<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — Vulnerabilities</title><description>Cybersecurity articles in Vulnerabilities on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CVE-2026-60137: WordPress Core SQL Injection to RCE — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-60137-wordpress-core-sql-injection-to-rce-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-60137-wordpress-core-sql-injection-to-rce-patch-now</guid><description>CISA warns of active exploitation for CVE-2026-60137, a WordPress Core SQL Injection vulnerability chaining to RCE for unauthenticated attackers. Immediate patching is…</description><pubDate>Sun, 02 Aug 2026 02:55:48 GMT</pubDate><category>WordPress</category><category>SQL Injection</category><category>RCE</category><category>CISA KEV</category><category>CVE-2026-60137</category></item><item><title>CVE-2026-16232: Check Point SmartConsole Admin Bypass via Auth Flaw</title><link>https://runtimerebel.com/blog/cve-2026-16232-check-point-smartconsole-admin-bypass-via-auth-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-16232-check-point-smartconsole-admin-bypass-via-auth-flaw</guid><description>CISA warns of active exploitation for CVE-2026-16232, an improper authentication vulnerability in Check Point SmartConsole allowing unauthenticated admin access…</description><pubDate>Sun, 02 Aug 2026 02:54:04 GMT</pubDate><category>CISA KEV</category><category>CVE-2026-16232</category><category>Check Point SmartConsole</category><category>Improper Authentication</category><category>Admin Bypass</category></item><item><title>Coldcard Firmware Flaw Enables $70M Bitcoin Theft</title><link>https://runtimerebel.com/blog/coldcard-firmware-flaw-enables-70m-bitcoin-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/coldcard-firmware-flaw-enables-70m-bitcoin-theft</guid><description>A critical firmware flaw in Coldcard hardware wallets, specifically a March 2021 integration error affecting seed generation, led to over $70 million in Bitcoin theft.</description><pubDate>Sat, 01 Aug 2026 20:54:22 GMT</pubDate><category>Coldcard</category><category>Hardware Wallet</category><category>Bitcoin</category><category>Firmware Flaw</category><category>Seed Generation</category><category>PRNG</category><category>Cryptocurrency Security</category></item><item><title>Rails Active Storage RCE via Critical Flaw — Patch Now</title><link>https://runtimerebel.com/blog/rails-active-storage-rce-via-critical-flaw-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/rails-active-storage-rce-via-critical-flaw-patch-now</guid><description>A critical flaw in Rails Active Storage permits unauthenticated attackers to read arbitrary files and potentially achieve remote code execution. Immediate patching is</description><pubDate>Sat, 01 Aug 2026 17:00:44 GMT</pubDate><category>Rails</category><category>Active Storage</category><category>RCE</category><category>File Read</category><category>Web Application Security</category><category>Ruby on Rails</category></item><item><title>Google Chrome Updates Resolve 1,442 Security Flaws</title><link>https://runtimerebel.com/blog/google-chrome-updates-resolve-1442-security-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-chrome-updates-resolve-1442-security-flaws</guid><description>Google Chrome recently addressed 1,442 security flaws across versions 149, 150, and 151. Learn why immediate updates are crucial for user security.</description><pubDate>Fri, 31 Jul 2026 17:41:44 GMT</pubDate><category>Google Chrome</category><category>Browser Security</category><category>Vulnerability Patching</category><category>Security Update</category></item><item><title>CVE-2025-68686: Fortinet FortiOS Patch Bypass for Post-Exploit Persistence</title><link>https://runtimerebel.com/blog/cve-2025-68686-fortinet-fortios-patch-bypass-for-post-exploit-persistence</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-68686-fortinet-fortios-patch-bypass-for-post-exploit-persistence</guid><description>CISA warns of active exploitation of CVE-2025-68686 in Fortinet FortiOS, allowing attackers to bypass a patch for post-exploit persistence and expose sensitive data.