<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Misconfiguration</title><description>Cybersecurity articles tagged #Misconfiguration on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Cloud Security Index 2026: Multi-Cloud Risk Analysis</title><link>https://runtimerebel.com/blog/cloud-security-index-2026-multi-cloud-risk-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/cloud-security-index-2026-multi-cloud-risk-analysis</guid><description>Intruder analyzed cloud misconfigurations across AWS, Azure, and GCP, revealing distinct risk profiles and universal IAM challenges.</description><pubDate>Mon, 07 Sep 2026 13:49:04 GMT</pubDate><category>Cloud Security</category><category>Google Cloud</category><category>IAM</category><category>Misconfiguration</category><category>AWS</category></item><item><title>Firebase Misconfiguration in tl;dv AI Tool Exposes Sensitive Meeting Data</title><link>https://runtimerebel.com/blog/firebase-misconfiguration-in-tl-dv-ai-tool-exposes-sensitive-meeting-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/firebase-misconfiguration-in-tl-dv-ai-tool-exposes-sensitive-meeting-data</guid><description>A Google Firebase misconfiguration in the tl;dv AI meeting tool allows unauthorized access to sensitive government and corporate video call information.</description><pubDate>Tue, 04 Aug 2026 17:32:06 GMT</pubDate><category>Misconfiguration</category><category>Data Exposure</category><category>Cloud Security</category><category>Tl Dv</category><category>Google Firebase</category></item><item><title>Widespread Exposure of Remote Access Services Risks Network Compromise</title><link>https://runtimerebel.com/blog/widespread-exposure-of-remote-access-services-risks-network-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/widespread-exposure-of-remote-access-services-risks-network-compromise</guid><description>Security analysts observe a surge in publicly exposed VPN, RDP, and SSH services, serving as critical entry points for attackers. Learn how to secure your perimeter.</description><pubDate>Fri, 31 Jul 2026 02:57:25 GMT</pubDate><category>Exposed Services</category><category>VPN</category><category>Remote Access</category><category>Network Security</category><category>Firewall</category><category>Misconfiguration</category><category>RDP</category><category>SSH</category><category>WireGuard</category><category>OpenVPN</category></item><item><title>Securing Non-Human Identities: Lessons from Cloud Integration Flaws</title><link>https://runtimerebel.com/blog/securing-non-human-identities-lessons-from-cloud-integration-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-non-human-identities-lessons-from-cloud-integration-flaws</guid><description>Analysis of how over-permissioned non-human identities and architectural misconfigurations in cloud integrations lead to cross-tenant compromise risks.</description><pubDate>Fri, 29 May 2026 13:20:18 GMT</pubDate><category>Cloud Security</category><category>Non Human Identities</category><category>Tenable</category><category>Identity and Access Management</category><category>Misconfiguration</category></item><item><title>Redis RCE via CONFIG Command Abuse: Detection and Mitigation</title><link>https://runtimerebel.com/blog/redis-rce-via-config-command-abuse-detection-and-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/redis-rce-via-config-command-abuse-detection-and-mitigation</guid><description>Learn how attackers exploit exposed Redis instances using the CONFIG command to achieve RCE and the specific steps required to secure your infrastructure.</description><pubDate>Wed, 22 Apr 2026 08:46:17 GMT</pubDate><category>Redis</category><category>RCE</category><category>Misconfiguration</category><category>Server Security</category><category>Lateral Movement</category></item><item><title>McGraw-Hill Data Breach: Salesforce Misconfiguration Exploited</title><link>https://runtimerebel.com/blog/mcgraw-hill-data-breach-salesforce-misconfiguration-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/mcgraw-hill-data-breach-salesforce-misconfiguration-exploited</guid><description>McGraw-Hill confirms a data breach after threat actors exploited a Salesforce misconfiguration, exposing internal records and student information.