<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Vulnerabilities</title><description>Cybersecurity articles tagged #Vulnerabilities on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Nightmare Eclipse Releases HardBreacher Kaspersky Exploit</title><link>https://runtimerebel.com/blog/nightmare-eclipse-releases-hardbreacher-kaspersky-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/nightmare-eclipse-releases-hardbreacher-kaspersky-exploit</guid><description>Security researcher Nightmare Eclipse releases HardBreacher, a privilege escalation proof-of-concept targeting Kaspersky Endpoint Security.</description><pubDate>Tue, 01 Sep 2026 02:40:36 GMT</pubDate><category>Kaspersky Endpoint Security</category><category>Zero-Day</category><category>Privilege Escalation</category><category>Exploit</category><category>Vulnerabilities</category></item><item><title>AI-Powered PLC Attacks Target Critical Infrastructure</title><link>https://runtimerebel.com/blog/ai-powered-plc-attacks-target-critical-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-powered-plc-attacks-target-critical-infrastructure</guid><description>U.S. agencies warn that threat actors are using AI to target internet-exposed Siemens S7 Series PLCs in critical infrastructure sectors.</description><pubDate>Mon, 24 Aug 2026 16:24:49 GMT</pubDate><category>Siemens</category><category>Zero-Day</category><category>Ransomware</category><category>Supply Chain Attack</category><category>Vulnerabilities</category></item><item><title>TSN Protocols Vulnerabilities Threaten OT Security</title><link>https://runtimerebel.com/blog/tsn-protocols-vulnerabilities-threaten-ot-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/tsn-protocols-vulnerabilities-threaten-ot-security</guid><description>New research reveals how unprotected Time-Sensitive Networking protocols in industrial systems could allow attackers to disrupt physical processes.</description><pubDate>Sun, 23 Aug 2026 16:17:17 GMT</pubDate><category>OT Security</category><category>Industrial Control Systems</category><category>Network Security</category><category>Vulnerabilities</category></item><item><title>Cisco Patches Nine Crosswork and Secure Workload Flaws</title><link>https://runtimerebel.com/blog/cisco-patches-nine-crosswork-and-secure-workload-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-patches-nine-crosswork-and-secure-workload-flaws</guid><description>Cisco patches nine vulnerabilities in Crosswork and Secure Workload platforms, with five flaws scoring the maximum CVSS 10.0 severity rating.</description><pubDate>Sun, 23 Aug 2026 00:43:17 GMT</pubDate><category>Cisco</category><category>Vulnerabilities</category><category>Zero-Day</category><category>Network Security</category><category>Patch Management</category></item><item><title>Webmail CSS Injection: Hidden Data Exfiltration Threats</title><link>https://runtimerebel.com/blog/webmail-css-injection-hidden-data-exfiltration-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/webmail-css-injection-hidden-data-exfiltration-threats</guid><description>Security researchers warn that Cascading Style Sheets can exfiltrate sensitive data from webmail inboxes if vendors fail to sanitize styles.</description><pubDate>Mon, 10 Aug 2026 01:01:51 GMT</pubDate><category>Web Security</category><category>Data Exfiltration</category><category>Phishing</category><category>Vulnerabilities</category></item><item><title>Chrome 151 Update Patches 41 Critical, High-Severity Flaws</title><link>https://runtimerebel.com/blog/chrome-151-update-patches-41-critical-high-severity-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/chrome-151-update-patches-41-critical-high-severity-flaws</guid><description>Google&apos;s Chrome 151 update addresses 41 critical and high-severity vulnerabilities, including memory safety bugs potentially leading to RCE.</description><pubDate>Sun, 09 Aug 2026 16:24:44 GMT</pubDate><category>Google Chrome</category><category>Vulnerabilities</category><category>Memory Safety</category><category>Use After Free</category><category>Out of Bounds Write</category></item><item><title>Microsoft &amp; Apple Patch Critical RCEs and Auth Bypass Flaws</title><link>https://runtimerebel.com/blog/microsoft-apple-patch-critical-rces-and-auth-bypass-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-apple-patch-critical-rces-and-auth-bypass-flaws</guid><description>Microsoft released patches for critical-severity RCE and EoP flaws across Active Directory, Azure, and Teams. Apple fixed a Screen Sharing authentication bypass.</description><pubDate>Sun, 09 Aug 2026 08:32:17 GMT</pubDate><category>Microsoft</category><category>Apple</category><category>Vulnerabilities</category><category>RCE</category><category>Authentication Bypass</category></item><item><title>New CSS Attacks Break Webmail Interfaces to Steal Credentials</title><link>https://runtimerebel.com/blog/new-css-attacks-break-webmail-interfaces-to-steal-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/new-css-attacks-break-webmail-interfaces-to-steal-credentials</guid><description>PortSwigger researchers revealed new CSS and HTML techniques breaking webmail defenses in Outlook, Gmail, and Yahoo to capture tokens and passwords.</description><pubDate>Sun, 09 Aug 2026 00:57:22 GMT</pubDate><category>Webmail</category><category>CSS Injection</category><category>Vulnerabilities</category><category>Zero-Day</category><category>Credential Theft</category></item><item><title>CVE-2026-18577: Attackers Exploit N-able Patch Bypass</title><link>https://runtimerebel.com/blog/cve-2026-18577-attackers-exploit-n-able-patch-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-18577-attackers-exploit-n-able-patch-bypass</guid><description>Security teams face active exploitation of CVE-2026-18577, an N-able authentication bypass vulnerability granting administrator access.