Skip to main content

Coverage

Vulnerabilities

1245 articles on vulnerability disclosures and exploits

Advertisement

Claude Mythos Identifies Thousands of Zero-Day Flaws in Major Systems
HIGH
Vulnerabilities

Claude Mythos Identifies Thousands of Zero-Day Flaws in Major Systems

Anthropic's Project Glasswing uses the Claude Mythos AI model to uncover thousands of zero-day vulnerabilities across infrastructure from AWS, Google, and Cisco.

Runtime Rebel Intel
4 min read · Apr 8, 2026
HIGH
Threat Intel

Detecting Malicious Web Shells: Analysis of Persistence and TTPs

Discover how attackers use deceptive naming and pre-set credentials in web shells to maintain persistence and how to detect these malicious files on servers.

Runtime Rebel Intel
4 min read · Apr 8, 2026
HIGH
Vulnerabilities

Ivanti CSA 4.6 Exploited via CVE-2024-9380: Migration Required

Attackers are actively exploiting Ivanti CSA 4.6 via CVE-2024-9379 and CVE-2024-9380. Learn how to detect these command injection exploits and migrate to version 5.0.

Runtime Rebel Intel
3 min read · Apr 8, 2026
Storm-1175: High-Velocity Medusa Ransomware Campaigns
HIGH
Threat Intel

Storm-1175: High-Velocity Medusa Ransomware Campaigns

Runtime Rebel reports on Storm-1175's rapid Medusa ransomware campaigns, exploiting N-day and zero-day vulnerabilities for financial gain.

Runtime Rebel Intel
5 min read · Apr 8, 2026
HIGH
Vulnerabilities

CVE-2023-3800: RCE Vulnerability in Ninja Forms File Uploads Extension

Attackers are exploiting a critical unauthenticated file upload flaw in Ninja Forms File Uploads. Secure your WordPress site and mitigate RCE risks immediately.

Runtime Rebel Intel
3 min read · Apr 8, 2026
INFO
Threat Intel

AI's Impact on Software Supply Chain Security and Vulnerability Management

AI is set to revolutionize software development, enabling 'instant software' and advanced vulnerability detection, profoundly reshaping future cybersecurity strategies.

Runtime Rebel Intel
5 min read · Apr 7, 2026
Grafana AI Assistant Flaw Exposes User Data — Immediate Patch Required
HIGH
Vulnerabilities

Grafana AI Assistant Flaw Exposes User Data — Immediate Patch Required

Grafana patched an AI vulnerability where malicious instructions on web pages could trick its AI assistant into leaking sensitive user data. Immediate action needed.

Runtime Rebel Intel
4 min read · Apr 7, 2026
HIGH
Vulnerabilities

Mitsubishi Electric ICS Vulnerabilities Expose SQL Credentials

High-severity vulnerabilities (CVE-2025-14815, CVE-2025-14816) in Mitsubishi Electric ICS/SCADA products risk SQL credential exposure and data compromise.

Runtime Rebel Intel
4 min read · Apr 7, 2026
CRITICAL
Vulnerabilities

Android StrongBox DoS Vulnerability Patched – Update Now

A critical Denial-of-Service vulnerability in Android's StrongBox keymaster and Framework component has been patched. Immediate updates are crucial for device security.

Runtime Rebel Intel
4 min read · Apr 7, 2026
HIGH
Vulnerabilities

Critical Flowise Vulnerability: Arbitrary Code Execution and File Access

A critical vulnerability in Flowise allows attackers to execute arbitrary code and access file systems due to improper JavaScript validation. Patching is urgent.

Runtime Rebel Intel
4 min read · Apr 7, 2026
CVE-2026-34040: Docker AuthZ Bypass and Host Access — Patch Now
HIGH
Vulnerabilities

CVE-2026-34040: Docker AuthZ Bypass and Host Access — Patch Now

Attackers can bypass Docker Engine AuthZ plugins via CVE-2026-34040, an incomplete fix for CVE-2024-41110. Secure your container host with this guide.

Runtime Rebel Intel
3 min read · Apr 7, 2026
HIGH
Malware

Medusa Ransomware: Rapid Vulnerability Weaponization and Analysis

An analysis of Medusa ransomware's rapid exploitation of vulnerabilities and Zero-Day bugs to exfiltrate and encrypt data within days of initial access.

