Skip to main content

All Articles

Security Intelligence

2469 articles · Updated every 4 hours

Advertisement

CVE-2026-42897: Microsoft Exchange OWA XSS Zero-Day Under Attack
CRITICAL
Vulnerabilities

CVE-2026-42897: Microsoft Exchange OWA XSS Zero-Day Under Attack

Active Zero-Day XSS vulnerability, CVE-2026-42897, impacts Microsoft Exchange OWA, allowing mailbox compromise. No patch available.

Runtime Rebel Intel
5 min read·May 19, 2026
CL
CRITICAL
Cloud Security

CISA Contractor Leaked AWS GovCloud Keys on GitHub: Critical Exposure

A CISA contractor publicly exposed highly privileged AWS GovCloud and internal system credentials on GitHub, detailing CISA's software development. This leak poses a

Runtime Rebel Intel
5 min read·May 19, 2026
MA
HIGH
Malware

SHub macOS Infostealer Spoofs Apple Security Updates, Installs Backdoor

A new SHub macOS infostealer variant employs fake Apple security update prompts via AppleScript to install a backdoor, threatening user data and system integrity.

Runtime Rebel Intel
4 min read·May 19, 2026
TH
HIGH
Threat Intel

Interpol Operation Ramz: 53 Servers Seized and 200+ Arrests Made

Interpol's Operation Ramz dismantled cybercrime infrastructure across MENA, seizing 53 servers used for phishing and malware while arresting 200 suspects.

Runtime Rebel Intel
3 min read·May 19, 2026
SU
HIGH
Supply Chain

TeamPCP Jenkins Plugin Compromise and Mini Shai-Hulud Worm Analysis

TeamPCP escalates its supply chain campaign with a confirmed Jenkins plugin compromise and a self-spreading worm targeting the npm and PyPI ecosystems.

Runtime Rebel Intel
3 min read·May 18, 2026
Shai-Hulud Worm Code Leak: How Clones Threaten Developer Environments
HIGH
Malware

Shai-Hulud Worm Code Leak: How Clones Threaten Developer Environments

The release of Shai-Hulud worm source code triggers a surge in self-replicating clones, targeting software developers and automated CI/CD pipelines.

Runtime Rebel Intel
4 min read·May 18, 2026
SU
HIGH
Supply Chain

Shai-Hulud Infostealer Surfaces in Malicious npm Package Campaign

Leaked Shai-Hulud malware is targeting Node.js developers via malicious npm packages, exfiltrating sensitive data and credentials to Telegram-based C2.

Runtime Rebel Intel
4 min read·May 18, 2026
CL
MEDIUM
Cloud Security

Mitigating Shadow AI: Framework for Detecting Unauthorized AI Tools

Comprehensive guide for security professionals on identifying, assessing, and governing unsanctioned AI applications to prevent corporate data leakage.

Runtime Rebel Intel
4 min read·May 18, 2026
INTERPOL Operation Ramz: 201 Arrested in MENA Cybercrime Crackdown
MEDIUM
Threat Intel

INTERPOL Operation Ramz: 201 Arrested in MENA Cybercrime Crackdown

INTERPOL's Operation Ramz results in 201 arrests across 13 MENA countries, disrupting infrastructure used for phishing, BEC, and financial fraud schemes.

Runtime Rebel Intel
4 min read·May 18, 2026
Iranian Cyber Offensive Targets Critical Fuel Tank Gauge Systems
HIGH
Threat Intel

Iranian Cyber Offensive Targets Critical Fuel Tank Gauge Systems

Iranian threat actors are targeting insecure automatic tank gauges in fuel infrastructure, posing risks of physical disruption and environmental damage.

Runtime Rebel Intel
3 min read·May 18, 2026
SU
HIGH
Supply Chain

Grafana GitHub Token Compromise: Codebase Stolen via PAT

Grafana Labs reports a source code breach after attackers leveraged a stolen GitHub Personal Access Token. Analysis of the impact and mitigation steps.

Runtime Rebel Intel
3 min read·May 18, 2026
Reducing Phishing Exposure: Strategies for Rapid Evidence Recovery
MEDIUM
Threat Intel

Reducing Phishing Exposure: Strategies for Rapid Evidence Recovery

Learn how SOC teams can close the visibility gap in phishing detection and use evidence-based analysis to prevent business disruption after a click.

Runtime Rebel Intel
3 min read·May 18, 2026