Skip to main content

Coverage

Vulnerabilities

748 articles on vulnerability disclosures and exploits

Advertisement

SU
HIGH
Supply Chain

CVE-2024-21390: EngageLab SDK Vulnerability Risks Android Crypto Wallets

Microsoft reveals a vulnerability in the EngageLab SDK affecting millions of Android crypto wallet users, potentially allowing for private key theft.

Runtime Rebel Intel
3 min read·Apr 10, 2026
EngageLab SDK Vulnerability: Protecting Crypto Wallets from Sandbox Bypass
HIGH
Vulnerabilities

EngageLab SDK Vulnerability: Protecting Crypto Wallets from Sandbox Bypass

A flaw in EngageLab SDK exposed 50 million Android users to data theft. Learn how attackers bypass the Android sandbox to access private cryptocurrency keys.

Runtime Rebel Intel
4 min read·Apr 10, 2026
Legacy Apache RCE and Hybrid P2P Botnet Resurgence Analysis
HIGH
Threat Intel

Legacy Apache RCE and Hybrid P2P Botnet Resurgence Analysis

Exploration of a resurrected 13-year-old Apache RCE and the operational shifts of a hybrid P2P botnet architecture targeting enterprise infrastructure.

Runtime Rebel Intel
3 min read·Apr 9, 2026
VU
HIGH
Vulnerabilities

Palo Alto Networks & SonicWall High-Severity Privilege Escalation Patches

Palo Alto Networks and SonicWall have issued patches for high-severity vulnerabilities allowing privilege escalation to administrator. Immediate patching is advised.

Runtime Rebel Intel
5 min read·Apr 9, 2026
VU
HIGH
Vulnerabilities

Exposed Google API Keys in Android Apps Grant Gemini Access

Analysis of Google API keys found in Android apps that enable unauthorized access to Gemini AI endpoints, detailing risks and mitigation for developers.

Runtime Rebel Intel
5 min read·Apr 9, 2026
Adobe Reader Zero-Day Exploited via Malicious PDF Documents
CRITICAL
Vulnerabilities

Adobe Reader Zero-Day Exploited via Malicious PDF Documents

Researchers reveal a sophisticated Adobe Reader zero-day exploit used in the wild since late 2025, involving malicious PDF invoices to compromise systems.

Runtime Rebel Intel
3 min read·Apr 9, 2026
VU
CRITICAL
Vulnerabilities

CVE-2026-1340: Ivanti EPMM Code Injection — Patch Now

CISA adds CVE-2026-1340, a critical code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM), to its KEV Catalog due to active exploitation. Immediate

Runtime Rebel Intel
4 min read·Apr 9, 2026
AI-Led Remediation Crisis: HackerOne Halts Bug Bounties
INFO
Threat Intel

AI-Led Remediation Crisis: HackerOne Halts Bug Bounties

HackerOne pauses bug bounties due to an AI-driven remediation crisis, highlighting how automated vulnerability discovery overwhelms open-source project capacity to fix

Runtime Rebel Intel
4 min read·Apr 9, 2026
VU
CRITICAL
Vulnerabilities

Apache ActiveMQ Classic RCE via Jolokia API: Patch Now

An unauthenticated Remote Code Execution flaw, present for 13 years, impacts Apache ActiveMQ Classic, allowing full system compromise. Immediate patching is critical.

Runtime Rebel Intel
4 min read·Apr 9, 2026
VU
HIGH
Vulnerabilities

OpenSSL: Data Leakage & DoS Vulnerabilities Patched

OpenSSL patches seven vulnerabilities, including a data leakage flaw and multiple denial-of-service risks. Update immediately to secure cryptographic communications.

Runtime Rebel Intel
5 min read·Apr 9, 2026
VU
CRITICAL
Vulnerabilities

Ninja Forms RCE via Arbitrary File Upload: Mitigation Guide

Hackers are actively exploiting a critical Ninja Forms vulnerability to upload arbitrary files and achieve RCE. Learn how to secure your WordPress site now.

Runtime Rebel Intel
3 min read·Apr 8, 2026
Claude Mythos Identifies Thousands of Zero-Day Flaws in Major Systems
HIGH
Vulnerabilities

Claude Mythos Identifies Thousands of Zero-Day Flaws in Major Systems

Anthropic's Project Glasswing uses the Claude Mythos AI model to uncover thousands of zero-day vulnerabilities across infrastructure from AWS, Google, and Cisco.

Runtime Rebel Intel
4 min read·Apr 8, 2026