Skip to main content

Coverage

Vulnerabilities

1245 articles on vulnerability disclosures and exploits

Advertisement

Apple's Accelerated Patch Policy: Responding to AI Exploit Generation
INFO
Threat Intel

Apple's Accelerated Patch Policy: Responding to AI Exploit Generation

Apple is shifting to more frequent security updates in response to AI's ability to accelerate exploit development, demanding faster patching cycles from organizations.

Runtime Rebel Intel
5 min read · Jul 3, 2026
CRITICAL
Vulnerabilities

CitrixBleed: NetScaler Memory Disclosure Exploited Post-Disclosure

CitrixBleed, a new vulnerability in NetScaler appliances, is being actively exploited using public PoC code to retrieve arbitrary memory content. Patch immediately.

Runtime Rebel Intel
4 min read · Jul 3, 2026
CVE-2025-5777: Anubis Ransomware Exploits Citrix Bleed 2
HIGH
Threat Intel

CVE-2025-5777: Anubis Ransomware Exploits Citrix Bleed 2

Anubis ransomware affiliates exploit Citrix Bleed 2 (CVE-2025-5777) and BYOVD techniques to breach networks via RMM tools and supply chain credentials.

Runtime Rebel Intel
3 min read · Jul 3, 2026
AI Compute Hijacking and BlueHammer Ransomware Analysis
HIGH
Threat Intel

AI Compute Hijacking and BlueHammer Ransomware Analysis

Analysis of emerging threats including AI compute hijacking via sandbox escapes, BlueHammer ransomware TTPs, and logic flaws in Apple email services.

Runtime Rebel Intel
3 min read · Jul 2, 2026
JADEPUFFER AI Agent Exploits Langflow RCE for Automated Ransomware
HIGH
Threat Intel

JADEPUFFER AI Agent Exploits Langflow RCE for Automated Ransomware

The threat actor JADEPUFFER has pioneered the use of AI agents to automate end-to-end ransomware attacks via Langflow RCE, from initial access to data wiping.

Runtime Rebel Intel
4 min read · Jul 2, 2026
HIGH
Vulnerabilities

CVE-2024-45133: Apache Druid RCE via YAML Deserialization

Critical unauthenticated RCE in Apache Druid CVE-2024-45133 allows attackers to execute code via unsafe SnakeYAML deserialization in ingestion tasks.

Runtime Rebel Intel
4 min read · Jul 2, 2026
HIGH
Threat Intel

Lynx Ransomware Linked to Massive FortiBleed Credential Theft

Threat actors behind Lynx and INC ransomware leverage FortiBleed campaign to harvest over 440,000 Fortinet VPN credentials via CVE-2023-48788 exploits.

Runtime Rebel Intel
4 min read · Jul 2, 2026
CVE-2026-45659: SharePoint RCE Exploitation - Mitigation Guide
HIGH
Vulnerabilities

CVE-2026-45659: SharePoint RCE Exploitation - Mitigation Guide

CISA adds CVE-2026-45659, a high-severity SharePoint Server deserialization flaw, to KEV catalog after confirmed active exploitation by threat actors.

Runtime Rebel Intel
3 min read · Jul 2, 2026
Unpatched Argo CD repo-server RCE via Internal Port Exposure
HIGH
Vulnerabilities

Unpatched Argo CD repo-server RCE via Internal Port Exposure

An unpatched vulnerability in the Argo CD repo-server allows unauthenticated attackers to achieve RCE and potentially take over Kubernetes clusters.

Runtime Rebel Intel
3 min read · Jul 2, 2026
Adobe ColdFusion, Campaign Classic RCE via 7 Critical Flaws – Patch Now
HIGH
Vulnerabilities

Adobe ColdFusion, Campaign Classic RCE via 7 Critical Flaws – Patch Now

Adobe addresses 7 critical CVSS 10.0 flaws in ColdFusion and Campaign Classic, enabling RCE and privilege escalation. Immediate patching is essential.

Runtime Rebel Intel
5 min read · Jul 1, 2026
HIGH
Vulnerabilities

NetScaler Vulnerabilities: HTTP/2 Bomb & High-Severity Info Disclosure

Citrix addresses six NetScaler vulnerabilities, including a new HTTP/2 Bomb and a high-severity information disclosure bug similar to CitrixBleed.

Runtime Rebel Intel
4 min read · Jul 1, 2026
CRITICAL
Vulnerabilities

Adobe ColdFusion & Campaign Classic: Critical RCE Patches

Adobe has released critical patches for ColdFusion and Campaign Classic, addressing seven vulnerabilities with 10/10 CVSS scores that allow remote code execution.

