Sign in

Rishi

@rxerium.com
27 followers 9 following 94 posts

CTI // rxerium.com

PostsRepliesMedia
Reposted by Rishi
The Shadowserver Foundation @shadowserver.bsky.social · 13/09/2026
For MikroTik with SSH enabled, check out our Accessible SSH reporting (shadowserver.org/what-we-do/n...), with the tag 'mikrotik' dashboard.shadowserver.org/statistics/c... - just over 119K seen daily currently
shadowserver.org
INFO: Accessible SSH Report | The Shadowserver Foundation
This report identifies hosts that have the Secure Shell (SSH) service running and accessible on the Internet.
021
Rishi @rxerium.com · 15/09/2026
🚨 Reporting a critical vuln in the Issabel Framework (CVE‑2026‑89026), rated CVSS 9.8 with early signs of exploitation in the wild. The vuln involves a hard-coded JWT signing key that allows unauthenticated attackers to forge tokens and ultimately achieve RCE on the underlying Asterisk system
100
Rishi @rxerium.com · 12/09/2026
🚨 Detection for the actively exploited GitLab vulnerability tagged as CVE-2026-85706 (CVSS 10.0) available here: github.com/projectdisco...
010
Rishi @rxerium.com · 27/08/2026
it was a pleasure to present at the conference this year; thank you for hosting such a wonderful event.
010
Rishi @rxerium.com · 27/08/2026
🚨 PaperCut NG/MF seeing active exploitation in the wild, as reported by @PrevidianCyber No CVE has been assigned at the time of posting. ~2000 instances of PaperCut NG/MF exposed to the internet which are likely vulnerable www.shodan.io/search?query...
100
Rishi @rxerium.com · 24/08/2026
Here are the slides from the Ghost in the Hiring Machine talk we presented at BSidesLV and DEF CON for those that requested it: lnkd.in/dqGpapTY Thank you once again to everyone who came along and asked great questions. #OSINT #InfoSec #HiringFraud #IdentityVerification
lnkd.in
https://lnkd.in/dqGpapTY
000
Rishi @rxerium.com · 03/08/2026
🇺🇸👋 Looking forward to Hacker Summer Camp in Vegas this week. Full schedule below. If you're around, lets connect. #HackerSummerCamp #DEFCON #BSidesLV
000
Rishi @rxerium.com · 21/07/2026
Grateful to ProjectDiscovery for featuring me in its latest Community Spotlight. We spoke about Nuclei, OSINT, detection engineering and the lessons I’ve learnt from contributing more than 500 templates. Full interview: projectdiscovery.io/blog/communi...
projectdiscovery.io
Community Spotlight: Rishi (@rxerium) — ProjectDiscovery Blog
“Open source isn’t about perfection; it’s about putting an idea forward and improving it together as a community.” Rishi (@rxerium) If you’ve spent any time in the Nuclei Templates repository, you’ve…
000
Rishi @rxerium.com · 15/07/2026
🚨 Two actively exploited zero-days affecting SonicWall SMA1000 appliances: CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2) I’ve created vulnerability detection templates here (with confidence levels): CVE-2026-15409: github.com/rxerium/rxer... CVE-2026-15410: github.com/rxerium/rxer...
120
Rishi @rxerium.com · 10/07/2026
🚨 Progress is warning ShareFile customers to shut down their Storage Zone Controller servers after identifying a "credible external security threat" targeting the on-prem side of the file sharing platform Live status: status.sharefile.com
100
Rishi @rxerium.com · 09/07/2026
🚨🇦🇺 ACSC warns of a large-scale campaign exploiting CMS devices worldwide - actors are mass-scanning for unauth file upload, RCE, SSRF and deserialisation bugs to drop webshells. A list of Nuclei templates to help detect exposure to these CVEs: github.com/rxerium/cms-...
