<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Endpoint Security</title><description>Cybersecurity articles tagged #Endpoint Security on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Malware Crypting Services: Evading Detection and Analysis</title><link>https://runtimerebel.com/blog/malware-crypting-services-evading-detection-and-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/malware-crypting-services-evading-detection-and-analysis</guid><description>Threat actors use crypting services to modify malicious payloads, bypassing AV/EDR detection and complicating analysis. This enables stealthier, persistent campaigns.</description><pubDate>Thu, 13 Aug 2026 16:48:33 GMT</pubDate><category>Malware Evasion</category><category>Endpoint Security</category><category>Anti Analysis</category><category>Crypting Services</category><category>Threat Actors</category></item><item><title>CVE-2026-50656: Microsoft Defender Privilege Escalation – Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-50656-microsoft-defender-privilege-escalation-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-50656-microsoft-defender-privilege-escalation-patch-now</guid><description>Microsoft patches &apos;RoguePlanet&apos; vulnerability, CVE-2026-50656, in Defender&apos;s Malware Protection Engine, enabling privilege escalation. Update immediately.</description><pubDate>Thu, 09 Jul 2026 11:03:10 GMT</pubDate><category>CVE-2026-50656</category><category>Microsoft Defender</category><category>Privilege Escalation</category><category>RoguePlanet</category><category>Malware Protection Engine</category><category>Endpoint Security</category></item><item><title>AI Coding Agents Mimic Malicious Activity in Endpoint Detections</title><link>https://runtimerebel.com/blog/ai-coding-agents-mimic-malicious-activity-in-endpoint-detections</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-coding-agents-mimic-malicious-activity-in-endpoint-detections</guid><description>AI coding agents like Claude Code and OpenAI Codex are triggering endpoint security alerts by performing actions similar to human attackers, demanding rule adjustments.</description><pubDate>Wed, 08 Jul 2026 17:38:20 GMT</pubDate><category>AI</category><category>Endpoint Security</category><category>Sophos</category><category>Claude Code</category><category>OpenAI Codex</category><category>Cursor</category><category>Behavioral Detections</category></item><item><title>Gentlemen Ransomware: EDR Evasion Tactics and Mitigation Strategies</title><link>https://runtimerebel.com/blog/gentlemen-ransomware-edr-evasion-tactics-and-mitigation-strategies</link><guid isPermaLink="true">https://runtimerebel.com/blog/gentlemen-ransomware-edr-evasion-tactics-and-mitigation-strategies</guid><description>Runtime Rebel details Gentlemen ransomware&apos;s advanced EDR killer suite, analyzing its impact and providing actionable strategies to defend against sophisticated evasion.</description><pubDate>Fri, 19 Jun 2026 01:11:06 GMT</pubDate><category>Gentlemen Ransomware</category><category>RaaS</category><category>EDR Evasion</category><category>Endpoint Security</category><category>Malware</category></item><item><title>Optimizing EDR for Operational Resilience and Threat Detection</title><link>https://runtimerebel.com/blog/optimizing-edr-for-operational-resilience-and-threat-detection</link><guid isPermaLink="true">https://runtimerebel.com/blog/optimizing-edr-for-operational-resilience-and-threat-detection</guid><description>Explore how leading organizations optimize EDR deployment to achieve operational resilience against advanced threats and move beyond legacy prevention models.</description><pubDate>Tue, 02 Jun 2026 13:26:38 GMT</pubDate><category>EDR</category><category>Endpoint Security</category><category>Operational Resilience</category><category>Threat Detection</category><category>SOC Optimization</category></item><item><title>FortiClient EMS Critical Flaw Exploited for Credential Stealing</title><link>https://runtimerebel.com/blog/forticlient-ems-critical-flaw-exploited-for-credential-stealing</link><guid isPermaLink="true">https://runtimerebel.com/blog/forticlient-ems-critical-flaw-exploited-for-credential-stealing</guid><description>Threat actors are actively exploiting a critical, patched FortiClient EMS vulnerability to deploy credential-stealing malware, bypassing trusted endpoint security.</description><pubDate>Thu, 28 May 2026 17:21:27 GMT</pubDate><category>FortiClient EMS</category><category>Credential Stealer</category><category>Endpoint Security</category><category>Exploitation</category><category>Malware</category></item><item><title>Automated Endpoint Isolation in Microsoft Defender for Endpoint</title><link>https://runtimerebel.com/blog/automated-endpoint-isolation-in-microsoft-defender-for-endpoint</link><guid isPermaLink="true">https://runtimerebel.com/blog/automated-endpoint-isolation-in-microsoft-defender-for-endpoint</guid><description>Microsoft Defender for Endpoint now features automatic device isolation to block lateral movement and contain high-confidence security breaches effectively.