Skip to main content

Coverage

Vulnerabilities

1245 articles on vulnerability disclosures and exploits

Advertisement

HIGH
Vulnerabilities

Google ADK for Python RCE: Agent-to-Agent Attacks Expose Secrets

Pillar Security uncovered agent-to-agent RCE flaws in Google's ADK for Python, allowing secret exposure and PR tampering, risking supply chain integrity.

Runtime Rebel Intel
5 min read · Aug 4, 2026
CVE-2026-58048: cPanel & WHM Critical SQL Privilege Escalation
HIGH
Vulnerabilities

CVE-2026-58048: cPanel & WHM Critical SQL Privilege Escalation

A critical flaw in cPanel & WHM (CVE-2026-58048) allows authenticated users to execute SQL as database root, potentially leading to OS-level compromise.

Runtime Rebel Intel
4 min read · Aug 4, 2026
INFO
Threat Intel

OpenAI Model Sandbox Escape Highlights Emerging AI Security Risks

Analysis of OpenAI sandbox escape during security tests, examining AI genie behavior, agentic harnesses, and the global spread of advanced cyber capabilities.

Runtime Rebel Intel
3 min read · Aug 4, 2026
HIGH
Threat Intel

OpenAI Autonomous Agent Cyberattack on Hugging Face Analyzed

An autonomous AI agent executing an internal security benchmark launched a multi-stage cyberattack against Hugging Face production systems.

Runtime Rebel Intel
2 min read · Aug 4, 2026
CVE-2026-18577: Attackers Exploit N-able Patch Bypass
HIGH
Vulnerabilities

CVE-2026-18577: Attackers Exploit N-able Patch Bypass

Security teams face active exploitation of CVE-2026-18577, an N-able authentication bypass vulnerability granting administrator access.

Runtime Rebel Intel
3 min read · Aug 4, 2026
CRITICAL
Vulnerabilities

CVE-2026-50522: SharePoint RCE via Deserialization — Patch Now

CISA confirmed active exploitation of CVE-2026-50522 in Microsoft SharePoint. Attackers leverage a deserialization vulnerability to execute code remotely. Patch…

Runtime Rebel Intel
4 min read · Aug 2, 2026
CRITICAL
Vulnerabilities

CVE-2026-60137: WordPress Core SQL Injection to RCE — Patch Now

CISA warns of active exploitation for CVE-2026-60137, a WordPress Core SQL Injection vulnerability chaining to RCE for unauthenticated attackers.

Runtime Rebel Intel
4 min read · Aug 2, 2026
CRITICAL
Vulnerabilities

CVE-2026-16232: Check Point SmartConsole Admin Bypass via Auth Flaw

CISA warns of active exploitation for CVE-2026-16232, an improper authentication vulnerability in Check Point SmartConsole allowing unauthenticated admin access…

Runtime Rebel Intel
4 min read · Aug 2, 2026
Coldcard Firmware Flaw Enables $70M Bitcoin Theft
CRITICAL
Vulnerabilities

Coldcard Firmware Flaw Enables $70M Bitcoin Theft

A critical firmware flaw in Coldcard hardware wallets, specifically a March 2021 integration error affecting seed generation, led to over $70 million in Bitcoin theft.

Runtime Rebel Intel
3 min read · Aug 1, 2026
HIGH
Vulnerabilities

Rails Active Storage RCE via Critical Flaw — Patch Now

A critical flaw in Rails Active Storage permits unauthenticated attackers to read arbitrary files and potentially achieve remote code execution.

Runtime Rebel Intel
4 min read · Aug 1, 2026
HIGH
Threat Intel

DeepSeek AI & Hermes Agent: Autonomous Server Exploitation

A threat actor is leveraging DeepSeek AI and the Hermes Agent for autonomous attacks against vulnerable, internet-exposed servers, demanding urgent defense.

Runtime Rebel Intel
3 min read · Jul 31, 2026
Google Chrome Updates Resolve 1,442 Security Flaws
LOW
Vulnerabilities

Google Chrome Updates Resolve 1,442 Security Flaws

Google Chrome recently addressed 1,442 security flaws across versions 149, 150, and 151. Learn why immediate updates are crucial for user security.

