Sign in

Rishi

@rxerium.com
27 followers 9 following 94 posts

CTI // rxerium.com

PostsRepliesMedia
Reposted by Rishi
UK OSINT Community @osint-community.bsky.social · 22h
A BIG thank you to Skylight:One for co-sponsoring the evening networking reception at the Global #OSINT Conference 🍻 🇬🇧 Learn more 👉 skylightinternet.com/
021
Reposted by Rishi
The Shadowserver Foundation @shadowserver.bsky.social · 13/09/2026
For MikroTik with SSH enabled, check out our Accessible SSH reporting (shadowserver.org/what-we-do/n...), with the tag 'mikrotik' dashboard.shadowserver.org/statistics/c... - just over 119K seen daily currently
shadowserver.org
INFO: Accessible SSH Report | The Shadowserver Foundation
This report identifies hosts that have the Secure Shell (SSH) service running and accessible on the Internet.
021
Rishi @rxerium.com · 15/09/2026
It carries a CVSS score of 9.8 and has already been observed being exploited in the wild by The Shadowserver Foundation (@shadowserver) as of 09/09. Thank you to @VulnCheck for the smooth collaboration throughout the CNA process. More details: www.cve.org/CVERecord?id...
cve.org
Common vulnerabilities and Exposures (CVE)
000
Rishi @rxerium.com · 15/09/2026
🚨 Reporting a critical vuln in the Issabel Framework (CVE‑2026‑89026), rated CVSS 9.8 with early signs of exploitation in the wild. The vuln involves a hard-coded JWT signing key that allows unauthenticated attackers to forge tokens and ultimately achieve RCE on the underlying Asterisk system
100
Rishi @rxerium.com · 12/09/2026
🚨 Detection for the actively exploited GitLab vulnerability tagged as CVE-2026-85706 (CVSS 10.0) available here: github.com/projectdisco...
010
Rishi @rxerium.com · 27/08/2026
it was a pleasure to present at the conference this year; thank you for hosting such a wonderful event.
010
Rishi @rxerium.com · 27/08/2026
PaperCut strongly recommends that you restrict web access to trusted IP addresses only. Emergency patches are available for those who are unable to restrict their PaperCut servers. Advisory: www.papercut.com/kb/Main/secu...
papercut.com
URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026)
Short description of what is in the security bulletin
010
Rishi @rxerium.com · 27/08/2026
🚨 PaperCut NG/MF seeing active exploitation in the wild, as reported by @PrevidianCyber No CVE has been assigned at the time of posting. ~2000 instances of PaperCut NG/MF exposed to the internet which are likely vulnerable www.shodan.io/search?query...
100
Rishi @rxerium.com · 24/08/2026
Here are the slides from the Ghost in the Hiring Machine talk we presented at BSidesLV and DEF CON for those that requested it: lnkd.in/dqGpapTY Thank you once again to everyone who came along and asked great questions. #OSINT #InfoSec #HiringFraud #IdentityVerification
lnkd.in
https://lnkd.in/dqGpapTY
000
Rishi @rxerium.com · 03/08/2026
🇺🇸👋 Looking forward to Hacker Summer Camp in Vegas this week. Full schedule below. If you're around, lets connect. #HackerSummerCamp #DEFCON #BSidesLV
000
Rishi @rxerium.com · 21/07/2026
Grateful to ProjectDiscovery for featuring me in its latest Community Spotlight. We spoke about Nuclei, OSINT, detection engineering and the lessons I’ve learnt from contributing more than 500 templates. Full interview: projectdiscovery.io/blog/communi...
projectdiscovery.io
Community Spotlight: Rishi (@rxerium) — ProjectDiscovery Blog
“Open source isn’t about perfection; it’s about putting an idea forward and improving it together as a community.” Rishi (@rxerium) If you’ve spent any time in the Nuclei Templates repository, you’ve…
000
Rishi @rxerium.com · 15/07/2026
CVE-2026-15409 is remotely exploitable without authentication, while CVE-2026-15410 requires an authenticated administrator. Platform hotfixes are available through SonicWall’s security advisory: psirt.global.sonicwall.com/vuln-detail/...
psirt.global.sonicwall.com
Security Advisory
000
Rishi @rxerium.com · 15/07/2026
🚨 Two actively exploited zero-days affecting SonicWall SMA1000 appliances: CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2) I’ve created vulnerability detection templates here (with confidence levels): CVE-2026-15409: github.com/rxerium/rxer... CVE-2026-15410: github.com/rxerium/rxer...