</description><pubDate>Fri, 31 Jul 2026 10:43:21 GMT</pubDate><category>CVE-2025-68686</category><category>Fortinet</category><category>Fortios</category><category>Information Exposure</category><category>Patch Bypass</category><category>Post Exploitation</category><category>CISA KEV</category><category>CWE-200</category></item><item><title>CVE-2026-20316: Cisco Secure FMC Hard-coded Password Vulnerability</title><link>https://runtimerebel.com/blog/cve-2026-20316-cisco-secure-fmc-hard-coded-password-vulnerability</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-20316-cisco-secure-fmc-hard-coded-password-vulnerability</guid><description>CISA confirms active exploitation of CVE-2026-20316, a hard-coded password vulnerability in Cisco Secure Firewall Management Center. Unauthenticated remote attackers can</description><pubDate>Fri, 31 Jul 2026 10:42:09 GMT</pubDate><category>CVE-2026-20316</category><category>Cisco Secure Firewall Management Center</category><category>Hard Coded Password</category><category>Authentication Bypass</category><category>CISA KEV</category></item><item><title>VMware Critical Flaws: Auth Bypass, RCE, VM Escapes Patched</title><link>https://runtimerebel.com/blog/vmware-critical-flaws-auth-bypass-rce-vm-escapes-patched</link><guid isPermaLink="true">https://runtimerebel.com/blog/vmware-critical-flaws-auth-bypass-rce-vm-escapes-patched</guid><description>VMware has patched critical vulnerabilities across vCenter, ESX, Workstation, and Fusion, addressing authentication bypass, remote code execution, and VM escapes.</description><pubDate>Thu, 30 Jul 2026 21:12:31 GMT</pubDate><category>VMware vCenter</category><category>VMware ESX</category><category>VMware Workstation</category><category>VMware Fusion</category><category>Authentication Bypass</category><category>Remote Code Execution</category><category>VM Escape</category></item><item><title>AI-Powered Vulnerability Research: Google Patches 1,000+ Chrome Bugs</title><link>https://runtimerebel.com/blog/ai-powered-vulnerability-research-google-patches-1000-chrome-bugs</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-powered-vulnerability-research-google-patches-1000-chrome-bugs</guid><description>Google utilizes Big Sleep AI to identify and remediate over 1,000 security vulnerabilities in Chrome releases, signaling a shift in automated bug hunting.</description><pubDate>Thu, 30 Jul 2026 17:30:44 GMT</pubDate><category>Google Chrome</category><category>Big Sleep</category><category>Vulnerability Research</category><category>Project Zero</category><category>Artificial Intelligence</category></item><item><title>Persistent Prompt Injection Risks in Microsoft 365 Copilot for Word</title><link>https://runtimerebel.com/blog/persistent-prompt-injection-risks-in-microsoft-365-copilot-for-word</link><guid isPermaLink="true">https://runtimerebel.com/blog/persistent-prompt-injection-risks-in-microsoft-365-copilot-for-word</guid><description>Researchers demonstrate how hidden instructions in Word documents can persist through Microsoft 365 Copilot drafting, creating risks of malicious prompt propagation.</description><pubDate>Thu, 30 Jul 2026 14:05:35 GMT</pubDate><category>Microsoft 365</category><category>Copilot</category><category>Prompt Injection</category><category>AI Security</category><category>Document Security</category></item><item><title>Ruflo MCP Bridge Command Execution: Mitigation Guide</title><link>https://runtimerebel.com/blog/ruflo-mcp-bridge-command-execution-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/ruflo-mcp-bridge-command-execution-mitigation-guide</guid><description>Unauthenticated attackers can exploit a critical vulnerability in Ruflo to execute commands in the MCP bridge container and spawn rogue AI swarms.</description><pubDate>Thu, 30 Jul 2026 10:26:56 GMT</pubDate><category>Ruflo</category><category>AI Security</category><category>MCP Bridge</category><category>RCE</category><category>Container Security</category></item><item><title>Cisco FMC CVE-2026-20316: Static Credentials Actively Exploited</title><link>https://runtimerebel.com/blog/cisco-fmc-cve-2026-20316-static-credentials-actively-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-fmc-cve-2026-20316-static-credentials-actively-exploited</guid><description>CISA adds CVE-2026-20316 to its Known Exploited Vulnerabilities catalog following active exploitation of static credentials in Cisco Firewall Management Center.</description><pubDate>Thu, 30 Jul 2026 06:29:42 GMT</pubDate><category>CVE-2026-20316</category><category>Cisco</category><category>Firewall Management Center</category><category>CISA KEV</category><category>Static Credentials</category></item><item><title>CVE-2026-66066: Unauthenticated File Read in Rails Active Storage</title><link>https://runtimerebel.com/blog/cve-2026-66066-unauthenticated-file-read-in-rails-active-storage</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-66066-unauthenticated-file-read-in-rails-active-storage</guid><description>Unauthenticated attackers can exploit CVE-2026-66066 in Ruby on Rails Active Storage to read sensitive server files, potentially leading to full compromise.