<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Data Exposure</title><description>Cybersecurity articles tagged #Data Exposure on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CVE-2026-34486: Apache Tomcat Encryption Bypass – Detection and Mitigation Guide</title><link>https://runtimerebel.com/blog/cve-2026-34486-apache-tomcat-encryption-bypass-detection-and-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-34486-apache-tomcat-encryption-bypass-detection-and-mitigation-guide</guid><description>Apache Tomcat CVE-2026-34486 enables EncryptInterceptor bypass, exposing sensitive data; learn impact, detection, and remediation steps.</description><pubDate>Tue, 04 Aug 2026 17:34:06 GMT</pubDate><category>CVE-2026-34486</category><category>Apache Tomcat</category><category>CWE-311</category><category>Data Exposure</category></item><item><title>Firebase Misconfiguration in tl;dv AI Tool Exposes Sensitive Meeting Data</title><link>https://runtimerebel.com/blog/firebase-misconfiguration-in-tl-dv-ai-tool-exposes-sensitive-meeting-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/firebase-misconfiguration-in-tl-dv-ai-tool-exposes-sensitive-meeting-data</guid><description>A Google Firebase misconfiguration in the tl;dv AI meeting tool allows unauthorized access to sensitive government and corporate video call information.</description><pubDate>Tue, 04 Aug 2026 17:32:06 GMT</pubDate><category>Misconfiguration</category><category>Data Exposure</category><category>Cloud Security</category><category>Tl Dv</category><category>Google Firebase</category></item><item><title>Apple Patches Hide My Email Bug Exposing Real Addresses in Logs</title><link>https://runtimerebel.com/blog/apple-patches-hide-my-email-bug-exposing-real-addresses-in-logs</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-patches-hide-my-email-bug-exposing-real-addresses-in-logs</guid><description>Apple addresses a privacy flaw in Hide My Email that leaked actual user email addresses in mail logs, undermining the service’s core anonymity features.</description><pubDate>Tue, 21 Jul 2026 21:11:31 GMT</pubDate><category>Apple</category><category>Hide My Email</category><category>Privacy Vulnerability</category><category>Email Security</category><category>Data Exposure</category></item><item><title>Meta Broken Access Control: Customer Support Data Exposure</title><link>https://runtimerebel.com/blog/meta-broken-access-control-customer-support-data-exposure</link><guid isPermaLink="true">https://runtimerebel.com/blog/meta-broken-access-control-customer-support-data-exposure</guid><description>A broken access control vulnerability in Meta&apos;s support infrastructure allowed exposure of sensitive customer support data. Learn about the impact and mitigations.</description><pubDate>Tue, 21 Jul 2026 10:41:01 GMT</pubDate><category>Meta</category><category>Broken Access Control</category><category>Data Exposure</category><category>Customer Data</category><category>Bug Bounty</category></item><item><title>CVE-2026-44747: SAP NetWeaver ABAP Out-of-Bounds Write Flaw</title><link>https://runtimerebel.com/blog/cve-2026-44747-sap-netweaver-abap-out-of-bounds-write-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-44747-sap-netweaver-abap-out-of-bounds-write-flaw</guid><description>SAP NetWeaver ABAP users must patch CVE-2026-44747 (CVSS 9.9) immediately to prevent authenticated attackers from exposing or modifying critical data via memory…</description><pubDate>Tue, 14 Jul 2026 21:02:15 GMT</pubDate><category>CVE-2026-44747</category><category>SAP NetWeaver ABAP</category><category>Out of Bounds Write</category><category>Memory Corruption</category><category>SAP Security</category><category>Data Exposure</category></item><item><title>Critical Flaw Exposes Indian Government Data in National Portal</title><link>https://runtimerebel.com/blog/critical-flaw-exposes-indian-government-data-in-national-portal</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-flaw-exposes-indian-government-data-in-national-portal</guid><description>A critical vulnerability and several others exposed private data within Indian government systems, allowing potential takeover of a national portal.</description><pubDate>Tue, 30 Jun 2026 09:20:21 GMT</pubDate><category>Indian Government</category><category>Data Exposure</category><category>Critical Vulnerability</category><category>National Portal</category></item><item><title>Dify AI Platform Data Exposure: Multi-Tenant Risks</title><link>https://runtimerebel.com/blog/dify-ai-platform-data-exposure-multi-tenant-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/dify-ai-platform-data-exposure-multi-tenant-risks</guid><description>Dify AI platform users face critical data exposure flaws, enabling access to private chats, documents, and internal APIs in multi-tenant environments.