Skip to main content

Coverage

Vulnerabilities

1245 articles on vulnerability disclosures and exploits

Advertisement

HIGH
Vulnerabilities

Certighost PoC Exploit: Hijacking Windows Active Directory Domains

A new proof-of-concept exploit for Certighost, targeting Windows Active Directory Certificate Services, enables authenticated attackers to compromise Windows domains.

Runtime Rebel Intel
4 min read · Jul 27, 2026
vBulletin 6.2.1 Pre-Auth RCE: Public Exploit Analysis and Mitigation
HIGH
Vulnerabilities

vBulletin 6.2.1 Pre-Auth RCE: Public Exploit Analysis and Mitigation

A public exploit for a pre-auth RCE vulnerability in vBulletin 6.2.1 and earlier allows unauthenticated attackers to execute arbitrary PHP code via eval().

Runtime Rebel Intel
4 min read · Jul 27, 2026
CRITICAL
Vulnerabilities

PTC Windchill RCE via CVE-2022-25247 — Mitigation Guide

Attackers are exploiting a critical deserialization flaw in PTC Windchill PLM software to deploy ransomware. Learn how to detect and patch CVE-2022-25247.

Runtime Rebel Intel
3 min read · Jul 27, 2026
n8n RCE via Expression Sandbox Escape — Mitigation Guide
HIGH
Vulnerabilities

n8n RCE via Expression Sandbox Escape — Mitigation Guide

Authenticated workflow editors in n8n can execute arbitrary OS commands via a sandbox escape. Update to versions 2.31.5 or 2.32.1 to mitigate this risk.

Runtime Rebel Intel
4 min read · Jul 27, 2026
Rogue AI Agents and Check Point Exploits: A Weekly Security Analysis
HIGH
Threat Intel

Rogue AI Agents and Check Point Exploits: A Weekly Security Analysis

Analysis of OpenAI's rogue AI agents, active Check Point VPN exploitation, and the emergence of Slopsquatting and ClickFix phishing lures in the wild.

Runtime Rebel Intel
3 min read · Jul 27, 2026
HIGH
Vulnerabilities

Java Spring Boot Actuator: Mitigating /actuator/heapdump Scans

Learn how to protect Java Spring Boot applications from /actuator/heapdump scans. Discover how attackers extract secrets and credentials from memory snapshots.

Runtime Rebel Intel
4 min read · Jul 27, 2026
CVE-2026-16723: Fastjson 1.x RCE Exploited in Spring Boot Applications
CRITICAL
Vulnerabilities

CVE-2026-16723: Fastjson 1.x RCE Exploited in Spring Boot Applications

Attackers are actively exploiting a critical unauthenticated RCE vulnerability (CVE-2026-16723) in Fastjson 1.x affecting Spring Boot environments.

Runtime Rebel Intel
4 min read · Jul 25, 2026
HIGH
Vulnerabilities

Rockwell Arena Simulation RCE: CVE-2024-37367 and CVE-2024-37368 Patch

Rockwell Automation addresses high-severity memory corruption flaws in Arena simulation software that enable remote code execution via malicious .doe files.

Runtime Rebel Intel
3 min read · Jul 25, 2026
GitLab 18.11.3 RCE via Jupyter Notebook Diff — Mitigation Guide
HIGH
Vulnerabilities

GitLab 18.11.3 RCE via Jupyter Notebook Diff — Mitigation Guide

An exploit PoC for GitLab 18.11.3 allows authenticated users to achieve RCE as the git user by requesting diffs of crafted Jupyter notebooks. Learn how to mitigate.

Runtime Rebel Intel
4 min read · Jul 25, 2026
HIGH
Threat Intel

Hermes AI Agent Automates Post-Exploitation Against Thai Ministry

Hermes AI agent automates post-exploitation during alleged breach of Thai Ministry of Finance. Learn TTPs, impact, and mitigation for AI-driven threats.

Runtime Rebel Intel
5 min read · Jul 24, 2026
Certighost Exploit: Domain Controller Impersonation via Active Directory Certificates
HIGH
Vulnerabilities

Certighost Exploit: Domain Controller Impersonation via Active Directory Certificates

The Certighost exploit enables low-privileged Active Directory users to obtain domain controller certificates, authenticate as DCs, and retrieve the krbtgt secret for…

Runtime Rebel Intel
5 min read · Jul 24, 2026
Bing Image Workers RCE via CVE-2026-32194: Technical Analysis
HIGH
Vulnerabilities

Bing Image Workers RCE via CVE-2026-32194: Technical Analysis

A critical vulnerability in Bing's image processing tier allowed attackers to execute code as SYSTEM/root via crafted SVGs. Learn about the remediation steps.

