<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Zero Click</title><description>Cybersecurity articles tagged #Zero Click on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CVE-2026-53413: Zoom Zero-Click RCE – Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-53413-zoom-zero-click-rce-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-53413-zoom-zero-click-rce-patch-now</guid><description>Zoom patches CVE-2026-53413, a critical zero-click RCE in its annotator function, affecting all clients. Immediate patching is advised.</description><pubDate>Tue, 11 Aug 2026 16:49:49 GMT</pubDate><category>Remote Code Execution</category><category>Zero Click</category><category>Memory Corruption</category><category>CVE-2026-53413</category><category>Zoom</category></item><item><title>AI Browsers Face &apos;PleaseFix&apos; Zero-Click Agent Hijacking</title><link>https://runtimerebel.com/blog/ai-browsers-face-pleasefix-zero-click-agent-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-browsers-face-pleasefix-zero-click-agent-hijacking</guid><description>Attackers can hijack AI browser agents via &apos;PleaseFix&apos; zero-click vulnerabilities, injecting malicious instructions through content poisoning. No simple fix exists.</description><pubDate>Sun, 09 Aug 2026 08:32:53 GMT</pubDate><category>AI Browsers</category><category>Zero Click</category><category>AI Security</category><category>Agent Hijacking</category><category>PleaseFix</category></item><item><title>CVE-2025-66376: APT28 Exploits Zimbra Zero-Click for Espionage</title><link>https://runtimerebel.com/blog/cve-2025-66376-apt28-exploits-zimbra-zero-click-for-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-66376-apt28-exploits-zimbra-zero-click-for-espionage</guid><description>Russian state-sponsored actors exploit a zero-click Zimbra vulnerability (CVE-2025-66376) to exfiltrate sensitive webmail data from targeted organizations.</description><pubDate>Sat, 08 Aug 2026 08:33:35 GMT</pubDate><category>CVE-2025-66376</category><category>Zimbra</category><category>Cyber Espionage</category><category>Zero Click</category><category>Phishing</category></item><item><title>Pixel 9 0-Click Sandbox Escape: BigWave UAF to Kernel R/W</title><link>https://runtimerebel.com/blog/pixel-9-0-click-sandbox-escape-bigwave-uaf-to-kernel-r-w</link><guid isPermaLink="true">https://runtimerebel.com/blog/pixel-9-0-click-sandbox-escape-bigwave-uaf-to-kernel-r-w</guid><description>A critical 0-click exploit chain targets Google Pixel 9 devices, leveraging a Use-After-Free in the BigWave driver for kernel arbitrary read/write.</description><pubDate>Sat, 08 Aug 2026 01:02:16 GMT</pubDate><category>Use After Free</category><category>Sandbox Escape</category><category>Zero Click</category><category>Pixel 9</category><category>BigWave Driver</category></item><item><title>Zimbra Zero-Click Exploitation by Russian APT for Email Theft</title><link>https://runtimerebel.com/blog/zimbra-zero-click-exploitation-by-russian-apt-for-email-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/zimbra-zero-click-exploitation-by-russian-apt-for-email-theft</guid><description>CISA warns of Russian APT Laundry Bear (Void Blizzard) exploiting a patched Zimbra zero-click flaw combined with phishing to compromise email servers for data…</description><pubDate>Thu, 23 Jul 2026 17:27:19 GMT</pubDate><category>Laundry Bear</category><category>Void Blizzard</category><category>APT28</category><category>Zimbra Collaboration</category><category>Zero Click</category><category>Email Theft</category><category>Phishing</category><category>Russian APT</category></item><item><title>Pixel 10 0-Click Exploit Chain: Re-Targeting CVE-2025-54957 for Root</title><link>https://runtimerebel.com/blog/pixel-10-0-click-exploit-chain-re-targeting-cve-2025-54957-for-root</link><guid isPermaLink="true">https://runtimerebel.com/blog/pixel-10-0-click-exploit-chain-re-targeting-cve-2025-54957-for-root</guid><description>Analysis of a zero-click exploit chain targeting the Google Pixel 10, achieving root via an adapted Dolby vulnerability (CVE-2025-54957). Critical threat. Patch now.</description><pubDate>Wed, 13 May 2026 20:40:26 GMT</pubDate><category>Pixel 10</category><category>Android</category><category>Zero Click</category><category>CVE-2025-54957</category><category>Exploit Chain</category><category>RET PAC</category><category>Root Exploit</category></item><item><title>Android CVE-2026-0073: Critical System RCE Patch Guidance</title><link>https://runtimerebel.com/blog/android-cve-2026-0073-critical-system-rce-patch-guidance</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-cve-2026-0073-critical-system-rce-patch-guidance</guid><description>Google addresses a critical zero-click RCE vulnerability (CVE-2026-0073) in the Android System component. Learn how to mitigate this high-impact security flaw.</description><pubDate>Tue, 05 May 2026 12:37:20 GMT</pubDate><category>CVE-2026-0073</category><category>Android</category><category>RCE</category><category>Zero Click</category><category>Google</category></item><item><title>APT28 Exploits Incomplete Windows Patch: Zero-Click Attacks Persist</title><link>https://runtimerebel.com/blog/apt28-exploits-incomplete-windows-patch-zero-click-attacks-persist</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-exploits-incomplete-windows-patch-zero-click-attacks-persist</guid><description>An incomplete Windows patch leaves systems vulnerable to zero-click attacks. Russia-linked APT28 exploited this against Ukraine and EU. Learn how to defend.</description><pubDate>Mon, 27 Apr 2026 16:40:47 GMT</pubDate><category>Windows</category><category>Zero Click</category><category>APT28</category><category>Patch Bypass</category><category>Vulnerability</category><category>Microsoft</category><category>Cyber Warfare</category></item><item><title>Apple DarkSword Protection Expands: Mitigating CVE-2023-38604 Zero-Click Exploits</title><link>https://runtimerebel.com/blog/apple-darksword-protection-expands-mitigating-cve-2023-38604-zero-click-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-darksword-protection-expands-mitigating-cve-2023-38604-zero-click-exploits</guid><description>Apple expands DarkSword exploit protection to all users, enhancing defenses against state-sponsored and commercial zero-click attacks like CVE-2023-38604.</description><pubDate>Thu, 02 Apr 2026 16:27:21 GMT</pubDate><category>Apple</category><category>DarkSword</category><category>CVE-2023-38604</category><category>Zero Click</category><category>Exploit Kit</category><category>State Sponsored</category><category>Commercial Spyware</category><category>iOS</category><category>macOS</category><category>iPadOS</category><category>watchOS</category><category>tvOS</category></item><item><title>Mail2Shell Zero-Click RCE Threatens FreeScout Servers</title><link>https://runtimerebel.com/blog/mail2shell-zero-click-rce-threatens-freescout-servers</link><guid isPermaLink="true">https://runtimerebel.com/blog/mail2shell-zero-click-rce-threatens-freescout-servers</guid><description>A critical Mail2Shell zero-click vulnerability in FreeScout helpdesk allows unauthenticated remote code execution, granting full server control.</description><pubDate>Thu, 05 Mar 2026 00:35:37 GMT</pubDate><category>Mail2Shell</category><category>FreeScout</category><category>Zero Click</category><category>RCE</category><category>Helpdesk</category><category>Mail Server</category></item></channel></rss>