<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Network Security</title><description>Cybersecurity articles tagged #Network Security on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>TSN Protocols Vulnerabilities Threaten OT Security</title><link>https://runtimerebel.com/blog/tsn-protocols-vulnerabilities-threaten-ot-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/tsn-protocols-vulnerabilities-threaten-ot-security</guid><description>New research reveals how unprotected Time-Sensitive Networking protocols in industrial systems could allow attackers to disrupt physical processes.</description><pubDate>Sun, 23 Aug 2026 16:17:17 GMT</pubDate><category>OT Security</category><category>Industrial Control Systems</category><category>Network Security</category><category>Vulnerabilities</category></item><item><title>Cisco Patches Nine Crosswork and Secure Workload Flaws</title><link>https://runtimerebel.com/blog/cisco-patches-nine-crosswork-and-secure-workload-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-patches-nine-crosswork-and-secure-workload-flaws</guid><description>Cisco patches nine vulnerabilities in Crosswork and Secure Workload platforms, with five flaws scoring the maximum CVSS 10.0 severity rating.</description><pubDate>Sun, 23 Aug 2026 00:43:17 GMT</pubDate><category>Cisco</category><category>Vulnerabilities</category><category>Zero-Day</category><category>Network Security</category><category>Patch Management</category></item><item><title>Threema Secure Messaging Service Disrupted by Large-Scale DDoS Attacks</title><link>https://runtimerebel.com/blog/threema-secure-messaging-service-disrupted-by-large-scale-ddos-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/threema-secure-messaging-service-disrupted-by-large-scale-ddos-attacks</guid><description>Threema, a secure messaging service, experienced severe disruptions from large-scale DDoS attacks that continuously changed patterns, challenging mitigation efforts.</description><pubDate>Mon, 17 Aug 2026 08:33:18 GMT</pubDate><category>Threema</category><category>DDoS</category><category>Denial of Service</category><category>Cyberattack</category><category>Network Security</category></item><item><title>Widespread Exposure of Remote Access Services Risks Network Compromise</title><link>https://runtimerebel.com/blog/widespread-exposure-of-remote-access-services-risks-network-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/widespread-exposure-of-remote-access-services-risks-network-compromise</guid><description>Security analysts observe a surge in publicly exposed VPN, RDP, and SSH services, serving as critical entry points for attackers. Learn how to secure your perimeter.</description><pubDate>Fri, 31 Jul 2026 02:57:25 GMT</pubDate><category>Exposed Services</category><category>VPN</category><category>Remote Access</category><category>Network Security</category><category>Firewall</category><category>Misconfiguration</category><category>RDP</category><category>SSH</category><category>WireGuard</category><category>OpenVPN</category></item><item><title>SSDP Reflection Attacks: How to Secure Port 1900 Against DDoS</title><link>https://runtimerebel.com/blog/ssdp-reflection-attacks-how-to-secure-port-1900-against-ddos</link><guid isPermaLink="true">https://runtimerebel.com/blog/ssdp-reflection-attacks-how-to-secure-port-1900-against-ddos</guid><description>Analyze the risks of SSDP reflection attacks and how misconfigured Simple Service Discovery Protocol services on port 1900 facilitate high-volume DDoS campaigns.</description><pubDate>Thu, 23 Jul 2026 10:28:23 GMT</pubDate><category>SSDP</category><category>DDoS</category><category>UPnP</category><category>Reflection Attack</category><category>Network Security</category></item><item><title>Identifying Origin IP Addresses Behind Cloudflare and WAF Services</title><link>https://runtimerebel.com/blog/identifying-origin-ip-addresses-behind-cloudflare-and-waf-services</link><guid isPermaLink="true">https://runtimerebel.com/blog/identifying-origin-ip-addresses-behind-cloudflare-and-waf-services</guid><description>Examine technical methods used to discover backend origin IPs hidden behind Cloudflare, including DNS history, TLS fingerprinting, and outbound leaks.