<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Post Exploitation</title><description>Cybersecurity articles tagged #Post Exploitation on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>khunt Toolkit Leverages SQLi in Oracle for SYSTEM Access</title><link>https://runtimerebel.com/blog/khunt-toolkit-leverages-sqli-in-oracle-for-system-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/khunt-toolkit-leverages-sqli-in-oracle-for-system-access</guid><description>Attackers exploit SQL injection in a public-facing web app to compile the khunt toolkit within Oracle, achieving SYSTEM-level access on Windows servers.</description><pubDate>Thu, 06 Aug 2026 10:29:03 GMT</pubDate><category>SQL Injection</category><category>Post Exploitation</category><category>Windows</category><category>Oracle Database</category><category>Khunt</category></item><item><title>CVE-2025-68686: Fortinet FortiOS Patch Bypass for Post-Exploit Persistence</title><link>https://runtimerebel.com/blog/cve-2025-68686-fortinet-fortios-patch-bypass-for-post-exploit-persistence</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-68686-fortinet-fortios-patch-bypass-for-post-exploit-persistence</guid><description>CISA warns of active exploitation of CVE-2025-68686 in Fortinet FortiOS, allowing attackers to bypass a patch for post-exploit persistence and expose sensitive data.</description><pubDate>Fri, 31 Jul 2026 10:43:21 GMT</pubDate><category>CVE-2025-68686</category><category>Fortinet</category><category>Fortios</category><category>Information Exposure</category><category>Patch Bypass</category><category>Post Exploitation</category><category>CISA KEV</category><category>CWE-200</category></item><item><title>Post-Exploitation Tactics: Persistence and Lateral Movement Analysis</title><link>https://runtimerebel.com/blog/post-exploitation-tactics-persistence-and-lateral-movement-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/post-exploitation-tactics-persistence-and-lateral-movement-analysis</guid><description>Analyze how threat actors establish persistence, disable security software, and move laterally after initial network access to ensure long-term compromise.</description><pubDate>Thu, 30 Jul 2026 14:07:01 GMT</pubDate><category>Post Exploitation</category><category>Persistence Mechanisms</category><category>Incident Response</category><category>Lateral Movement</category><category>Huntress</category></item><item><title>Hermes AI Agent Automates Post-Exploitation Against Thai Ministry</title><link>https://runtimerebel.com/blog/hermes-ai-agent-automates-post-exploitation-against-thai-ministry</link><guid isPermaLink="true">https://runtimerebel.com/blog/hermes-ai-agent-automates-post-exploitation-against-thai-ministry</guid><description>Hermes AI agent automates post-exploitation during alleged breach of Thai Ministry of Finance. Learn TTPs, impact, and mitigation for AI-driven threats.</description><pubDate>Fri, 24 Jul 2026 21:05:58 GMT</pubDate><category>Hermes AI</category><category>AI Automation</category><category>Post Exploitation</category><category>Thai Ministry of Finance</category><category>Government Target</category></item><item><title>CVE-2026-39987: Attackers Use LLM Agents for Post-Exploitation</title><link>https://runtimerebel.com/blog/cve-2026-39987-attackers-use-llm-agents-for-post-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-39987-attackers-use-llm-agents-for-post-exploitation</guid><description>Discover how threat actors are leveraging LLM agents to automate post-exploitation tasks after compromising Marimo notebooks via CVE-2026-39987.</description><pubDate>Fri, 29 May 2026 17:18:30 GMT</pubDate><category>CVE-2026-39987</category><category>Marimo</category><category>LLM Agent</category><category>Post Exploitation</category><category>Cloud Security</category></item><item><title>RoadK1ll WebSocket Implant: New Threat for Stealthy Lateral Movement</title><link>https://runtimerebel.com/blog/roadk1ll-websocket-implant-new-threat-for-stealthy-lateral-movement</link><guid isPermaLink="true">https://runtimerebel.com/blog/roadk1ll-websocket-implant-new-threat-for-stealthy-lateral-movement</guid><description>Analysis of the new RoadK1ll WebSocket implant, detailing its capabilities for lateral movement on compromised networks and offering detection and mitigation strategies.</description><pubDate>Tue, 31 Mar 2026 00:40:12 GMT</pubDate><category>RoadK1ll</category><category>WebSocket</category><category>Lateral Movement</category><category>Post Exploitation</category><category>Implant</category></item><item><title>Ransomware TTPs Shift: From Cobalt Strike to Native Tools, Data Theft Surges</title><link>https://runtimerebel.com/blog/ransomware-ttps-shift-from-cobalt-strike-to-native-tools-data-theft-surges</link><guid isPermaLink="true">https://runtimerebel.com/blog/ransomware-ttps-shift-from-cobalt-strike-to-native-tools-data-theft-surges</guid><description>Ransomware actors are abandoning Cobalt Strike for native Windows tools as payment rates decline, leading to a significant surge in data theft.</description><pubDate>Wed, 18 Mar 2026 00:37:35 GMT</pubDate><category>Ransomware</category><category>TTPs</category><category>Cobalt Strike</category><category>Data Theft</category><category>Native Windows Tools</category><category>Post Exploitation</category></item><item><title>Warlock Ransomware: BYOVD Techniques and Post-Exploitation Analysis</title><link>https://runtimerebel.com/blog/warlock-ransomware-byovd-techniques-and-post-exploitation-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/warlock-ransomware-byovd-techniques-and-post-exploitation-analysis</guid><description>The Warlock ransomware group has evolved its tactics, utilizing BYOVD techniques and stealthy cross-network activity to bypass EDR and security controls.</description><pubDate>Tue, 17 Mar 2026 16:31:42 GMT</pubDate><category>Warlock Ransomware</category><category>BYOVD</category><category>EDR Evasion</category><category>Lateral Movement</category><category>Post Exploitation</category></item></channel></rss>