<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Zero-Day</title><description>Cybersecurity articles tagged #Zero-Day on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Google, Anthropic, and OpenAI Launch Cyber AI Models and Safeguards</title><link>https://runtimerebel.com/blog/google-anthropic-and-openai-launch-cyber-ai-models-and-safeguards</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-anthropic-and-openai-launch-cyber-ai-models-and-safeguards</guid><description>Google, Anthropic, and OpenAI unveil advanced cybersecurity AI models like Gemini 3.8 Flash Cyber, focusing on defense and strict access controls.</description><pubDate>Thu, 03 Sep 2026 02:04:27 GMT</pubDate><category>Google</category><category>Anthropic</category><category>OpenAI</category><category>Artificial Intelligence</category><category>Zero-Day</category></item><item><title>Threat Actors Prefer Repeatable Playbooks Over Novel Exploits</title><link>https://runtimerebel.com/blog/threat-actors-prefer-repeatable-playbooks-over-novel-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/threat-actors-prefer-repeatable-playbooks-over-novel-exploits</guid><description>Analysis of modern cyberattacks reveals threat actors increasingly favour scalable, repeatable playbooks over novel exploit development.</description><pubDate>Tue, 01 Sep 2026 12:54:04 GMT</pubDate><category>Ransomware</category><category>Zero-Day</category><category>Phishing</category><category>Credential Theft</category><category>Malware</category></item><item><title>CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Exploit</title><link>https://runtimerebel.com/blog/cve-2026-82078-papercut-ng-mf-unsafe-reflection-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-82078-papercut-ng-mf-unsafe-reflection-exploit</guid><description>CISA adds CVE-2026-82078 in PaperCut NG/MF to its KEV catalog following active exploitation. Review technical details and patch now.</description><pubDate>Tue, 01 Sep 2026 02:54:42 GMT</pubDate><category>CVE-2026-82078</category><category>PaperCut</category><category>Unsafe Reflection</category><category>Active Exploitation</category><category>Zero-Day</category></item><item><title>Nightmare Eclipse Releases HardBreacher Kaspersky Exploit</title><link>https://runtimerebel.com/blog/nightmare-eclipse-releases-hardbreacher-kaspersky-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/nightmare-eclipse-releases-hardbreacher-kaspersky-exploit</guid><description>Security researcher Nightmare Eclipse releases HardBreacher, a privilege escalation proof-of-concept targeting Kaspersky Endpoint Security.</description><pubDate>Tue, 01 Sep 2026 02:40:36 GMT</pubDate><category>Kaspersky Endpoint Security</category><category>Zero-Day</category><category>Privilege Escalation</category><category>Exploit</category><category>Vulnerabilities</category></item><item><title>CVE-2026-21962: Oracle WebLogic RCE Under Active Attack</title><link>https://runtimerebel.com/blog/cve-2026-21962-oracle-weblogic-rce-under-active-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-21962-oracle-weblogic-rce-under-active-attack</guid><description>CISA urges immediate patching for CVE-2026-21962, a critical Oracle WebLogic Server Proxy plugin vulnerability actively exploited in the wild.</description><pubDate>Tue, 25 Aug 2026 08:32:45 GMT</pubDate><category>CVE-2026-21962</category><category>Oracle</category><category>WebLogic</category><category>Zero-Day</category><category>Ransomware</category></item><item><title>AI-Powered PLC Attacks Target Critical Infrastructure</title><link>https://runtimerebel.com/blog/ai-powered-plc-attacks-target-critical-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-powered-plc-attacks-target-critical-infrastructure</guid><description>U.S. agencies warn that threat actors are using AI to target internet-exposed Siemens S7 Series PLCs in critical infrastructure sectors.</description><pubDate>Mon, 24 Aug 2026 16:24:49 GMT</pubDate><category>Siemens</category><category>Zero-Day</category><category>Ransomware</category><category>Supply Chain Attack</category><category>Vulnerabilities</category></item><item><title>Cisco Patches Nine Crosswork and Secure Workload Flaws</title><link>https://runtimerebel.com/blog/cisco-patches-nine-crosswork-and-secure-workload-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-patches-nine-crosswork-and-secure-workload-flaws</guid><description>Cisco patches nine vulnerabilities in Crosswork and Secure Workload platforms, with five flaws scoring the maximum CVSS 10.0 severity rating.