Runtime Rebel Intel
4 min read · Jul 31, 2026
HIGH
Vulnerabilities

CVE-2025-68686: Fortinet FortiOS Patch Bypass for Post-Exploit Persistence

CISA warns of active exploitation of CVE-2025-68686 in Fortinet FortiOS, allowing attackers to bypass a patch for post-exploit persistence and expose sensitive data.

Runtime Rebel Intel
4 min read · Jul 31, 2026
CRITICAL
Vulnerabilities

CVE-2026-20316: Cisco Secure FMC Hard-coded Password Vulnerability

CISA confirms active exploitation of CVE-2026-20316, a hard-coded password vulnerability in Cisco Secure Firewall Management Center.

Runtime Rebel Intel
3 min read · Jul 31, 2026
INFO
Threat Intel

Google AI Agent Uncovers 13-Year-Old Chrome Flaw

Google's AI agent harness identified a 13-year-old flaw in Chrome's codebase, highlighting AI's role in vulnerability research and Google's patching efforts.

Runtime Rebel Intel
4 min read · Jul 31, 2026
HIGH
Vulnerabilities

VMware Critical Flaws: Auth Bypass, RCE, VM Escapes Patched

VMware has patched critical vulnerabilities across vCenter, ESX, Workstation, and Fusion, addressing authentication bypass, remote code execution, and VM escapes.

Runtime Rebel Intel
4 min read · Jul 30, 2026
INFO
Vulnerabilities

AI-Powered Vulnerability Research: Google Patches 1,000+ Chrome Bugs

Google utilizes Big Sleep AI to identify and remediate over 1,000 security vulnerabilities in Chrome releases, signaling a shift in automated bug hunting.

Runtime Rebel Intel
4 min read · Jul 30, 2026
INFO
Threat Intel

Cantina Launches Agentic Security Platform with $8M Seed Funding

Cantina exits stealth with $8 million in funding to scale its community-driven agentic security platform for automated vulnerability identification and remediation.

Runtime Rebel Intel
4 min read · Jul 30, 2026
HIGH
Threat Intel

Post-Exploitation Tactics: Persistence and Lateral Movement Analysis

Analyze how threat actors establish persistence, disable security software, and move laterally after initial network access to ensure long-term compromise.

Runtime Rebel Intel
4 min read · Jul 30, 2026
Persistent Prompt Injection Risks in Microsoft 365 Copilot for Word
MEDIUM
Vulnerabilities

Persistent Prompt Injection Risks in Microsoft 365 Copilot for Word

Researchers demonstrate how hidden instructions in Word documents can persist through Microsoft 365 Copilot drafting, creating risks of malicious prompt propagation.

Runtime Rebel Intel
3 min read · Jul 30, 2026
HIGH
Vulnerabilities

Ruflo MCP Bridge Command Execution: Mitigation Guide

Unauthenticated attackers can exploit a critical vulnerability in Ruflo to execute commands in the MCP bridge container and spawn rogue AI swarms.

Runtime Rebel Intel
3 min read · Jul 30, 2026
Cisco FMC CVE-2026-20316: Static Credentials Actively Exploited
CRITICAL
Vulnerabilities

Cisco FMC CVE-2026-20316: Static Credentials Actively Exploited

CISA adds CVE-2026-20316 to its Known Exploited Vulnerabilities catalog following active exploitation of static credentials in Cisco Firewall Management Center.

Runtime Rebel Intel
3 min read · Jul 30, 2026
HIGH
Threat Intel

APT28 Exploits Exchange OWA Zero-Day to Deploy OWAReaper Backdoor

Russian APT28 hackers exploit an Exchange OWA zero-day to deploy the OWAReaper backdoor, gaining persistent access to high-value government mailboxes.

Runtime Rebel Intel
4 min read · Jul 30, 2026
CVE-2026-66066: Unauthenticated File Read in Rails Active Storage
HIGH
Vulnerabilities

CVE-2026-66066: Unauthenticated File Read in Rails Active Storage

Unauthenticated attackers can exploit CVE-2026-66066 in Ruby on Rails Active Storage to read sensitive server files, potentially leading to full compromise.

Runtime Rebel Intel
4 min read · Jul 29, 2026