Skip to main content

Coverage

Vulnerabilities

1245 articles on vulnerability disclosures and exploits

Advertisement

HIGH
Vulnerabilities

CVE-2025-55182: Hackers Exploit React2Shell in Next.js Applications

Security researchers observe automated credential theft campaigns exploiting the React2Shell vulnerability (CVE-2025-55182) in vulnerable Next.js frameworks.

Runtime Rebel Intel
3 min read · Apr 5, 2026
CVE-2026-35616: Critical FortiClient EMS API Bypass Exploited
CRITICAL
Vulnerabilities

CVE-2026-35616: Critical FortiClient EMS API Bypass Exploited

Fortinet releases out-of-band patches for CVE-2026-35616, a critical API access bypass in FortiClient EMS enabling unauthenticated privilege escalation.

Runtime Rebel Intel
3 min read · Apr 5, 2026
36 Malicious npm Packages Target Strapi, Redis, and PostgreSQL
HIGH
Supply Chain

36 Malicious npm Packages Target Strapi, Redis, and PostgreSQL

36 malicious npm packages disguised as Strapi CMS plugins target Redis and PostgreSQL environments to deploy persistent implants and reverse shells.

Runtime Rebel Intel
4 min read · Apr 5, 2026
Apple Patches DarkSword for iOS 18 — Security Analysis
HIGH
Vulnerabilities

Apple Patches DarkSword for iOS 18 — Security Analysis

Apple breaks precedent by patching the DarkSword mobile exploitation framework for iOS 18, addressing critical kernel-level risks and RCE vulnerabilities.

Runtime Rebel Intel
3 min read · Apr 4, 2026
Cookie-Controlled PHP Web Shells Evade Detection on Linux Servers
HIGH
Threat Intel

Cookie-Controlled PHP Web Shells Evade Detection on Linux Servers

Microsoft researchers warn of stealthy PHP web shells on Linux using HTTP cookies for command execution and cron jobs for long-term persistence.

Runtime Rebel Intel
3 min read · Apr 4, 2026
CRITICAL
Threat Intel

TrueConf Zero-Day: Exploitation Against Asian Governments

A Chinese threat actor is actively exploiting a TrueConf video conferencing zero-day to conduct reconnaissance and achieve privilege escalation against Asian government…

Runtime Rebel Intel
4 min read · Apr 3, 2026
INFO
Threat Intel

Shadow AI & Zero-Click Exploits Expand Enterprise Mobile Attack Surface

Enterprises face a growing mobile attack surface from shadow AI in apps, outdated devices, and zero-click exploits, leading to unseen risks for corporate data.

Runtime Rebel Intel
4 min read · Apr 3, 2026
HIGH
Vulnerabilities

CVE-2023-24489: Citrix ShareFile StorageZones Controller Unauthenticated RCE

Critical unauthenticated RCE in Citrix ShareFile StorageZones Controller (CVE-2023-24489) enables arbitrary file upload and full system compromise. Patch immediately.

Runtime Rebel Intel
4 min read · Apr 3, 2026
CRITICAL
Vulnerabilities

Ivanti Connect Secure RCE: Internal Network Vulnerability Detection

Analyze the impact of Ivanti Connect Secure vulnerabilities and learn how to conduct internal network vulnerability scanning for Ivanti appliances to detect flaws.

Runtime Rebel Intel
3 min read · Apr 3, 2026
MEDIUM
Vulnerabilities

Yokogawa CENTUM VP CVE-2025-7741 Hardcoded Password Patch Guidance

CISA identifies a hardcoded password in Yokogawa CENTUM VP (CVE-2025-7741). Learn how to secure the PROG account and apply the R7.01.10 patch now.

Runtime Rebel Intel
4 min read · Apr 3, 2026
HIGH
Vulnerabilities

Siemens SICAM 8 CPCI85 and RTUM85 DoS Vulnerabilities: Patch Guide

Siemens issued an advisory for SICAM 8 products fixing vulnerabilities in CPCI85 and RTUM85 that could cause system crashes in critical infrastructure.

Runtime Rebel Intel
4 min read · Apr 3, 2026
HIGH
Vulnerabilities

Anthropic Claude Code Vulnerability Analysis — Mitigation Guide

Anthropic's Claude Code faces critical scrutiny following a source code leak and the discovery of a vulnerability allowing arbitrary command execution.

