Chain

36 Malicious npm Packages Target Strapi, Redis, and PostgreSQL

36 malicious npm packages disguised as Strapi CMS plugins target Redis and PostgreSQL environments to deploy persistent implants and reverse shells.

Runtime Rebel Intel
4 min read · Apr 5, 2026
HIGH
Supply Chain

Axios npm Hijack Attempt: Detecting Social Engineering Tactics

North Korean threat actors targeted an Axios maintainer with a fake Microsoft Teams fix, highlighting critical risks to open-source supply chains.

Runtime Rebel Intel
3 min read · Apr 5, 2026
MEDIUM
Threat Intel

LinkedIn Browser Fingerprinting: Privacy Risks of Extension Scanning

LinkedIn is reportedly scanning users for over 6,000 Chrome extensions using browser fingerprinting techniques, raising significant privacy concerns.

Runtime Rebel Intel
4 min read · Apr 4, 2026
MEDIUM
Identity & Access

OAuth 2.0 Device Code Phishing Surge: Protecting M365 and Google

Device code phishing attacks have surged 37x this year. Learn how adversaries abuse the OAuth 2.0 Device Authorization Grant to bypass MFA and hijack accounts.

Runtime Rebel Intel
4 min read · Apr 4, 2026