</description><pubDate>Tue, 23 Jun 2026 16:56:39 GMT</pubDate><category>Dify</category><category>AI Platform</category><category>Data Exposure</category><category>Multi Tenant</category><category>Cloud Security</category></item><item><title>DifyTap Flaws Expose AI Chats in Dify Platform Without Auth</title><link>https://runtimerebel.com/blog/difytap-flaws-expose-ai-chats-in-dify-platform-without-auth</link><guid isPermaLink="true">https://runtimerebel.com/blog/difytap-flaws-expose-ai-chats-in-dify-platform-without-auth</guid><description>Zafran Security details DifyTap, a set of four vulnerabilities in Dify, allowing unauthenticated access to cross-tenant AI chat data. Learn impact and mitigation.</description><pubDate>Mon, 22 Jun 2026 17:36:20 GMT</pubDate><category>Dify</category><category>DifyTap</category><category>Zafran Security</category><category>AI Security</category><category>Multi Tenant</category><category>Data Exposure</category></item><item><title>Salesforce Disables Klue App Integration Following OAuth Token Abuse</title><link>https://runtimerebel.com/blog/salesforce-disables-klue-app-integration-following-oauth-token-abuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/salesforce-disables-klue-app-integration-following-oauth-token-abuse</guid><description>Salesforce suspends Klue Battlecards integration after OAuth token abuse exposed customer data, highlighting significant SaaS supply chain security risks.</description><pubDate>Fri, 19 Jun 2026 09:40:39 GMT</pubDate><category>Salesforce</category><category>Klue</category><category>Oauth Abuse</category><category>Supply Chain Attack</category><category>Data Exposure</category></item><item><title>ServiceNow Data Exposure via Unauthenticated API Flaw</title><link>https://runtimerebel.com/blog/servicenow-data-exposure-via-unauthenticated-api-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/servicenow-data-exposure-via-unauthenticated-api-flaw</guid><description>ServiceNow warns customers about a security incident after attackers exploited an unauthenticated API vulnerability to access and query customer instance data.</description><pubDate>Wed, 10 Jun 2026 01:03:52 GMT</pubDate><category>ServiceNow</category><category>API Security</category><category>Data Exposure</category><category>Unauthenticated Access</category><category>Cloud Security Incident</category></item><item><title>Shadow AI Risks: Securing Production against Exposed Vibe-Coded Apps</title><link>https://runtimerebel.com/blog/shadow-ai-risks-securing-production-against-exposed-vibe-coded-apps</link><guid isPermaLink="true">https://runtimerebel.com/blog/shadow-ai-risks-securing-production-against-exposed-vibe-coded-apps</guid><description>Analysis of the &apos;Shadow Builders&apos; report identifying 2,000 exposed AI-generated apps and the critical security gaps in AI-assisted software development.</description><pubDate>Fri, 29 May 2026 13:16:59 GMT</pubDate><category>Shadow AI</category><category>Vibe Coding</category><category>AppSec</category><category>AI Security</category><category>Data Exposure</category></item><item><title>CISA GitHub Repo Exposes Secrets &amp; Credentials in Public View</title><link>https://runtimerebel.com/blog/cisa-github-repo-exposes-secrets-credentials-in-public-view</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-github-repo-exposes-secrets-credentials-in-public-view</guid><description>CISA inadvertently exposed sensitive secrets and credentials within a publicly accessible GitHub repository.</description><pubDate>Tue, 19 May 2026 20:42:19 GMT</pubDate><category>CISA</category><category>GitHub</category><category>Data Exposure</category><category>Credentials</category><category>Secrets Management</category><category>Cloud Security Misconfiguration</category></item><item><title>SMS Blaster Fraud and OpenEMR Security: Analysis of Recent Threats</title><link>https://runtimerebel.com/blog/sms-blaster-fraud-and-openemr-security-analysis-of-recent-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/sms-blaster-fraud-and-openemr-security-analysis-of-recent-threats</guid><description>Expert analysis of SMS Blaster fake cell tower fraud, critical OpenEMR vulnerabilities, and widespread server misconfigurations affecting millions of users.</description><pubDate>Thu, 30 Apr 2026 16:36:42 GMT</pubDate><category>Sms Blaster</category><category>Openemr</category><category>Roblox</category><category>IMSI Catcher</category><category>Data Exposure</category></item><item><title>LiteLLM Proxy Data Exposure &amp; Modification — Urgent Patch Required</title><link>https://runtimerebel.com/blog/litellm-proxy-data-exposure-modification-urgent-patch-required</link><guid isPermaLink="true">https://runtimerebel.com/blog/litellm-proxy-data-exposure-modification-urgent-patch-required</guid><description>Critical vulnerability in LiteLLM proxy enables unauthorized database read/modify access. Exploitation observed shortly after disclosure. Patch immediately.