Sign in

Rishi

@rxerium.com
27 followers 9 following 94 posts

CTI // rxerium.com

PostsRepliesMedia
Rishi @rxerium.com · 12/09/2026
🚨 Detection for the actively exploited GitLab vulnerability tagged as CVE-2026-85706 (CVSS 10.0) available here: github.com/projectdisco...
010
Rishi @rxerium.com · 27/08/2026
🚨 PaperCut NG/MF seeing active exploitation in the wild, as reported by @PrevidianCyber No CVE has been assigned at the time of posting. ~2000 instances of PaperCut NG/MF exposed to the internet which are likely vulnerable www.shodan.io/search?query...
100
Rishi @rxerium.com · 03/08/2026
🇺🇸👋 Looking forward to Hacker Summer Camp in Vegas this week. Full schedule below. If you're around, lets connect. #HackerSummerCamp #DEFCON #BSidesLV
000
Rishi @rxerium.com · 15/07/2026
🚨 Two actively exploited zero-days affecting SonicWall SMA1000 appliances: CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2) I’ve created vulnerability detection templates here (with confidence levels): CVE-2026-15409: github.com/rxerium/rxer... CVE-2026-15410: github.com/rxerium/rxer...
120
Rishi @rxerium.com · 10/07/2026
🚨 Progress is warning ShareFile customers to shut down their Storage Zone Controller servers after identifying a "credible external security threat" targeting the on-prem side of the file sharing platform Live status: status.sharefile.com
100
Rishi @rxerium.com · 17/06/2026
🚨 Critical improper access control vulnerability tagged CVE-2026-48907, affecting Joomla Content Editor is seeing active exploitation in the wild (reported by CISA) Vulnerability detection script: github.com/rxerium/rxer... Patches and mitigations: www.sentinelone.com/vulnerabilit...
000
Rishi @rxerium.com · 17/06/2026
It's been a year since I last had the chance to fix the template notifier feed, but it's now up and running again. Subscribe to get notified when a new detection script goes live: rxerium.com/templates-fe...
010
Rishi @rxerium.com · 16/06/2026
🚨 CVE-2026-53435, a high severity (CVSS 8.8) deserialization vulnerability in Jenkins is now seeing active exploitation as per @DefusedCyber . Scan your infrastructure: github.com/rxerium/rxer... Patches are available per the vendor advisory: jenkins.io/security/adv...
010
Rishi @rxerium.com · 10/06/2026
🚨 CVE-2026-10520, a critical CVSS 10 OS Command Injection vuln in Ivanti Sentry is now under active exploitation as reported by Defused Scan infrastructure to see if you're vulnerable: github.com/rxerium/rxer... Patches are available as per Ivanti's advisory: hub.ivanti.com/s/article/Se...
010
Rishi @rxerium.com · 21/04/2026
🇨🇿 In Prague this week for BSides Prague - if you’re around, it would be great to catch up! Drop me a DM 👋
010
Rishi @rxerium.com · 14/04/2026
🚨 Fortinet just disclosed CVE-2026-39808 and CVE-2026-39813 - 2 critical vulnerabilities affecting FortiSandbox. No active exploitation itw reported as of yet Scan your infrastructure to find vulnerable instances: CVE-2026-39808: github.com/rxerium/rxer... CVE-2026-39813: github.com/rxerium/rxer...
111
Rishi @rxerium.com · 12/04/2026
🚨 Pre-Auth RCE vuln tagged as CVE-2026-39987 (CVSS 9.3) seeing active exploitation in the wild as reported by Vulncheck and Bleeping Computer. Passively scan infrastructure to find potentially vulnerable instances: github.com/rxerium/rxer...
100
Rishi @rxerium.com · 04/04/2026
🚨 Forticlient EMS Zero Day disclosed minutes ago actively being exploited in the wild as being report by @DefusedCyber & @Fortinet I've created a vulnerability detection script to check for vulnerable instances: github.com/rxerium/rxer...