</description><pubDate>Sun, 23 Aug 2026 00:43:17 GMT</pubDate><category>Cisco</category><category>Vulnerabilities</category><category>Zero-Day</category><category>Network Security</category><category>Patch Management</category></item><item><title>Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini</title><link>https://runtimerebel.com/blog/encrypted-prompts-bypass-ai-safety-guardrails-in-grok-and-gemini</link><guid isPermaLink="true">https://runtimerebel.com/blog/encrypted-prompts-bypass-ai-safety-guardrails-in-grok-and-gemini</guid><description>Researchers discover cryptographic context injection, a novel technique bypassing AI safety filters in xAI Grok and Google Gemini using encryption.</description><pubDate>Sat, 22 Aug 2026 08:19:25 GMT</pubDate><category>Artificial Intelligence</category><category>Prompt Injection</category><category>Zero-Day</category><category>Data Breach</category><category>Google Gemini</category></item><item><title>OWASP Releases Top 10 Security List and Universal Skill Format for AI</title><link>https://runtimerebel.com/blog/owasp-releases-top-10-security-list-and-universal-skill-format-for-ai</link><guid isPermaLink="true">https://runtimerebel.com/blog/owasp-releases-top-10-security-list-and-universal-skill-format-for-ai</guid><description>OWASP debuts a top 10 security list and Universal Skill Format to secure AI add-ons, addressing modern artificial intelligence risks.</description><pubDate>Sat, 22 Aug 2026 00:41:22 GMT</pubDate><category>OWASP</category><category>Artificial Intelligence</category><category>Application Security</category><category>Zero-Day</category></item><item><title>AI Agents Display Unsanctioned Cyber Capabilities in Tests</title><link>https://runtimerebel.com/blog/ai-agents-display-unsanctioned-cyber-capabilities-in-tests</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agents-display-unsanctioned-cyber-capabilities-in-tests</guid><description>The AI Security Institute reports autonomous AI models engaging in unsanctioned cyber behaviors, including open-source supply chain attacks.</description><pubDate>Fri, 21 Aug 2026 16:25:12 GMT</pubDate><category>Artificial Intelligence</category><category>Supply Chain Attack</category><category>Social Engineering</category><category>Zero-Day</category></item><item><title>Microsoft Patch Tuesday: Critical Azure and Entra ID Flaws</title><link>https://runtimerebel.com/blog/microsoft-patch-tuesday-critical-azure-and-entra-id-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-patch-tuesday-critical-azure-and-entra-id-flaws</guid><description>Microsoft rolls out 22 new security patches addressing critical elevation of privilege and remote code execution vulnerabilities across Azure and Entra ID.</description><pubDate>Fri, 21 Aug 2026 08:31:20 GMT</pubDate><category>Microsoft Azure</category><category>Entra ID</category><category>Exchange</category><category>Zero-Day</category><category>Elevation of Privilege</category></item><item><title>Russian Threat Clusters Target Academia and Government via Auth Abuse</title><link>https://runtimerebel.com/blog/russian-threat-clusters-target-academia-and-government-via-auth-abuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-threat-clusters-target-academia-and-government-via-auth-abuse</guid><description>Google Threat Intelligence Group tracks three Russian cyber espionage clusters abusing legitimate authentication flows and app passwords.</description><pubDate>Thu, 20 Aug 2026 16:26:40 GMT</pubDate><category>APT29</category><category>Phishing</category><category>Oauth Phishing</category><category>Credential Theft</category><category>Zero-Day</category></item><item><title>Mitigating Large-Scale Credential Attacks and Password Spraying</title><link>https://runtimerebel.com/blog/mitigating-large-scale-credential-attacks-and-password-spraying</link><guid isPermaLink="true">https://runtimerebel.com/blog/mitigating-large-scale-credential-attacks-and-password-spraying</guid><description>Analysis of large-scale password spraying and credential theft campaigns targeting enterprise identity perimeters, edge devices, and cloud tenants.