github.com
GitHub - rxerium/cms-exploitation-campaign: Large Scale Exploitation Campaign against CMS devices reported in July 2026
Large Scale Exploitation Campaign against CMS devices reported in July 2026 - rxerium/cms-exploitation-campaign
100
Rishi @rxerium.com · 29/06/2026
Excited to share that I'll be presenting at DEF CON once again this year - always an honour to be back. I'm also thrilled to be taking the stage alongside Michael Reimsbach at BSides Las Vegas. Full details coming soon. See you there! 🚀
010
Reposted by Rishi
Phillip Wylie @phillipwylie.bsky.social · 22/06/2026
I am looking forward to attending and speaking at Boardwalk Bytes in Atlantic City on July 10, 2026. It's a fun and information-packed conference. Tickets are still available; get yours today! See you there! Registration: www.eventbrite.com/e/boardwalk-... Agenda: boardwalkbytes.org/schedule/
041
Reposted by Rishi
The Shadowserver Foundation @shadowserver.bsky.social · 23/06/2026
Last week we added scanning for Joomla JCE editor extension CVE-2026-48907 vulnerable instances. This RCE vulnerability is exploited in the wild & on US CISA KEV. 4840 vulnerable instances seen 2026-06-22 down from 5146 on 2026-06-19. Top affected: US dashboard.shadowserver.org/statistics/c...
144
Rishi @rxerium.com · 17/06/2026
🚨 Critical improper access control vulnerability tagged CVE-2026-48907, affecting Joomla Content Editor is seeing active exploitation in the wild (reported by CISA) Vulnerability detection script: github.com/rxerium/rxer... Patches and mitigations: www.sentinelone.com/vulnerabilit...
000
Rishi @rxerium.com · 17/06/2026
It's been a year since I last had the chance to fix the template notifier feed, but it's now up and running again. Subscribe to get notified when a new detection script goes live: rxerium.com/templates-fe...
010
Rishi @rxerium.com · 16/06/2026
🚨 CVE-2026-53435, a high severity (CVSS 8.8) deserialization vulnerability in Jenkins is now seeing active exploitation as per @DefusedCyber . Scan your infrastructure: github.com/rxerium/rxer... Patches are available per the vendor advisory: jenkins.io/security/adv...
010
Rishi @rxerium.com · 16/06/2026
Looking forward to presenting with Michael at HackGlasgow! See you soon 🏴󠁧󠁢󠁳󠁣󠁴󠁿
020
Reposted by Rishi
Heinbrian @heinbrian.bsky.social · 11/06/2026
Last week I had the honour to do the closing Keynote for @elbsides.bsky.social together with CJ - the fantastic @dnsfilter.bsky.social team now published the slides, the recording and a transcript at www.dnsfilter.com/blog/who-com... A big shout out to the @elbsides.bsky.social team
053
Rishi @rxerium.com · 10/06/2026
🚨 CVE-2026-10520, a critical CVSS 10 OS Command Injection vuln in Ivanti Sentry is now under active exploitation as reported by Defused Scan infrastructure to see if you're vulnerable: github.com/rxerium/rxer... Patches are available as per Ivanti's advisory: hub.ivanti.com/s/article/Se...
010
Rishi @rxerium.com · 21/04/2026
🇨🇿 In Prague this week for BSides Prague - if you’re around, it would be great to catch up! Drop me a DM 👋
010
Rishi @rxerium.com · 14/04/2026
🚨 Fortinet just disclosed CVE-2026-39808 and CVE-2026-39813 - 2 critical vulnerabilities affecting FortiSandbox. No active exploitation itw reported as of yet Scan your infrastructure to find vulnerable instances: CVE-2026-39808: github.com/rxerium/rxer... CVE-2026-39813: github.com/rxerium/rxer...
111
Rishi @rxerium.com · 12/04/2026
🚨 Pre-Auth RCE vuln tagged as CVE-2026-39987 (CVSS 9.3) seeing active exploitation in the wild as reported by Vulncheck and Bleeping Computer. Passively scan infrastructure to find potentially vulnerable instances: github.com/rxerium/rxer...
100
Rishi @rxerium.com · 04/04/2026
🚨 Forticlient EMS Zero Day disclosed minutes ago actively being exploited in the wild as being report by @DefusedCyber & @Fortinet I've created a vulnerability detection script to check for vulnerable instances: github.com/rxerium/rxer...
110
Rishi @rxerium.com · 31/03/2026
🚨 Axios was hit by a supply chain attack as of the early hours of this morning. I'm currently hunting affected repos on GitHub, here is what I have so far: Vulnerable versions (via package.json): github.com/search?q=%2F... Presence of plain-crypto-js: github.com/search?q=pla...
github.com
210
Rishi @rxerium.com · 30/03/2026
🚨 CVE-2026-21643 an SQL Injection vulnerability (CVSS 9.8) is seeing active exploitation in the wild as reported by @DefusedCyber Vulnerability detection script available here: github.com/rxerium/rxer... Upgrade to 7.4.5 or later as reported by Fortinet: fortiguard.fortinet.com/psirt/FG-IR-...
