Skip to main content

All Articles

Security Intelligence

3410 articles · Updated every 8 hours

Severity (this page):

Advertisement

CRITICAL
Vulnerabilities

Ghost CMS CVE-2022-41654: Over 700 Websites Compromised

Attackers are exploiting a critical Ghost CMS vulnerability to inject malicious scripts into sites belonging to Harvard, Oxford, and DuckDuckGo.

Runtime Rebel Intel
3 min read · May 25, 2026
Linux Vulnerabilities and Defender Zero-Days: Weekly Threat Recap
HIGH
Threat Intel

Linux Vulnerabilities and Defender Zero-Days: Weekly Threat Recap

Weekly intelligence recap covering Linux flaws, Microsoft Defender zero-days, router botnets, and supply chain compromises targeting developer toolchains.

Runtime Rebel Intel
3 min read · May 25, 2026
HIGH
Data Breach

Radiology Associates of Richmond Breach Affects 266,000 Patients

A data breach at Radiology Associates of Richmond has exposed the sensitive health and personal information of over 266,000 individuals.

Runtime Rebel Intel
4 min read · May 25, 2026
MEDIUM
Data Breach

Oncology Institute Discloses Third-Party Data Breach via Vendor

The Oncology Institute reports a data breach involving a third-party vendor, potentially TriZetto, exposing patient PHI and sensitive healthcare data.

Runtime Rebel Intel
3 min read · May 25, 2026
HIGH
Threat Intel

FBI Warns of Kali365 PhaaS Targeting Microsoft 365 Accounts

The FBI issues an advisory on Kali365, a Phishing-as-a-Service platform exploiting OAuth device code flows to bypass MFA and hijack Microsoft 365 accounts.

Runtime Rebel Intel
3 min read · May 25, 2026
Next-Gen NDR: Reducing Alert Fatigue with Agentic AI Capabilities
INFO
Threat Intel

Next-Gen NDR: Reducing Alert Fatigue with Agentic AI Capabilities

Examine how agentic AI is transforming Network Detection and Response to mitigate alert fatigue and improve threat triage efficiency for SOC teams.

Runtime Rebel Intel
4 min read · May 25, 2026

Advertisement

CVE-2026-26980: Ghost CMS SQL Injection Leads to ClickFix Attacks
CRITICAL
Vulnerabilities

CVE-2026-26980: Ghost CMS SQL Injection Leads to ClickFix Attacks

Attackers exploit CVE-2026-26980 in Ghost CMS to compromise 700+ websites, deploying ClickFix malware that tricks users into executing malicious scripts.

Runtime Rebel Intel
4 min read · May 25, 2026
HIGH
Supply Chain

Megalodon Supply Chain Attack Infects 5,500+ GitHub Repositories

Attackers used automated commits to inject malicious GitHub Actions workflows into 5,500+ repositories, targeting CI/CD secrets and sensitive tokens.

Runtime Rebel Intel
4 min read · May 25, 2026
TrapDoor Campaign: Detecting Cross-Ecosystem Supply Chain Attacks
HIGH
Supply Chain

TrapDoor Campaign: Detecting Cross-Ecosystem Supply Chain Attacks

The TrapDoor campaign targets npm, PyPI, and Crates.io with over 384 malicious versions designed to exfiltrate developer credentials and sensitive data.

Runtime Rebel Intel
4 min read · May 25, 2026
HIGH
Vulnerabilities

CVE-2026-5426: RCE via ViewState Deserialization in KnowledgeDeliver

Attackers exploit CVE-2026-5426 in the KnowledgeDeliver LMS to achieve RCE via shared ASP.NET machine keys. Immediate key rotation and patching are required.

Runtime Rebel Intel
3 min read · May 25, 2026
MEDIUM
Threat Intel

Chinese-Language PhaaS: Real-Time OTP Interception and Tokenization

Chinese-language PhaaS providers like Darcula are shifting to real-time OTP interception and digital wallet tokenization to bypass modern MFA controls.

Runtime Rebel Intel
4 min read · May 25, 2026
MEDIUM
Vulnerabilities

Wireshark 4.6.6: Fixing Critical Vulnerability and Dissector Bugs

Wireshark 4.6.6 release addresses one security vulnerability and 11 functional bugs. Learn how this update secures packet analysis and prevents dissector crashes.