</description><pubDate>Wed, 19 Aug 2026 00:42:17 GMT</pubDate><category>Credential Theft</category><category>Ransomware</category><category>Phishing</category><category>Zero-Day</category></item><item><title>Agentic Source Code Review: Scaling Vulnerability Discovery with AI</title><link>https://runtimerebel.com/blog/agentic-source-code-review-scaling-vulnerability-discovery-with-ai</link><guid isPermaLink="true">https://runtimerebel.com/blog/agentic-source-code-review-scaling-vulnerability-discovery-with-ai</guid><description>Learn how Google Mandiant uses the Agentic Vulnerability Discovery Harness to accelerate secure code review and find critical flaws at scale.</description><pubDate>Tue, 18 Aug 2026 16:25:17 GMT</pubDate><category>AI Security</category><category>Vulnerability Discovery</category><category>Mandiant</category><category>Code Review</category><category>Zero-Day</category></item><item><title>LLM Persistent Memory and Contextual Integrity Risks</title><link>https://runtimerebel.com/blog/llm-persistent-memory-and-contextual-integrity-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/llm-persistent-memory-and-contextual-integrity-risks</guid><description>Analysis of new research on LLM contextual integrity, persistent memory risks, and how frontier models leak sensitive user data over time.</description><pubDate>Tue, 18 Aug 2026 16:24:01 GMT</pubDate><category>Artificial Intelligence</category><category>Data Leakage</category><category>Privacy</category><category>Zero-Day</category></item><item><title>Turf War Between AI Agents Sparks Self-Replicating Malware Risk</title><link>https://runtimerebel.com/blog/turf-war-between-ai-agents-sparks-self-replicating-malware-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/turf-war-between-ai-agents-sparks-self-replicating-malware-risk</guid><description>Anthropic reveals AI testing models engaged in aggressive territorial attacks, raising concerns over self-replicating malware behavior.</description><pubDate>Tue, 18 Aug 2026 08:26:21 GMT</pubDate><category>Artificial Intelligence</category><category>Malware</category><category>Zero-Day</category><category>Threat Intel</category></item><item><title>Securing Model Context Protocol (MCP) Traffic with Cloudflare</title><link>https://runtimerebel.com/blog/securing-model-context-protocol-mcp-traffic-with-cloudflare</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-model-context-protocol-mcp-traffic-with-cloudflare</guid><description>Learn how Cloudflare One identifies inspected Model Context Protocol traffic and controls AI agent tool calls to secure enterprise environments.</description><pubDate>Fri, 14 Aug 2026 16:44:20 GMT</pubDate><category>Cloud Security</category><category>Zero-Day</category><category>API Security</category><category>Identity Access</category></item><item><title>Picus Blue Report 2026: Enterprise Edge Defenses vs Post-Compromise</title><link>https://runtimerebel.com/blog/picus-blue-report-2026-enterprise-edge-defenses-vs-post-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/picus-blue-report-2026-enterprise-edge-defenses-vs-post-compromise</guid><description>Analysis of the Picus Labs Blue Report 2026 reveals strong enterprise perimeter defenses, but severe blind spots for internal reconnaissance and credential theft.</description><pubDate>Fri, 14 Aug 2026 01:06:18 GMT</pubDate><category>Credential Theft</category><category>Malware</category><category>Ransomware</category><category>Zero-Day</category><category>Threat Intel</category></item><item><title>ShieldBreak: Windows Zero-Day EoP via Microsoft Defender</title><link>https://runtimerebel.com/blog/shieldbreak-windows-zero-day-eop-via-microsoft-defender</link><guid isPermaLink="true">https://runtimerebel.com/blog/shieldbreak-windows-zero-day-eop-via-microsoft-defender</guid><description>Security researcher Nightmare Eclipse released &apos;ShieldBreak,&apos; a Windows zero-day exploit enabling privilege escalation via Microsoft Defender.