000
Rishi @rxerium.com · 23/03/2026
🚨 CVE-2026-3055 (CVSS 9.3), a unauth memory overread vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances that could see active exploitation itw Vulnerability detection script: github.com/rxerium/rxer... Patches are available: support.citrix.com/support-home...
github.com
rxerium-templates/2026/CVE-2026-3055.yaml at main · rxerium/rxerium-templates
Nuclei scripts created by @rxerium for zero days / actively exploited vulnerabilities. - rxerium/rxerium-templates
011
Rishi @rxerium.com · 18/02/2026
🚨 Mandiant have identified zero-day exploitation of a high-risk vulnerability in Dell RecoverPoint for Virtual Machines, tracked as CVE-2026-22769. RecoverPoint can be detected using this Nuclei template: github.com/projectdisco... Very limited exposure to the internet.
100
Rishi @rxerium.com · 05/02/2026
Yet another critical vulnerability in n8n - CVE-2026-25049 (CVSS 9.4). Vulnerability detection script here: github.com/rxerium/rxer... Patched versions are 1.123.17 / 2.5.2 as per: github.com/n8n-io/n8n/s...
010
Rishi @rxerium.com · 29/01/2026
🚨 2 new vulnerability scripts created for the n8n vulnerabilities disclosed today: CVE-2026-1470: github.com/rxerium/rxer... CVE-2026-0863: github.com/rxerium/rxer... Happy hunting.
000
Rishi @rxerium.com · 29/01/2026
🚨 2 critical authentication bypass and RCE vulns in Solarwinds WHD have been disclosed. Detection scripts can be found below: CVE-2025-40552: github.com/rxerium/rxer... CVE-2025-40554: github.com/rxerium/rxer...
100
Rishi @rxerium.com · 26/01/2026
🔎 With all the recent buzz around Clawdbot, I've created a Nuclei template to detect this product: github.com/projectdisco... Currently, there are 240 exposed instances (via Shodan) accessible on the internet at the time of posting, but I expect that number to grow: www.shodan.io/search?query...
010
Reposted by Rishi
OWASP London Chapter @owasplondon.bsky.social · 25/01/2026
Many thanks to Rishi C (@rxerium.com) for presenting his talk: "DNS Based #OSINT Techniques for Product and Service Discovery" at our meetup last week. The video recording of the talk is available to watch 📺 on the #OWASPLondon YouTube Channel [PLEASE SUBSCRIBE!]: 👇 www.youtube.com/watch?v=lGO3...
youtube.com
DNS Based OSINT Techniques for Product and Service Discovery - Rishi C
YouTube video by OWASP London
023
Rishi @rxerium.com · 14/01/2026
🔍 Compete with 200 others and put your investigation skills to the test! CTFs are one of the best ways to develop real-world OSINT skills. You’ll learn new techniques, discover useful tools, and practice creative problem-solving in realistic scenarios. Join the UK OSINT Community CTF today 👇
020
Rishi @rxerium.com · 14/01/2026
🚨 CVE-2025-64155: Critical unauthenticated OS command injection in Fortinet FortiSIEM - CVSS 9.4 I've created a vulnerability detection script here: github.com/rxerium/rxer... Fortinet's advisory fortiguard.fortinet.com/psirt/FG-IR-...
020
Rishi @rxerium.com · 14/01/2026
🚨 Critical (CVSS 9.6) vulnerability in Appsmith allows account takeover via Origin header manipulation in password reset/email verification flows. I've created a vulnerability detection script here: github.com/rxerium/rxer... Reference: github.com/appsmithorg/...
000
Rishi @rxerium.com · 09/01/2026
Following the recently released CTF challenge from the UK OSINT Community, Joshua Richards will be walking through the approach, key decisions, and OSINT techniques used step by step. Join us tomorrow at 5PM GMT on the Discord for a live walkthrough. Join the Discord: osint.uk/join
020
Rishi @rxerium.com · 07/01/2026
🚨 Yet another critical (CVSS 10) vulnerability affecting n8n instances tagged as CVE-2026-21877. Vulnerability detection script here: github.com/rxerium/rxer... The issue has been resolved in n8n version 1.121.3. Advisory: github.com/advisories/G...
000
Rishi @rxerium.com · 30/12/2025
🚨 CVE-2025-52691 (CVSS 10) in SmarterMail allows unauthenticated arbitrary file upload leading to RCE. Affects Build ≤9406. Update to 9413+. Detection script: github.com/rxerium/CVE-2025-52691 CSA Alert: www.csa.gov.sg/alerts-and-a...
