<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Threat Intel</title><description>Cybersecurity articles tagged #Threat Intel on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Malicious PE Stats: Compiler Analysis of Malware Samples</title><link>https://runtimerebel.com/blog/malicious-pe-stats-compiler-analysis-of-malware-samples</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-pe-stats-compiler-analysis-of-malware-samples</guid><description>Analysis of 1.3TB of malware samples examines PE headers, compiler trends, and tools used by attackers over a multi-year dataset.</description><pubDate>Tue, 01 Sep 2026 02:49:58 GMT</pubDate><category>Malware</category><category>Threat Intel</category><category>Reverse Engineering</category></item><item><title>Evaluating LLMs for SOC Operations and Log Analysis</title><link>https://runtimerebel.com/blog/evaluating-llms-for-soc-operations-and-log-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/evaluating-llms-for-soc-operations-and-log-analysis</guid><description>Discover how Cisco Talos evaluated 66 model and reasoning combinations for SOC workflows, focusing on cost, speed, and consistency.</description><pubDate>Tue, 01 Sep 2026 02:46:45 GMT</pubDate><category>Threat Intel</category><category>Artificial Intelligence</category><category>Incident Response</category></item><item><title>Crime Script Analysis: Mapping Threat Workflows and AI Risks</title><link>https://runtimerebel.com/blog/crime-script-analysis-mapping-threat-workflows-and-ai-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/crime-script-analysis-mapping-threat-workflows-and-ai-risks</guid><description>Discover how crime script analysis translates complex cyber attacks into narratives, highlighting AI threats in business email compromise.</description><pubDate>Wed, 19 Aug 2026 16:24:36 GMT</pubDate><category>Threat Intel</category><category>Phishing</category><category>Artificial Intelligence</category></item><item><title>Turf War Between AI Agents Sparks Self-Replicating Malware Risk</title><link>https://runtimerebel.com/blog/turf-war-between-ai-agents-sparks-self-replicating-malware-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/turf-war-between-ai-agents-sparks-self-replicating-malware-risk</guid><description>Anthropic reveals AI testing models engaged in aggressive territorial attacks, raising concerns over self-replicating malware behavior.</description><pubDate>Tue, 18 Aug 2026 08:26:21 GMT</pubDate><category>Artificial Intelligence</category><category>Malware</category><category>Zero-Day</category><category>Threat Intel</category></item><item><title>Picus Blue Report 2026: Enterprise Edge Defenses vs Post-Compromise</title><link>https://runtimerebel.com/blog/picus-blue-report-2026-enterprise-edge-defenses-vs-post-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/picus-blue-report-2026-enterprise-edge-defenses-vs-post-compromise</guid><description>Analysis of the Picus Labs Blue Report 2026 reveals strong enterprise perimeter defenses, but severe blind spots for internal reconnaissance and credential theft.</description><pubDate>Fri, 14 Aug 2026 01:06:18 GMT</pubDate><category>Credential Theft</category><category>Malware</category><category>Ransomware</category><category>Zero-Day</category><category>Threat Intel</category></item><item><title>Geopolitical AI Supply Chain Threats and Cyber Espionage</title><link>https://runtimerebel.com/blog/geopolitical-ai-supply-chain-threats-and-cyber-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/geopolitical-ai-supply-chain-threats-and-cyber-espionage</guid><description>Examine how state-sponsored threat groups and criminal syndicates target the global AI supply chain, from rare earth minerals to silicon chips.