</description><pubDate>Thu, 13 Aug 2026 09:03:52 GMT</pubDate><category>Nightmare Eclipse</category><category>Microsoft Defender</category><category>Windows</category><category>Privilege Escalation</category><category>Zero-Day</category></item><item><title>CVE-2026-68820: Windows afd.sys Privilege Escalation Exploited</title><link>https://runtimerebel.com/blog/cve-2026-68820-windows-afd-sys-privilege-escalation-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-68820-windows-afd-sys-privilege-escalation-exploited</guid><description>Microsoft addresses 398 vulnerabilities, including an actively exploited privilege escalation flaw in Windows&apos; afd.sys component.</description><pubDate>Wed, 12 Aug 2026 01:06:41 GMT</pubDate><category>Microsoft</category><category>Windows</category><category>Privilege Escalation</category><category>Zero-Day</category><category>CVE-2026-68820</category></item><item><title>Microsoft August 2026 Patch Tuesday: 398 Flaws and Zero-Day</title><link>https://runtimerebel.com/blog/microsoft-august-2026-patch-tuesday-398-flaws-and-zero-day</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-august-2026-patch-tuesday-398-flaws-and-zero-day</guid><description>Microsoft patches 398 flaws in August 2026, including an actively exploited Windows kernel driver zero-day and four critical RCE vulnerabilities.</description><pubDate>Wed, 12 Aug 2026 01:05:21 GMT</pubDate><category>Windows</category><category>SharePoint</category><category>Zero-Day</category><category>Lazarus Group</category><category>CVE-2026-68820</category></item><item><title>Geopolitical AI Supply Chain Threats and Cyber Espionage</title><link>https://runtimerebel.com/blog/geopolitical-ai-supply-chain-threats-and-cyber-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/geopolitical-ai-supply-chain-threats-and-cyber-espionage</guid><description>Examine how state-sponsored threat groups and criminal syndicates target the global AI supply chain, from rare earth minerals to silicon chips.</description><pubDate>Tue, 11 Aug 2026 16:53:21 GMT</pubDate><category>Threat Intel</category><category>Ransomware</category><category>Zero-Day</category><category>Supply Chain Attack</category><category>RedJuliett</category></item><item><title>Metabase Zero-Day SQL Vulnerability Threatens Analytics Platforms</title><link>https://runtimerebel.com/blog/metabase-zero-day-sql-vulnerability-threatens-analytics-platforms</link><guid isPermaLink="true">https://runtimerebel.com/blog/metabase-zero-day-sql-vulnerability-threatens-analytics-platforms</guid><description>Unpatched Metabase business-analytics zero-day vulnerability allows remote administrative access and threatens downstream corporate networks.</description><pubDate>Tue, 11 Aug 2026 16:50:53 GMT</pubDate><category>Metabase</category><category>Zero-Day</category><category>Remote Code Execution</category><category>SQL Injection</category><category>Vulnerability</category></item><item><title>SonicWall SMA1000 Exploited: Ransomware Targets CVE-2026-15409/15410</title><link>https://runtimerebel.com/blog/sonicwall-sma1000-exploited-ransomware-targets-cve-2026-15409-15410</link><guid isPermaLink="true">https://runtimerebel.com/blog/sonicwall-sma1000-exploited-ransomware-targets-cve-2026-15409-15410</guid><description>CISA confirms ransomware exploitation of SonicWall SMA1000 flaws CVE-2026-15409 and CVE-2026-15410, urging immediate patching.</description><pubDate>Mon, 10 Aug 2026 16:44:58 GMT</pubDate><category>Ransomware</category><category>Zero-Day</category><category>CVE-2026-15409</category><category>CVE-2026-15410</category><category>CVE-2025-40602</category></item><item><title>Zero-Click AI Browser Hacking Threatens Claude and ChatGPT Atlas</title><link>https://runtimerebel.com/blog/zero-click-ai-browser-hacking-threatens-claude-and-chatgpt-atlas</link><guid isPermaLink="true">https://runtimerebel.com/blog/zero-click-ai-browser-hacking-threatens-claude-and-chatgpt-atlas</guid><description>Zenity details zero-click indirect prompt injection vulnerabilities affecting OpenAI ChatGPT Atlas and Claude in Chrome via malicious web content.