</description><pubDate>Tue, 26 May 2026 13:11:01 GMT</pubDate><category>Microsoft Defender</category><category>Endpoint Security</category><category>Lateral Movement</category><category>Automated Response</category><category>Mde</category></item><item><title>Zero Trust: Why Device Security is Essential Beyond Identity</title><link>https://runtimerebel.com/blog/zero-trust-why-device-security-is-essential-beyond-identity</link><guid isPermaLink="true">https://runtimerebel.com/blog/zero-trust-why-device-security-is-essential-beyond-identity</guid><description>Identity-only security fails against stolen tokens and compromised devices. Learn why robust device security is critical for effective Zero Trust strategies.</description><pubDate>Wed, 20 May 2026 17:12:24 GMT</pubDate><category>Zero Trust</category><category>Device Security</category><category>Identity and Access Management</category><category>Session Hijacking</category><category>Endpoint Security</category></item><item><title>Managed Windows 11 Bloatware Removal: New IT Admin Policy Controls</title><link>https://runtimerebel.com/blog/managed-windows-11-bloatware-removal-new-it-admin-policy-controls</link><guid isPermaLink="true">https://runtimerebel.com/blog/managed-windows-11-bloatware-removal-new-it-admin-policy-controls</guid><description>Microsoft updates Windows 11 policy allowing IT admins to selectively uninstall pre-installed Store apps, reducing the attack surface in managed environments.</description><pubDate>Fri, 01 May 2026 12:28:31 GMT</pubDate><category>Windows 11</category><category>Microsoft Intune</category><category>Attack Surface Reduction</category><category>MDM Policy</category><category>Endpoint Security</category></item><item><title>Microsoft Teams Efficiency Mode: Optimizing Resource Usage for PCs</title><link>https://runtimerebel.com/blog/microsoft-teams-efficiency-mode-optimizing-resource-usage-for-pcs</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-teams-efficiency-mode-optimizing-resource-usage-for-pcs</guid><description>Microsoft introduces Efficiency Mode for Teams to reduce CPU and memory consumption on resource-constrained devices, improving overall system responsiveness.</description><pubDate>Wed, 22 Apr 2026 12:31:39 GMT</pubDate><category>Microsoft Teams</category><category>Windows 11</category><category>Performance Optimization</category><category>Endpoint Security</category></item><item><title>Signed Software Abuse: How Malicious Scripts Disable EDR and AV</title><link>https://runtimerebel.com/blog/signed-software-abuse-how-malicious-scripts-disable-edr-and-av</link><guid isPermaLink="true">https://runtimerebel.com/blog/signed-software-abuse-how-malicious-scripts-disable-edr-and-av</guid><description>Analysis of signed adware being used to deploy antivirus-killing scripts with SYSTEM privileges across government and healthcare sectors.</description><pubDate>Wed, 15 Apr 2026 20:22:56 GMT</pubDate><category>Signed Software</category><category>Antivirus Evasion</category><category>EDR Bypass</category><category>Endpoint Security</category><category>Privilege Escalation</category></item><item><title>Windows 11 Version 24H2 Force Upgrade for Unmanaged PCs</title><link>https://runtimerebel.com/blog/windows-11-version-24h2-force-upgrade-for-unmanaged-pcs</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-11-version-24h2-force-upgrade-for-unmanaged-pcs</guid><description>Microsoft initiates forced upgrades to Windows 11 24H2 for unmanaged Home and Pro devices to maintain security support and critical update delivery.</description><pubDate>Fri, 03 Apr 2026 08:23:19 GMT</pubDate><category>Windows 11</category><category>Microsoft Servicing</category><category>Endpoint Security</category><category>Patch Management</category></item><item><title>Mitigating the Rise of Trusted Tool Abuse in Modern Cyberattacks</title><link>https://runtimerebel.com/blog/mitigating-the-rise-of-trusted-tool-abuse-in-modern-cyberattacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/mitigating-the-rise-of-trusted-tool-abuse-in-modern-cyberattacks</guid><description>Explore why threat actors are pivoting from malware to Living-off-the-Land (LotL) techniques by abusing trusted administrative tools and native binaries.</description><pubDate>Wed, 01 Apr 2026 12:26:47 GMT</pubDate><category>Living-off-the-Land</category><category>LOTL</category><category>Adversary Ttps</category><category>Endpoint Security</category><category>Defense Evasion</category></item><item><title>Windows 11 KB5079391: Smart App Control AI Enhancements for 24H2</title><link>https://runtimerebel.com/blog/windows-11-kb5079391-smart-app-control-ai-enhancements-for-24h2</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-11-kb5079391-smart-app-control-ai-enhancements-for-24h2</guid><description>Microsoft releases Windows 11 KB5079391 preview update, enhancing Smart App Control with AI models to mitigate malicious software execution on 24H2 systems.</description><pubDate>Fri, 27 Mar 2026 12:24:20 GMT</pubDate><category>KB5079391</category><category>Windows 11 24H2</category><category>Smart App Control</category><category>Microsoft</category><category>Endpoint Security</category></item><item><title>AI Coding Tools: New Challenges for Endpoint Security Defenses</title><link>https://runtimerebel.com/blog/ai-coding-tools-new-challenges-for-endpoint-security-defenses</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-coding-tools-new-challenges-for-endpoint-security-defenses</guid><description>A security researcher demonstrates how AI coding tools can bypass traditional endpoint security measures, prompting a reevaluation of defense strategies.