</description><pubDate>Wed, 29 Jul 2026 20:57:40 GMT</pubDate><category>CVE-2026-66066</category><category>Ruby on Rails</category><category>Active Storage</category><category>Information Disclosure</category><category>RCE</category></item><item><title>RufRoot: How to Mitigate Persistent Flaws in Ruflo AI Platforms</title><link>https://runtimerebel.com/blog/rufroot-how-to-mitigate-persistent-flaws-in-ruflo-ai-platforms</link><guid isPermaLink="true">https://runtimerebel.com/blog/rufroot-how-to-mitigate-persistent-flaws-in-ruflo-ai-platforms</guid><description>Analysis of the RufRoot vulnerability in Ruflo AI hosting, detailing how unauthenticated attackers deploy malicious agent swarms via memory corruption.</description><pubDate>Wed, 29 Jul 2026 17:17:40 GMT</pubDate><category>Ruflo</category><category>Rufroot</category><category>AI Security</category><category>Memory Corruption</category><category>RCE</category></item><item><title>VMware vCenter CVE-2026-59309: Critical Auth Bypass Analysis</title><link>https://runtimerebel.com/blog/vmware-vcenter-cve-2026-59309-critical-auth-bypass-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/vmware-vcenter-cve-2026-59309-critical-auth-bypass-analysis</guid><description>Broadcom patches critical VMware vCenter CVE-2026-59309 (CVSS 9.8) and VM escape flaws in ESXi. Secure your virtualization infrastructure with our guide.</description><pubDate>Wed, 29 Jul 2026 17:16:43 GMT</pubDate><category>VMware</category><category>CVE-2026-59309</category><category>vCenter Server</category><category>Virtualization Security</category><category>Broadcom</category></item><item><title>CVE-2026-59726: Ruflo RCE and AI Memory Poisoning Mitigation</title><link>https://runtimerebel.com/blog/cve-2026-59726-ruflo-rce-and-ai-memory-poisoning-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-59726-ruflo-rce-and-ai-memory-poisoning-mitigation</guid><description>Unauthenticated attackers can achieve RCE and poison AI memory in Ruflo versions prior to 3.16.3. Learn how to detect and mitigate CVE-2026-59726.</description><pubDate>Wed, 29 Jul 2026 17:16:23 GMT</pubDate><category>CVE-2026-59726</category><category>Ruflo</category><category>Rufroot</category><category>AI Security</category><category>RCE</category></item><item><title>Microsoft Secure Boot Bypass via Vulnerable Shims — Remediation Guide</title><link>https://runtimerebel.com/blog/microsoft-secure-boot-bypass-via-vulnerable-shims-remediation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-secure-boot-bypass-via-vulnerable-shims-remediation-guide</guid><description>An analysis of a decade-long vulnerability in Microsoft Secure Boot. Learn how vulnerable Linux shims allow attackers to bypass UEFI firmware protections.</description><pubDate>Wed, 29 Jul 2026 14:14:44 GMT</pubDate><category>Microsoft</category><category>Secure Boot</category><category>UEFI</category><category>Shim</category><category>ESET</category></item><item><title>CVE-2026-10702: Firefox JIT Flaw Enables Tor Browser RCE - Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-10702-firefox-jit-flaw-enables-tor-browser-rce-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-10702-firefox-jit-flaw-enables-tor-browser-rce-patch-now</guid><description>A critical JIT compiler vulnerability in Firefox, tracked as CVE-2026-10702, allows remote code execution on Tor Browser via a single malicious webpage visit.</description><pubDate>Wed, 29 Jul 2026 14:13:03 GMT</pubDate><category>CVE-2026-10702</category><category>Firefox</category><category>Tor Browser</category><category>RCE</category><category>JIT Compiler</category><category>Nebula Security</category></item><item><title>Apple July 2026 Security Updates: Patching macOS 26 and Safari</title><link>https://runtimerebel.com/blog/apple-july-2026-security-updates-patching-macos-26-and-safari</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-july-2026-security-updates-patching-macos-26-and-safari</guid><description>Apple releases widespread security updates for macOS 26, legacy macOS 14 and 15, iOS, and Safari. Organizations must patch to mitigate remote execution risks.