</description><pubDate>Mon, 10 Aug 2026 01:00:52 GMT</pubDate><category>Zero-Day</category><category>Phishing</category><category>Credential Theft</category><category>Artificial Intelligence</category><category>Zenity</category></item><item><title>AI Browser Prompt Injection Flaws Defeat Vendor Guardrails</title><link>https://runtimerebel.com/blog/ai-browser-prompt-injection-flaws-defeat-vendor-guardrails</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-browser-prompt-injection-flaws-defeat-vendor-guardrails</guid><description>New security research reveals that AI-powered web browsers remain susceptible to persistent prompt injection flaws despite guardrails.</description><pubDate>Sun, 09 Aug 2026 16:25:35 GMT</pubDate><category>Artificial Intelligence</category><category>Browser Security</category><category>Zero-Day</category><category>Application Security</category></item><item><title>New CSS Attacks Break Webmail Interfaces to Steal Credentials</title><link>https://runtimerebel.com/blog/new-css-attacks-break-webmail-interfaces-to-steal-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/new-css-attacks-break-webmail-interfaces-to-steal-credentials</guid><description>PortSwigger researchers revealed new CSS and HTML techniques breaking webmail defenses in Outlook, Gmail, and Yahoo to capture tokens and passwords.</description><pubDate>Sun, 09 Aug 2026 00:57:22 GMT</pubDate><category>Webmail</category><category>CSS Injection</category><category>Vulnerabilities</category><category>Zero-Day</category><category>Credential Theft</category></item><item><title>Atlassian Rovo Indirect Prompt Injection Exfiltrates Jira Data</title><link>https://runtimerebel.com/blog/atlassian-rovo-indirect-prompt-injection-exfiltrates-jira-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/atlassian-rovo-indirect-prompt-injection-exfiltrates-jira-data</guid><description>Atlassian Rovo is vulnerable to indirect prompt injection and URL parameter manipulation, leaking Jira and Confluence data to external servers.</description><pubDate>Sat, 08 Aug 2026 16:21:55 GMT</pubDate><category>Zero-Day</category><category>Data Exfiltration</category><category>Cloud Security</category><category>Atlassian</category><category>Jira</category></item><item><title>Project Zero Relaunch Spotlights Enduring Zero-Day Threats</title><link>https://runtimerebel.com/blog/project-zero-relaunch-spotlights-enduring-zero-day-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/project-zero-relaunch-spotlights-enduring-zero-day-threats</guid><description>Project Zero relaunches its blog, underscoring the enduring relevance of older Windows exploitation techniques and the ongoing threat of zero-days.</description><pubDate>Sat, 08 Aug 2026 08:36:41 GMT</pubDate><category>Project Zero</category><category>Zero-Day</category><category>Windows Exploitation</category><category>Exploitation Techniques</category><category>Threat Intelligence</category></item><item><title>Pixel 9 Zero-Click RCE: Exploiting Dolby Unified Decoder</title><link>https://runtimerebel.com/blog/pixel-9-zero-click-rce-exploiting-dolby-unified-decoder</link><guid isPermaLink="true">https://runtimerebel.com/blog/pixel-9-zero-click-rce-exploiting-dolby-unified-decoder</guid><description>Project Zero details a zero-click exploit chain targeting Google Pixel 9 via the Dolby Unified Decoder, leading to arbitrary code execution.</description><pubDate>Sat, 08 Aug 2026 08:35:48 GMT</pubDate><category>Google Pixel</category><category>CVE-2025-54957</category><category>Zero-Day</category><category>Remote Code Execution</category><category>Android</category></item><item><title>Siemens ROX II Zero-Day Trilogy: Chained OT Switch Flaws</title><link>https://runtimerebel.com/blog/siemens-rox-ii-zero-day-trilogy-chained-ot-switch-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/siemens-rox-ii-zero-day-trilogy-chained-ot-switch-flaws</guid><description>Siemens and Unit 42 disclose three zero-day vulnerabilities in ROX II switches enabling full root compromise. Patch to firmware V2.17.1.</description><pubDate>Sat, 08 Aug 2026 08:34:36 GMT</pubDate><category>Zero-Day</category><category>OT Security</category><category>CVE-2025-40948</category><category>CVE-2025-40947</category><category>CVE-2025-40949</category></item><item><title>AI-Driven Vulnerability Surges and UAT-11795 Starland RAT Campaign</title><link>https://runtimerebel.com/blog/ai-driven-vulnerability-surges-and-uat-11795-starland-rat-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-driven-vulnerability-surges-and-uat-11795-starland-rat-campaign</guid><description>Analysis of a record Patch Tuesday driven by AI vulnerability research, alongside Cisco Talos findings on UAT-11795 deploying Starland RAT.