<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Initial Access</title><description>Cybersecurity articles tagged #Initial Access on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Identity Attacks &amp; MFA Bypass: The New Ransomware Entry Point</title><link>https://runtimerebel.com/blog/identity-attacks-mfa-bypass-the-new-ransomware-entry-point</link><guid isPermaLink="true">https://runtimerebel.com/blog/identity-attacks-mfa-bypass-the-new-ransomware-entry-point</guid><description>Identity-based attacks, particularly email phishing, are now the leading cause of ransomware infections.</description><pubDate>Wed, 15 Jul 2026 21:10:35 GMT</pubDate><category>Ransomware</category><category>Identity Attacks</category><category>MFA Bypass</category><category>Phishing</category><category>Credential Theft</category><category>Initial Access</category></item><item><title>EtherRAT Malware via Microsoft Teams IT Support Impersonation</title><link>https://runtimerebel.com/blog/etherrat-malware-via-microsoft-teams-it-support-impersonation</link><guid isPermaLink="true">https://runtimerebel.com/blog/etherrat-malware-via-microsoft-teams-it-support-impersonation</guid><description>Threat actors leverage fake IT support calls on Microsoft Teams to deploy EtherRAT malware, gaining initial access to corporate networks.</description><pubDate>Mon, 06 Jul 2026 21:39:59 GMT</pubDate><category>EtherRAT</category><category>Microsoft Teams</category><category>Social Engineering</category><category>Impersonation</category><category>Initial Access</category><category>Malware</category></item><item><title>ClickFix Social Engineering: How to Detect Fake Browser Update Attacks</title><link>https://runtimerebel.com/blog/clickfix-social-engineering-how-to-detect-fake-browser-update-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-social-engineering-how-to-detect-fake-browser-update-attacks</guid><description>ClickFix has become the dominant malware delivery method. Learn how attackers use fake browser error overlays to trick users into executing malicious PowerShell.</description><pubDate>Thu, 02 Jul 2026 07:39:48 GMT</pubDate><category>ClickFix</category><category>Social Engineering</category><category>Lumma Stealer</category><category>Initial Access</category><category>ClearFake</category></item><item><title>Adaptive Phishing: How Attackers Fingerprint Devices via User-Agents</title><link>https://runtimerebel.com/blog/adaptive-phishing-how-attackers-fingerprint-devices-via-user-agents</link><guid isPermaLink="true">https://runtimerebel.com/blog/adaptive-phishing-how-attackers-fingerprint-devices-via-user-agents</guid><description>Threat actors are using real-time device fingerprinting to deliver OS-specific phishing payloads, increasing the success rates of social engineering attacks.</description><pubDate>Thu, 02 Jul 2026 07:37:51 GMT</pubDate><category>Phishing</category><category>Social Engineering</category><category>Device Fingerprinting</category><category>User Agent</category><category>Initial Access</category></item><item><title>Outdated REDCap Servers Targeted by China-linked UNC6508</title><link>https://runtimerebel.com/blog/outdated-redcap-servers-targeted-by-china-linked-unc6508</link><guid isPermaLink="true">https://runtimerebel.com/blog/outdated-redcap-servers-targeted-by-china-linked-unc6508</guid><description>A majority of internet-accessible REDCap servers remain unpatched, making them prime targets for initial access and backdoor deployment by China-linked UNC6508.</description><pubDate>Thu, 18 Jun 2026 17:10:13 GMT</pubDate><category>REDCap</category><category>UNC6508</category><category>Outdated Software</category><category>Healthcare</category><category>Initial Access</category><category>Backdoor</category></item><item><title>Onboarding Password Risk: Securing First-Day Account Access</title><link>https://runtimerebel.com/blog/onboarding-password-risk-securing-first-day-account-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/onboarding-password-risk-securing-first-day-account-access</guid><description>Temporary onboarding passwords, often sent insecurely and reused, pose significant risk. Learn how to secure initial employee access and mitigate threats.</description><pubDate>Mon, 15 Jun 2026 14:21:06 GMT</pubDate><category>Onboarding Security</category><category>Password Policy</category><category>Identity Management</category><category>Initial Access</category><category>Employee Risk</category><category>Zero Trust</category></item><item><title>FBI Disrupts First VPN Service Used by Ransomware Groups</title><link>https://runtimerebel.com/blog/fbi-disrupts-first-vpn-service-used-by-ransomware-groups</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-disrupts-first-vpn-service-used-by-ransomware-groups</guid><description>The FBI and international partners dismantled First VPN, a specialized service used by dozens of ransomware groups for reconnaissance and intrusions.</description><pubDate>Fri, 22 May 2026 13:00:22 GMT</pubDate><category>First VPN</category><category>Ransomware</category><category>Fbi Disruption</category><category>Reconnaissance</category><category>Initial Access</category></item><item><title>Canadian Man Arrested for Kimwolf Botnet Operations</title><link>https://runtimerebel.com/blog/canadian-man-arrested-for-kimwolf-botnet-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/canadian-man-arrested-for-kimwolf-botnet-operations</guid><description>Jacob Butler faces US extradition for operating the Kimwolf botnet. Analysis of the arrest, botnet infrastructure, and its role in the initial access market.