Runtime Rebel Intel
4 min read · Apr 7, 2026
HIGH
Vulnerabilities

GPUBreach Attack: Exploiting GPU Rowhammer for Root Shell Access

Research reveals GPUBreach, a technique using GPU-based Rowhammer to achieve root shell access and privilege escalation on shared memory systems.

Runtime Rebel Intel
4 min read · Apr 7, 2026
Flowise AI CVE-2025-59528 RCE Exploitation: Mitigation Guide
CRITICAL
Vulnerabilities

Flowise AI CVE-2025-59528 RCE Exploitation: Mitigation Guide

Active exploitation of CVE-2025-59528 (CVSS 10.0) targets Flowise AI's CustomMCP node. Learn how to detect and patch this critical RCE vulnerability today.

Runtime Rebel Intel
3 min read · Apr 7, 2026
Storm-1175: China-Linked Zero-Day Exploits Deploy Medusa Ransomware
HIGH
Threat Intel

Storm-1175: China-Linked Zero-Day Exploits Deploy Medusa Ransomware

China-linked actor Storm-1175 is weaponizing zero-day and N-day vulnerabilities in perimeter assets to execute high-velocity Medusa ransomware attacks.

Runtime Rebel Intel
3 min read · Apr 7, 2026
CRITICAL
Vulnerabilities

CVE-2024-29847: Ivanti Endpoint Manager RCE Patch and Detection Guide

Ivanti Endpoint Manager (EPM) critical RCE (CVE-2024-29847) allows unauthenticated attackers to execute code with SYSTEM privileges via deserialization.

Runtime Rebel Intel
3 min read · Apr 7, 2026
HIGH
Vulnerabilities

GPUBreach Attack: Exploiting GDDR6 via GPU Rowhammer Bit-Flips

Researchers discover GPUBreach, a Rowhammer-style attack on GDDR6 memory that enables privilege escalation and full system takeover on modern GPUs.

Runtime Rebel Intel
3 min read · Apr 7, 2026
LOW
Vulnerabilities

Fix for Classic Outlook 0x80040115 Error Restores Email Delivery

Microsoft resolves a persistent bug in Classic Outlook causing 0x80040115 errors and email delivery failures for Outlook.com users. Learn how to fix it.

Runtime Rebel Intel
4 min read · Apr 6, 2026
CRITICAL
Vulnerabilities

CVE-2026-35616: Fortinet FortiClient EMS Vulnerability — KEV Alert

CISA adds CVE-2026-35616 affecting Fortinet FortiClient EMS to its Known Exploited Vulnerabilities catalog. Learn how to mitigate this access control flaw.

Runtime Rebel Intel
4 min read · Apr 6, 2026
UAT-10608 Exploits Next.js CVE-2024-34351 via React2Shell Script
HIGH
Threat Intel

UAT-10608 Exploits Next.js CVE-2024-34351 via React2Shell Script

Threat actor UAT-10608 is leveraging an automated script to exploit a Next.js SSRF flaw, exfiltrating credentials and environment secrets from web applications.

Runtime Rebel Intel
3 min read · Apr 6, 2026
CRITICAL
Vulnerabilities

FortiClient EMS RCE via CVE-2023-48788 — Patch Guidance

CISA mandates federal agencies patch the critical FortiClient EMS SQL injection flaw, CVE-2023-48788, which allows unauthenticated remote code execution.

Runtime Rebel Intel
3 min read · Apr 6, 2026
Chrome Zero-Day and Fortinet Exploits: Weekly Threat Intelligence
HIGH
Threat Intel

Chrome Zero-Day and Fortinet Exploits: Weekly Threat Intelligence

Intelligence analysis of the latest Chrome zero-day, Fortinet vulnerabilities, and the Axios security breach, including technical remediation for SOC teams.

Runtime Rebel Intel
3 min read · Apr 6, 2026
HIGH
Vulnerabilities

CVE-2024-32113: Apache OFBiz RCE Exploited for Mirai Botnet

Technical analysis of CVE-2024-32113 exploitation in Apache OFBiz. Learn how attackers use path traversal to deploy Mirai botnet malware and how to patch.

Runtime Rebel Intel
3 min read · Apr 6, 2026
CRITICAL
Vulnerabilities

FortiClient EMS RCE via CVE-2026-35616 — Mitigation Guide

Fortinet releases emergency patches for CVE-2026-35616, a critical SQL injection flaw in FortiClient EMS exploited to achieve unauthenticated RCE.

Runtime Rebel Intel
4 min read · Apr 5, 2026