<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Information Disclosure</title><description>Cybersecurity articles tagged #Information Disclosure on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CVE-2026-66066: Unauthenticated File Read in Rails Active Storage</title><link>https://runtimerebel.com/blog/cve-2026-66066-unauthenticated-file-read-in-rails-active-storage</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-66066-unauthenticated-file-read-in-rails-active-storage</guid><description>Unauthenticated attackers can exploit CVE-2026-66066 in Ruby on Rails Active Storage to read sensitive server files, potentially leading to full compromise.</description><pubDate>Wed, 29 Jul 2026 20:57:40 GMT</pubDate><category>CVE-2026-66066</category><category>Ruby on Rails</category><category>Active Storage</category><category>Information Disclosure</category><category>RCE</category></item><item><title>24,650 Exposed BMCs Leak IPMI Password Hashes via RAKP Flaw</title><link>https://runtimerebel.com/blog/24650-exposed-bmcs-leak-ipmi-password-hashes-via-rakp-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/24650-exposed-bmcs-leak-ipmi-password-hashes-via-rakp-flaw</guid><description>Over 24,000 BMC management interfaces are exposing IPMI password hashes to the internet, allowing attackers to perform offline cracking and server takeover.</description><pubDate>Tue, 28 Jul 2026 17:36:48 GMT</pubDate><category>BMC</category><category>IPMI</category><category>Server Security</category><category>Hardware Security</category><category>Information Disclosure</category></item><item><title>Java Spring Boot Actuator: Mitigating /actuator/heapdump Scans</title><link>https://runtimerebel.com/blog/java-spring-boot-actuator-mitigating-actuator-heapdump-scans</link><guid isPermaLink="true">https://runtimerebel.com/blog/java-spring-boot-actuator-mitigating-actuator-heapdump-scans</guid><description>Learn how to protect Java Spring Boot applications from /actuator/heapdump scans. Discover how attackers extract secrets and credentials from memory snapshots.</description><pubDate>Mon, 27 Jul 2026 11:28:08 GMT</pubDate><category>Java</category><category>Spring Boot</category><category>Actuator</category><category>Information Disclosure</category><category>Heapdump</category></item><item><title>Opera GX Mod Auto-Installation Vulnerability Analysis</title><link>https://runtimerebel.com/blog/opera-gx-mod-auto-installation-vulnerability-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/opera-gx-mod-auto-installation-vulnerability-analysis</guid><description>A critical flaw in Opera GX allowed malicious sites to auto-install mods and exfiltrate sensitive data. Learn how to detect and mitigate this browser threat.</description><pubDate>Mon, 06 Jul 2026 08:26:02 GMT</pubDate><category>Opera GX</category><category>Browser Security</category><category>Information Disclosure</category><category>Malicious Add Ons</category></item><item><title>NetScaler Vulnerabilities: HTTP/2 Bomb &amp; High-Severity Info Disclosure</title><link>https://runtimerebel.com/blog/netscaler-vulnerabilities-http-2-bomb-high-severity-info-disclosure</link><guid isPermaLink="true">https://runtimerebel.com/blog/netscaler-vulnerabilities-http-2-bomb-high-severity-info-disclosure</guid><description>Citrix addresses six NetScaler vulnerabilities, including a new HTTP/2 Bomb and a high-severity information disclosure bug similar to CitrixBleed.</description><pubDate>Wed, 01 Jul 2026 13:06:13 GMT</pubDate><category>NetScaler</category><category>Citrix</category><category>HTTP 2 Bomb</category><category>Information Disclosure</category><category>Vulnerability</category><category>Patch</category></item><item><title>CVE-2026-4020: Gravity SMTP Exploit Exposes WordPress API Keys</title><link>https://runtimerebel.com/blog/cve-2026-4020-gravity-smtp-exploit-exposes-wordpress-api-keys</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-4020-gravity-smtp-exploit-exposes-wordpress-api-keys</guid><description>Unauthenticated attackers are exploiting CVE-2026-4020 in the Gravity SMTP WordPress plugin to extract API keys, secrets, and OAuth tokens from 100,000 sites.