</description><pubDate>Tue, 14 Apr 2026 20:25:19 GMT</pubDate><category>McGraw Hill</category><category>Salesforce</category><category>Mogilevich</category><category>Misconfiguration</category><category>Data Exfiltration</category></item><item><title>Exposed Google API Keys in Android Apps Grant Gemini Access</title><link>https://runtimerebel.com/blog/exposed-google-api-keys-in-android-apps-grant-gemini-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/exposed-google-api-keys-in-android-apps-grant-gemini-access</guid><description>Analysis of Google API keys found in Android apps that enable unauthorized access to Gemini AI endpoints, detailing risks and mitigation for developers.</description><pubDate>Thu, 09 Apr 2026 12:47:35 GMT</pubDate><category>Google API Keys</category><category>Android Security</category><category>Gemini AI</category><category>API Security</category><category>Data Exposure</category><category>Misconfiguration</category></item><item><title>AI-Assisted Supply Chain Attack Targets GitHub Misconfigurations</title><link>https://runtimerebel.com/blog/ai-assisted-supply-chain-attack-targets-github-misconfigurations</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-assisted-supply-chain-attack-targets-github-misconfigurations</guid><description>Analysis of the AI-assisted PRT-scan supply chain attack targeting GitHub misconfigurations. Learn about automated threats and securing repositories.</description><pubDate>Tue, 07 Apr 2026 00:41:26 GMT</pubDate><category>PRT Scan</category><category>GitHub</category><category>AI</category><category>Supply Chain Attack</category><category>Misconfiguration</category></item><item><title>Vite Exposed Installs: Exploitation Attempts &amp; Mitigation for CVE-2025-30208</title><link>https://runtimerebel.com/blog/vite-exposed-installs-exploitation-attempts-mitigation-for-cve-2025-30208</link><guid isPermaLink="true">https://runtimerebel.com/blog/vite-exposed-installs-exploitation-attempts-mitigation-for-cve-2025-30208</guid><description>Runtime Rebel warns of active exploitation attempts targeting exposed Vite development environments. Learn about CVE-2025-30208 and critical mitigation steps.</description><pubDate>Thu, 02 Apr 2026 16:30:01 GMT</pubDate><category>Vite</category><category>CVE-2025-30208</category><category>Frontend Development</category><category>Exploitation</category><category>Misconfiguration</category><category>Development Environment Security</category></item><item><title>Google Vertex AI Over-Privilege: Data Theft &amp; Cloud Intrusion Risk</title><link>https://runtimerebel.com/blog/google-vertex-ai-over-privilege-data-theft-cloud-intrusion-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-vertex-ai-over-privilege-data-theft-cloud-intrusion-risk</guid><description>Palo Alto Networks researchers found over-privileged AI agents in Google Vertex AI could be exploited for data exfiltration and access to restricted cloud infrastructure.</description><pubDate>Wed, 01 Apr 2026 00:44:59 GMT</pubDate><category>Google Vertex AI</category><category>Cloud Security</category><category>Privilege Escalation</category><category>Misconfiguration</category><category>AI Security</category><category>GCP</category></item><item><title>Secure Salesforce Cloud: Restricting Guest User Permissions</title><link>https://runtimerebel.com/blog/secure-salesforce-cloud-restricting-guest-user-permissions</link><guid isPermaLink="true">https://runtimerebel.com/blog/secure-salesforce-cloud-restricting-guest-user-permissions</guid><description>Runtime Rebel analyzes critical Salesforce guest user misconfigurations exposing sensitive client data.</description><pubDate>Wed, 11 Mar 2026 00:32:44 GMT</pubDate><category>Salesforce</category><category>Cloud Security</category><category>Misconfiguration</category><category>Guest User</category><category>Data Exposure</category><category>Identity and Access Management</category></item><item><title>Salesforce Experience Cloud Mass-Scanning via Modified AuraInspector</title><link>https://runtimerebel.com/blog/salesforce-experience-cloud-mass-scanning-via-modified-aurainspector</link><guid isPermaLink="true">https://runtimerebel.com/blog/salesforce-experience-cloud-mass-scanning-via-modified-aurainspector</guid><description>Threat actors use a modified AuraInspector tool to exploit Salesforce Experience Cloud misconfigurations, exposing sensitive guest user data.</description><pubDate>Tue, 10 Mar 2026 08:16:45 GMT</pubDate><category>Salesforce</category><category>Experience Cloud</category><category>AuraInspector</category><category>Misconfiguration</category><category>Data Exposure</category></item></channel></rss>