Runtime Rebel Intel
4 min read · May 24, 2026
HIGH
Vulnerabilities

CVE-2025-26980: Ghost CMS SQL Injection Exploited in ClickFix Campaign

A critical SQL injection vulnerability in Ghost CMS (CVE-2025-26980) is being exploited to deliver ClickFix malware through malicious JavaScript injections.

Runtime Rebel Intel
3 min read · May 24, 2026
HIGH
Supply Chain

Laravel Lang Hijack: Supply Chain Attack via Malicious GitHub Tags

Analysis of the Laravel Lang supply chain attack involving malicious GitHub tags v13.8.1 and v13.8.2 used to steal environmental secrets and credentials.

Runtime Rebel Intel
4 min read · May 24, 2026
Packagist Supply Chain Attack: 8 Packages Deliver Linux Malware
HIGH
Supply Chain

Packagist Supply Chain Attack: 8 Packages Deliver Linux Malware

Security researchers identified a supply chain attack on Packagist involving eight infected packages that deploy Linux malware via GitHub Releases URLs.

Runtime Rebel Intel
3 min read · May 23, 2026
npm Staged Publishing: New 2FA Controls Prevent Supply Chain Attacks
MEDIUM
Supply Chain

npm Staged Publishing: New 2FA Controls Prevent Supply Chain Attacks

GitHub introduces staged publishing for npm, requiring manual 2FA approval for package releases to mitigate malicious automated updates and account takeovers.

Runtime Rebel Intel
4 min read · May 23, 2026
MEDIUM
Threat Intel

Italy Dismantles CINEMAGOAL App for Streaming Auth Token Theft

Italian authorities dismantled the CINEMAGOAL piracy app, which harvested authentication tokens and session cookies from users to access streaming services.

Runtime Rebel Intel
3 min read · May 23, 2026
Anthropic Project Glasswing Uncovers 10,000 High-Severity Flaws
HIGH
Vulnerabilities

Anthropic Project Glasswing Uncovers 10,000 High-Severity Flaws

Anthropic's Claude Mythos AI identifies over 10,000 critical and high-severity vulnerabilities in systemically important software via Project Glasswing.

Runtime Rebel Intel
4 min read · May 23, 2026
HIGH
Vulnerabilities

Underminr Vulnerability: Bypassing DNS Filtering via Trusted Domains

The Underminr vulnerability affects 88 million domains, allowing attackers to hide C2 traffic and bypass DNS filtering using shared infrastructure.

Runtime Rebel Intel
4 min read · May 23, 2026
Laravel-Lang PHP Packages Compromised: Credential Stealer Alert
HIGH
Supply Chain

Laravel-Lang PHP Packages Compromised: Credential Stealer Alert

Multiple Laravel-Lang PHP packages have been compromised to deliver a cross-platform credential stealer. Learn how to detect and mitigate this supply chain threat.

Runtime Rebel Intel
4 min read · May 23, 2026
INFO
Malware

Obfuscating Strings in C++ Implants: Detection and Analysis

Analyze how stack strings help malware authors evade static analysis. Explore the assembly-level mechanics and detection strategies for Windows implants.

Runtime Rebel Intel
4 min read · May 23, 2026
CVE-2026-9082: Drupal Core SQL Injection Added to CISA KEV Catalog
HIGH
Vulnerabilities

CVE-2026-9082: Drupal Core SQL Injection Added to CISA KEV Catalog

CISA warns of active exploitation of CVE-2026-9082, a critical SQL injection vulnerability in Drupal Core. Organizations must patch to prevent data exposure.

Runtime Rebel Intel
3 min read · May 23, 2026
CVE-2026-48172: LiteSpeed cPanel Plugin Privilege Escalation - Patch Now
CRITICAL
Vulnerabilities

CVE-2026-48172: LiteSpeed cPanel Plugin Privilege Escalation - Patch Now

Exploitation of CVE-2026-48172 in the LiteSpeed cPanel plugin allows local users to gain root access. Organizations should update to version 1.2.2 immediately.

Runtime Rebel Intel
3 min read · May 23, 2026
CRITICAL
Vulnerabilities

ABB B&R Automation Studio <6.5: Multiple Critical SQLite Vulnerabilities

Critical SQLite vulnerabilities in ABB B&R Automation Studio <6.5 expose ICS to RCE, data exposure, and unauthorized access. Update to version 6.5 immediately.

Runtime Rebel Intel
4 min read · May 23, 2026