Runtime Rebel Intel
4 min read · Apr 3, 2026
CVE-2025-55182: Next.js React2Shell Exploited to Steal Cloud Secrets
HIGH
Threat Intel

CVE-2025-55182: Next.js React2Shell Exploited to Steal Cloud Secrets

Attackers are exploiting the CVE-2025-55182 React2Shell vulnerability in Next.js to harvest AWS secrets, SSH keys, and database credentials from 766 hosts.

Runtime Rebel Intel
3 min read · Apr 3, 2026
Cisco IMC and SSM RCE via CVE-2026-20093 — Mitigation Guide
CRITICAL
Vulnerabilities

Cisco IMC and SSM RCE via CVE-2026-20093 — Mitigation Guide

Cisco patches a critical 9.8 CVSS vulnerability in Integrated Management Controller (IMC) allowing unauthenticated remote attackers to gain full system access.

Runtime Rebel Intel
3 min read · Apr 2, 2026
HIGH
Threat Intel

Vite Exposed Installs: Exploitation Attempts & Mitigation for CVE-2025-30208

Runtime Rebel warns of active exploitation attempts targeting exposed Vite development environments. Learn about CVE-2025-30208 and critical mitigation steps.

Runtime Rebel Intel
4 min read · Apr 2, 2026
HIGH
Threat Intel

BRICKSTORM Malware: Hardening vSphere & VCSA Against Advanced Threats

Defend VMware vSphere and VCSA against BRICKSTORM malware. Learn hardening strategies, identity management, Zero Trust networking, and advanced logging to thwart…

Runtime Rebel Intel
9 min read · Apr 2, 2026
HIGH
Vulnerabilities

Apple DarkSword Protection Expands: Mitigating CVE-2023-38604 Zero-Click Exploits

Apple expands DarkSword exploit protection to all users, enhancing defenses against state-sponsored and commercial zero-click attacks like CVE-2023-38604.

Runtime Rebel Intel
4 min read · Apr 2, 2026
ThreatsDay Bulletin: Pre-Auth Chains, Android Rootkits, & Cloud Evasion
HIGH
Threat Intel

ThreatsDay Bulletin: Pre-Auth Chains, Android Rootkits, & Cloud Evasion

Analysis of the latest ThreatsDay Bulletin covering critical pre-authentication exploit chains, stealthy Android rootkits, and advanced CloudTrail evasion techniques.

Runtime Rebel Intel
5 min read · Apr 2, 2026
HIGH
Threat Intel

Coruna: Sophisticated iPhone Hacking Toolkit Bypasses iOS Defenses

Google researchers uncovered "Coruna," a powerful iOS exploit kit leveraging 23 vulnerabilities to silently install malware on iPhones, likely state-sponsored.

Runtime Rebel Intel
5 min read · Apr 2, 2026
HIGH
Vulnerabilities

CVE-2024-20359: Cisco IMC Auth Bypass Grants Admin Access

Cisco IMC critical authentication bypass (CVE-2024-20359) allows unauthenticated attackers admin access. Learn about the vulnerability and urgent patch guidance.

Runtime Rebel Intel
4 min read · Apr 2, 2026
Open Source Security: Key Findings from 2025 Trust Report
INFO
Supply Chain

Open Source Security: Key Findings from 2025 Trust Report

Analysis of the 2025 State of Trusted Open Source Report, detailing prevalent vulnerabilities and consumption patterns in container images and language libraries.

Runtime Rebel Intel
4 min read · Apr 2, 2026
HIGH
Vulnerabilities

Ivanti Connect Secure RCE via CVE-2024-21887 — Mitigation Guide

Critical Ivanti Connect Secure vulnerabilities CVE-2023-46805 and CVE-2024-21887 continue to be exploited. Learn detection strategies and mitigation steps.

Runtime Rebel Intel
4 min read · Apr 2, 2026
CRITICAL
Vulnerabilities

CVE-2026-5281: Google Dawn RCE via Use-After-Free — Mitigation Guide

CISA adds CVE-2026-5281 to the Known Exploited Vulnerabilities Catalog following evidence of active exploitation in Google Dawn's WebGPU implementation.

Runtime Rebel Intel
4 min read · Apr 2, 2026
HIGH
Vulnerabilities

CVE-2023-46747: 14,000 F5 BIG-IP APM Instances Exposed to RCE

Over 14,000 F5 BIG-IP APM instances remain vulnerable to critical RCE flaws. Learn about CVE-2023-46747 exploitation risks and how to secure your perimeter.

Runtime Rebel Intel
3 min read · Apr 2, 2026