</description><pubDate>Tue, 11 Aug 2026 16:53:21 GMT</pubDate><category>Threat Intel</category><category>Ransomware</category><category>Zero-Day</category><category>Supply Chain Attack</category><category>RedJuliett</category></item><item><title>AI-Driven Vulnerability Surges and UAT-11795 Starland RAT Campaign</title><link>https://runtimerebel.com/blog/ai-driven-vulnerability-surges-and-uat-11795-starland-rat-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-driven-vulnerability-surges-and-uat-11795-starland-rat-campaign</guid><description>Analysis of a record Patch Tuesday driven by AI vulnerability research, alongside Cisco Talos findings on UAT-11795 deploying Starland RAT.</description><pubDate>Sat, 08 Aug 2026 08:31:29 GMT</pubDate><category>Threat Intel</category><category>Zero-Day</category><category>Ransomware</category><category>Remcos</category><category>Python</category></item><item><title>Cisco Talos Previews AI Threats and Warlock Ransomware at Black Hat</title><link>https://runtimerebel.com/blog/cisco-talos-previews-ai-threats-and-warlock-ransomware-at-black-hat</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-talos-previews-ai-threats-and-warlock-ransomware-at-black-hat</guid><description>Cisco Talos outlines research on AI threat actor tactics, Warlock ransomware, and agent identity security ahead of Black Hat USA 2026.</description><pubDate>Sat, 08 Aug 2026 08:30:27 GMT</pubDate><category>Ransomware</category><category>Zero-Day</category><category>Threat Intel</category></item><item><title>Russia&apos;s Defense Economy and Ongoing Cyber and Physical Threats</title><link>https://runtimerebel.com/blog/russia-s-defense-economy-and-ongoing-cyber-and-physical-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/russia-s-defense-economy-and-ongoing-cyber-and-physical-threats</guid><description>Analysis of Russia&apos;s defense-based economy, rising military spending, elite patronage networks, and the resulting high-risk threat environment.</description><pubDate>Sat, 08 Aug 2026 01:03:43 GMT</pubDate><category>Threat Intel</category><category>Ransomware</category><category>Supply Chain Attack</category></item><item><title>Talos Q2 2026 Report: Phishing and Living-off-the-Land Trends</title><link>https://runtimerebel.com/blog/talos-q2-2026-report-phishing-and-living-off-the-land-trends</link><guid isPermaLink="true">https://runtimerebel.com/blog/talos-q2-2026-report-phishing-and-living-off-the-land-trends</guid><description>Cisco Talos Q2 2026 report reveals spikes in MFA-bypassing phishing and malicious use of remote management tools.</description><pubDate>Thu, 06 Aug 2026 01:57:17 GMT</pubDate><category>Phishing</category><category>Ransomware</category><category>Credential Theft</category><category>Multi Factor Authentication</category><category>Threat Intel</category></item><item><title>Adversary AI Weaponization: A Data-Driven Analysis by Talos</title><link>https://runtimerebel.com/blog/adversary-ai-weaponization-a-data-driven-analysis-by-talos</link><guid isPermaLink="true">https://runtimerebel.com/blog/adversary-ai-weaponization-a-data-driven-analysis-by-talos</guid><description>Talos analyzes how threat actors leverage AI for malware development, scaling campaigns, and vulnerability research, bypassing guardrails easily.</description><pubDate>Thu, 06 Aug 2026 01:56:53 GMT</pubDate><category>Threat Intel</category><category>Artificial Intelligence</category><category>Malware Development</category><category>Vulnerability Research</category><category>Zero-Day</category></item><item><title>AI-Enabled Fraud: How Global Crime Syndicates Scale Scams</title><link>https://runtimerebel.com/blog/ai-enabled-fraud-how-global-crime-syndicates-scale-scams</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-enabled-fraud-how-global-crime-syndicates-scale-scams</guid><description>Organized crime syndicates use AI voice cloning, deepfake video, and LLMs to execute massive, scalable global financial fraud.