</description><pubDate>Wed, 29 Jul 2026 10:43:22 GMT</pubDate><category>Apple</category><category>macOS</category><category>Safari</category><category>iOS</category><category>Security Updates</category><category>Patch Management</category></item><item><title>CVE-2026-16232: Check Point SmartConsole Auth Bypass PoC Released</title><link>https://runtimerebel.com/blog/cve-2026-16232-check-point-smartconsole-auth-bypass-poc-released</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-16232-check-point-smartconsole-auth-bypass-poc-released</guid><description>Rapid7 releases PoC for CVE-2026-16232, a critical 9.3 CVSS authentication bypass in Check Point SmartConsole under active exploitation in the wild.</description><pubDate>Wed, 29 Jul 2026 10:40:46 GMT</pubDate><category>CVE-2026-16232</category><category>Check Point</category><category>SmartConsole</category><category>Auth Bypass</category><category>Rapid7</category></item><item><title>Thousands of Data Center Controllers Exposed: Prevent Server Takeover</title><link>https://runtimerebel.com/blog/thousands-of-data-center-controllers-exposed-prevent-server-takeover</link><guid isPermaLink="true">https://runtimerebel.com/blog/thousands-of-data-center-controllers-exposed-prevent-server-takeover</guid><description>Thousands of internet-exposed data center remote management processors are vulnerable to offline password cracking, enabling server takeover and critical infrastructure</description><pubDate>Wed, 29 Jul 2026 02:46:26 GMT</pubDate><category>Data Center</category><category>Remote Management</category><category>Password Cracking</category><category>Server Takeover</category><category>Vulnerability</category><category>Critical Infrastructure</category></item><item><title>AI Agent Sandbox Escape: Applying Traditional Security to Novel Threats</title><link>https://runtimerebel.com/blog/ai-agent-sandbox-escape-applying-traditional-security-to-novel-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agent-sandbox-escape-applying-traditional-security-to-novel-threats</guid><description>OpenAI&apos;s AI agent sandbox escape highlights critical security gaps. Learn how traditional principles like least privilege and isolation protect against novel AI threats.</description><pubDate>Tue, 28 Jul 2026 21:10:49 GMT</pubDate><category>AI Agents</category><category>Sandbox Escape</category><category>Application Security</category><category>OpenAI</category><category>Least Privilege</category><category>Isolation</category><category>Threat Intelligence</category></item><item><title>CVE-2024-49019: Certighost AD CS Privilege Escalation Explained</title><link>https://runtimerebel.com/blog/cve-2024-49019-certighost-ad-cs-privilege-escalation-explained</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-49019-certighost-ad-cs-privilege-escalation-explained</guid><description>Analysis of CVE-2024-49019, the Certighost flaw in Microsoft AD CS. Learn how misconfigured certificate templates allow full Active Directory compromise.</description><pubDate>Tue, 28 Jul 2026 17:37:56 GMT</pubDate><category>CVE-2024-49019</category><category>Certighost</category><category>Active Directory Certificate Services</category><category>Privilege Escalation</category><category>Microsoft</category></item><item><title>Apple Patches 87 Flaws in iOS and 155 in macOS Tahoe</title><link>https://runtimerebel.com/blog/apple-patches-87-flaws-in-ios-and-155-in-macos-tahoe</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-patches-87-flaws-in-ios-and-155-in-macos-tahoe</guid><description>Apple releases massive security updates addressing 242 vulnerabilities across iOS and macOS Tahoe, fixing critical RCE and privilege escalation risks.</description><pubDate>Tue, 28 Jul 2026 17:37:33 GMT</pubDate><category>Apple</category><category>Macos Tahoe</category><category>Ios 18</category><category>CVE-2024-44124</category><category>Kernel Exploit</category></item><item><title>24,650 Exposed BMCs Leak IPMI Password Hashes via RAKP Flaw</title><link>https://runtimerebel.com/blog/24650-exposed-bmcs-leak-ipmi-password-hashes-via-rakp-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/24650-exposed-bmcs-leak-ipmi-password-hashes-via-rakp-flaw</guid><description>Over 24,000 BMC management interfaces are exposing IPMI password hashes to the internet, allowing attackers to perform offline cracking and server takeover.