</description><pubDate>Wed, 25 Mar 2026 00:37:30 GMT</pubDate><category>AI Coding Tools</category><category>Endpoint Security</category><category>Application Security</category><category>Threat Research</category></item><item><title>1stProtect&apos;s Behavioral Endpoint Security Emerges</title><link>https://runtimerebel.com/blog/1stprotect-s-behavioral-endpoint-security-emerges</link><guid isPermaLink="true">https://runtimerebel.com/blog/1stprotect-s-behavioral-endpoint-security-emerges</guid><description>1stProtect launches with $20M funding, offering an endpoint security platform that uses behavioral monitoring and user intent verification to stop real-time cyberattacks.</description><pubDate>Thu, 19 Mar 2026 20:17:12 GMT</pubDate><category>Endpoint Security</category><category>Behavioral Monitoring</category><category>User Intent Verification</category><category>Real Time Protection</category><category>Cybersecurity Funding</category><category>Security Platform</category></item><item><title>Secure Microsoft Intune Systems Against Wipe Attacks - CISA Warning</title><link>https://runtimerebel.com/blog/secure-microsoft-intune-systems-against-wipe-attacks-cisa-warning</link><guid isPermaLink="true">https://runtimerebel.com/blog/secure-microsoft-intune-systems-against-wipe-attacks-cisa-warning</guid><description>CISA urges organizations to secure Microsoft Intune following a breach at Stryker where attackers used the management tool to wipe corporate systems.</description><pubDate>Thu, 19 Mar 2026 12:19:16 GMT</pubDate><category>Microsoft Intune</category><category>Stryker Breach</category><category>CISA Advisory</category><category>Endpoint Security</category><category>Data Wipe</category></item><item><title>OAuth Exploitation and EDR Termination: New Bulletin Analysis</title><link>https://runtimerebel.com/blog/oauth-exploitation-and-edr-termination-new-bulletin-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/oauth-exploitation-and-edr-termination-new-bulletin-analysis</guid><description>Analysis of current threats including OAuth token theft, EDR termination techniques, Signal phishing, and &apos;Zombie ZIP&apos; archive evasion strategies.</description><pubDate>Thu, 12 Mar 2026 16:28:23 GMT</pubDate><category>Oauth Abuse</category><category>EDR Bypass</category><category>Phishing</category><category>Archive Evasion</category><category>Endpoint Security</category></item><item><title>Cylake Launches Local AI-Native Security for Data Sovereignty</title><link>https://runtimerebel.com/blog/cylake-launches-local-ai-native-security-for-data-sovereignty</link><guid isPermaLink="true">https://runtimerebel.com/blog/cylake-launches-local-ai-native-security-for-data-sovereignty</guid><description>Cylake introduces an AI-native security platform that processes data locally to address data sovereignty and privacy concerns in sensitive environments.</description><pubDate>Sun, 08 Mar 2026 08:11:05 GMT</pubDate><category>Cylake</category><category>AI Native Security</category><category>Data Sovereignty</category><category>On Premises AI</category><category>Endpoint Security</category></item><item><title>Windows 11 Hardens Batch File Execution to Counter Script Attacks</title><link>https://runtimerebel.com/blog/windows-11-hardens-batch-file-execution-to-counter-script-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-11-hardens-batch-file-execution-to-counter-script-attacks</guid><description>Microsoft tests security enhancements for batch and CMD files in Windows 11 Insider Build 27723 to mitigate Living-off-the-Land (LotL) script abuse.</description><pubDate>Fri, 27 Feb 2026 20:11:55 GMT</pubDate><category>Windows 11</category><category>Batch Files</category><category>CMD</category><category>LOTL</category><category>Endpoint Security</category><category>Microsoft Insider</category></item><item><title>Addressing Enterprise Risk in Third-Party Software Patching</title><link>https://runtimerebel.com/blog/addressing-enterprise-risk-in-third-party-software-patching</link><guid isPermaLink="true">https://runtimerebel.com/blog/addressing-enterprise-risk-in-third-party-software-patching</guid><description>Analyze the security risks of third-party software drift and learn why automated patch management is essential for reducing the modern attack surface.</description><pubDate>Fri, 27 Feb 2026 16:16:06 GMT</pubDate><category>Patch Management</category><category>Vulnerability Management</category><category>Third Party Risk</category><category>Endpoint Security</category><category>Shadow IT</category></item><item><title>Token Theft and Session Hijacking: Mitigating Device Trust Failures</title><link>https://runtimerebel.com/blog/token-theft-and-session-hijacking-mitigating-device-trust-failures</link><guid isPermaLink="true">https://runtimerebel.com/blog/token-theft-and-session-hijacking-mitigating-device-trust-failures</guid><description>An analysis of post-authentication attack vectors involving token theft and the technical requirement for continuous device posture verification within Zero Trust…</description><pubDate>Mon, 23 Feb 2026 16:23:45 GMT</pubDate><category>Token Theft</category><category>Session Hijacking</category><category>Zero Trust</category><category>Endpoint Security</category></item></channel></rss>