</description><pubDate>Sat, 20 Jun 2026 12:44:14 GMT</pubDate><category>CVE-2026-4020</category><category>WordPress</category><category>Gravity SMTP</category><category>Information Disclosure</category></item><item><title>CVE-2024-49403: Gravity SMTP Information Disclosure Patch Guidance</title><link>https://runtimerebel.com/blog/cve-2024-49403-gravity-smtp-information-disclosure-patch-guidance</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-49403-gravity-smtp-information-disclosure-patch-guidance</guid><description>Exploitation of CVE-2024-49403 in the Gravity SMTP WordPress plugin allows unauthenticated actors to steal SMTP credentials. Learn how to secure your site now.</description><pubDate>Sat, 20 Jun 2026 05:36:09 GMT</pubDate><category>CVE-2024-49403</category><category>Gravity SMTP</category><category>WordPress</category><category>Information Disclosure</category></item><item><title>CVE-2022-21371: CISA Warns of Oracle WebLogic Exploitation</title><link>https://runtimerebel.com/blog/cve-2022-21371-cisa-warns-of-oracle-weblogic-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2022-21371-cisa-warns-of-oracle-weblogic-exploitation</guid><description>CISA adds CVE-2022-21371 to its KEV catalog, warning of active exploitation of an information disclosure flaw in Oracle WebLogic Server. Patch immediately.</description><pubDate>Tue, 02 Jun 2026 13:27:03 GMT</pubDate><category>CVE-2022-21371</category><category>Oracle WebLogic</category><category>CISA KEV</category><category>Information Disclosure</category></item><item><title>CVE-2026-9082: Drupal Core RCE via Database API (PostgreSQL)</title><link>https://runtimerebel.com/blog/cve-2026-9082-drupal-core-rce-via-database-api-postgresql</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-9082-drupal-core-rce-via-database-api-postgresql</guid><description>A highly critical flaw, CVE-2026-9082, in Drupal Core&apos;s database abstraction API allows RCE, privilege escalation, and info disclosure on PostgreSQL sites.</description><pubDate>Thu, 21 May 2026 05:31:49 GMT</pubDate><category>CVE-2026-9082</category><category>Drupal Core</category><category>RCE</category><category>Postgresql</category><category>Privilege Escalation</category><category>Information Disclosure</category></item><item><title>CVE-2024-24919: Critical Information Disclosure in Check Point Gateways</title><link>https://runtimerebel.com/blog/cve-2024-24919-critical-information-disclosure-in-check-point-gateways</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-24919-critical-information-disclosure-in-check-point-gateways</guid><description>A technical analysis of CVE-2024-24919, a high-severity information disclosure flaw in Check Point Quantum Gateways, including exploit detection and mitigation.</description><pubDate>Wed, 20 May 2026 09:17:42 GMT</pubDate><category>CVE-2024-24919</category><category>Check Point</category><category>Quantum Gateway</category><category>Information Disclosure</category><category>Vulnerability Analysis</category></item><item><title>CVE-2024-24919: Exploit Analysis and Check Point Gateway Mitigation</title><link>https://runtimerebel.com/blog/cve-2024-24919-exploit-analysis-and-check-point-gateway-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-24919-exploit-analysis-and-check-point-gateway-mitigation</guid><description>Technical analysis of CVE-2024-24919, a critical information disclosure vulnerability in Check Point Security Gateways exploited for credential harvesting.</description><pubDate>Wed, 29 Apr 2026 08:56:39 GMT</pubDate><category>CVE-2024-24919</category><category>Check Point</category><category>VPN Security</category><category>Information Disclosure</category></item><item><title>WhatsApp Metadata Leak: Exposure Risks and Mitigation Strategies</title><link>https://runtimerebel.com/blog/whatsapp-metadata-leak-exposure-risks-and-mitigation-strategies</link><guid isPermaLink="true">https://runtimerebel.com/blog/whatsapp-metadata-leak-exposure-risks-and-mitigation-strategies</guid><description>WhatsApp&apos;s metadata leakage allows strangers to infer limited user information without interaction, potentially aiding targeted social engineering or other malicious…</description><pubDate>Mon, 20 Apr 2026 16:34:38 GMT</pubDate><category>WhatsApp</category><category>Metadata Leak</category><category>Privacy</category><category>Social Engineering</category><category>Information Disclosure</category></item><item><title>Grafana AI Assistant Flaw Exposes User Data — Immediate Patch Required</title><link>https://runtimerebel.com/blog/grafana-ai-assistant-flaw-exposes-user-data-immediate-patch-required</link><guid isPermaLink="true">https://runtimerebel.com/blog/grafana-ai-assistant-flaw-exposes-user-data-immediate-patch-required</guid><description>Grafana patched an AI vulnerability where malicious instructions on web pages could trick its AI assistant into leaking sensitive user data. Immediate action needed.