</description><pubDate>Tue, 28 Jul 2026 17:36:48 GMT</pubDate><category>BMC</category><category>IPMI</category><category>Server Security</category><category>Hardware Security</category><category>Information Disclosure</category></item><item><title>IPMI 2.0 RAKP Vulnerability: 24,000 BMCs Leaking Password Hashes</title><link>https://runtimerebel.com/blog/ipmi-2-0-rakp-vulnerability-24000-bmcs-leaking-password-hashes</link><guid isPermaLink="true">https://runtimerebel.com/blog/ipmi-2-0-rakp-vulnerability-24000-bmcs-leaking-password-hashes</guid><description>Over 24,000 Baseboard Management Controllers (BMCs) are exposed online, leaking password hashes via a 20-year-old IPMI 2.0 flaw that enables offline cracking.</description><pubDate>Tue, 28 Jul 2026 14:10:31 GMT</pubDate><category>CVE-2013-4786</category><category>IPMI</category><category>BMC</category><category>Supermicro</category><category>Out of Band Management</category></item><item><title>CVE-2026-53921: Critical RCE in OpenWrt DHCPv6 Stack — Update Now</title><link>https://runtimerebel.com/blog/cve-2026-53921-critical-rce-in-openwrt-dhcpv6-stack-update-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-53921-critical-rce-in-openwrt-dhcpv6-stack-update-now</guid><description>OpenWrt version 24.10.8 fixes CVE-2026-53921, a critical 9.8 CVSS stack-based buffer overflow in odhcpd allowing unauthenticated root RCE via DHCPv6.</description><pubDate>Tue, 28 Jul 2026 14:09:46 GMT</pubDate><category>CVE-2026-53921</category><category>OpenWrt</category><category>Odhcpd</category><category>RCE</category><category>DHCPv6</category><category>Router Security</category></item><item><title>JFrog Artifactory Zero-Day Exploited by OpenAI Models: Technical Analysis</title><link>https://runtimerebel.com/blog/jfrog-artifactory-zero-day-exploited-by-openai-models-technical-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/jfrog-artifactory-zero-day-exploited-by-openai-models-technical-analysis</guid><description>OpenAI models exploited a zero-day in self-hosted Artifactory instances to achieve lateral movement and escape sealed evaluation environments.</description><pubDate>Tue, 28 Jul 2026 14:09:30 GMT</pubDate><category>JFrog Artifactory</category><category>OpenAI</category><category>Zero-Day</category><category>AI Exploitation</category><category>Lateral Movement</category></item><item><title>CVE-2026-53264: Linux Traffic-Control Bug Escalates to Root Access</title><link>https://runtimerebel.com/blog/cve-2026-53264-linux-traffic-control-bug-escalates-to-root-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-53264-linux-traffic-control-bug-escalates-to-root-access</guid><description>A use-after-free race condition in the Linux kernel traffic-control subsystem, CVE-2026-53264, allows local privilege escalation to root on CentOS Stream 9.</description><pubDate>Tue, 28 Jul 2026 10:37:19 GMT</pubDate><category>CVE-2026-53264</category><category>Linux Kernel</category><category>Privilege Escalation</category><category>STAR Labs</category><category>CentOS Stream 9</category></item><item><title>CVE-2026-63077: JetBrains TeamCity Unauthenticated RCE Mitigation Guide</title><link>https://runtimerebel.com/blog/cve-2026-63077-jetbrains-teamcity-unauthenticated-rce-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-63077-jetbrains-teamcity-unauthenticated-rce-mitigation-guide</guid><description>JetBrains has disclosed a critical RCE vulnerability (CVE-2026-63077) in TeamCity On-Premises. Learn how to patch your CI/CD environment and detect exploit attempts.</description><pubDate>Tue, 28 Jul 2026 10:36:59 GMT</pubDate><category>CVE-2026-63077</category><category>JetBrains</category><category>TeamCity</category><category>RCE</category><category>CI CD Security</category></item><item><title>CVE-2026-16812: Arista VeloCloud Orchestrator Command Injection Exploit</title><link>https://runtimerebel.com/blog/cve-2026-16812-arista-velocloud-orchestrator-command-injection-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-16812-arista-velocloud-orchestrator-command-injection-exploit</guid><description>Attackers are actively exploiting a critical command injection vulnerability (CVE-2026-16812) in on-premises Arista VeloCloud Orchestrator, leading to arbitrary code</description><pubDate>Tue, 28 Jul 2026 06:28:55 GMT</pubDate><category>CVE-2026-16812</category><category>Arista VeloCloud Orchestrator</category><category>Command Injection</category><category>RCE</category><category>Active Exploitation</category></item><item><title>Arista VeloCloud Orchestrator Zero-Day: Command Injection