All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
Understanding Stack Overflow Exploitation: A Primer
Gain a foundational understanding of how program stacks work and why stack overflows are a critical attack vector for hijacking execution flow.
ADFS Golden SAML: Recovering Signing Keys via Machine DPAPI
Learn how ADFS configuration drift allows attackers to recover active signing keys from Machine DPAPI, enabling SAML assertion forgery and MFA bypass.
Phishing Campaign Uses Nested Redirects to Hijack Google Accounts
Marketing professionals are being targeted by a sophisticated phishing campaign using nested redirects and fake job offers to compromise Google credentials.
State IDs for AI Agents: Estonia’s Path to Machine Identity
Estonia is developing digital identities for AI agents, raising critical questions about accountability, authentication, and the future of machine identity.
Gitea CVE-2026-20896 Authentication Bypass Under Active Exploitation
Attackers are exploiting CVE-2026-20896 in Gitea to bypass authentication via HTTP headers, risking unauthorized access to private code and secrets.
Licking County Pays $1M Ransom to Embargo Group Over Data Theft
Licking County, Ohio, reportedly paid $1 million to the Embargo extortion group to prevent the leak of sensitive data, highlighting risks to local governments.
Advertisement
UniFi OS Command Injection: CVE-2024-42028 Exploitation & Patching
Ubiquiti patches critical vulnerabilities in UniFi OS, including a CVSS 10.0 command injection flaw. Immediate update to version 4.0.18 is required.
CVE-2024-37014: CISA Orders Federal Agencies to Patch Langflow
CISA added CVE-2024-37014, a critical authentication bypass in the Langflow AI framework, to its KEV catalog following reports of active exploitation.
UAT-7810 Expands LapDogs ORB Network via LONGLEASH Malware
China-linked actor UAT-7810 is leveraging new LONGLEASH malware to expand the LapDogs ORB network, targeting internet-facing networking devices for proxying.
CVE-2026-48282: Adobe ColdFusion Path Traversal RCE — Patch Now
CISA adds actively exploited Adobe ColdFusion vulnerability [CVE-2026-48282] to KEV catalog, warning of critical remote code execution risks.
CVE-2026-43499: GhostLock Linux Kernel Privilege Escalation Analysis
A 15-year-old Linux kernel flaw, CVE-2026-43499 (GhostLock), enables local root access and container escape across major distributions since 2011.
Accenture Confirms Breach: LockBit 2.0 Ransomware and Stolen Data
Accenture confirmed a security breach involving LockBit 2.0 ransomware, leading to 35 GB of stolen source code and proprietary data. Runtime Rebel analyzes the impact.
Google Dialogflow CX: Critical Flaw Allows Agent Hijack
A critical flaw in Google Dialogflow CX allowed attackers with edit rights to one agent to hijack others in the same project, exposing user data.
RedWing MaaS: Android Bank Fraud via Telegram Rental Service Analysis
RedWing MaaS is an Android bank fraud malware-as-a-service rented on Telegram, enabling low-skill attackers to steal banking logins and OTPs.
GitHub Actions Attack Patterns Evade CI Security Scanners
Learn how sophisticated GitHub Actions attack patterns bypass traditional CI security scanners, exposing CI/CD pipelines to supply chain risks.
Writer AI Platform: Critical Session Isolation Flaw 'WriteOut'
Runtime Rebel details the critical 'WriteOut' session isolation vulnerability in Writer AI, enabling cross-tenant compromise and unauthorized agent takeover.
Windows Device ID Aids FBI in Tracing Alleged Scattered Spider Hacker
A court filing reveals how a persistent Windows device ID helped the FBI trace an alleged Scattered Spider hacker to a luxury retailer intrusion.
Google Sues Outsider Enterprise Over Gemini-Powered Phishing-as-a-Service
Google takes legal action against Outsider Enterprise, a Chinese cybercrime network using Gemini AI to automate sophisticated phishing campaigns against global users.
Keyfactor's $1B+ Investment: Addressing AI & Post-Quantum Threats
Keyfactor secures over $1 billion to advance its machine identity and PKI platform, preparing enterprises for future AI-driven and post-quantum cryptographic challenges.
Linux Kernel Januscape Flaw: VM Escape on KVM Hypervisors
Analysis of the 16-year-old Januscape flaw affecting Linux KVM hypervisors, enabling VM escape and potential host code execution on Intel and AMD systems.
BeyondTrust RS/PRA Critical Authentication Bypass Flaws Addressed
BeyondTrust has issued an urgent advisory for critical authentication bypass flaws in Remote Support (RS) and Privileged Remote Access (PRA) software.
Windows 11 26H2 Default Backup for Entra-Joined Systems
Microsoft will enable Windows settings backup by default for Entra-joined organizational systems after Windows 11 26H2 upgrade, impacting IT management and compliance.
CVE-2026-11405: Tenda Router Firmware Admin Backdoor Exposed
CERT/CC warns of an undocumented admin backdoor, CVE-2026-11405, in Tenda router firmware, enabling full administrative access bypass. Immediate action advised.
Microsoft Introduces Windows 11 Cloud Rebuild Recovery Feature
Microsoft is testing the new Cloud Rebuild recovery feature for Windows 11 Insider Preview, offering a streamlined, cloud-based OS reinstallation option.