120
Rishi @rxerium.com · 10/07/2026
~460 look to be exposed to the internet at the time of sending this post: www.shodan.io/search?query... Bleeping Computer: www.bleepingcomputer.com/news/securit...
000
Rishi @rxerium.com · 10/07/2026
🚨 Progress is warning ShareFile customers to shut down their Storage Zone Controller servers after identifying a "credible external security threat" targeting the on-prem side of the file sharing platform Live status: status.sharefile.com
100
Rishi @rxerium.com · 09/07/2026
Advisory can be found below: www.cyber.gov.au/about-us/vie...
cyber.gov.au
000
Rishi @rxerium.com · 09/07/2026
🚨🇦🇺 ACSC warns of a large-scale campaign exploiting CMS devices worldwide - actors are mass-scanning for unauth file upload, RCE, SSRF and deserialisation bugs to drop webshells. A list of Nuclei templates to help detect exposure to these CVEs: github.com/rxerium/cms-...
github.com
GitHub - rxerium/cms-exploitation-campaign: Large Scale Exploitation Campaign against CMS devices reported in July 2026
Large Scale Exploitation Campaign against CMS devices reported in July 2026 - rxerium/cms-exploitation-campaign
100
Rishi @rxerium.com · 29/06/2026
Excited to share that I'll be presenting at DEF CON once again this year - always an honour to be back. I'm also thrilled to be taking the stage alongside Michael Reimsbach at BSides Las Vegas. Full details coming soon. See you there! 🚀
010
Reposted by Rishi
Phillip Wylie @phillipwylie.bsky.social · 22/06/2026
I am looking forward to attending and speaking at Boardwalk Bytes in Atlantic City on July 10, 2026. It's a fun and information-packed conference. Tickets are still available; get yours today! See you there! Registration: www.eventbrite.com/e/boardwalk-... Agenda: boardwalkbytes.org/schedule/
041
Reposted by Rishi
The Shadowserver Foundation @shadowserver.bsky.social · 23/06/2026
Last week we added scanning for Joomla JCE editor extension CVE-2026-48907 vulnerable instances. This RCE vulnerability is exploited in the wild & on US CISA KEV. 4840 vulnerable instances seen 2026-06-22 down from 5146 on 2026-06-19. Top affected: US dashboard.shadowserver.org/statistics/c...
144
Rishi @rxerium.com · 17/06/2026
🚨 Critical improper access control vulnerability tagged CVE-2026-48907, affecting Joomla Content Editor is seeing active exploitation in the wild (reported by CISA) Vulnerability detection script: github.com/rxerium/rxer... Patches and mitigations: www.sentinelone.com/vulnerabilit...
000
Rishi @rxerium.com · 17/06/2026
It's been a year since I last had the chance to fix the template notifier feed, but it's now up and running again. Subscribe to get notified when a new detection script goes live: rxerium.com/templates-fe...
010
Rishi @rxerium.com · 16/06/2026
🚨 CVE-2026-53435, a high severity (CVSS 8.8) deserialization vulnerability in Jenkins is now seeing active exploitation as per @DefusedCyber . Scan your infrastructure: github.com/rxerium/rxer... Patches are available per the vendor advisory: jenkins.io/security/adv...
010
Rishi @rxerium.com · 16/06/2026
Looking forward to presenting with Michael at HackGlasgow! See you soon 🏴󠁧󠁢󠁳󠁣󠁴󠁿
020
Reposted by Rishi
Heinbrian @heinbrian.bsky.social · 11/06/2026
Last week I had the honour to do the closing Keynote for @elbsides.bsky.social together with CJ - the fantastic @dnsfilter.bsky.social team now published the slides, the recording and a transcript at www.dnsfilter.com/blog/who-com... A big shout out to the @elbsides.bsky.social team
053
Rishi @rxerium.com · 10/06/2026
🚨 CVE-2026-10520, a critical CVSS 10 OS Command Injection vuln in Ivanti Sentry is now under active exploitation as reported by Defused Scan infrastructure to see if you're vulnerable: github.com/rxerium/rxer... Patches are available as per Ivanti's advisory: hub.ivanti.com/s/article/Se...