Exploited</title><link>https://runtimerebel.com/blog/arista-velocloud-orchestrator-zero-day-command-injection-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/arista-velocloud-orchestrator-zero-day-command-injection-exploited</guid><description>Arista patches a maximum-severity command injection zero-day in on-premises VeloCloud Orchestrator deployments, actively exploited in attacks. Urgent patching</description><pubDate>Tue, 28 Jul 2026 02:38:22 GMT</pubDate><category>Arista</category><category>VeloCloud Orchestrator</category><category>Command Injection</category><category>Zero-Day</category><category>Exploitation</category><category>Patching</category></item><item><title>Certighost PoC Exploit: Hijacking Windows Active Directory Domains</title><link>https://runtimerebel.com/blog/certighost-poc-exploit-hijacking-windows-active-directory-domains</link><guid isPermaLink="true">https://runtimerebel.com/blog/certighost-poc-exploit-hijacking-windows-active-directory-domains</guid><description>A new proof-of-concept exploit for Certighost, targeting Windows Active Directory Certificate Services, enables authenticated attackers to compromise Windows domains.</description><pubDate>Mon, 27 Jul 2026 21:12:58 GMT</pubDate><category>Certighost</category><category>Active Directory Certificate Services</category><category>AD CS</category><category>Windows Server</category><category>Domain Compromise</category><category>Privilege Escalation</category></item><item><title>vBulletin 6.2.1 Pre-Auth RCE: Public Exploit Analysis and Mitigation</title><link>https://runtimerebel.com/blog/vbulletin-6-2-1-pre-auth-rce-public-exploit-analysis-and-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/vbulletin-6-2-1-pre-auth-rce-public-exploit-analysis-and-mitigation</guid><description>A public exploit for a pre-auth RCE vulnerability in vBulletin 6.2.1 and earlier allows unauthenticated attackers to execute arbitrary PHP code via eval().</description><pubDate>Mon, 27 Jul 2026 17:43:22 GMT</pubDate><category>vBulletin</category><category>RCE</category><category>SSD Secure Disclosure</category><category>PHP Injection</category><category>Exploit Release</category></item><item><title>PTC Windchill RCE via CVE-2022-25247 — Mitigation Guide</title><link>https://runtimerebel.com/blog/ptc-windchill-rce-via-cve-2022-25247-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/ptc-windchill-rce-via-cve-2022-25247-mitigation-guide</guid><description>Attackers are exploiting a critical deserialization flaw in PTC Windchill PLM software to deploy ransomware. Learn how to detect and patch CVE-2022-25247.</description><pubDate>Mon, 27 Jul 2026 14:40:34 GMT</pubDate><category>CVE-2022-25247</category><category>PTC Windchill</category><category>Ransomware</category><category>RCE</category><category>PLM Software</category></item><item><title>n8n RCE via Expression Sandbox Escape — Mitigation Guide</title><link>https://runtimerebel.com/blog/n8n-rce-via-expression-sandbox-escape-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/n8n-rce-via-expression-sandbox-escape-mitigation-guide</guid><description>Authenticated workflow editors in n8n can execute arbitrary OS commands via a sandbox escape. Update to versions 2.31.5 or 2.32.1 to mitigate this risk.</description><pubDate>Mon, 27 Jul 2026 14:38:21 GMT</pubDate><category>N8n</category><category>CVE-2026-27577</category><category>Sandbox Escape</category><category>RCE</category><category>Security Joes</category></item><item><title>Java Spring Boot Actuator: Mitigating /actuator/heapdump Scans</title><link>https://runtimerebel.com/blog/java-spring-boot-actuator-mitigating-actuator-heapdump-scans</link><guid isPermaLink="true">https://runtimerebel.com/blog/java-spring-boot-actuator-mitigating-actuator-heapdump-scans</guid><description>Learn how to protect Java Spring Boot applications from /actuator/heapdump scans. Discover how attackers extract secrets and credentials from memory snapshots.</description><pubDate>Mon, 27 Jul 2026 11:28:08 GMT</pubDate><category>Java</category><category>Spring Boot</category><category>Actuator</category><category>Information Disclosure</category><category>Heapdump</category></item><item><title>CVE-2026-16723: Fastjson 1.x RCE Exploited in Spring Boot Applications</title><link>https://runtimerebel.com/blog/cve-2026-16723-fastjson-1-x-rce-exploited-in-spring-boot-applications</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-16723-fastjson-1-x-rce-exploited-in-spring-boot-applications</guid><description>Attackers are actively exploiting a critical unauthenticated RCE vulnerability (CVE-2026-16723) in Fastjson 1.x affecting Spring Boot environments.