110
Rishi @rxerium.com · 30/03/2026
🚨 CVE-2026-21643 an SQL Injection vulnerability (CVSS 9.8) is seeing active exploitation in the wild as reported by @DefusedCyber Vulnerability detection script available here: github.com/rxerium/rxer... Upgrade to 7.4.5 or later as reported by Fortinet: fortiguard.fortinet.com/psirt/FG-IR-...
000
Rishi @rxerium.com · 18/02/2026
🚨 Mandiant have identified zero-day exploitation of a high-risk vulnerability in Dell RecoverPoint for Virtual Machines, tracked as CVE-2026-22769. RecoverPoint can be detected using this Nuclei template: github.com/projectdisco... Very limited exposure to the internet.
100
Rishi @rxerium.com · 05/02/2026
Yet another critical vulnerability in n8n - CVE-2026-25049 (CVSS 9.4). Vulnerability detection script here: github.com/rxerium/rxer... Patched versions are 1.123.17 / 2.5.2 as per: github.com/n8n-io/n8n/s...
010
Rishi @rxerium.com · 29/01/2026
🚨 2 new vulnerability scripts created for the n8n vulnerabilities disclosed today: CVE-2026-1470: github.com/rxerium/rxer... CVE-2026-0863: github.com/rxerium/rxer... Happy hunting.
000
Rishi @rxerium.com · 29/01/2026
🚨 2 critical authentication bypass and RCE vulns in Solarwinds WHD have been disclosed. Detection scripts can be found below: CVE-2025-40552: github.com/rxerium/rxer... CVE-2025-40554: github.com/rxerium/rxer...
100
Rishi @rxerium.com · 26/01/2026
🔎 With all the recent buzz around Clawdbot, I've created a Nuclei template to detect this product: github.com/projectdisco... Currently, there are 240 exposed instances (via Shodan) accessible on the internet at the time of posting, but I expect that number to grow: www.shodan.io/search?query...
010
Rishi @rxerium.com · 14/01/2026
🚨 CVE-2025-64155: Critical unauthenticated OS command injection in Fortinet FortiSIEM - CVSS 9.4 I've created a vulnerability detection script here: github.com/rxerium/rxer... Fortinet's advisory fortiguard.fortinet.com/psirt/FG-IR-...
020
Rishi @rxerium.com · 14/01/2026
🚨 Critical (CVSS 9.6) vulnerability in Appsmith allows account takeover via Origin header manipulation in password reset/email verification flows. I've created a vulnerability detection script here: github.com/rxerium/rxer... Reference: github.com/appsmithorg/...
000
Rishi @rxerium.com · 07/01/2026
🚨 Yet another critical (CVSS 10) vulnerability affecting n8n instances tagged as CVE-2026-21877. Vulnerability detection script here: github.com/rxerium/rxer... The issue has been resolved in n8n version 1.121.3. Advisory: github.com/advisories/G...
000
Rishi @rxerium.com · 30/12/2025
🚨 CVE-2025-52691 (CVSS 10) in SmarterMail allows unauthenticated arbitrary file upload leading to RCE. Affects Build ≤9406. Update to 9413+. Detection script: github.com/rxerium/CVE-2025-52691 CSA Alert: www.csa.gov.sg/alerts-and-a...
010
Rishi @rxerium.com · 22/12/2025
🚨 Critical RCE (CVSS 10) vulnerability affecting n8n instances: CVE-2025-68613 I've created a vulnerability detection script here: github.com/rxerium/CVE-... Advisory: github.com/n8n-io/n8n/s...
011
Rishi @rxerium.com · 27/11/2025
🇵🇹✈️ Next stop: Portugal I’m honoured to be delivering a workshop-style talk on DNS-based OSINT techniques at BSides Porto this Saturday, 29 November! If you’re attending, I’d love to meet up and discuss all things cyber! Looking forward to seeing you there 👋
010
Rishi @rxerium.com · 11/10/2025
🚨 Active Exploitation of Gladinet CentreStack and Triofox Local File Inclusion Flaw (CVE-2025-11371) I've created a vulnerability detection script here: github.com/rxerium/CVE-... As reported by Huntress this is an unauthenticated Local File Inclusion flaw in Gladinet CentreStack and Triofox.