</description><pubDate>Tue, 04 Aug 2026 01:29:18 GMT</pubDate><category>CVE-2026-18577</category><category>N Able</category><category>Authentication Bypass</category><category>Remote Monitoring and Management</category><category>Vulnerabilities</category></item><item><title>AI-Generated Code Vulnerabilities: Framework Pairing is Key to Risk</title><link>https://runtimerebel.com/blog/ai-generated-code-vulnerabilities-framework-pairing-is-key-to-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-generated-code-vulnerabilities-framework-pairing-is-key-to-risk</guid><description>AI-generated code introduces an average of 15 vulnerabilities per codebase. This analysis explores how framework choices significantly influence the actual security risk.</description><pubDate>Tue, 21 Jul 2026 13:56:54 GMT</pubDate><category>AI Generated Code</category><category>Code Security</category><category>Application Security</category><category>Vulnerabilities</category><category>Developer Security</category><category>Secure Development</category></item><item><title>Microsoft Patch Tuesday: 9 Critical Flaws Among 137 Total Fixes</title><link>https://runtimerebel.com/blog/microsoft-patch-tuesday-9-critical-flaws-among-137-total-fixes</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-patch-tuesday-9-critical-flaws-among-137-total-fixes</guid><description>Microsoft&apos;s latest Patch Tuesday addresses 137 vulnerabilities, including 9 critical flaws. While no zero-days were reported, timely patching is essential.</description><pubDate>Wed, 13 May 2026 00:54:28 GMT</pubDate><category>Microsoft</category><category>Patch Tuesday</category><category>Vulnerabilities</category><category>Critical Vulnerabilities</category><category>Security Updates</category></item><item><title>Apple May 2024 Security Updates Address 84 Vulnerabilities</title><link>https://runtimerebel.com/blog/apple-may-2024-security-updates-address-84-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-may-2024-security-updates-address-84-vulnerabilities</guid><description>Apple&apos;s May 2024 security updates patch 84 vulnerabilities across iOS, macOS, watchOS, tvOS, and visionOS. Immediate patching is crucial for all users.</description><pubDate>Tue, 12 May 2026 00:50:06 GMT</pubDate><category>Apple</category><category>iOS</category><category>macOS</category><category>iPadOS</category><category>watchOS</category><category>tvOS</category><category>visionOS</category><category>Security Update</category><category>Vulnerabilities</category></item><item><title>Cisco FMC Zero-Day Exploited by Interlock Ransomware: March 2026 CVEs</title><link>https://runtimerebel.com/blog/cisco-fmc-zero-day-exploited-by-interlock-ransomware-march-2026-cves</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-fmc-zero-day-exploited-by-interlock-ransomware-march-2026-cves</guid><description>Runtime Rebel analyzes March 2026&apos;s significant rise in high-impact CVEs, including a Cisco FMC zero-day actively exploited by Interlock Ransomware.</description><pubDate>Tue, 14 Apr 2026 00:47:47 GMT</pubDate><category>Cisco FMC</category><category>Interlock Ransomware Group</category><category>Zero-Day</category><category>Vulnerabilities</category><category>March 2026</category></item><item><title>Apple Addresses 85 Vulnerabilities in Recent OS Updates</title><link>https://runtimerebel.com/blog/apple-addresses-85-vulnerabilities-in-recent-os-updates</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-addresses-85-vulnerabilities-in-recent-os-updates</guid><description>Apple released significant security updates patching 85 vulnerabilities across macOS, iOS, iPadOS, tvOS, watchOS, and visionOS, with no active exploitation reported.</description><pubDate>Thu, 26 Mar 2026 00:41:00 GMT</pubDate><category>Apple</category><category>macOS</category><category>iOS</category><category>iPadOS</category><category>tvOS</category><category>watchOS</category><category>visionOS</category><category>Security Update</category><category>Vulnerabilities</category><category>Patch Management</category></item><item><title>Adobe Security Update: 80 Vulnerabilities Across 8 Products Patched</title><link>https://runtimerebel.com/blog/adobe-security-update-80-vulnerabilities-across-8-products-patched</link><guid isPermaLink="true">https://runtimerebel.com/blog/adobe-security-update-80-vulnerabilities-across-8-products-patched</guid><description>Adobe&apos;s comprehensive security update addresses 80 vulnerabilities across 8 products, including Commerce, Acrobat Reader, and Premiere Pro. Immediate patching is vital.</description><pubDate>Tue, 10 Mar 2026 20:14:20 GMT</pubDate><category>Adobe</category><category>Vulnerabilities</category><category>Patches</category><category>Security Update</category><category>Adobe Commerce</category><category>Adobe Acrobat Reader</category><category>Adobe Illustrator</category><category>Adobe Premiere Pro</category></item><item><title>Microsoft Patch Tuesday: 83 Vulnerabilities, Critical Flaw Addressed</title><link>https://runtimerebel.com/blog/microsoft-patch-tuesday-83-vulnerabilities-critical-flaw-addressed</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-patch-tuesday-83-vulnerabilities-critical-flaw-addressed</guid><description>Microsoft&apos;s latest Patch Tuesday addresses 83 vulnerabilities across its product line, including one critical flaw. Security teams must prioritize immediate patching.</description><pubDate>Tue, 10 Mar 2026 20:13:59 GMT</pubDate><category>Microsoft</category><category>Patch Tuesday</category><category>Vulnerabilities</category><category>Security Updates</category><category>Critical Vulnerability</category></item></channel></rss>