</description><pubDate>Fri, 22 May 2026 12:59:57 GMT</pubDate><category>Kimwolf</category><category>Botnet</category><category>Law Enforcement</category><category>Initial Access</category><category>Credential Theft</category></item><item><title>KongTuke Exploits Microsoft Teams for Rapid Corporate Breaches</title><link>https://runtimerebel.com/blog/kongtuke-exploits-microsoft-teams-for-rapid-corporate-breaches</link><guid isPermaLink="true">https://runtimerebel.com/blog/kongtuke-exploits-microsoft-teams-for-rapid-corporate-breaches</guid><description>Initial access broker KongTuke leverages Microsoft Teams to deploy DarkGate malware, achieving network persistence in under five minutes via social engineering.</description><pubDate>Thu, 14 May 2026 12:45:59 GMT</pubDate><category>KongTuke</category><category>Microsoft Teams</category><category>DarkGate</category><category>Initial Access</category><category>Storm 0324</category></item><item><title>Neutralizing Patient Zero: Strategies to Prevent Stealth Breaches</title><link>https://runtimerebel.com/blog/neutralizing-patient-zero-strategies-to-prevent-stealth-breaches</link><guid isPermaLink="true">https://runtimerebel.com/blog/neutralizing-patient-zero-strategies-to-prevent-stealth-breaches</guid><description>Analyze how AI-driven social engineering creates a Patient Zero scenario and explore technical strategies to contain stealth breaches before total shutdown.</description><pubDate>Thu, 07 May 2026 16:39:36 GMT</pubDate><category>Phishing</category><category>Initial Access</category><category>Lateral Movement</category><category>Incident Response</category><category>Social Engineering</category></item><item><title>Malicious PDF Files: Analyzing AcroForm JavaScript for Initial Access</title><link>https://runtimerebel.com/blog/malicious-pdf-files-analyzing-acroform-javascript-for-initial-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-pdf-files-analyzing-acroform-javascript-for-initial-access</guid><description>Security analysts have identified malicious PDF files utilizing AcroForm dictionaries to execute JavaScript and fetch remote payloads from external servers.</description><pubDate>Mon, 04 May 2026 05:14:53 GMT</pubDate><category>PDF Malware</category><category>AcroForm</category><category>JavaScript</category><category>Initial Access</category><category>Adobe Reader</category></item><item><title>Defending Against Identity-Based Attacks and Stolen Credentials</title><link>https://runtimerebel.com/blog/defending-against-identity-based-attacks-and-stolen-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/defending-against-identity-based-attacks-and-stolen-credentials</guid><description>Identity-based attacks use stolen credentials to bypass security. Learn why these attacks are the primary entry point and how to mitigate the risk.</description><pubDate>Tue, 21 Apr 2026 12:30:18 GMT</pubDate><category>Identity Based Attacks</category><category>Credential Stuffing</category><category>Phishing</category><category>Initial Access</category></item><item><title>PDF JavaScript Exploitation: Analysis of PowerShell Delivery</title><link>https://runtimerebel.com/blog/pdf-javascript-exploitation-analysis-of-powershell-delivery</link><guid isPermaLink="true">https://runtimerebel.com/blog/pdf-javascript-exploitation-analysis-of-powershell-delivery</guid><description>Technical analysis of malicious PDF documents using embedded JavaScript and /OpenAction triggers to execute PowerShell for initial access and C2 establishment.</description><pubDate>Fri, 17 Apr 2026 08:45:08 GMT</pubDate><category>PDF Malware</category><category>Javascript Obfuscation</category><category>PowerShell Execution</category><category>Initial Access</category></item><item><title>ClickFix Social Engineering Clusters Target Windows and macOS Systems</title><link>https://runtimerebel.com/blog/clickfix-social-engineering-clusters-target-windows-and-macos-systems</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-social-engineering-clusters-target-windows-and-macos-systems</guid><description>Insikt Group identifies five ClickFix clusters using obfuscated commands to exploit native system tools via fake browser error overlays on Windows and macOS.</description><pubDate>Wed, 25 Mar 2026 12:25:41 GMT</pubDate><category>ClickFix</category><category>Social Engineering</category><category>macOS Security</category><category>Powershell Obfuscation</category><category>Initial Access</category></item><item><title>U.S. Sentences Yanluowang Ransomware Facilitator Aleksei Volkov</title><link>https://runtimerebel.com/blog/u-s-sentences-yanluowang-ransomware-facilitator-aleksei-volkov</link><guid isPermaLink="true">https://runtimerebel.com/blog/u-s-sentences-yanluowang-ransomware-facilitator-aleksei-volkov</guid><description>Russian national Aleksei Volkov sentenced to 81 months for facilitating Yanluowang ransomware attacks, causing $9M in damages to U.S. organizations.</description><pubDate>Tue, 24 Mar 2026 08:20:40 GMT</pubDate><category>Yanluowang</category><category>Ransomware</category><category>Aleksei Olegovich Volkov</category><category>Cybercrime Sentencing</category><category>Initial Access</category></item></channel></rss>