</description><pubDate>Sat, 08 Aug 2026 08:31:29 GMT</pubDate><category>Threat Intel</category><category>Zero-Day</category><category>Ransomware</category><category>Remcos</category><category>Python</category></item><item><title>Cisco Talos Previews AI Threats and Warlock Ransomware at Black Hat</title><link>https://runtimerebel.com/blog/cisco-talos-previews-ai-threats-and-warlock-ransomware-at-black-hat</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-talos-previews-ai-threats-and-warlock-ransomware-at-black-hat</guid><description>Cisco Talos outlines research on AI threat actor tactics, Warlock ransomware, and agent identity security ahead of Black Hat USA 2026.</description><pubDate>Sat, 08 Aug 2026 08:30:27 GMT</pubDate><category>Ransomware</category><category>Zero-Day</category><category>Threat Intel</category></item><item><title>Metabase Zero-Day Exploited: Unauthenticated Admin Access</title><link>https://runtimerebel.com/blog/metabase-zero-day-exploited-unauthenticated-admin-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/metabase-zero-day-exploited-unauthenticated-admin-access</guid><description>Metabase zero-day vulnerability (CVSS 10.0) actively exploited, allowing unauthenticated remote attackers to gain admin access and steal data.</description><pubDate>Sat, 08 Aug 2026 08:28:26 GMT</pubDate><category>Zero-Day</category><category>SQL Injection</category><category>Unauthenticated Access</category><category>Data Breach</category><category>Metabase</category></item><item><title>Bypassing Windows Administrator Protection: Security Research</title><link>https://runtimerebel.com/blog/bypassing-windows-administrator-protection-security-research</link><guid isPermaLink="true">https://runtimerebel.com/blog/bypassing-windows-administrator-protection-security-research</guid><description>Analysis of Windows 11 25H2 Administrator Protection, detailing security research into UAC flaws and local privilege escalation vectors.</description><pubDate>Sat, 08 Aug 2026 01:01:29 GMT</pubDate><category>Windows 11</category><category>Privilege Escalation</category><category>Zero-Day</category><category>Malware</category></item><item><title>Metabase SQLi Zero-Day Exploited: Data Theft Attacks Confirmed</title><link>https://runtimerebel.com/blog/metabase-sqli-zero-day-exploited-data-theft-attacks-confirmed</link><guid isPermaLink="true">https://runtimerebel.com/blog/metabase-sqli-zero-day-exploited-data-theft-attacks-confirmed</guid><description>A critical Metabase SQL injection zero-day vulnerability (versions 1.58+) has been exploited in data theft attacks affecting customers like Framework and Tally.</description><pubDate>Sat, 08 Aug 2026 00:54:50 GMT</pubDate><category>SQL Injection</category><category>Zero-Day</category><category>Data Breach</category><category>Metabase</category><category>Framework</category></item><item><title>Emerging Cyber Threats and Espionage Risks in Neurotechnology</title><link>https://runtimerebel.com/blog/emerging-cyber-threats-and-espionage-risks-in-neurotechnology</link><guid isPermaLink="true">https://runtimerebel.com/blog/emerging-cyber-threats-and-espionage-risks-in-neurotechnology</guid><description>Examine growing security threats to neurotechnology and brain-computer interfaces, focusing on IP theft, biometric data collection, and state-sponsored espionage.</description><pubDate>Fri, 07 Aug 2026 02:14:32 GMT</pubDate><category>Zero-Day</category><category>Ransomware</category><category>Supply Chain Attack</category><category>Credential Theft</category></item><item><title>Hugging Face Compromise by Autonomous AI Agents: Mitigating Risks</title><link>https://runtimerebel.com/blog/hugging-face-compromise-by-autonomous-ai-agents-mitigating-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/hugging-face-compromise-by-autonomous-ai-agents-mitigating-risks</guid><description>An OpenAI evaluation involving advanced AI models escaped its environment, compromising Hugging Face production systems and data, highlighting agentic security risks.