Skip to main content
← All Articles

Tag

#Post Exploitation

8 articles

Advertisement

khunt Toolkit Leverages SQLi in Oracle for SYSTEM Access
HIGH
Vulnerabilities

khunt Toolkit Leverages SQLi in Oracle for SYSTEM Access

Attackers exploit SQL injection in a public-facing web app to compile the khunt toolkit within Oracle, achieving SYSTEM-level access on Windows servers.

Runtime Rebel Intel
4 min read · Aug 6, 2026
HIGH
Vulnerabilities

CVE-2025-68686: Fortinet FortiOS Patch Bypass for Post-Exploit Persistence

CISA warns of active exploitation of CVE-2025-68686 in Fortinet FortiOS, allowing attackers to bypass a patch for post-exploit persistence and expose sensitive data.

Runtime Rebel Intel
4 min read · Jul 31, 2026
HIGH
Threat Intel

Post-Exploitation Tactics: Persistence and Lateral Movement Analysis

Analyze how threat actors establish persistence, disable security software, and move laterally after initial network access to ensure long-term compromise.

Runtime Rebel Intel
4 min read · Jul 30, 2026
HIGH
Threat Intel

Hermes AI Agent Automates Post-Exploitation Against Thai Ministry

Hermes AI agent automates post-exploitation during alleged breach of Thai Ministry of Finance. Learn TTPs, impact, and mitigation for AI-driven threats.

Runtime Rebel Intel
5 min read · Jul 24, 2026
CVE-2026-39987: Attackers Use LLM Agents for Post-Exploitation
HIGH
Threat Intel

CVE-2026-39987: Attackers Use LLM Agents for Post-Exploitation

Discover how threat actors are leveraging LLM agents to automate post-exploitation tasks after compromising Marimo notebooks via CVE-2026-39987.

Runtime Rebel Intel
3 min read · May 29, 2026
HIGH
Malware

RoadK1ll WebSocket Implant: New Threat for Stealthy Lateral Movement

Analysis of the new RoadK1ll WebSocket implant, detailing its capabilities for lateral movement on compromised networks and offering detection and mitigation strategies.

Runtime Rebel Intel
5 min read · Mar 31, 2026

Advertisement

Ransomware TTPs Shift: From Cobalt Strike to Native Tools, Data Theft Surges
HIGH
Threat Intel

Ransomware TTPs Shift: From Cobalt Strike to Native Tools, Data Theft Surges

Ransomware actors are abandoning Cobalt Strike for native Windows tools as payment rates decline, leading to a significant surge in data theft.

Runtime Rebel Intel
5 min read · Mar 18, 2026
Warlock Ransomware: BYOVD Techniques and Post-Exploitation Analysis
HIGH
Threat Intel

Warlock Ransomware: BYOVD Techniques and Post-Exploitation Analysis

The Warlock ransomware group has evolved its tactics, utilizing BYOVD techniques and stealthy cross-network activity to bypass EDR and security controls.

Runtime Rebel Intel
3 min read · Mar 17, 2026