010
Rishi @rxerium.com · 22/12/2025
🚨 Critical RCE (CVSS 10) vulnerability affecting n8n instances: CVE-2025-68613 I've created a vulnerability detection script here: github.com/rxerium/CVE-... Advisory: github.com/n8n-io/n8n/s...
011
Rishi @rxerium.com · 27/11/2025
🇵🇹✈️ Next stop: Portugal I’m honoured to be delivering a workshop-style talk on DNS-based OSINT techniques at BSides Porto this Saturday, 29 November! If you’re attending, I’d love to meet up and discuss all things cyber! Looking forward to seeing you there 👋
010
Reposted by Rishi
SirAppSec @sirappsec.bsky.social · 21/11/2025
Is your AI coding agent a security expert? 20+ Claude Code skills: SAST • DAST • SCA • Secrets • Containers • Policy • Offensive Security - and more! Looking for testers and contributors 👀 github.com/AgentSecOps/... #DevSecOps #AI #Security #OpenSource #ClaudeCodeSkills #AgentSecOps #Claude
051
Rishi @rxerium.com · 11/10/2025
🚨 Active Exploitation of Gladinet CentreStack and Triofox Local File Inclusion Flaw (CVE-2025-11371) I've created a vulnerability detection script here: github.com/rxerium/CVE-... As reported by Huntress this is an unauthenticated Local File Inclusion flaw in Gladinet CentreStack and Triofox.
110
Rishi @rxerium.com · 05/10/2025
🚨 Critical zero-day tagged as CVE-2025-61882 (CVSS 9.8) affecting Oracle E-Business Suite I've created a vulnerability detection script here: github.com/rxerium/CVE-... This vulnerability is remotely exploitable without authentication.
github.com
GitHub - rxerium/CVE-2025-61882: Detection for CVE-2025-61882
Detection for CVE-2025-61882. Contribute to rxerium/CVE-2025-61882 development by creating an account on GitHub.
130
Rishi @rxerium.com · 23/09/2025
Solarwinds critical vuln - CVE-2025-26399 "Given SolarWinds’ past, in-the-wild exploitation is highly likely" as being reported by WatchTowr Labs I've created a detection script for this vuln: github.com/rxerium/CVE-... 128 currently vulnerable across 22 countries / 90 cities:
github.com
020
Rishi @rxerium.com · 20/09/2025
🚨 Critical — CVE-2025-10035 (CVSS 10.0): Fortra has disclosed a deserialization flaw in the GoAnywhere MFT License Servlet that can allow remote command-injection. I've created a #nuclei script to detect vulnerable instances at scale: github.com/rxerium/CVE-...
100
Rishi @rxerium.com · 11/09/2025
Detection for critical SAP Netweaver vulnerability (CVE-2025-42944): github.com/rxerium/CVE-...
000
Reposted by Rishi
UK OSINT Community @osint-community.bsky.social · 08/09/2025
🕵️‍♂️ New OSINT training drop: Learn how to use X (Twitter) Advanced Search to trace usernames, map networks & uncover hidden accounts. Presented by @rxerium.com for the UK OSINT Community. 🎥 Watch here: www.youtube.com/watch?v=Yj2m...
youtube.com
Using OSINT to Investigate on Twitter/X
YouTube video by UK OSINT Community
032
Rishi @rxerium.com · 04/09/2025
🚨 New zero day added to the CISA KEV under an hour ago and is actively being exploited in the wild - CVE-2025-53690; CVSS 9.0 (Critical) Check to see if you're vulnerable: github.com/rxerium/CVE-... Patches / workarounds are available: support.sitecore.com/kb?id=kb_art...
021
Rishi @rxerium.com · 28/08/2025
🚨 Undiscolsed zero day affecting FreePBX servers: - No patches are available at the time of this post. - Workarounds are to limit access to your FreePBX instance - I've created a detection template here to check if you're vulnerable: github.com/rxerium/free... #freepbx #zeroday #cybersecurity
github.com
GitHub - rxerium/freepbx-zeroday-detection: Zero day detection script for recent zero day affecting FreePBX instances - August 2025
Zero day detection script for recent zero day affecting FreePBX instances - August 2025 - GitHub - rxerium/freepbx-zeroday-detection: Zero day detection script for recent zero day affecting FreePB...
010