</description><pubDate>Mon, 20 Jul 2026 03:26:59 GMT</pubDate><category>Cloudflare</category><category>Reconnaissance</category><category>Origin Ip</category><category>Waf Bypass</category><category>Network Security</category></item><item><title>FIFA Network Vulnerability: Minimal Access Leads to Broad Compromise</title><link>https://runtimerebel.com/blog/fifa-network-vulnerability-minimal-access-leads-to-broad-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/fifa-network-vulnerability-minimal-access-leads-to-broad-compromise</guid><description>An unidentified vulnerability exposed FIFA&apos;s network to compromise with minimal access, highlighting risks of overlooked attack surfaces and privilege escalation.</description><pubDate>Tue, 14 Jul 2026 17:26:07 GMT</pubDate><category>FIFA</category><category>Network Security</category><category>Minimal Access</category><category>Vulnerability</category><category>Privilege Escalation</category></item><item><title>Cisco SD-WAN CVE-2023-20252 Exploited via Rogue Peering - Patch Now</title><link>https://runtimerebel.com/blog/cisco-sd-wan-cve-2023-20252-exploited-via-rogue-peering-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-sd-wan-cve-2023-20252-exploited-via-rogue-peering-patch-now</guid><description>Attackers exploited Cisco SD-WAN Manager flaws like CVE-2023-20252 for two months before disclosure. Learn how to secure your vManage infrastructure today.</description><pubDate>Thu, 25 Jun 2026 05:27:10 GMT</pubDate><category>Cisco SD WAN</category><category>CVE-2023-20252</category><category>Zero-Day</category><category>Network Security</category></item><item><title>FortiBleed: 73,932 FortiGate Systems Exposed – Credential Leak Analysis</title><link>https://runtimerebel.com/blog/fortibleed-73932-fortigate-systems-exposed-credential-leak-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortibleed-73932-fortigate-systems-exposed-credential-leak-analysis</guid><description>Analysis of the FortiBleed campaign, detailing the exposure of administrative and VPN credentials for over 73,000 Fortinet FortiGate firewalls and critical mitigation…</description><pubDate>Sat, 20 Jun 2026 05:36:54 GMT</pubDate><category>FortiBleed</category><category>FortiGate</category><category>Fortinet</category><category>Credential Exposure</category><category>Firewall Security</category><category>Network Security</category></item><item><title>Coordinated SSH Brute Force Attacks: Three-Month Analysis &amp; Defenses</title><link>https://runtimerebel.com/blog/coordinated-ssh-brute-force-attacks-three-month-analysis-defenses</link><guid isPermaLink="true">https://runtimerebel.com/blog/coordinated-ssh-brute-force-attacks-three-month-analysis-defenses</guid><description>Analysis of coordinated SSH brute-force attacks over three months, detailing observed patterns and providing actionable strategies to protect SSH servers.</description><pubDate>Thu, 18 Jun 2026 09:59:47 GMT</pubDate><category>SSH</category><category>Brute Force</category><category>Credential Stuffing</category><category>Threat Intelligence</category><category>Network Security</category><category>Fail2ban</category></item><item><title>EU&apos;s Shield-6G Initiative: Proactive Defense for Future Networks</title><link>https://runtimerebel.com/blog/eu-s-shield-6g-initiative-proactive-defense-for-future-networks</link><guid isPermaLink="true">https://runtimerebel.com/blog/eu-s-shield-6g-initiative-proactive-defense-for-future-networks</guid><description>The EU&apos;s Shield-6G project is proactively integrating AI, digital twins, and honeypots to fortify future 6G networks against emerging cyber threats.</description><pubDate>Thu, 18 Jun 2026 09:51:20 GMT</pubDate><category>6G</category><category>Network Security</category><category>AI</category><category>Digital Twins</category><category>Honeypots</category><category>EU</category><category>Telecommunications</category></item><item><title>AI and the Persistent Limitations of Modern Cryptography</title><link>https://runtimerebel.com/blog/ai-and-the-persistent-limitations-of-modern-cryptography</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-and-the-persistent-limitations-of-modern-cryptography</guid><description>Expert analysis on Bruce Schneier’s thesis regarding why cryptography fails to protect modern networks from AI-driven threats and architectural weaknesses.</description><pubDate>Tue, 02 Jun 2026 13:28:53 GMT</pubDate><category>Cryptography</category><category>Artificial Intelligence</category><category>Network Security</category><category>Bruce Schneier</category></item><item><title>AI-Powered DDoS Attacks: Emerging Tactics and Defensive Strategies</title><link>https://runtimerebel.com/blog/ai-powered-ddos-attacks-emerging-tactics-and-defensive-strategies</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-powered-ddos-attacks-emerging-tactics-and-defensive-strategies</guid><description>Threat actors are leveraging artificial intelligence to automate DDoS attacks, increasing speed and evasion capabilities against traditional network defenses.