Skip to main content

All Articles

Security Intelligence

2477 articles · Updated every 4 hours

Advertisement

TH
HIGH
Threat Intel

Tycoon2FA Phishing Kit Targets Microsoft 365 via Device Code Flow

Tycoon2FA phishing kit now leverages Microsoft 365 device code flows and Trustifi URL abuse to bypass MFA and hijack enterprise accounts.

Runtime Rebel Intel
3 min read·May 17, 2026
NGINX CVE-2026-42945: Heap Buffer Overflow Exploited — Patch Now
CRITICAL
Vulnerabilities

NGINX CVE-2026-42945: Heap Buffer Overflow Exploited — Patch Now

Active exploitation of CVE-2026-42945 in NGINX ngx_http_rewrite_module allows for worker process crashes and remote code execution. Update to version 1.31.0.

Runtime Rebel Intel
4 min read·May 17, 2026
Grafana GitHub Token Leak: Codebase Access and Extortion Attempt
HIGH
Supply Chain

Grafana GitHub Token Leak: Codebase Access and Extortion Attempt

Grafana discloses a security incident where an unauthorized party used a GitHub token to download source code, leading to a failed extortion attempt.

Runtime Rebel Intel
3 min read·May 17, 2026
CL
MEDIUM
Cloud Security

Azure Backup for AKS Vulnerability: Risks of Silent Patches

A reported Azure Backup for AKS vulnerability allowed potential cluster compromise. Learn why Microsoft rejected the report and the impact of silent fixes.

Runtime Rebel Intel
3 min read·May 17, 2026
Funnel Builder Plugin Exploited for WooCommerce Checkout Skimming
CRITICAL
Vulnerabilities

Funnel Builder Plugin Exploited for WooCommerce Checkout Skimming

Attackers are exploiting a vulnerability in the Funnel Builder WordPress plugin to inject skimming scripts and steal payment data from WooCommerce sites.

Runtime Rebel Intel
3 min read·May 16, 2026
TH
HIGH
Threat Intel

Turla Updates Kazuar Backdoor with Modular P2P Botnet Capabilities

Russian threat actor Turla (Secret Blizzard) has upgraded its Kazuar backdoor with peer-to-peer botnet functionality and modular architecture for stealth.

Runtime Rebel Intel
4 min read·May 16, 2026
VU
CRITICAL
Vulnerabilities

NGINX HTTP/3 RCE via CVE-2024-24989 — Mitigation Guide

Proof of Concept code released for critical NGINX CVE-2024-24989 and CVE-2024-24990. Learn how to detect and patch these HTTP/3 vulnerabilities immediately.

Runtime Rebel Intel
3 min read·May 16, 2026
TH
INFO
Threat Intel

Community-Moderated Threat Intel: Lessons from Schneier on Security

An analysis of community-driven threat intelligence aggregation and the role of moderation in maintaining high-signal security data for SOC teams.

Runtime Rebel Intel
3 min read·May 16, 2026
AI-Generated Code and Autonomous Agents: New Risks for Defenders
MEDIUM
Threat Intel

AI-Generated Code and Autonomous Agents: New Risks for Defenders

AI agents are automating vulnerability discovery in AI-generated codebases, forcing a shift in defensive security strategies and response times.

Runtime Rebel Intel
3 min read·May 16, 2026
TH
CRITICAL
Threat Intel

BlackFile: Analyzing UNC6671 Vishing & Cloud Data Extortion

Examines UNC6671's BlackFile vishing, AiTM, and cloud data exfiltration tactics against Microsoft 365 & Okta. Actionable mitigations included.

Runtime Rebel Intel
6 min read·May 15, 2026
VU
CRITICAL
Vulnerabilities

CVE-2026-42897: Microsoft Exchange XSS Under Active Exploitation

CISA adds CVE-2026-42897, a Microsoft Exchange Server Cross-Site Scripting vulnerability, to KEV Catalog due to active exploitation. Immediate patching advised.

Runtime Rebel Intel
4 min read·May 15, 2026
VU
CRITICAL
Vulnerabilities

Pwn2Own Berlin: Microsoft Exchange, Windows 11 Zero-Day Exploits

Zero-day vulnerabilities in Microsoft Exchange, Windows 11, and Red Hat Enterprise Linux demonstrated at Pwn2Own Berlin. Runtime Rebel details the impact.

Runtime Rebel Intel
4 min read·May 15, 2026