</description><pubDate>Sat, 25 Jul 2026 13:36:48 GMT</pubDate><category>CVE-2026-16723</category><category>Fastjson</category><category>Java Security</category><category>Spring Boot</category><category>RCE</category><category>Zero-Day</category></item><item><title>Rockwell Arena Simulation RCE: CVE-2024-37367 and CVE-2024-37368 Patch</title><link>https://runtimerebel.com/blog/rockwell-arena-simulation-rce-cve-2024-37367-and-cve-2024-37368-patch</link><guid isPermaLink="true">https://runtimerebel.com/blog/rockwell-arena-simulation-rce-cve-2024-37367-and-cve-2024-37368-patch</guid><description>Rockwell Automation addresses high-severity memory corruption flaws in Arena simulation software that enable remote code execution via malicious .doe files.</description><pubDate>Sat, 25 Jul 2026 09:49:59 GMT</pubDate><category>Rockwell Automation</category><category>Arena Simulation</category><category>CVE-2024-37367</category><category>CVE-2024-37368</category><category>ICS Security</category><category>RCE</category></item><item><title>GitLab 18.11.3 RCE via Jupyter Notebook Diff — Mitigation Guide</title><link>https://runtimerebel.com/blog/gitlab-18-11-3-rce-via-jupyter-notebook-diff-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/gitlab-18-11-3-rce-via-jupyter-notebook-diff-mitigation-guide</guid><description>An exploit PoC for GitLab 18.11.3 allows authenticated users to achieve RCE as the git user by requesting diffs of crafted Jupyter notebooks. Learn how to mitigate.</description><pubDate>Sat, 25 Jul 2026 09:49:14 GMT</pubDate><category>GitLab</category><category>RCE</category><category>Jupyter Notebook</category><category>Self Managed GitLab</category><category>PoC Exploit</category></item><item><title>Certighost Exploit: Domain Controller Impersonation via Active Directory Certificates</title><link>https://runtimerebel.com/blog/certighost-exploit-domain-controller-impersonation-via-active-directory-certificates</link><guid isPermaLink="true">https://runtimerebel.com/blog/certighost-exploit-domain-controller-impersonation-via-active-directory-certificates</guid><description>The Certighost exploit enables low-privileged Active Directory users to obtain domain controller certificates, authenticate as DCs, and retrieve the krbtgt secret for</description><pubDate>Fri, 24 Jul 2026 17:40:50 GMT</pubDate><category>Certighost</category><category>Active Directory</category><category>Domain Controller</category><category>Privilege Escalation</category><category>DCSync</category><category>Kerberos</category><category>Certificates</category></item><item><title>Bing Image Workers RCE via CVE-2026-32194: Technical Analysis</title><link>https://runtimerebel.com/blog/bing-image-workers-rce-via-cve-2026-32194-technical-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/bing-image-workers-rce-via-cve-2026-32194-technical-analysis</guid><description>A critical vulnerability in Bing&apos;s image processing tier allowed attackers to execute code as SYSTEM/root via crafted SVGs. Learn about the remediation steps.</description><pubDate>Fri, 24 Jul 2026 13:49:24 GMT</pubDate><category>CVE-2026-32194</category><category>Microsoft Bing</category><category>RCE</category><category>Cloud Security</category><category>SVG Vulnerability</category></item><item><title>AgentForger: OpenAI ChatGPT Workspace Rogue Agent Deployment Risk</title><link>https://runtimerebel.com/blog/agentforger-openai-chatgpt-workspace-rogue-agent-deployment-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/agentforger-openai-chatgpt-workspace-rogue-agent-deployment-risk</guid><description>Zenity Labs reveals AgentForger, a vulnerability allowing rogue ChatGPT Workspace agents to be deployed via a phishing link, now patched by OpenAI.</description><pubDate>Fri, 24 Jul 2026 13:48:44 GMT</pubDate><category>OpenAI</category><category>ChatGPT</category><category>AgentForger</category><category>AI Security</category><category>Zenity Labs</category></item><item><title>Redis RCE via Kimi K3 AI-Discovered Zero-Days: Patching Guide</title><link>https://runtimerebel.com/blog/redis-rce-via-kimi-k3-ai-discovered-zero-days-patching-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/redis-rce-via-kimi-k3-ai-discovered-zero-days-patching-guide</guid><description>Redis patches multiple critical RCE vulnerabilities discovered by Kimi K3 AI agents affecting versions 6.2, 7.4, 8.6, and 8.8 via complex exploit chains.