Skip to main content

All Articles

Security Intelligence

3410 articles · Updated every 8 hours

Severity (this page):

Advertisement

OpenEMR Flaws: Database Compromise, RCE, and Patient Data Theft Risks
HIGH
Vulnerabilities

OpenEMR Flaws: Database Compromise, RCE, and Patient Data Theft Risks

Analysis of 38 security flaws in OpenEMR, an EHR platform used by over 100,000 healthcare providers, enabling database compromise, RCE, and data theft.

Runtime Rebel Intel
5 min read · Apr 29, 2026
GitHub High-Severity Bug Discovered via AI Reverse Engineering
HIGH
Vulnerabilities

GitHub High-Severity Bug Discovered via AI Reverse Engineering

Wiz utilized AI reverse-engineering to uncover a high-severity vulnerability within GitHub, demonstrating advanced discovery methods for complex bugs.

Runtime Rebel Intel
4 min read · Apr 29, 2026
HIGH
Identity & Access

Roblox Account Hijacking: 610,000 Accounts Compromised and Sold

Ukrainian police arrested a group for hijacking 610,000 Roblox accounts and generating $225,000 in profits through illegal sales of user data.

Runtime Rebel Intel
4 min read · Apr 29, 2026
CRITICAL
Vulnerabilities

LiteLLM Proxy Data Exposure & Modification — Urgent Patch Required

Critical vulnerability in LiteLLM proxy enables unauthorized database read/modify access. Exploitation observed shortly after disclosure. Patch immediately.

Runtime Rebel Intel
4 min read · Apr 29, 2026
MEDIUM
Threat Intel

European Police Dismantle €50 Million Crypto Investment Fraud Ring

Authorities in Austria and Albania shut down a massive crypto investment scam involving fraudulent call centers and over €50 million in victim losses.

Runtime Rebel Intel
3 min read · Apr 29, 2026
HIGH
Vulnerabilities

CVE-2020-27686: cPanel and WHM 2FA Authentication Bypass Mitigation

Administrators must patch cPanel and WHM immediately to address a critical 2FA bypass vulnerability that allows attackers to brute-force security codes.

Runtime Rebel Intel
3 min read · Apr 29, 2026

Advertisement

AI-Generated npm Supply Chain Attack: DPRK Exploits Claude Opus
HIGH
Supply Chain

AI-Generated npm Supply Chain Attack: DPRK Exploits Claude Opus

North Korean actors leverage LLMs like Claude Opus to insert malicious npm packages into developer workflows, leading to RCE and data theft via @validate-sdk/v2.

Runtime Rebel Intel
4 min read · Apr 29, 2026
SAP npm Packages Compromised by “Mini Shai-Hulud” Malware
HIGH
Supply Chain

SAP npm Packages Compromised by “Mini Shai-Hulud” Malware

The Mini Shai-Hulud campaign targets SAP cloud application developers with credential-stealing npm packages. Learn how to detect and mitigate this threat.

Runtime Rebel Intel
4 min read · Apr 29, 2026
HIGH
Vulnerabilities

Firefox 150 Patch: 271 Zero-Days Found via Claude Mythos — Update Now

Firefox 150 addresses 271 vulnerabilities discovered by Anthropic’s Claude Mythos AI model, highlighting a shift in automated vulnerability discovery.

Runtime Rebel Intel
4 min read · Apr 29, 2026
HIGH
Supply Chain

Checkmarx Supply Chain Attack: GitHub Data Exfiltration Confirmed

Checkmarx confirms data exfiltration from its GitHub environment following a malicious code publication. Learn about the TTPs and mitigation strategies.

Runtime Rebel Intel
4 min read · Apr 29, 2026
MEDIUM
Threat Intel

Internet-Facing VNC and RDP Expose ICS/OT Systems — Remediation Guide

Forescout research identifies hundreds of exposed VNC servers in critical sectors, posing severe risks to global industrial control systems and OT environments.

Runtime Rebel Intel
4 min read · Apr 29, 2026
CRITICAL
Vulnerabilities

Windows Kernel LPE CVE-2024-21338: Lazarus Group Exploits Zero-Day

CISA adds CVE-2024-21338 to KEV catalog after Lazarus Group exploited the Windows Kernel vulnerability to deploy rootkits and bypass security controls.