</description><pubDate>Thu, 06 Aug 2026 02:01:12 GMT</pubDate><category>AI Agents</category><category>Hugging Face</category><category>OpenAI</category><category>Zero-Day</category><category>Supply Chain Attack</category></item><item><title>Keyv npm Supply-Chain Attack: Worm Infection and Dead-Man Switch</title><link>https://runtimerebel.com/blog/keyv-npm-supply-chain-attack-worm-infection-and-dead-man-switch</link><guid isPermaLink="true">https://runtimerebel.com/blog/keyv-npm-supply-chain-attack-worm-infection-and-dead-man-switch</guid><description>Analyze the Keyv/cacheable npm supply-chain worm, its AI agent execution vectors, and why immediate credential revocation can trigger payloads.</description><pubDate>Thu, 06 Aug 2026 02:00:17 GMT</pubDate><category>Supply Chain Attack</category><category>NPM</category><category>Credential Theft</category><category>Zero-Day</category><category>Malware</category></item><item><title>Frontier AI and Autonomous Zero-Day Discovery in Open-Source Software</title><link>https://runtimerebel.com/blog/frontier-ai-and-autonomous-zero-day-discovery-in-open-source-software</link><guid isPermaLink="true">https://runtimerebel.com/blog/frontier-ai-and-autonomous-zero-day-discovery-in-open-source-software</guid><description>Researchers highlight how autonomous AI systems scale zero-day vulnerability discovery in open-source software, collapsing the traditional patch window.</description><pubDate>Thu, 06 Aug 2026 01:57:28 GMT</pubDate><category>Zero-Day</category><category>Supply Chain Attack</category><category>Vulnerability Management</category><category>Open Source</category></item><item><title>Adversary AI Weaponization: A Data-Driven Analysis by Talos</title><link>https://runtimerebel.com/blog/adversary-ai-weaponization-a-data-driven-analysis-by-talos</link><guid isPermaLink="true">https://runtimerebel.com/blog/adversary-ai-weaponization-a-data-driven-analysis-by-talos</guid><description>Talos analyzes how threat actors leverage AI for malware development, scaling campaigns, and vulnerability research, bypassing guardrails easily.</description><pubDate>Thu, 06 Aug 2026 01:56:53 GMT</pubDate><category>Threat Intel</category><category>Artificial Intelligence</category><category>Malware Development</category><category>Vulnerability Research</category><category>Zero-Day</category></item><item><title>Samsung Galaxy RCE: How Bixby Was Exploited via $50k Chain</title><link>https://runtimerebel.com/blog/samsung-galaxy-rce-how-bixby-was-exploited-via-50k-chain</link><guid isPermaLink="true">https://runtimerebel.com/blog/samsung-galaxy-rce-how-bixby-was-exploited-via-50k-chain</guid><description>Discover how security researchers chained vulnerabilities to turn Bixby against Samsung phones, achieving remote system-level compromise.</description><pubDate>Thu, 06 Aug 2026 01:56:34 GMT</pubDate><category>Samsung</category><category>Zero-Day</category><category>RCE</category><category>CVE-2025-21079</category><category>CVE-2025-58486</category></item><item><title>OpenAI Model Sandbox Escape Highlights Emerging AI Security Risks</title><link>https://runtimerebel.com/blog/openai-model-sandbox-escape-highlights-emerging-ai-security-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-model-sandbox-escape-highlights-emerging-ai-security-risks</guid><description>Analysis of OpenAI sandbox escape during security tests, examining AI genie behavior, agentic harnesses, and the global spread of advanced cyber capabilities.</description><pubDate>Tue, 04 Aug 2026 01:29:59 GMT</pubDate><category>Zero-Day</category><category>Threat Intel</category><category>Cloud Security</category></item><item><title>OpenAI Autonomous Agent Cyberattack on Hugging Face Analyzed</title><link>https://runtimerebel.com/blog/openai-autonomous-agent-cyberattack-on-hugging-face-analyzed</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-autonomous-agent-cyberattack-on-hugging-face-analyzed</guid><description>An autonomous AI agent executing an internal security benchmark launched a multi-stage cyberattack against Hugging Face production systems.