</description><pubDate>Tue, 26 May 2026 13:09:46 GMT</pubDate><category>DDoS</category><category>Artificial Intelligence</category><category>Botnets</category><category>Automation</category><category>Network Security</category></item><item><title>Analyzing Suspicious TLS Traffic Patterns with JA3 Fingerprinting</title><link>https://runtimerebel.com/blog/analyzing-suspicious-tls-traffic-patterns-with-ja3-fingerprinting</link><guid isPermaLink="true">https://runtimerebel.com/blog/analyzing-suspicious-tls-traffic-patterns-with-ja3-fingerprinting</guid><description>Improve threat detection by identifying TLS handshake anomalies, JA3 fingerprints, and SNI mismatches to expose hidden malicious network activity.</description><pubDate>Tue, 26 May 2026 05:26:26 GMT</pubDate><category>TLS Fingerprinting</category><category>JA3</category><category>Network Security</category><category>Traffic Analysis</category><category>Malware Detection</category><category>SNI Inspection</category></item><item><title>Wireshark 4.6.6: Fixing Critical Vulnerability and Dissector Bugs</title><link>https://runtimerebel.com/blog/wireshark-4-6-6-fixing-critical-vulnerability-and-dissector-bugs</link><guid isPermaLink="true">https://runtimerebel.com/blog/wireshark-4-6-6-fixing-critical-vulnerability-and-dissector-bugs</guid><description>Wireshark 4.6.6 release addresses one security vulnerability and 11 functional bugs. Learn how this update secures packet analysis and prevents dissector crashes.</description><pubDate>Sun, 24 May 2026 20:25:16 GMT</pubDate><category>Wireshark</category><category>Network Security</category><category>Packet Analysis</category><category>Vulnerability Management</category></item><item><title>Dismantling First VPN: Global Takedown of Ransomware Infrastructure</title><link>https://runtimerebel.com/blog/dismantling-first-vpn-global-takedown-of-ransomware-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/dismantling-first-vpn-global-takedown-of-ransomware-infrastructure</guid><description>Authorities dismantle First VPN Service, a critical infrastructure hub used by 25 ransomware groups for masking data theft and DDoS attacks.</description><pubDate>Fri, 22 May 2026 20:37:05 GMT</pubDate><category>First VPN Service</category><category>Ransomware Infrastructure</category><category>Law Enforcement Takedown</category><category>Cybercrime</category><category>Network Security</category></item><item><title>CVE-2026-20182: Cisco SD-WAN Auth Bypass Actively Exploited</title><link>https://runtimerebel.com/blog/cve-2026-20182-cisco-sd-wan-auth-bypass-actively-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-20182-cisco-sd-wan-auth-bypass-actively-exploited</guid><description>Cisco Catalyst SD-WAN Controller and Manager face critical authentication bypass CVE-2026-20182, actively exploited for admin access. Patch now.</description><pubDate>Thu, 14 May 2026 20:36:04 GMT</pubDate><category>CVE-2026-20182</category><category>Cisco Catalyst SD WAN Controller</category><category>Cisco Catalyst SD WAN Manager</category><category>Authentication Bypass</category><category>SD WAN</category><category>Network Security</category></item><item><title>Routing Non-Proxy-Aware Application Traffic for Security Analysis</title><link>https://runtimerebel.com/blog/routing-non-proxy-aware-application-traffic-for-security-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/routing-non-proxy-aware-application-traffic-for-security-analysis</guid><description>Technical analysis of routing non-proxy-aware EXE traffic through security gateways to improve SOC visibility and mitigate egress evasion risks.</description><pubDate>Wed, 13 May 2026 05:23:43 GMT</pubDate><category>Network Security</category><category>Egress Filtering</category><category>Proxifier</category><category>Traffic Analysis</category><category>C2 Detection</category></item><item><title>Firestarter Malware Persists on Cisco Firewalls Post-Update</title><link>https://runtimerebel.com/blog/firestarter-malware-persists-on-cisco-firewalls-post-update</link><guid isPermaLink="true">https://runtimerebel.com/blog/firestarter-malware-persists-on-cisco-firewalls-post-update</guid><description>U.S. and U.K. agencies warn about Firestarter malware exhibiting post-update persistence on Cisco Firepower and Secure Firewalls running ASA/FTD.