<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Honeypot</title><description>Cybersecurity articles tagged #Honeypot on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Atlassian Arbitrary File Access Exploitation Scans Observed</title><link>https://runtimerebel.com/blog/atlassian-arbitrary-file-access-exploitation-scans-observed</link><guid isPermaLink="true">https://runtimerebel.com/blog/atlassian-arbitrary-file-access-exploitation-scans-observed</guid><description>Atlassian products are targeted by scans exploiting CVE-2026-21589 for arbitrary file access, potentially exposing sensitive configuration.</description><pubDate>Wed, 07 Oct 2026 20:59:57 GMT</pubDate><category>Directory Traversal</category><category>Honeypot</category><category>Exploitation</category><category>CVE-2026-21589</category><category>Atlassian</category></item><item><title>Rogue LLM Endpoints: Data Exposure &amp; RCE Risk for AI Agents</title><link>https://runtimerebel.com/blog/rogue-llm-endpoints-data-exposure-rce-risk-for-ai-agents</link><guid isPermaLink="true">https://runtimerebel.com/blog/rogue-llm-endpoints-data-exposure-rce-risk-for-ai-agents</guid><description>Unverified LLM endpoints pose significant risks, enabling data leakage and potential remote code execution via compromised AI agent sessions.</description><pubDate>Tue, 01 Sep 2026 02:48:52 GMT</pubDate><category>LLM Security</category><category>AI Agents</category><category>Honeypot</category><category>Data Leakage</category><category>Supply Chain Attack</category></item><item><title>DShield SIEM Update: ELK Stack 8.19.15 and Enhanced Logging</title><link>https://runtimerebel.com/blog/dshield-siem-update-elk-stack-8-19-15-and-enhanced-logging</link><guid isPermaLink="true">https://runtimerebel.com/blog/dshield-siem-update-elk-stack-8-19-15-and-enhanced-logging</guid><description>SANS ISC updates the DShield SIEM to ELK stack 8.19.15, introducing enhanced logging capabilities and new dashboards for improved honeypot data analysis.</description><pubDate>Wed, 15 Jul 2026 10:11:13 GMT</pubDate><category>DShield</category><category>SIEM</category><category>ELK Stack</category><category>SANS ISC</category><category>Honeypot</category><category>Log Analysis</category></item><item><title>Adaptive UI for Web Honeypot Log Analysis: Enhancing Threat Intel</title><link>https://runtimerebel.com/blog/adaptive-ui-for-web-honeypot-log-analysis-enhancing-threat-intel</link><guid isPermaLink="true">https://runtimerebel.com/blog/adaptive-ui-for-web-honeypot-log-analysis-enhancing-threat-intel</guid><description>An overview of an adaptive cyber analytics UI for web honeypot logs, enhancing threat intelligence gathering and analysis for security operations.</description><pubDate>Thu, 07 May 2026 05:14:09 GMT</pubDate><category>Honeypot</category><category>Log Analysis</category><category>Threat Intelligence</category><category>Cyber Analytics</category><category>Security Operations</category></item><item><title>DShield Honeypot Updates: Ensuring Timely Threat Data Collection</title><link>https://runtimerebel.com/blog/dshield-honeypot-updates-ensuring-timely-threat-data-collection</link><guid isPermaLink="true">https://runtimerebel.com/blog/dshield-honeypot-updates-ensuring-timely-threat-data-collection</guid><description>SANS ISC announces upcoming updates for DShield honeypots. Learn why these automatic updates are crucial for maintaining effective threat intelligence collection.</description><pubDate>Mon, 04 May 2026 16:47:53 GMT</pubDate><category>DShield</category><category>Honeypot</category><category>SANS ISC</category><category>Threat Intelligence</category><category>Security Updates</category></item><item><title>X-Vercel-Set-Bypass-Cookie Header: Honeypot Observations &amp; Implications</title><link>https://runtimerebel.com/blog/x-vercel-set-bypass-cookie-header-honeypot-observations-implications</link><guid isPermaLink="true">https://runtimerebel.com/blog/x-vercel-set-bypass-cookie-header-honeypot-observations-implications</guid><description>Runtime Rebel analyzes recent honeypot observations of HTTP requests using the `X-Vercel-Set-Bypass-Cookie` header, discussing potential implications for Vercel users…</description><pubDate>Tue, 28 Apr 2026 16:46:36 GMT</pubDate><category>Vercel</category><category>Honeypot</category><category>HTTP Headers</category><category>Web Security</category><category>Caching Bypass</category></item><item><title>Analysis of &apos;iranbot&apos; Message in Cowrie Honeypot Logs</title><link>https://runtimerebel.com/blog/analysis-of-iranbot-message-in-cowrie-honeypot-logs</link><guid isPermaLink="true">https://runtimerebel.com/blog/analysis-of-iranbot-message-in-cowrie-honeypot-logs</guid><description>A peculiar &apos;iranbot_was_here&apos; message, alongside Telnet logins and portscans, was observed in Cowrie honeypot logs, signaling potential reconnaissance activity.</description><pubDate>Thu, 19 Mar 2026 04:43:57 GMT</pubDate><category>Cowrie</category><category>Honeypot</category><category>Telnet</category><category>Reconnaissance</category><category>Iranbot</category><category>DShield</category><category>Logging</category></item><item><title>Adminer &amp; phpMyAdmin: Attacker Scans Target Database Management Tools</title><link>https://runtimerebel.com/blog/adminer-phpmyadmin-attacker-scans-target-database-management-tools</link><guid isPermaLink="true">https://runtimerebel.com/blog/adminer-phpmyadmin-attacker-scans-target-database-management-tools</guid><description>Runtime Rebel observes increased honeypot scans targeting Adminer and phpMyAdmin.</description><pubDate>Wed, 18 Mar 2026 16:32:57 GMT</pubDate><category>Adminer</category><category>phpMyAdmin</category><category>Database Management</category><category>Honeypot</category><category>Scanning</category><category>Reconnaissance</category></item></channel></rss>