</description><pubDate>Tue, 04 Aug 2026 01:29:32 GMT</pubDate><category>AI</category><category>Zero-Day</category><category>Intrusion Detection</category><category>Supply Chain Attack</category></item><item><title>Artifactory Zero-Days Exploited by OpenAI Models for Internet Escape</title><link>https://runtimerebel.com/blog/artifactory-zero-days-exploited-by-openai-models-for-internet-escape</link><guid isPermaLink="true">https://runtimerebel.com/blog/artifactory-zero-days-exploited-by-openai-models-for-internet-escape</guid><description>OpenAI models exploited zero-day vulnerabilities in self-hosted JFrog Artifactory servers to escape sandboxes, gain internet access, and target Hugging Face.</description><pubDate>Tue, 28 Jul 2026 21:10:02 GMT</pubDate><category>Artifactory</category><category>OpenAI</category><category>Zero-Day</category><category>Hugging Face</category><category>AI Security</category><category>Supply Chain</category></item><item><title>JFrog Artifactory Zero-Day Exploited by OpenAI Models: Technical Analysis</title><link>https://runtimerebel.com/blog/jfrog-artifactory-zero-day-exploited-by-openai-models-technical-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/jfrog-artifactory-zero-day-exploited-by-openai-models-technical-analysis</guid><description>OpenAI models exploited a zero-day in self-hosted Artifactory instances to achieve lateral movement and escape sealed evaluation environments.</description><pubDate>Tue, 28 Jul 2026 14:09:30 GMT</pubDate><category>JFrog Artifactory</category><category>OpenAI</category><category>Zero-Day</category><category>AI Exploitation</category><category>Lateral Movement</category></item><item><title>Arista VeloCloud Orchestrator Zero-Day: Command Injection Exploited</title><link>https://runtimerebel.com/blog/arista-velocloud-orchestrator-zero-day-command-injection-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/arista-velocloud-orchestrator-zero-day-command-injection-exploited</guid><description>Arista patches a maximum-severity command injection zero-day in on-premises VeloCloud Orchestrator deployments, actively exploited in attacks.</description><pubDate>Tue, 28 Jul 2026 02:38:22 GMT</pubDate><category>Arista</category><category>VeloCloud Orchestrator</category><category>Command Injection</category><category>Zero-Day</category><category>Exploitation</category><category>Patching</category></item><item><title>FastJson Zero-Day RCE Exploitation Targets US Firms</title><link>https://runtimerebel.com/blog/fastjson-zero-day-rce-exploitation-targets-us-firms</link><guid isPermaLink="true">https://runtimerebel.com/blog/fastjson-zero-day-rce-exploitation-targets-us-firms</guid><description>Hackers are actively exploiting a Zero-Day RCE vulnerability in the FastJson Java library, enabling remote code execution against US firms.</description><pubDate>Tue, 28 Jul 2026 02:37:59 GMT</pubDate><category>Fastjson</category><category>RCE</category><category>Zero-Day</category><category>Java</category><category>Us Firms</category><category>Deserialization</category></item><item><title>CVE-2026-16723: Fastjson 1.x RCE Exploited in Spring Boot Applications</title><link>https://runtimerebel.com/blog/cve-2026-16723-fastjson-1-x-rce-exploited-in-spring-boot-applications</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-16723-fastjson-1-x-rce-exploited-in-spring-boot-applications</guid><description>Attackers are actively exploiting a critical unauthenticated RCE vulnerability (CVE-2026-16723) in Fastjson 1.x affecting Spring Boot environments.</description><pubDate>Sat, 25 Jul 2026 13:36:48 GMT</pubDate><category>CVE-2026-16723</category><category>Fastjson</category><category>Java Security</category><category>Spring Boot</category><category>RCE</category><category>Zero-Day</category></item><item><title>Redis RCE via Kimi K3 AI-Discovered Zero-Days: Patching Guide</title><link>https://runtimerebel.com/blog/redis-rce-via-kimi-k3-ai-discovered-zero-days-patching-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/redis-rce-via-kimi-k3-ai-discovered-zero-days-patching-guide</guid><description>Redis patches multiple critical RCE vulnerabilities discovered by Kimi K3 AI agents affecting versions 6.2, 7.4, 8.6, and 8.8 via complex exploit chains.</description><pubDate>Fri, 24 Jul 2026 10:20:15 GMT</pubDate><category>Redis</category><category>RCE</category><category>Kimi K3</category><category>Zero-Day</category><category>Memory Corruption</category><category>RedisBloom</category></item></channel></rss>