</description><pubDate>Tue, 07 Apr 2026 20:20:18 GMT</pubDate><category>Grafana</category><category>AI</category><category>Data Leak</category><category>Vulnerability</category><category>Information Disclosure</category><category>Instruction Injection</category></item><item><title>Citrix NetScaler CVE-2026-3055 Memory Overread — Mitigation Guide</title><link>https://runtimerebel.com/blog/citrix-netscaler-cve-2026-3055-memory-overread-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/citrix-netscaler-cve-2026-3055-memory-overread-mitigation-guide</guid><description>Attackers are actively scanning for CVE-2026-3055, a CVSS 9.3 memory overread flaw in Citrix NetScaler ADC and Gateway. Patch vulnerable instances immediately.</description><pubDate>Sat, 28 Mar 2026 12:20:11 GMT</pubDate><category>CVE-2026-3055</category><category>Citrix NetScaler</category><category>ADC</category><category>Gateway</category><category>Memory Overread</category><category>Information Disclosure</category></item><item><title>Citrix NetScaler Info Disclosure: CVE-2024-8069 Patch Guide</title><link>https://runtimerebel.com/blog/citrix-netscaler-info-disclosure-cve-2024-8069-patch-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/citrix-netscaler-info-disclosure-cve-2024-8069-patch-guide</guid><description>Citrix urges immediate patching of two NetScaler ADC and Gateway vulnerabilities, including a flaw similar to the high-impact CitrixBleed exploit.</description><pubDate>Wed, 25 Mar 2026 16:31:56 GMT</pubDate><category>CVE-2024-8068</category><category>CVE-2024-8069</category><category>Citrix</category><category>NetScaler</category><category>Information Disclosure</category></item><item><title>CVE-2025-47813: CISA Warns of Wing FTP Server Path Leakage Exploitation</title><link>https://runtimerebel.com/blog/cve-2025-47813-cisa-warns-of-wing-ftp-server-path-leakage-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-47813-cisa-warns-of-wing-ftp-server-path-leakage-exploitation</guid><description>CISA adds CVE-2025-47813 to its KEV catalog, highlighting active exploitation of a Wing FTP Server information disclosure flaw that leaks internal server paths.</description><pubDate>Tue, 17 Mar 2026 08:21:05 GMT</pubDate><category>CVE-2025-47813</category><category>Wing FTP</category><category>Information Disclosure</category><category>CISA KEV</category></item><item><title>CVE-2025-47813: Wing FTP Server Information Disclosure Added to KEV</title><link>https://runtimerebel.com/blog/cve-2025-47813-wing-ftp-server-information-disclosure-added-to-kev</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-47813-wing-ftp-server-information-disclosure-added-to-kev</guid><description>CISA adds CVE-2025-47813 to the Known Exploited Vulnerabilities catalog, signaling active exploitation of Wing FTP Server. Immediate patching is required.</description><pubDate>Mon, 16 Mar 2026 20:17:21 GMT</pubDate><category>CVE-2025-47813</category><category>Wing Ftp Server</category><category>CISA KEV</category><category>Information Disclosure</category></item><item><title>Google Cloud API Keys Exposed via Public Gemini Access</title><link>https://runtimerebel.com/blog/google-cloud-api-keys-exposed-via-public-gemini-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-cloud-api-keys-exposed-via-public-gemini-access</guid><description>Research reveals nearly 3,000 public GCP API keys exposed in client-side code grant unauthorized access to sensitive Gemini and Vertex AI endpoints.</description><pubDate>Sat, 28 Feb 2026 12:12:17 GMT</pubDate><category>GCP</category><category>Google Cloud</category><category>Gemini</category><category>API Security</category><category>Truffle Security</category><category>Information Disclosure</category></item></channel></rss>