<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Reconnaissance</title><description>Cybersecurity articles tagged #Reconnaissance on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Identifying Origin IP Addresses Behind Cloudflare and WAF Services</title><link>https://runtimerebel.com/blog/identifying-origin-ip-addresses-behind-cloudflare-and-waf-services</link><guid isPermaLink="true">https://runtimerebel.com/blog/identifying-origin-ip-addresses-behind-cloudflare-and-waf-services</guid><description>Examine technical methods used to discover backend origin IPs hidden behind Cloudflare, including DNS history, TLS fingerprinting, and outbound leaks.</description><pubDate>Mon, 20 Jul 2026 03:26:59 GMT</pubDate><category>Cloudflare</category><category>Reconnaissance</category><category>Origin Ip</category><category>Waf Bypass</category><category>Network Security</category></item><item><title>Scans Target Model Context Protocol Servers and AI Credentials</title><link>https://runtimerebel.com/blog/scans-target-model-context-protocol-servers-and-ai-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/scans-target-model-context-protocol-servers-and-ai-credentials</guid><description>Security researchers observe an increase in scans targeting Model Context Protocol (MCP) servers and AI credentials, potentially exposing sensitive data.</description><pubDate>Mon, 13 Jul 2026 06:54:49 GMT</pubDate><category>MCP</category><category>Anthropic</category><category>AI Security</category><category>Credential Theft</category><category>Reconnaissance</category></item><item><title>GitHub API Abuse: Detecting Ghost Account Reconnaissance Campaigns</title><link>https://runtimerebel.com/blog/github-api-abuse-detecting-ghost-account-reconnaissance-campaigns</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-api-abuse-detecting-ghost-account-reconnaissance-campaigns</guid><description>Threat actors are leveraging thousands of ghost accounts to map GitHub organizations via API abuse, facilitating future targeted supply chain attacks.</description><pubDate>Sat, 11 Jul 2026 20:51:29 GMT</pubDate><category>GitHub</category><category>API Security</category><category>Reconnaissance</category><category>Ghost Accounts</category></item><item><title>GitHub API Abuse: Attackers Map Corporate Orgs via Dormant Accounts</title><link>https://runtimerebel.com/blog/github-api-abuse-attackers-map-corporate-orgs-via-dormant-accounts</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-api-abuse-attackers-map-corporate-orgs-via-dormant-accounts</guid><description>Datadog Security Labs warns of systematic GitHub API enumeration campaigns using dormant accounts and compromised OAuth tokens to map corporate organizations.</description><pubDate>Thu, 09 Jul 2026 21:25:09 GMT</pubDate><category>GitHub</category><category>API Abuse</category><category>Reconnaissance</category><category>OAuth Token</category><category>Supply Chain</category><category>Datadog</category></item><item><title>Automated Favicon.ico Reconnaissance for Host Enumeration</title><link>https://runtimerebel.com/blog/automated-favicon-ico-reconnaissance-for-host-enumeration</link><guid isPermaLink="true">https://runtimerebel.com/blog/automated-favicon-ico-reconnaissance-for-host-enumeration</guid><description>Understand how attackers automate favicon.ico analysis for host reconnaissance. Learn to identify and defend against this common, yet often overlooked, enumeration…</description><pubDate>Mon, 29 Jun 2026 13:41:34 GMT</pubDate><category>Favicon Ico</category><category>Reconnaissance</category><category>Host Enumeration</category><category>Pentesting</category><category>Threat Intelligence</category><category>Web Fingerprinting</category></item><item><title>JDY Botnet: China-Linked Campaign Targets US Military Networks</title><link>https://runtimerebel.com/blog/jdy-botnet-china-linked-campaign-targets-us-military-networks</link><guid isPermaLink="true">https://runtimerebel.com/blog/jdy-botnet-china-linked-campaign-targets-us-military-networks</guid><description>Analysis of the China-linked JDY botnet&apos;s expanded targeting of U.S. military networks, its reconnaissance TTPs, and critical mitigation strategies.</description><pubDate>Wed, 10 Jun 2026 17:15:50 GMT</pubDate><category>JDY Botnet</category><category>Volt Typhoon</category><category>China Linked</category><category>US Military</category><category>Reconnaissance</category><category>National Security</category></item><item><title>Detecting API Discovery Scans for swagger.json: Security Guide</title><link>https://runtimerebel.com/blog/detecting-api-discovery-scans-for-swagger-json-security-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/detecting-api-discovery-scans-for-swagger-json-security-guide</guid><description>Analysis of automated scans for swagger.json and OpenAPI files. Learn how to secure RESTful APIs against discovery-based attacks and reconnaissance.</description><pubDate>Wed, 03 Jun 2026 13:51:10 GMT</pubDate><category>API Security</category><category>Reconnaissance</category><category>Swagger</category><category>OpenAPI</category><category>SANS ISC</category></item><item><title>FBI Disrupts First VPN Service Used by Ransomware Groups</title><link>https://runtimerebel.com/blog/fbi-disrupts-first-vpn-service-used-by-ransomware-groups</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-disrupts-first-vpn-service-used-by-ransomware-groups</guid><description>The FBI and international partners dismantled First VPN, a specialized service used by dozens of ransomware groups for reconnaissance and intrusions.