<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Web Security</title><description>Cybersecurity articles tagged #Web Security on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Webmail CSS Injection: Hidden Data Exfiltration Threats</title><link>https://runtimerebel.com/blog/webmail-css-injection-hidden-data-exfiltration-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/webmail-css-injection-hidden-data-exfiltration-threats</guid><description>Security researchers warn that Cascading Style Sheets can exfiltrate sensitive data from webmail inboxes if vendors fail to sanitize styles.</description><pubDate>Mon, 10 Aug 2026 01:01:51 GMT</pubDate><category>Web Security</category><category>Data Exfiltration</category><category>Phishing</category><category>Vulnerabilities</category></item><item><title>CVE-2026-64638: WordPress Pre-Auth XSS Leads to PHP RCE</title><link>https://runtimerebel.com/blog/cve-2026-64638-wordpress-pre-auth-xss-leads-to-php-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-64638-wordpress-pre-auth-xss-leads-to-php-rce</guid><description>A pre-authentication reflected XSS (CVE-2026-64638) in WordPress can be chained for PHP code execution. Patch immediately.</description><pubDate>Fri, 07 Aug 2026 16:42:22 GMT</pubDate><category>WordPress</category><category>XSS</category><category>RCE</category><category>Web Security</category><category>CVE-2026-64638</category></item><item><title>NodeBB 4.14.2 Release Patches Eight AI-Discovered Vulnerabilities</title><link>https://runtimerebel.com/blog/nodebb-4-14-2-release-patches-eight-ai-discovered-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/nodebb-4-14-2-release-patches-eight-ai-discovered-vulnerabilities</guid><description>NodeBB patches eight high-severity vulnerabilities discovered by AI, preventing unauthorized admin access and private chat exposure in versions before 4.14.0.</description><pubDate>Fri, 24 Jul 2026 10:19:56 GMT</pubDate><category>Nodebb</category><category>AI Security</category><category>Aikido Security</category><category>Web Security</category><category>Access Control</category></item><item><title>WP2Shell: WordPress RCE via Chained CVE-2026-60137 &amp; CVE-2026-63030</title><link>https://runtimerebel.com/blog/wp2shell-wordpress-rce-via-chained-cve-2026-60137-cve-2026-63030</link><guid isPermaLink="true">https://runtimerebel.com/blog/wp2shell-wordpress-rce-via-chained-cve-2026-60137-cve-2026-63030</guid><description>WP2Shell exploits CVE-2026-60137 and CVE-2026-63030 to achieve remote takeover on millions of WordPress sites. Immediate patching is critical.</description><pubDate>Tue, 21 Jul 2026 02:54:17 GMT</pubDate><category>Wp2shell</category><category>WordPress</category><category>RCE</category><category>CVE-2026-60137</category><category>CVE-2026-63030</category><category>Web Security</category></item><item><title>Isira Adithya: Research Insights and Bug Bounty Defense Strategies</title><link>https://runtimerebel.com/blog/isira-adithya-research-insights-and-bug-bounty-defense-strategies</link><guid isPermaLink="true">https://runtimerebel.com/blog/isira-adithya-research-insights-and-bug-bounty-defense-strategies</guid><description>Examine the methodologies of security researcher Isira Adithya and how ethical hacker insights improve vulnerability management and web application security.</description><pubDate>Wed, 17 Jun 2026 05:47:05 GMT</pubDate><category>Ethical Hacking</category><category>Bug Bounty</category><category>Vulnerability Research</category><category>Web Security</category></item><item><title>Framing Protection Trends: Defending Against Clickjacking</title><link>https://runtimerebel.com/blog/framing-protection-trends-defending-against-clickjacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/framing-protection-trends-defending-against-clickjacking</guid><description>Analyze the 3-year adoption trends of X-Frame-Options and CSP frame-ancestors across 1 million domains to improve your clickjacking defense strategy.</description><pubDate>Thu, 11 Jun 2026 09:47:19 GMT</pubDate><category>X Frame Options</category><category>Content Security Policy</category><category>Clickjacking</category><category>Web Security</category><category>Tranco List</category></item><item><title>Ghost CMS CVE-2022-41654: Over 700 Websites Compromised</title><link>https://runtimerebel.com/blog/ghost-cms-cve-2022-41654-over-700-websites-compromised</link><guid isPermaLink="true">https://runtimerebel.com/blog/ghost-cms-cve-2022-41654-over-700-websites-compromised</guid><description>Attackers are exploiting a critical Ghost CMS vulnerability to inject malicious scripts into sites belonging to Harvard, Oxford, and DuckDuckGo.</description><pubDate>Mon, 25 May 2026 16:50:54 GMT</pubDate><category>Ghost CMS</category><category>CVE-2022-41654</category><category>Active Exploitation</category><category>Web Security</category></item><item><title>Typosquatting Evolution: How AI Lookalike Domains Target Supply Chains</title><link>https://runtimerebel.com/blog/typosquatting-evolution-how-ai-lookalike-domains-target-supply-chains</link><guid isPermaLink="true">https://runtimerebel.com/blog/typosquatting-evolution-how-ai-lookalike-domains-target-supply-chains</guid><description>Attackers are weaponizing AI-generated lookalike domains within third-party scripts, turning typosquatting into a sophisticated supply chain threat for enterprises.