</description><pubDate>Sat, 25 Apr 2026 04:53:41 GMT</pubDate><category>FIRESTARTER</category><category>Cisco Firepower</category><category>Cisco Secure Firewall</category><category>ASA</category><category>FTD</category><category>Malware Persistence</category><category>Network Security</category></item><item><title>IPv6 Security: Mitigating Rogue Router Advertisements and NDP Risks</title><link>https://runtimerebel.com/blog/ipv6-security-mitigating-rogue-router-advertisements-and-ndp-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/ipv6-security-mitigating-rogue-router-advertisements-and-ndp-risks</guid><description>Analysis of IPv6 Neighbor Discovery Protocol vulnerabilities and why security teams must prioritize RA Guard and monitoring to prevent traffic interception.</description><pubDate>Tue, 14 Apr 2026 08:41:10 GMT</pubDate><category>IPv6</category><category>Ndp</category><category>Network Security</category><category>SANS ISC</category><category>Router Advertisement</category></item><item><title>Juniper Junos OS: Critical RCE Vulnerability &amp; Dozens of Patches</title><link>https://runtimerebel.com/blog/juniper-junos-os-critical-rce-vulnerability-dozens-of-patches</link><guid isPermaLink="true">https://runtimerebel.com/blog/juniper-junos-os-critical-rce-vulnerability-dozens-of-patches</guid><description>Juniper Networks released patches for dozens of Junos OS vulnerabilities, including a critical RCE that allows unauthenticated remote device takeover. Update immediately.</description><pubDate>Fri, 10 Apr 2026 16:27:12 GMT</pubDate><category>Juniper Networks</category><category>Junos OS</category><category>RCE</category><category>Vulnerability Management</category><category>Network Security</category></item><item><title>Palo Alto Networks &amp; SonicWall High-Severity Privilege Escalation Patches</title><link>https://runtimerebel.com/blog/palo-alto-networks-sonicwall-high-severity-privilege-escalation-patches</link><guid isPermaLink="true">https://runtimerebel.com/blog/palo-alto-networks-sonicwall-high-severity-privilege-escalation-patches</guid><description>Palo Alto Networks and SonicWall have issued patches for high-severity vulnerabilities allowing privilege escalation to administrator. Immediate patching is advised.</description><pubDate>Thu, 09 Apr 2026 12:47:56 GMT</pubDate><category>Palo Alto Networks</category><category>SonicWall</category><category>Privilege Escalation</category><category>Vulnerability</category><category>Network Security</category></item><item><title>Cisco IMC and SSM RCE via CVE-2026-20093 — Mitigation Guide</title><link>https://runtimerebel.com/blog/cisco-imc-and-ssm-rce-via-cve-2026-20093-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-imc-and-ssm-rce-via-cve-2026-20093-mitigation-guide</guid><description>Cisco patches a critical 9.8 CVSS vulnerability in Integrated Management Controller (IMC) allowing unauthenticated remote attackers to gain full system access.</description><pubDate>Thu, 02 Apr 2026 20:15:12 GMT</pubDate><category>Cisco</category><category>CVE-2026-20093</category><category>Authentication Bypass</category><category>RCE</category><category>Network Security</category></item><item><title>Cisco SD-WAN vManage RCE: Fake PoCs &amp; CVE-2023-20252 Exploitation</title><link>https://runtimerebel.com/blog/cisco-sd-wan-vmanage-rce-fake-pocs-cve-2023-20252-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-sd-wan-vmanage-rce-fake-pocs-cve-2023-20252-exploitation</guid><description>Threat intelligence reveals fake PoCs for Cisco SD-WAN vManage CVE-2023-20252. Understand actual RCE risks and critical patching for affected systems.</description><pubDate>Fri, 13 Mar 2026 20:15:16 GMT</pubDate><category>Cisco SD WAN</category><category>vManage</category><category>CVE-2023-20252</category><category>RCE</category><category>Command Injection</category><category>PoC Fraud</category><category>Network Security</category></item><item><title>Encrypted Client Hello (ECH): Implications for Network Visibility</title><link>https://runtimerebel.com/blog/encrypted-client-hello-ech-implications-for-network-visibility</link><guid isPermaLink="true">https://runtimerebel.com/blog/encrypted-client-hello-ech-implications-for-network-visibility</guid><description>New RFCs for Encrypted Client Hello (ECH) signal a shift in TLS. This analysis explores ECH&apos;s privacy benefits and challenges for network security monitoring.