</description><pubDate>Fri, 22 May 2026 13:00:22 GMT</pubDate><category>First VPN</category><category>Ransomware</category><category>Fbi Disruption</category><category>Reconnaissance</category><category>Initial Access</category></item><item><title>Emerging Reconnaissance: Attackers Actively Probe AI Models</title><link>https://runtimerebel.com/blog/emerging-reconnaissance-attackers-actively-probe-ai-models</link><guid isPermaLink="true">https://runtimerebel.com/blog/emerging-reconnaissance-attackers-actively-probe-ai-models</guid><description>DShield sensors detect increasing scanning activity targeting popular AI models like Claude and Hugging Face, signaling a potential new attack vector for threat actors.</description><pubDate>Wed, 15 Apr 2026 00:46:56 GMT</pubDate><category>AI Models</category><category>Scanning</category><category>Reconnaissance</category><category>Threat Intelligence</category><category>DShield</category><category>Hugging Face</category><category>Claude</category><category>OpenClaw</category></item><item><title>TrueConf Zero-Day: Exploitation Against Asian Governments</title><link>https://runtimerebel.com/blog/trueconf-zero-day-exploitation-against-asian-governments</link><guid isPermaLink="true">https://runtimerebel.com/blog/trueconf-zero-day-exploitation-against-asian-governments</guid><description>A Chinese threat actor is actively exploiting a TrueConf video conferencing zero-day to conduct reconnaissance and achieve privilege escalation against Asian government…</description><pubDate>Fri, 03 Apr 2026 16:17:33 GMT</pubDate><category>TrueConf</category><category>Zero-Day</category><category>Asian Government</category><category>Privilege Escalation</category><category>Reconnaissance</category><category>Chinese Threat Actor</category></item><item><title>Analysis of &apos;iranbot&apos; Message in Cowrie Honeypot Logs</title><link>https://runtimerebel.com/blog/analysis-of-iranbot-message-in-cowrie-honeypot-logs</link><guid isPermaLink="true">https://runtimerebel.com/blog/analysis-of-iranbot-message-in-cowrie-honeypot-logs</guid><description>A peculiar &apos;iranbot_was_here&apos; message, alongside Telnet logins and portscans, was observed in Cowrie honeypot logs, signaling potential reconnaissance activity.</description><pubDate>Thu, 19 Mar 2026 04:43:57 GMT</pubDate><category>Cowrie</category><category>Honeypot</category><category>Telnet</category><category>Reconnaissance</category><category>Iranbot</category><category>DShield</category><category>Logging</category></item><item><title>Adminer &amp; phpMyAdmin: Attacker Scans Target Database Management Tools</title><link>https://runtimerebel.com/blog/adminer-phpmyadmin-attacker-scans-target-database-management-tools</link><guid isPermaLink="true">https://runtimerebel.com/blog/adminer-phpmyadmin-attacker-scans-target-database-management-tools</guid><description>Runtime Rebel observes increased honeypot scans targeting Adminer and phpMyAdmin.</description><pubDate>Wed, 18 Mar 2026 16:32:57 GMT</pubDate><category>Adminer</category><category>phpMyAdmin</category><category>Database Management</category><category>Honeypot</category><category>Scanning</category><category>Reconnaissance</category></item><item><title>Analyzing Proxy Scanner Activity: Monitoring /proxy/ URI Patterns</title><link>https://runtimerebel.com/blog/analyzing-proxy-scanner-activity-monitoring-proxy-uri-patterns</link><guid isPermaLink="true">https://runtimerebel.com/blog/analyzing-proxy-scanner-activity-monitoring-proxy-uri-patterns</guid><description>Threat actors are shifting scanning patterns to identify open proxies using /proxy/ URI prefixes. Learn how to detect and mitigate these reconnaissance scans.</description><pubDate>Mon, 16 Mar 2026 16:31:05 GMT</pubDate><category>Proxy Scanning</category><category>Reconnaissance</category><category>Web Server Security</category><category>Honeypot Analysis</category><category>URI Patterns</category></item><item><title>CyberStrikeAI Exploitation: AI Tools Targeting Fortinet Firewalls</title><link>https://runtimerebel.com/blog/cyberstrikeai-exploitation-ai-tools-targeting-fortinet-firewalls</link><guid isPermaLink="true">https://runtimerebel.com/blog/cyberstrikeai-exploitation-ai-tools-targeting-fortinet-firewalls</guid><description>Threat actors are repurposing CyberStrikeAI to automate reconnaissance and exploit critical vulnerabilities in Fortinet FortiGate firewalls and edge devices.</description><pubDate>Tue, 03 Mar 2026 00:36:03 GMT</pubDate><category>CyberStrikeAI</category><category>Fortinet</category><category>CVE-2024-21762</category><category>AI Powered Attacks</category><category>Reconnaissance</category></item><item><title>Automated Reconnaissance Targeting React2Shell Implementations</title><link>https://runtimerebel.com/blog/automated-reconnaissance-targeting-react2shell-implementations</link><guid isPermaLink="true">https://runtimerebel.com/blog/automated-reconnaissance-targeting-react2shell-implementations</guid><description>Analysis of a specialized toolkit currently utilized by threat actors to identify and exploit React2Shell vulnerabilities within enterprise network perimeters.</description><pubDate>Mon, 23 Feb 2026 05:34:37 GMT</pubDate><category>Reconnaissance</category><category>React2Shell</category><category>RCE</category><category>Exploitation</category></item></channel></rss>