</description><pubDate>Wed, 29 Apr 2026 16:39:36 GMT</pubDate><category>LiteLLM</category><category>Data Exposure</category><category>LLM Security</category><category>Proxy Vulnerability</category><category>Database Access</category></item><item><title>Anthropic AI Agent Memory Vulnerability: Data Exposure Risks</title><link>https://runtimerebel.com/blog/anthropic-ai-agent-memory-vulnerability-data-exposure-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/anthropic-ai-agent-memory-vulnerability-data-exposure-risks</guid><description>Cisco discovered a significant memory handling vulnerability in Anthropic AI agents, risking data exposure. This highlights persistent security challenges in AI systems.</description><pubDate>Thu, 23 Apr 2026 16:43:20 GMT</pubDate><category>Anthropic</category><category>AI Security</category><category>Memory Management</category><category>Data Exposure</category><category>Cisco</category></item><item><title>Moltbook Data Exposure: 1.5M AI Agent API Tokens Leaked</title><link>https://runtimerebel.com/blog/moltbook-data-exposure-1-5m-ai-agent-api-tokens-leaked</link><guid isPermaLink="true">https://runtimerebel.com/blog/moltbook-data-exposure-1-5m-ai-agent-api-tokens-leaked</guid><description>Moltbook database exposure revealed 1.5 million API tokens and plaintext OpenAI keys, highlighting risks of third-party credential sharing in AI agents.</description><pubDate>Wed, 22 Apr 2026 12:30:54 GMT</pubDate><category>Moltbook</category><category>AI Security</category><category>Api Token Leak</category><category>Data Exposure</category><category>OpenAI</category></item><item><title>Exposed Google API Keys in Android Apps Grant Gemini Access</title><link>https://runtimerebel.com/blog/exposed-google-api-keys-in-android-apps-grant-gemini-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/exposed-google-api-keys-in-android-apps-grant-gemini-access</guid><description>Analysis of Google API keys found in Android apps that enable unauthorized access to Gemini AI endpoints, detailing risks and mitigation for developers.</description><pubDate>Thu, 09 Apr 2026 12:47:35 GMT</pubDate><category>Google API Keys</category><category>Android Security</category><category>Gemini AI</category><category>API Security</category><category>Data Exposure</category><category>Misconfiguration</category></item><item><title>WebinarTV Secretly Records Public Zoom Meetings: Privacy Risks</title><link>https://runtimerebel.com/blog/webinartv-secretly-records-public-zoom-meetings-privacy-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/webinartv-secretly-records-public-zoom-meetings-privacy-risks</guid><description>WebinarTV records and publishes public Zoom meetings without consent. Understand the privacy risks and implement immediate mitigations for sensitive data exposure.</description><pubDate>Fri, 03 Apr 2026 12:23:35 GMT</pubDate><category>Zoom</category><category>Privacy</category><category>WebinarTV</category><category>Data Exposure</category><category>Meeting Security</category><category>Consent</category></item><item><title>Secure Salesforce Cloud: Restricting Guest User Permissions</title><link>https://runtimerebel.com/blog/secure-salesforce-cloud-restricting-guest-user-permissions</link><guid isPermaLink="true">https://runtimerebel.com/blog/secure-salesforce-cloud-restricting-guest-user-permissions</guid><description>Runtime Rebel analyzes critical Salesforce guest user misconfigurations exposing sensitive client data.</description><pubDate>Wed, 11 Mar 2026 00:32:44 GMT</pubDate><category>Salesforce</category><category>Cloud Security</category><category>Misconfiguration</category><category>Guest User</category><category>Data Exposure</category><category>Identity and Access Management</category></item><item><title>Salesforce Experience Cloud Mass-Scanning via Modified AuraInspector</title><link>https://runtimerebel.com/blog/salesforce-experience-cloud-mass-scanning-via-modified-aurainspector</link><guid isPermaLink="true">https://runtimerebel.com/blog/salesforce-experience-cloud-mass-scanning-via-modified-aurainspector</guid><description>Threat actors use a modified AuraInspector tool to exploit Salesforce Experience Cloud misconfigurations, exposing sensitive guest user data.</description><pubDate>Tue, 10 Mar 2026 08:16:45 GMT</pubDate><category>Salesforce</category><category>Experience Cloud</category><category>AuraInspector</category><category>Misconfiguration</category><category>Data Exposure</category></item></channel></rss>