010
Rishi @rxerium.com · 21/04/2026
🇨🇿 In Prague this week for BSides Prague - if you’re around, it would be great to catch up! Drop me a DM 👋
010
Rishi @rxerium.com · 14/04/2026
Patches are available as per vendor advisories: fortiguard.fortinet.com/psirt/FG-IR-... fortiguard.fortinet.com/psirt/FG-IR-...
fortiguard.fortinet.com
PSIRT | FortiGuard Labs
None
001
Rishi @rxerium.com · 14/04/2026
🚨 Fortinet just disclosed CVE-2026-39808 and CVE-2026-39813 - 2 critical vulnerabilities affecting FortiSandbox. No active exploitation itw reported as of yet Scan your infrastructure to find vulnerable instances: CVE-2026-39808: github.com/rxerium/rxer... CVE-2026-39813: github.com/rxerium/rxer...
111
Rishi @rxerium.com · 12/04/2026
An unauthenticated attacker can obtain a full interactive root shell on the server via a single WebSocket connection. No user interaction or authentication token is required, even when authentication is enabled on the marimo instance. Patched version is 0.23.0: github.com/marimo-team/...
github.com
Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
## Summary Marimo (19.6k stars) has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint `/terminal/ws` lacks authentication validation, allowing an unauthenticated attacker to obtain a...
000
Rishi @rxerium.com · 12/04/2026
🚨 Pre-Auth RCE vuln tagged as CVE-2026-39987 (CVSS 9.3) seeing active exploitation in the wild as reported by Vulncheck and Bleeping Computer. Passively scan infrastructure to find potentially vulnerable instances: github.com/rxerium/rxer...
100
Rishi @rxerium.com · 04/04/2026
Fortinet recommends that you install hotfixes for EMS 7.4.5 / 7.4.6 as per their advisory: www.fortiguard.com/psirt/FG-IR-...
fortiguard.com
000
Rishi @rxerium.com · 04/04/2026
🚨 Forticlient EMS Zero Day disclosed minutes ago actively being exploited in the wild as being report by @DefusedCyber & @Fortinet I've created a vulnerability detection script to check for vulnerable instances: github.com/rxerium/rxer...
110
Rishi @rxerium.com · 31/03/2026
Note: these queries only surface public repos that explicitly committed the affected versions. The impact is far wider.
010
Rishi @rxerium.com · 31/03/2026
Full technical analysis from StepSecurity: www.stepsecurity.io/blog/axios-c...
stepsecurity.io
axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity
Hijacked maintainer account used to publish poisoned axios releases including 1.14.1 and 0.30.4. The attacker injected a hidden dependency that drops a cross platform RAT. We are actively…
000
Rishi @rxerium.com · 31/03/2026
🚨 Axios was hit by a supply chain attack as of the early hours of this morning. I'm currently hunting affected repos on GitHub, here is what I have so far: Vulnerable versions (via package.json): github.com/search?q=%2F... Presence of plain-crypto-js: github.com/search?q=pla...
github.com
210
Rishi @rxerium.com · 30/03/2026
🚨 CVE-2026-21643 an SQL Injection vulnerability (CVSS 9.8) is seeing active exploitation in the wild as reported by @DefusedCyber Vulnerability detection script available here: github.com/rxerium/rxer... Upgrade to 7.4.5 or later as reported by Fortinet: fortiguard.fortinet.com/psirt/FG-IR-...
