Skip to main content

Coverage

Vulnerabilities

903 articles on vulnerability disclosures and exploits

Advertisement

ClawJacked: Hijacking Local OpenClaw AI Agents via WebSocket
HIGH
Vulnerabilities

ClawJacked: Hijacking Local OpenClaw AI Agents via WebSocket

A high-severity vulnerability in the OpenClaw AI gateway allows malicious websites to take control of local AI agents by exploiting WebSocket flaws.

Runtime Rebel Intel
4 min read·Feb 28, 2026
900+ Sangoma FreePBX Servers Compromised via Web Shell Exploitation
HIGH
Vulnerabilities

900+ Sangoma FreePBX Servers Compromised via Web Shell Exploitation

Over 900 Sangoma FreePBX instances are currently infected with web shells following a command injection campaign first observed in late 2025.

Runtime Rebel Intel
4 min read·Feb 27, 2026
VU
HIGH
Vulnerabilities

Addressing Enterprise Risk in Third-Party Software Patching

Analyze the security risks of third-party software drift and learn why automated patch management is essential for reducing the modern attack surface.

Runtime Rebel Intel
3 min read·Feb 27, 2026
MA
CRITICAL
Malware

CISA Warns of RESURGE Malware Persistence on Ivanti Devices

CISA details RESURGE, a sophisticated implant exploiting CVE-2025-0282 in Ivanti Connect Secure, capable of remaining dormant to bypass detection and recovery.

Runtime Rebel Intel
4 min read·Feb 27, 2026
VU
CRITICAL
Vulnerabilities

Juniper PTX Routers Face Critical RCE via Junos OS Evolved Flaw

Juniper Networks patches a critical 9.8 CVSS RCE vulnerability (CVE-2024-21602) in PTX Series routers. Learn the technical details and mitigation steps.

Runtime Rebel Intel
3 min read·Feb 27, 2026
VU
HIGH
Vulnerabilities

Critical Vulnerabilities in Gardyn Smart Gardens Enable Remote Takeover

CISA warns of critical flaws in Gardyn Smart Gardens, including CVE-2024-39682 and CVE-2024-39683, allowing remote code execution and unauthorized access.

Runtime Rebel Intel
4 min read·Feb 27, 2026
VU
MEDIUM
Vulnerabilities

OpenLDAP and lldpd Vulnerabilities: Analyzing DoS Risks

Detailed analysis of CVE-2025-25164 in OpenLDAP and CVE-2025-25330 in lldpd, focusing on NULL pointer dereference and memory leak impacts on infrastructure.

Runtime Rebel Intel
4 min read·Feb 27, 2026
Cisco SD-WAN Zero-Day Under Exploitation for 3 Years
CRITICAL
Vulnerabilities

Cisco SD-WAN Zero-Day Under Exploitation for 3 Years

A critical zero-day vulnerability, CVE-2026-20127, in Cisco SD-WAN has been actively exploited by a sophisticated threat actor for three years.

Runtime Rebel Intel
4 min read·Feb 27, 2026
VU
HIGH
Vulnerabilities

GetProcessHandleFromHwnd API: UAC Bypass Implications

Investigate the GetProcessHandleFromHwnd API's role in a Quick Assist UAC bypass. Understand its mechanism, UIAccess implications, and defender recommendations.

Runtime Rebel Intel
4 min read·Feb 26, 2026
VU
MEDIUM
Vulnerabilities

Multiple DoS/RCE Vulnerabilities in Yokogawa CENTUM VP R6, R7

CISA alerts to multiple medium-severity vulnerabilities in Yokogawa CENTUM VP R6 and R7, allowing DoS and RCE via crafted packets in critical infrastructure

Runtime Rebel Intel
4 min read·Feb 26, 2026
VU
CRITICAL
Vulnerabilities

Critical Authentication Flaws in Chargemap EV Infrastructure

CISA warns of critical vulnerabilities in Chargemap EV charging stations, including unauthenticated WebSocket access and session hijacking (CVE-2026-25851).

Runtime Rebel Intel
3 min read·Feb 26, 2026
VU
CRITICAL
Vulnerabilities

Trend Micro Patches Critical RCE Flaws in Apex One Security Platform

Trend Micro addresses two critical vulnerabilities, CVE-2023-32524 and CVE-2023-32525, in its Apex One platform that allow for remote code execution.

Runtime Rebel Intel
4 min read·Feb 26, 2026