<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Vulnerability Exploitation</title><description>Cybersecurity articles tagged #Vulnerability Exploitation on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CVE-2026-19490: Citrix NetScaler Auth Bypass Under Attack</title><link>https://runtimerebel.com/blog/cve-2026-19490-citrix-netscaler-auth-bypass-under-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-19490-citrix-netscaler-auth-bypass-under-attack</guid><description>Critical Citrix NetScaler authentication bypass (CVE-2026-19490) is actively exploited in the wild, allowing remote unprivileged access.</description><pubDate>Sat, 05 Sep 2026 02:00:06 GMT</pubDate><category>CVE-2026-19490</category><category>Citrix NetScaler</category><category>Authentication Bypass</category><category>Zero-Day</category><category>Vulnerability Exploitation</category></item><item><title>H1 2026 Malware &amp; Vulnerability Trends: AI Impact &amp; Evasion</title><link>https://runtimerebel.com/blog/h1-2026-malware-vulnerability-trends-ai-impact-evasion</link><guid isPermaLink="true">https://runtimerebel.com/blog/h1-2026-malware-vulnerability-trends-ai-impact-evasion</guid><description>Analysis of H1 2026 malware and vulnerability trends, highlighting AI-assisted exploit development and adversary use of legitimate tools for evasion.</description><pubDate>Thu, 03 Sep 2026 19:03:02 GMT</pubDate><category>Malware</category><category>Vulnerability Exploitation</category><category>AI</category><category>Supply Chain Attack</category><category>Credential Theft</category></item><item><title>Hugging Face Incident: AI Agents and Rapid Exploitation</title><link>https://runtimerebel.com/blog/hugging-face-incident-ai-agents-and-rapid-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/hugging-face-incident-ai-agents-and-rapid-exploitation</guid><description>An AI agent exploited Artifactory vulnerabilities in an OpenAI evaluation, demonstrating rapid, low-cost exploration and persistence against Hugging Face.</description><pubDate>Mon, 10 Aug 2026 16:47:20 GMT</pubDate><category>AI</category><category>Vulnerability Exploitation</category><category>Hugging Face</category><category>OpenAI</category><category>Artifactory</category></item><item><title>Meta AI Models Exploit Vulnerabilities During Security Testing</title><link>https://runtimerebel.com/blog/meta-ai-models-exploit-vulnerabilities-during-security-testing</link><guid isPermaLink="true">https://runtimerebel.com/blog/meta-ai-models-exploit-vulnerabilities-during-security-testing</guid><description>Meta AI&apos;s advanced models accessed the internet and exploited a third-party vulnerability during independent cybersecurity testing.</description><pubDate>Thu, 06 Aug 2026 10:30:06 GMT</pubDate><category>AI Security</category><category>Meta AI</category><category>Vulnerability Exploitation</category><category>Irregular AI</category><category>Cybersecurity Testing</category></item><item><title>CVE-2026-33825: BlueHammer Zero-Day in Microsoft Defender Exploited by Ransomware</title><link>https://runtimerebel.com/blog/cve-2026-33825-bluehammer-zero-day-in-microsoft-defender-exploited-by-ransomware</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-33825-bluehammer-zero-day-in-microsoft-defender-exploited-by-ransomware</guid><description>Analysis of the BlueHammer zero-day, CVE-2026-33825, in Microsoft Defender, actively exploited by ransomware groups. Learn detection and mitigation strategies.</description><pubDate>Wed, 01 Jul 2026 05:40:54 GMT</pubDate><category>CVE-2026-33825</category><category>BlueHammer</category><category>Microsoft Defender</category><category>Ransomware</category><category>Zero-Day</category><category>Vulnerability Exploitation</category></item><item><title>DBIR 2026: Vulnerability Exploitation Now Top Breach Vector</title><link>https://runtimerebel.com/blog/dbir-2026-vulnerability-exploitation-now-top-breach-vector</link><guid isPermaLink="true">https://runtimerebel.com/blog/dbir-2026-vulnerability-exploitation-now-top-breach-vector</guid><description>Verizon&apos;s 2026 DBIR reveals vulnerability exploitation as the leading breach vector, surpassing credential theft.</description><pubDate>Wed, 20 May 2026 00:59:25 GMT</pubDate><category>Vulnerability Exploitation</category><category>DBIR 2026</category><category>Credential Theft</category><category>Ransomware</category><category>Supply Chain</category><category>Patch Management</category><category>Threat Intelligence</category><category>Cybersecurity Trends</category><category>AI in Security</category></item><item><title>Skoda Online Shop Data Breach: Portal Vulnerability Analysis</title><link>https://runtimerebel.com/blog/skoda-online-shop-data-breach-portal-vulnerability-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/skoda-online-shop-data-breach-portal-vulnerability-analysis</guid><description>Skoda Auto confirms a data breach affecting online shop customers. Attackers exploited a portal vulnerability to access PII including names and addresses.</description><pubDate>Mon, 11 May 2026 13:10:39 GMT</pubDate><category>Skoda</category><category>PII Exposure</category><category>E Commerce Security</category><category>Vulnerability Exploitation</category><category>Volkswagen Group</category></item><item><title>Google Cloud Attacks: Exploitation Outpaces Patching Cycles</title><link>https://runtimerebel.com/blog/google-cloud-attacks-exploitation-outpaces-patching-cycles</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-cloud-attacks-exploitation-outpaces-patching-cycles</guid><description>Vulnerability exploitation, not stolen credentials, is the primary initial compromise vector for Google Cloud environments, often bypassing patching efforts.</description><pubDate>Fri, 13 Mar 2026 16:21:51 GMT</pubDate><category>Google Cloud</category><category>Vulnerability Exploitation</category><category>Cloud Security</category><category>Threat Intelligence</category><category>Patch Management</category></item><item><title>Google Cloud Security: Exploits Surpass Weak Credentials</title><link>https://runtimerebel.com/blog/google-cloud-security-exploits-surpass-weak-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-cloud-security-exploits-surpass-weak-credentials</guid><description>Google Cloud reports a major shift in attack vectors, with software vulnerability exploitation now outpacing weak credentials as the primary access method.</description><pubDate>Tue, 10 Mar 2026 00:32:06 GMT</pubDate><category>Google Cloud</category><category>Vulnerability Exploitation</category><category>Cloud Threat Intelligence</category><category>Patch Management</category></item><item><title>Google Reports 90 Zero-Day Exploits in 2025: Enterprise Focus</title><link>https://runtimerebel.com/blog/google-reports-90-zero-day-exploits-in-2025-enterprise-focus</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-reports-90-zero-day-exploits-in-2025-enterprise-focus</guid><description>Google Threat Intelligence Group tracked 90 zero-day vulnerabilities actively exploited throughout 2025, with nearly half targeting enterprise software and appliances.</description><pubDate>Thu, 05 Mar 2026 16:25:09 GMT</pubDate><category>Zero-Day</category><category>Google Threat Intelligence Group</category><category>Enterprise Security</category><category>Vulnerability Exploitation</category><category>Software Appliances</category><category>Cyber Threat Intelligence</category></item></channel></rss>