Runtime Rebel Intel
4 min read · Jul 1, 2026
CRITICAL
Vulnerabilities

CVE-2026-33825: BlueHammer Zero-Day in Microsoft Defender Exploited by Ransomware

Analysis of the BlueHammer zero-day, CVE-2026-33825, in Microsoft Defender, actively exploited by ransomware groups. Learn detection and mitigation strategies.

Runtime Rebel Intel
4 min read · Jul 1, 2026
NetScaler ADC CVE-2026-8451: Mitigating Arbitrary File Read Risks
HIGH
Vulnerabilities

NetScaler ADC CVE-2026-8451: Mitigating Arbitrary File Read Risks

Citrix patches six NetScaler ADC and Gateway vulnerabilities, including CVE-2026-8451. Secure your infrastructure against file reads and denial-of-service.

Runtime Rebel Intel
3 min read · Jul 1, 2026
GuardFall: Shell Injection Risks in Open-Source AI Coding Agents
HIGH
Vulnerabilities

GuardFall: Shell Injection Risks in Open-Source AI Coding Agents

GuardFall bypass exposes 10 of 11 popular open-source AI coding agents to decades-old shell injection vulnerabilities. Understand the threat and mitigation.

Runtime Rebel Intel
4 min read · Jun 30, 2026
INFO
Vulnerabilities

June Apple Security Updates for iOS, macOS, Safari: Patch Now

Apple released essential security updates for iOS/iPadOS, macOS, and Safari in June. Learn why timely patching is critical for protecting your devices and data.

Runtime Rebel Intel
4 min read · Jun 30, 2026
NIST NVD Enrichment Changes: Impact on CVE Coverage and Accuracy
INFO
Vulnerabilities

NIST NVD Enrichment Changes: Impact on CVE Coverage and Accuracy

NIST's reduction in NVD enrichment impacts CVE coverage and data accuracy, challenging security professionals to adapt vulnerability management strategies.

Runtime Rebel Intel
4 min read · Jun 30, 2026
AirDrop and Quick Share: Proximity Flaws Cause Crashes and Bypass Checks
HIGH
Vulnerabilities

AirDrop and Quick Share: Proximity Flaws Cause Crashes and Bypass Checks

Researchers found six security flaws in AirDrop and Quick Share, enabling nearby attackers to crash devices and bypass security checks without user interaction.

Runtime Rebel Intel
4 min read · Jun 30, 2026
CVE-2026-48558: SimpleHelp OIDC Authentication Bypass & Malware
CRITICAL
Vulnerabilities

CVE-2026-48558: SimpleHelp OIDC Authentication Bypass & Malware

Threat actors are actively exploiting CVE-2026-48558, a critical SimpleHelp OpenID Connect authentication bypass vulnerability, to deploy TaskWeaver and Djinn Stealer…

Runtime Rebel Intel
5 min read · Jun 30, 2026
Critical Flaw Exposes Indian Government Data in National Portal
HIGH
Vulnerabilities

Critical Flaw Exposes Indian Government Data in National Portal

A critical vulnerability and several others exposed private data within Indian government systems, allowing potential takeover of a national portal.

Runtime Rebel Intel
4 min read · Jun 30, 2026
Djinn Stealer Targets Cloud & AI Credentials via SimpleHelp CVE-2026-48558
HIGH
Malware

Djinn Stealer Targets Cloud & AI Credentials via SimpleHelp CVE-2026-48558

Analysis of Djinn Stealer, an infostealer delivered via critical SimpleHelp CVE-2026-48558, targeting cloud and AI development credentials.

Runtime Rebel Intel
4 min read · Jun 30, 2026
CRITICAL
Vulnerabilities

Critical SimpleHelp Vulnerability Exploited for Malware Delivery

A critical vulnerability in SimpleHelp is actively exploited to deploy malware, targeting credentials, SSH keys, and crypto wallets. Immediate patching is essential.

Runtime Rebel Intel
4 min read · Jun 30, 2026
CVE-2026-8037: Progress Kemp LoadMaster Pre-Auth RCE Threat
HIGH
Vulnerabilities

CVE-2026-8037: Progress Kemp LoadMaster Pre-Auth RCE Threat

A critical pre-authentication RCE (CVE-2026-8037) in Progress Kemp LoadMaster allows unauthenticated attackers to execute root commands via a crafted API request.

Runtime Rebel Intel
4 min read · Jun 30, 2026
HIGH
Vulnerabilities

CVE-2024-2821: Critical RCE in Daktronics Controllers — Patch Now

Critical vulnerabilities (CVE-2024-2821, CVE-2024-2822, CVE-2024-2823) in Daktronics Venus 1500 and Vanguard controllers allow remote hacking of highway signs and…

Runtime Rebel Intel
4 min read · Jun 30, 2026