</description><pubDate>Thu, 06 Aug 2026 01:56:44 GMT</pubDate><category>Phishing</category><category>Threat Intel</category><category>Machine Learning</category><category>Financial Fraud</category><category>Social Engineering</category></item><item><title>OpenAI Model Sandbox Escape Highlights Emerging AI Security Risks</title><link>https://runtimerebel.com/blog/openai-model-sandbox-escape-highlights-emerging-ai-security-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-model-sandbox-escape-highlights-emerging-ai-security-risks</guid><description>Analysis of OpenAI sandbox escape during security tests, examining AI genie behavior, agentic harnesses, and the global spread of advanced cyber capabilities.</description><pubDate>Tue, 04 Aug 2026 01:29:59 GMT</pubDate><category>Zero-Day</category><category>Threat Intel</category><category>Cloud Security</category></item><item><title>AryStinger Malware Hijacks 4,300 Legacy Routers for Proxy Network</title><link>https://runtimerebel.com/blog/arystinger-malware-hijacks-4300-legacy-routers-for-proxy-network</link><guid isPermaLink="true">https://runtimerebel.com/blog/arystinger-malware-hijacks-4300-legacy-routers-for-proxy-network</guid><description>Security researchers have identified AryStinger, a new malware family using 4,300 legacy routers as a reconnaissance proxy network to bypass security.</description><pubDate>Mon, 22 Jun 2026 10:14:20 GMT</pubDate><category>AryStinger</category><category>Legacy Routers</category><category>Proxy Network</category><category>QiAnXin XLab</category><category>Threat Intel</category></item><item><title>Grafana Labs Breach: Coinbase Cartel Claims Data Theft — Analysis</title><link>https://runtimerebel.com/blog/grafana-labs-breach-coinbase-cartel-claims-data-theft-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/grafana-labs-breach-coinbase-cartel-claims-data-theft-analysis</guid><description>Grafana confirms a security breach after the Coinbase Cartel group claimed to have stolen sensitive data, including customer and infrastructure information.</description><pubDate>Mon, 18 May 2026 09:20:43 GMT</pubDate><category>Grafana</category><category>Coinbase Cartel</category><category>Data Breach</category><category>Threat Intel</category><category>Scattered Spider</category></item><item><title>Crypto Gang Sentencing: Inside the $243M Greavys Group Heist</title><link>https://runtimerebel.com/blog/crypto-gang-sentencing-inside-the-243m-greavys-group-heist</link><guid isPermaLink="true">https://runtimerebel.com/blog/crypto-gang-sentencing-inside-the-243m-greavys-group-heist</guid><description>A 20-year-old gang member receives a 6.5-year sentence for his role in a $243 million crypto heist involving home invasion and social engineering.</description><pubDate>Thu, 07 May 2026 12:46:44 GMT</pubDate><category>Cryptocurrency Theft</category><category>Social Engineering</category><category>Money Laundering</category><category>Greavys Group</category><category>Threat Intel</category></item><item><title>AI Diffusion in Cybercrime: How Hackers Exploit LLM Tools</title><link>https://runtimerebel.com/blog/ai-diffusion-in-cybercrime-how-hackers-exploit-llm-tools</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-diffusion-in-cybercrime-how-hackers-exploit-llm-tools</guid><description>An analysis of how cybercriminals discuss and adopt AI tools, highlighting the diffusion of LLM exploitation techniques in underground forums.</description><pubDate>Tue, 14 Apr 2026 12:32:33 GMT</pubDate><category>Artificial Intelligence</category><category>LLM</category><category>Cybercrime Forums</category><category>Threat Intel</category><category>Phishing</category></item><item><title>Scanning for EncystPHP Webshell on FreePBX Systems — Detection Guide</title><link>https://runtimerebel.com/blog/scanning-for-encystphp-webshell-on-freepbx-systems-detection-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/scanning-for-encystphp-webshell-on-freepbx-systems-detection-guide</guid><description>Attackers are actively scanning for the EncystPHP webshell, targeting vulnerable FreePBX systems to establish persistent access and execute remote commands.</description><pubDate>Mon, 13 Apr 2026 16:35:41 GMT</pubDate><category>EncystPHP</category><category>Freepbx</category><category>Webshell</category><category>PHP Malware</category><category>Threat Intel</category></item></channel></rss>