</description><pubDate>Wed, 20 May 2026 13:00:44 GMT</pubDate><category>Typosquatting</category><category>Third Party Risk</category><category>AI Threats</category><category>Web Security</category></item><item><title>CVE-2024-7109: Burst Statistics WordPress Plugin Auth Bypass Exploited</title><link>https://runtimerebel.com/blog/cve-2024-7109-burst-statistics-wordpress-plugin-auth-bypass-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-7109-burst-statistics-wordpress-plugin-auth-bypass-exploited</guid><description>Hackers are actively exploiting CVE-2024-7109, a critical authentication bypass in Burst Statistics WordPress plugin, to gain admin access. Patch immediately.</description><pubDate>Fri, 15 May 2026 00:52:51 GMT</pubDate><category>Burst Statistics</category><category>WordPress</category><category>Authentication Bypass</category><category>Plugin Vulnerability</category><category>Web Security</category><category>CVE-2024-7109</category></item><item><title>Bot Mitigation with CAPTCHAs: Understanding Cloudflare Turnstile</title><link>https://runtimerebel.com/blog/bot-mitigation-with-captchas-understanding-cloudflare-turnstile</link><guid isPermaLink="true">https://runtimerebel.com/blog/bot-mitigation-with-captchas-understanding-cloudflare-turnstile</guid><description>Understand how Cloudflare Turnstile and other CAPTCHAs mitigate bot traffic, improve web performance, and enhance security against automated attacks.</description><pubDate>Mon, 11 May 2026 17:02:53 GMT</pubDate><category>Bot Mitigation</category><category>CAPTCHA</category><category>Cloudflare Turnstile</category><category>Web Security</category><category>Automated Attacks</category><category>DDoS</category></item><item><title>X-Vercel-Set-Bypass-Cookie Header: Honeypot Observations &amp; Implications</title><link>https://runtimerebel.com/blog/x-vercel-set-bypass-cookie-header-honeypot-observations-implications</link><guid isPermaLink="true">https://runtimerebel.com/blog/x-vercel-set-bypass-cookie-header-honeypot-observations-implications</guid><description>Runtime Rebel analyzes recent honeypot observations of HTTP requests using the `X-Vercel-Set-Bypass-Cookie` header, discussing potential implications for Vercel users…</description><pubDate>Tue, 28 Apr 2026 16:46:36 GMT</pubDate><category>Vercel</category><category>Honeypot</category><category>HTTP Headers</category><category>Web Security</category><category>Caching Bypass</category></item><item><title>Google DeepMind Research: Six Web Attack Vectors Against AI Agents</title><link>https://runtimerebel.com/blog/google-deepmind-research-six-web-attack-vectors-against-ai-agents</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-deepmind-research-six-web-attack-vectors-against-ai-agents</guid><description>DeepMind researchers reveal how malicious web content can manipulate AI agents, highlighting risks like indirect prompt injection and data exfiltration.</description><pubDate>Mon, 06 Apr 2026 16:22:06 GMT</pubDate><category>Google Deepmind</category><category>AI Agents</category><category>Indirect Prompt Injection</category><category>Web Security</category><category>LLM Security</category></item><item><title>Apache Struts 2.5.33 Patch Guidance: Mitigating CVE-2023-50164 RCE</title><link>https://runtimerebel.com/blog/apache-struts-2-5-33-patch-guidance-mitigating-cve-2023-50164-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/apache-struts-2-5-33-patch-guidance-mitigating-cve-2023-50164-rce</guid><description>Technical analysis of CVE-2023-50164, a critical RCE vulnerability in Apache Struts. Learn how to detect exploits and secure your file upload implementations.</description><pubDate>Tue, 31 Mar 2026 04:53:12 GMT</pubDate><category>CVE-2023-50164</category><category>Apache Struts</category><category>RCE</category><category>File Upload Vulnerability</category><category>Web Security</category></item><item><title>PHP 8.1 End-of-Life: Security Risks and Upgrade Path Analysis</title><link>https://runtimerebel.com/blog/php-8-1-end-of-life-security-risks-and-upgrade-path-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/php-8-1-end-of-life-security-risks-and-upgrade-path-analysis</guid><description>PHP 8.1 has reached its end-of-life status. Learn about the security implications of running unsupported software and the technical steps for remediation.</description><pubDate>Mon, 23 Mar 2026 04:48:54 GMT</pubDate><category>PHP</category><category>End of Life</category><category>Software Lifecycle</category><category>Web Security</category></item><item><title>Compromised Site Management Panels: A Commoditized Cybercrime Threat</title><link>https://runtimerebel.com/blog/compromised-site-management-panels-a-commoditized-cybercrime-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/compromised-site-management-panels-a-commoditized-cybercrime-threat</guid><description>Underground markets commoditize compromised cPanel and other site management panels, fueling phishing and scam infrastructure. Learn to secure web admin interfaces.</description><pubDate>Tue, 03 Mar 2026 16:23:08 GMT</pubDate><category>cPanel</category><category>Web Hosting</category><category>Phishing</category><category>Scams</category><category>Credential Theft</category><category>Cybercrime Markets</category><category>Web Security</category></item><item><title>Open Redirects: Overlooked Vulnerability Impact &amp; Analysis</title><link>https://runtimerebel.com/blog/open-redirects-overlooked-vulnerability-impact-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/open-redirects-overlooked-vulnerability-impact-analysis</guid><description>An analysis of open redirect vulnerabilities, their historical context in OWASP, common exploitation vectors like phishing, and essential mitigation strategies.</description><pubDate>Wed, 25 Feb 2026 04:46:43 GMT</pubDate><category>Open Redirect</category><category>OWASP</category><category>Phishing</category><category>Web Security</category><category>Vulnerability</category></item></channel></rss>