000
Rishi @rxerium.com · 23/03/2026
🚨 CVE-2026-3055 (CVSS 9.3), a unauth memory overread vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances that could see active exploitation itw Vulnerability detection script: github.com/rxerium/rxer... Patches are available: support.citrix.com/support-home...
github.com
rxerium-templates/2026/CVE-2026-3055.yaml at main · rxerium/rxerium-templates
Nuclei scripts created by @rxerium for zero days / actively exploited vulnerabilities. - rxerium/rxerium-templates
011
Rishi @rxerium.com · 18/02/2026
Dell recommends upgrading to version 6.0.3.1 HF1 or later. Mitigations are also available. Mandiant report: cloud.google.com/blog/topics/...
cloud.google.com
UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day | Google Cloud Blog
UNC6201 utilizes a newly discovered zero-day in Dell RecoverPoint for Virtual Machines to deliver BRICKSTORM and subsequently backdoors.
000
Rishi @rxerium.com · 18/02/2026
🚨 Mandiant have identified zero-day exploitation of a high-risk vulnerability in Dell RecoverPoint for Virtual Machines, tracked as CVE-2026-22769. RecoverPoint can be detected using this Nuclei template: github.com/projectdisco... Very limited exposure to the internet.
100
Rishi @rxerium.com · 05/02/2026
Yet another critical vulnerability in n8n - CVE-2026-25049 (CVSS 9.4). Vulnerability detection script here: github.com/rxerium/rxer... Patched versions are 1.123.17 / 2.5.2 as per: github.com/n8n-io/n8n/s...
010
Rishi @rxerium.com · 29/01/2026
🚨 2 new vulnerability scripts created for the n8n vulnerabilities disclosed today: CVE-2026-1470: github.com/rxerium/rxer... CVE-2026-0863: github.com/rxerium/rxer... Happy hunting.
000
Rishi @rxerium.com · 29/01/2026
No signs of active exploitation in the wild yet but it is strongly recommended that you patch as per Solarwind's security advisory: documentation.solarwinds.com/en/success_c...
documentation.solarwinds.com
WHD 2026.1 release notes
SOLARWINDS ACADEMY
000
Rishi @rxerium.com · 29/01/2026
🚨 2 critical authentication bypass and RCE vulns in Solarwinds WHD have been disclosed. Detection scripts can be found below: CVE-2025-40552: github.com/rxerium/rxer... CVE-2025-40554: github.com/rxerium/rxer...
100
Rishi @rxerium.com · 26/01/2026
🔎 With all the recent buzz around Clawdbot, I've created a Nuclei template to detect this product: github.com/projectdisco... Currently, there are 240 exposed instances (via Shodan) accessible on the internet at the time of posting, but I expect that number to grow: www.shodan.io/search?query...
010
Reposted by Rishi
OWASP London Chapter @owasplondon.bsky.social · 25/01/2026
Many thanks to Rishi C (@rxerium.com) for presenting his talk: "DNS Based #OSINT Techniques for Product and Service Discovery" at our meetup last week. The video recording of the talk is available to watch 📺 on the #OWASPLondon YouTube Channel [PLEASE SUBSCRIBE!]: 👇 www.youtube.com/watch?v=lGO3...
youtube.com
DNS Based OSINT Techniques for Product and Service Discovery - Rishi C
YouTube video by OWASP London
023
Rishi @rxerium.com · 14/01/2026
🔍 Compete with 200 others and put your investigation skills to the test! CTFs are one of the best ways to develop real-world OSINT skills. You’ll learn new techniques, discover useful tools, and practice creative problem-solving in realistic scenarios. Join the UK OSINT Community CTF today 👇
020
Rishi @rxerium.com · 14/01/2026
🚨 CVE-2025-64155: Critical unauthenticated OS command injection in Fortinet FortiSIEM - CVSS 9.4 I've created a vulnerability detection script here: github.com/rxerium/rxer... Fortinet's advisory fortiguard.fortinet.com/psirt/FG-IR-...
020
Rishi @rxerium.com · 14/01/2026
🚨 Critical (CVSS 9.6) vulnerability in Appsmith allows account takeover via Origin header manipulation in password reset/email verification flows. I've created a vulnerability detection script here: github.com/rxerium/rxer... Reference: github.com/appsmithorg/...
000
Rishi @rxerium.com · 09/01/2026
Following the recently released CTF challenge from the UK OSINT Community, Joshua Richards will be walking through the approach, key decisions, and OSINT techniques used step by step. Join us tomorrow at 5PM GMT on the Discord for a live walkthrough. Join the Discord: osint.uk/join
020