110
Rishi @rxerium.com · 20/09/2025
🚨 Critical — CVE-2025-10035 (CVSS 10.0): Fortra has disclosed a deserialization flaw in the GoAnywhere MFT License Servlet that can allow remote command-injection. I've created a #nuclei script to detect vulnerable instances at scale: github.com/rxerium/CVE-...
100
Rishi @rxerium.com · 11/09/2025
Detection for critical SAP Netweaver vulnerability (CVE-2025-42944): github.com/rxerium/CVE-...
000
Rishi @rxerium.com · 04/09/2025
🚨 New zero day added to the CISA KEV under an hour ago and is actively being exploited in the wild - CVE-2025-53690; CVSS 9.0 (Critical) Check to see if you're vulnerable: github.com/rxerium/CVE-... Patches / workarounds are available: support.sitecore.com/kb?id=kb_art...
021
Rishi @rxerium.com · 17/08/2025
I've created a vulnerability script for CVE-2025-8875 and CVE-2025-8876 - both currently being actively exploited in the wild as reported by @cisacyber. Detection script: github.com/rxerium/CVE-... Patches are available: status.n-able.com/2025/08/13/a...
010
Rishi @rxerium.com · 01/08/2025
Catch me at #BSidesVegas or #DEFCON - I’ll be handing out exclusive UK OSINT swag. Come say hi and snag some before its all gone! 👋
041
Rishi @rxerium.com · 25/07/2025
Detection script for Micollab SQL injection vulnerability, tagged CVE-2025-52914 (high severity): github.com/rxerium/CVE-... www.mitel.com/support/secu...
010
Rishi @rxerium.com · 21/07/2025
I’m thrilled to be speaking at DEFCON in Las Vegas this year! I’ll be sharing insights from my recent contributions to the OWASP Amass project and Project Discovery’s Nuclei, focusing on DNS-based techniques for Product and Service Discovery. More details below:
100
Rishi @rxerium.com · 19/07/2025
🚨 new zero day affecting crushFTP instances (CVE-2025-54309) being exploited in the wild: ~291,903 exposed devices running crushFTP (as of 19.07.25) according to @shodanhq: `http.html:"crushftp"` Patch now: www.crushftp.com/crush11wiki/...
000
Rishi @rxerium.com · 16/07/2025
I've created a passive detection script to detect instances that are vulnerable to critical RCE tagged as CVE-2025-47812: github.com/rxerium/CVE-... Around ~4000 instances exposed to the internet as of 25.07.16 `http.favicon.hash:963565804`
000
Rishi @rxerium.com · 03/06/2025
I've created a script to detect CVE-2025-49113 based on versions exposed in the html body: github.com/rxerium/CVE-... Use at your own risk.
010
Rishi @rxerium.com · 26/04/2025
I've created a Nuclei template to detect this vulnerability looking at server headers: t.co/FLyLb7I0sJ
110
Rishi @rxerium.com · 02/04/2025
i've created 2 detection scripts to check if websites have been seized by the #fbi - the first looks at the html body for common phrases and the other looks at nameservers. nameserver detection: github.com/projectdisco... word matching: github.com/projectdisco... #security #CyberSecurity
010
Rishi @rxerium.com · 04/03/2025
esxi detection through Shodan: `html:"esxUiApp"` buff.ly/r6l4pRN you can use the PowerCLI tool to find versions though this only works locally: `Get-VMhost | Select-Object Name,Version,Build`
000
Rishi @rxerium.com · 28/01/2025
508k instances still possibly vulnerable to CVE-2024-12084 we can't detect versions of rsync over the internet but we can extract protocols from which we can map to versions vulnerable: <= 3.2.7 - protocol 31 unaffected: < 3.4.0 - protocol 32 buff.ly/4hx8udb
100