</description><pubDate>Mon, 09 Mar 2026 16:35:49 GMT</pubDate><category>Encrypted Client Hello</category><category>ECH</category><category>TLS 1 3</category><category>Network Visibility</category><category>Privacy</category><category>RFC</category><category>Network Security</category></item><item><title>AirSnitch: Cross-Layer Desynchronization Enables Wi-Fi MitM Attacks</title><link>https://runtimerebel.com/blog/airsnitch-cross-layer-desynchronization-enables-wi-fi-mitm-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/airsnitch-cross-layer-desynchronization-enables-wi-fi-mitm-attacks</guid><description>Research reveals AirSnitch, a vulnerability exploiting Wi-Fi Layers 1 and 2 to execute bidirectional MitM attacks across home and enterprise networks.</description><pubDate>Mon, 09 Mar 2026 12:20:24 GMT</pubDate><category>Airsnitch</category><category>Wi Fi Security</category><category>Mitm Attack</category><category>802 11 Vulnerability</category><category>Network Security</category></item><item><title>CVE-2026-20122: Cisco Catalyst SD-WAN Manager Exploited in the Wild</title><link>https://runtimerebel.com/blog/cve-2026-20122-cisco-catalyst-sd-wan-manager-exploited-in-the-wild</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-20122-cisco-catalyst-sd-wan-manager-exploited-in-the-wild</guid><description>Cisco confirms active exploitation of CVE-2026-20122 in Catalyst SD-WAN Manager, allowing authenticated attackers to perform arbitrary file overwrites.</description><pubDate>Thu, 05 Mar 2026 20:15:56 GMT</pubDate><category>Cisco</category><category>Catalyst SD WAN</category><category>CVE-2026-20122</category><category>Network Security</category><category>Exploitation</category></item><item><title>Targeted vs. Opportunistic: Differentiating Cyber Intrusions</title><link>https://runtimerebel.com/blog/targeted-vs-opportunistic-differentiating-cyber-intrusions</link><guid isPermaLink="true">https://runtimerebel.com/blog/targeted-vs-opportunistic-differentiating-cyber-intrusions</guid><description>Learn to distinguish targeted cyber intrusions from automated opportunistic scanning.</description><pubDate>Thu, 05 Mar 2026 04:41:01 GMT</pubDate><category>Threat Intelligence</category><category>Network Security</category><category>Incident Response</category><category>Scanning</category><category>Targeted Attack</category><category>Opportunistic Attack</category><category>Threat Classification</category></item><item><title>Cybersecurity &apos;Hive Mind&apos;: Collective Defense Against Emerging Threats</title><link>https://runtimerebel.com/blog/cybersecurity-hive-mind-collective-defense-against-emerging-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/cybersecurity-hive-mind-collective-defense-against-emerging-threats</guid><description>Explore how &apos;hive mind&apos; principles can enhance enterprise cybersecurity defenses through collective intelligence, shared threat awareness, and unified response…</description><pubDate>Wed, 04 Mar 2026 20:16:15 GMT</pubDate><category>Collective Defense</category><category>Threat Intelligence</category><category>Network Security</category><category>Incident Response</category><category>Enterprise Security</category><category>Cybersecurity Operations</category></item><item><title>AI-Driven Development and the Crisis of Firewall Rule Backlogs</title><link>https://runtimerebel.com/blog/ai-driven-development-and-the-crisis-of-firewall-rule-backlogs</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-driven-development-and-the-crisis-of-firewall-rule-backlogs</guid><description>Examine how AI-accelerated coding creates network security bottlenecks and why manual firewall management fails in modern DevSecOps environments.</description><pubDate>Tue, 03 Mar 2026 04:38:38 GMT</pubDate><category>Ai Driven Development</category><category>Firewall Management</category><category>Network Security</category><category>DevSecOps</category><category>Automation</category></item><item><title>Wireshark 4.6.4 Patch Fixes Dissector Vulnerabilities — Update Guide</title><link>https://runtimerebel.com/blog/wireshark-4-6-4-patch-fixes-dissector-vulnerabilities-update-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/wireshark-4-6-4-patch-fixes-dissector-vulnerabilities-update-guide</guid><description>Wireshark 4.6.4 addresses multiple dissector vulnerabilities, including CVE-2025-1811 and CVE-2025-1812, which could lead to application crashes.