Runtime Rebel Intel
3 min read · Apr 29, 2026
cPanel Authentication Bypass: Patch Guidance for Versions 11.132.0.29
HIGH
Vulnerabilities

cPanel Authentication Bypass: Patch Guidance for Versions 11.132.0.29

cPanel releases critical updates to address an authentication bypass vulnerability affecting all supported versions. Administrators should patch immediately.

Runtime Rebel Intel
3 min read · Apr 29, 2026
Optimizing Exposure Management: Beyond CVSS and Patch Fatigue
INFO
Vulnerabilities

Optimizing Exposure Management: Beyond CVSS and Patch Fatigue

A technical analysis of Continuous Threat Exposure Management (CTEM) and why modern security teams must prioritize vulnerabilities based on business risk.

Runtime Rebel Intel
3 min read · Apr 29, 2026
Detecting and Mitigating Money Mule Accounts to Prevent APP Fraud
MEDIUM
Threat Intel

Detecting and Mitigating Money Mule Accounts to Prevent APP Fraud

Learn how intelligence-driven mule account detection disrupts the fraud ecosystem and prevents Authorized Push Payment losses before funds are exfiltrated.

Runtime Rebel Intel
4 min read · Apr 29, 2026
HIGH
Vulnerabilities

CVE-2024-24919: Exploit Analysis and Check Point Gateway Mitigation

Technical analysis of CVE-2024-24919, a critical information disclosure vulnerability in Check Point Security Gateways exploited for credential harvesting.

Runtime Rebel Intel
3 min read · Apr 29, 2026
CRITICAL
Vulnerabilities

CVE-2024-1708 & CVE-2026-32202: CISA KEV Update — Patch Now

CISA adds CVE-2024-1708 and CVE-2026-32202 to the Known Exploited Vulnerabilities Catalog following evidence of active exploitation in the wild.

Runtime Rebel Intel
4 min read · Apr 29, 2026
MEDIUM
Vulnerabilities

NSA GRASSMARLIN XXE Vulnerability CVE-2026-6807 — Mitigation Guide

CISA warns of a Medium-severity XXE vulnerability in NSA GRASSMARLIN. With the tool reaching end-of-life, defenders must address CVE-2026-6807 via decommissioning.

Runtime Rebel Intel
3 min read · Apr 29, 2026
NSA Insider Threat Lessons: Chris Inglis on Post-Snowden Security
INFO
Threat Intel

NSA Insider Threat Lessons: Chris Inglis on Post-Snowden Security

Former NSA Deputy Director Chris Inglis reflects on the Snowden leaks, offering critical insights for CISOs on insider threat detection and enculturation.

Runtime Rebel Intel
4 min read · Apr 29, 2026
BlueNoroff Exploits Fake Zoom Meetings to Deploy macOS Malware
HIGH
Threat Intel

BlueNoroff Exploits Fake Zoom Meetings to Deploy macOS Malware

BlueNoroff leverages AI avatars and stolen video to compromise crypto executives via fake Zoom calls and the Hidden Risk macOS malware family.

Runtime Rebel Intel
4 min read · Apr 29, 2026
HIGH
Vulnerabilities

GitHub Enterprise Server RCE via CVE-2024-6800 — Mitigation Guide

GitHub has patched a critical RCE vulnerability (CVE-2024-6800) in GHES that allows remote attackers to gain administrative access via SAML SSO bypass.

Runtime Rebel Intel
3 min read · Apr 29, 2026
LOW
Cloud Security

Microsoft Teams Free Backend Change Disrupts Chat and Calling

Microsoft confirms a backend configuration change has broken core functionality for Microsoft Teams Free users, impacting global business communication.

Runtime Rebel Intel
3 min read · Apr 29, 2026
CVE-2026-42208: Active Exploitation of LiteLLM SQL Injection
CRITICAL
Vulnerabilities

CVE-2026-42208: Active Exploitation of LiteLLM SQL Injection

Attackers are actively exploiting CVE-2026-42208, a critical SQL injection flaw in LiteLLM, within 36 hours of disclosure. Patch to prevent database compromise.

Runtime Rebel Intel
4 min read · Apr 29, 2026
INFO
Threat Intel

Quantifying Cyber Risk: CISO Budgeting with Insurance Data

CISOs now have powerful data from cyber insurance policies to quantify cyber risk, demonstrate ROI, and justify critical security investments to boards.

Runtime Rebel Intel
4 min read · Apr 29, 2026