Runtime Rebel Intel
3 min read · Jul 24, 2026
AgentForger: OpenAI ChatGPT Workspace Rogue Agent Deployment Risk
HIGH
Vulnerabilities

AgentForger: OpenAI ChatGPT Workspace Rogue Agent Deployment Risk

Zenity Labs reveals AgentForger, a vulnerability allowing rogue ChatGPT Workspace agents to be deployed via a phishing link, now patched by OpenAI.

Runtime Rebel Intel
4 min read · Jul 24, 2026
Assessing AI Guardrail Gaps in Multilingual LLM Deployments
MEDIUM
Threat Intel

Assessing AI Guardrail Gaps in Multilingual LLM Deployments

Research indicates AI guardrails fail to prevent jailbreaking in non-English languages, posing risks for multilingual enterprise deployments.

Runtime Rebel Intel
3 min read · Jul 24, 2026
HIGH
Threat Intel

PTC Windchill and FlexPLM Targeted in Clop Data Theft Campaign

Clop ransomware targets PTC Windchill and FlexPLM systems. Learn about the CVE-2022-25247 exploit risks and how to secure exposed PLM instances from extortion.

Runtime Rebel Intel
3 min read · Jul 24, 2026
Redis RCE via Kimi K3 AI-Discovered Zero-Days: Patching Guide
HIGH
Vulnerabilities

Redis RCE via Kimi K3 AI-Discovered Zero-Days: Patching Guide

Redis patches multiple critical RCE vulnerabilities discovered by Kimi K3 AI agents affecting versions 6.2, 7.4, 8.6, and 8.8 via complex exploit chains.

Runtime Rebel Intel
4 min read · Jul 24, 2026
NodeBB 4.14.2 Release Patches Eight AI-Discovered Vulnerabilities
HIGH
Vulnerabilities

NodeBB 4.14.2 Release Patches Eight AI-Discovered Vulnerabilities

NodeBB patches eight high-severity vulnerabilities discovered by AI, preventing unauthorized admin access and private chat exposure in versions before 4.14.0.

Runtime Rebel Intel
4 min read · Jul 24, 2026
CRITICAL
Vulnerabilities

SolarWinds ARM RCE via CVE-2024-28995 — Technical Mitigation Guide

Critical vulnerabilities in SolarWinds Access Rights Manager (ARM), including CVE-2024-28995, allow unauthenticated RCE. Update to version 2024.3 now.

Runtime Rebel Intel
3 min read · Jul 24, 2026
Zimbra Zero-Day Exploited by Laundry Bear Against US & Ukraine
HIGH
Threat Intel

Zimbra Zero-Day Exploited by Laundry Bear Against US & Ukraine

Russian state-sponsored group 'Laundry Bear' exploits a Zimbra zero-day via 'half-click' phishing, targeting US and Ukrainian entities for credential theft and backdoor…

Runtime Rebel Intel
4 min read · Jul 24, 2026
Russian APT Exploits Zimbra Zero-Day to Exfiltrate Mail and 2FA Codes
HIGH
Threat Intel

Russian APT Exploits Zimbra Zero-Day to Exfiltrate Mail and 2FA Codes

Russian state-supported actors leveraged a Zimbra Zero-Day to steal 90 days of email history and bypass security by exfiltrating 2FA recovery codes.

Runtime Rebel Intel
3 min read · Jul 23, 2026
INFO
Threat Intel

AI Exploit Generation: Rethinking Vulnerability Management Strategy

AI-driven exploit generation threatens traditional patching. This analysis explores the shift required in vulnerability management for proactive cyber defense.

Runtime Rebel Intel
4 min read · Jul 23, 2026
HIGH
Vulnerabilities

ChatGPT AgentForger Flaw Fixed: Preventing AI Insider Threats

OpenAI patched a ChatGPT agent flaw, AgentForger, enabling attackers to remotely control an invisible AI insider within organizations. Learn mitigation strategies.

Runtime Rebel Intel
4 min read · Jul 23, 2026
Claude Cowork Sandbox Escape: VM to macOS File Access
HIGH
Vulnerabilities

Claude Cowork Sandbox Escape: VM to macOS File Access

A critical sandbox escape vulnerability in Anthropic's Claude Cowork allows AI agents to break out of their Linux VM, gaining full file access on macOS hosts, affecting…

Runtime Rebel Intel
5 min read · Jul 23, 2026
HIGH
Vulnerabilities

CVE-2026-64600: Local Root via Linux XFS Race Condition — Patch Now

A nine-year-old race condition in the Linux kernel XFS filesystem, known as RefluXFS, allows local attackers to achieve root privileges via file overwrites.

Runtime Rebel Intel
4 min read · Jul 23, 2026