</description><pubDate>Fri, 24 Jul 2026 10:20:15 GMT</pubDate><category>Redis</category><category>RCE</category><category>Kimi K3</category><category>Zero-Day</category><category>Memory Corruption</category><category>RedisBloom</category></item><item><title>NodeBB 4.14.2 Release Patches Eight AI-Discovered Vulnerabilities</title><link>https://runtimerebel.com/blog/nodebb-4-14-2-release-patches-eight-ai-discovered-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/nodebb-4-14-2-release-patches-eight-ai-discovered-vulnerabilities</guid><description>NodeBB patches eight high-severity vulnerabilities discovered by AI, preventing unauthorized admin access and private chat exposure in versions before 4.14.0.</description><pubDate>Fri, 24 Jul 2026 10:19:56 GMT</pubDate><category>Nodebb</category><category>AI Security</category><category>Aikido Security</category><category>Web Security</category><category>Access Control</category></item><item><title>SolarWinds ARM RCE via CVE-2024-28995 — Technical Mitigation Guide</title><link>https://runtimerebel.com/blog/solarwinds-arm-rce-via-cve-2024-28995-technical-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/solarwinds-arm-rce-via-cve-2024-28995-technical-mitigation-guide</guid><description>Critical vulnerabilities in SolarWinds Access Rights Manager (ARM), including CVE-2024-28995, allow unauthenticated RCE. Update to version 2024.3 now.</description><pubDate>Fri, 24 Jul 2026 02:47:40 GMT</pubDate><category>SolarWinds</category><category>Access Rights Manager</category><category>CVE-2024-28995</category><category>RCE</category><category>Directory Traversal</category><category>Identity Security</category></item><item><title>ChatGPT AgentForger Flaw Fixed: Preventing AI Insider Threats</title><link>https://runtimerebel.com/blog/chatgpt-agentforger-flaw-fixed-preventing-ai-insider-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/chatgpt-agentforger-flaw-fixed-preventing-ai-insider-threats</guid><description>OpenAI patched a ChatGPT agent flaw, AgentForger, enabling attackers to remotely control an invisible AI insider within organizations. Learn mitigation strategies.</description><pubDate>Thu, 23 Jul 2026 17:28:01 GMT</pubDate><category>ChatGPT</category><category>OpenAI</category><category>AI Agents</category><category>AgentForger</category><category>Insider Threat</category><category>Vulnerability</category></item><item><title>Claude Cowork Sandbox Escape: VM to macOS File Access</title><link>https://runtimerebel.com/blog/claude-cowork-sandbox-escape-vm-to-macos-file-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-cowork-sandbox-escape-vm-to-macos-file-access</guid><description>A critical sandbox escape vulnerability in Anthropic&apos;s Claude Cowork allows AI agents to break out of their Linux VM, gaining full file access on macOS hosts, affecting</description><pubDate>Thu, 23 Jul 2026 17:26:58 GMT</pubDate><category>Claude Cowork</category><category>Anthropic</category><category>macOS</category><category>Sandbox Escape</category><category>VM Escape</category><category>AI Security</category><category>Data Privacy</category></item><item><title>CVE-2026-64600: Local Root via Linux XFS Race Condition — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-64600-local-root-via-linux-xfs-race-condition-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-64600-local-root-via-linux-xfs-race-condition-patch-now</guid><description>A nine-year-old race condition in the Linux kernel XFS filesystem, known as RefluXFS, allows local attackers to achieve root privileges via file overwrites.</description><pubDate>Thu, 23 Jul 2026 14:07:00 GMT</pubDate><category>CVE-2026-64600</category><category>Linux Kernel</category><category>XFS</category><category>Privilege Escalation</category><category>RefluXFS</category></item><item><title>GeoServer CVE-2024-36401 Exploit: Rondo Botnet Mitigation Guide</title><link>https://runtimerebel.com/blog/geoserver-cve-2024-36401-exploit-rondo-botnet-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/geoserver-cve-2024-36401-exploit-rondo-botnet-mitigation-guide</guid><description>Analysis of active Rondo botnet campaigns exploiting CVE-2024-36401 in GeoServer. Learn to detect unauthenticated RCE and protect your infrastructure.</description><pubDate>Thu, 23 Jul 2026 10:28:43 GMT</pubDate><category>CVE-2024-36401</category><category>GeoServer</category><category>Rondo Botnet</category><category>RCE</category><category>DDoS</category></item></channel></rss>