</description><pubDate>Mon, 02 Mar 2026 12:20:02 GMT</pubDate><category>CVE-2025-1811</category><category>CVE-2025-1812</category><category>CVE-2025-1813</category><category>Wireshark</category><category>Network Security</category></item><item><title>CVE-2025-24036: Critical RCE in Ivanti Connect Secure — Patch Now</title><link>https://runtimerebel.com/blog/cve-2025-24036-critical-rce-in-ivanti-connect-secure-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-24036-critical-rce-in-ivanti-connect-secure-patch-now</guid><description>Exploit analysis of CVE-2025-24036 in Ivanti Connect Secure and Policy Secure. Learn to detect unauthenticated RCE attempts and apply mitigation strategies.</description><pubDate>Mon, 02 Mar 2026 03:15:14 GMT</pubDate><category>CVE-2025-24036</category><category>Ivanti</category><category>RCE</category><category>Network Security</category><category>Volt Typhoon</category></item><item><title>Zyxel Fixes Critical RCE Vulnerability in UPnP Implementation</title><link>https://runtimerebel.com/blog/zyxel-fixes-critical-rce-vulnerability-in-upnp-implementation</link><guid isPermaLink="true">https://runtimerebel.com/blog/zyxel-fixes-critical-rce-vulnerability-in-upnp-implementation</guid><description>Zyxel releases patches for CVE-2024-42057, a command injection flaw in the UPnP function of several VMG and fiber router models, allowing unauthenticated RCE.</description><pubDate>Thu, 26 Feb 2026 12:21:38 GMT</pubDate><category>Zyxel</category><category>CVE-2024-42057</category><category>UPnP</category><category>RCE</category><category>VMG Series</category><category>Network Security</category></item><item><title>Cisco SD-WAN Exploitation: Critical Authentication Bypass &amp; Escalation</title><link>https://runtimerebel.com/blog/cisco-sd-wan-exploitation-critical-authentication-bypass-escalation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-sd-wan-exploitation-critical-authentication-bypass-escalation</guid><description>CISA alerts on active global exploitation of Cisco SD-WAN, leveraging CVE-2026-20127 for initial access and CVE-2022-20775 for privilege escalation.</description><pubDate>Wed, 25 Feb 2026 20:17:23 GMT</pubDate><category>Cisco SD WAN</category><category>CVE-2026-20127</category><category>CVE-2022-20775</category><category>Authentication Bypass</category><category>Privilege Escalation</category><category>Known Exploited Vulnerabilities</category><category>KEV</category><category>Network Security</category><category>CISA Emergency Directive</category></item><item><title>Critical Cisco SD-WAN Zero-Day Exploited Since 2023</title><link>https://runtimerebel.com/blog/critical-cisco-sd-wan-zero-day-exploited-since-2023</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-cisco-sd-wan-zero-day-exploited-since-2023</guid><description>Cisco Catalyst SD-WAN critical authentication bypass (CVE-2026-20127) actively exploited since 2023, enabling remote compromise and rogue peer addition.</description><pubDate>Wed, 25 Feb 2026 20:15:55 GMT</pubDate><category>Cisco Catalyst SD WAN</category><category>CVE-2026-20127</category><category>Authentication Bypass</category><category>Zero-Day</category><category>Network Security</category></item><item><title>Automated AI-Driven Exploitation of FortiGate Management Interfaces in AWS Environments</title><link>https://runtimerebel.com/blog/automated-ai-driven-exploitation-of-fortigate-management-interfaces-in-aws-environments</link><guid isPermaLink="true">https://runtimerebel.com/blog/automated-ai-driven-exploitation-of-fortigate-management-interfaces-in-aws-environments</guid><description>Threat actors are utilizing artificial intelligence to automate credential stuffing and exploit exposed administrative ports on Fortinet devices within AWS…</description><pubDate>Mon, 23 Feb 2026 12:21:29 GMT</pubDate><category>FortiGate</category><category>AWS</category><category>Credential Stuffing</category><category>AI</category><category>Network Security</category></item><item><title>AI-Automated Campaign Targets Global FortiGate Edge Infrastructure</title><link>https://runtimerebel.com/blog/ai-automated-campaign-targets-global-fortigate-edge-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-automated-campaign-targets-global-fortigate-edge-infrastructure</guid><description>A Russian-speaking threat actor leveraged generative AI to automate the compromise of over 600 FortiGate devices across 55 countries between January and February 2026.</description><pubDate>Mon, 23 Feb 2026 04:05:57 GMT</pubDate><category>FortiGate</category><category>GenAI</category><category>Credential Stuffing</category><category>Threat Intelligence</category><category>Network Security</category></item></channel></rss>