13 Followers
5 Following
64 Posts
Senior Security Researcher // rxerium.com
Websitehttps://rxerium.com

🚨 CVE-2026-10520, a critical (CVSS 10.0) OS Command Injection vulnerability in Ivanti Sentry is now under active exploitation as reported by Defused

Scan infrastructure to see if you're vulnerable:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-10520.yaml

Patches are available as per Ivanti's advisory:
https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US

πŸ‡¨πŸ‡Ώ In Prague this week for BSides Prague - if you’re around, it would be great to catch up! Drop me a DM πŸ‘‹

RE: https://infosec.exchange/@BSidesLuxembourg/116420285582471119

looking forward to presenting, see you in a few weeks πŸ‘‹πŸ‡±πŸ‡Ί

πŸ” Inside the Tech: New Talk Added to BSides Luxembourg

πŸŒπŸ“‘ π—§π—›π—˜ 𝗙𝗒π—₯π—šπ—’π—§π—§π—˜π—‘ π—™π—œπ—‘π—šπ—˜π—₯𝗣π—₯π—œπ—‘π—§: 𝗗𝗑𝗦 π—•π—”π—¦π—˜π—— π—’π—¦π—œπ—‘π—§ π—§π—˜π—–π—›π—‘π—œπ—€π—¨π—˜π—¦ 𝗙𝗒π—₯ 𝗣π—₯𝗒𝗗𝗨𝗖𝗧 & π—¦π—˜π—₯π—©π—œπ—–π—˜ π——π—œπ—¦π—–π—’π—©π—˜π—₯𝗬 – Rishi ( @rxerium )

⚑ Reveal hidden infrastructure in a Talk (40 min) using DNS TXT records to map technologies, dependencies, and external services at scale.

DNS is often treated as infrastructure plumbing, but TXT records quietly expose far more than most defenders realize. This session introduces a DNS-based OSINT methodology that leverages large-scale TXT record analysis to uncover embedded service dependencies such as cloud platforms, SaaS integrations, and identity providers.

By programmatically scanning DNS zones and integrating the technique into tools like Nuclei and OWASP Amass, this approach enables security teams to build detailed maps of organizational technology stacks and attack surfaces. A real-world case study from the Salesloft breach demonstrates how these signals translate into actionable intelligence for both offensive and defensive use cases.

Rishi ( @rxerium ) is a London-based security researcher focused on vulnerability research, threat intelligence, and OSINT-driven attack surface discovery. He contributes to open-source security tooling, supports the UK OSINT community, and focuses on building scalable reconnaissance and detection methodologies.

πŸ“… Conference Dates: 6–8 May 2026 | 09:00–18:00
πŸ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/

πŸ“… Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/

πŸ“² View full schedule & build your agenda: https://hackertracker.app/schedule?conf=BSIDESLUX2026

#BSidesLuxembourg2026 #OSINT #DNS #AttackSurface #ThreatIntelligence #CyberSecurity

🚨 Fortinet just disclosed CVE-2026-39808 and CVE-2026-39813 - 2 critical vulnerabilities affecting FortiSandbox. No active exploitation itw reported as of yet.

Scan your infrastructure to find vulnerable instances:
CVE-2026-39808: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-39808.yaml
CVE-2026-39813: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-39813.yaml

CVE-2026-39808 (CVSS 9.1):
An Improper Neutralization of Special Elements used in an OS Command ('OS command injection') vulnerability [CWE-78] in FortiSandbox may allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

CVE-2026-39813 (CVSS 9.1):
A Path Traversal vulnerability [CWE-24] in FortiSandbox JRPC API may allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests.

Patches are available as per vendor advisories:
https://fortiguard.fortinet.com/psirt/FG-IR-26-112
https://fortiguard.fortinet.com/psirt/FG-IR-26-100

🚨 Pre-Auth RCE vuln tagged as CVE-2026-39987 (CVSS 9.3) seeing active exploitation in the wild as reported by Vulncheck and Bleeping Computer.

Passively scan infrastructure to find potentially vulnerable instances:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-39987.yaml

An unauthenticated attacker can obtain a full interactive root shell on the server via a single WebSocket connection. No user interaction or authentication token is required, even when authentication is enabled on the marimo instance
https://github.com/marimo-team/marimo/security/advisories/GHSA-2679-6mx9-h9xc

Another talk announcement for BSides Luxembourg!

🎣⚑ 𝗙π—₯𝗒𝗠 π— π—”π—‘π—¨π—”π—Ÿ 𝗛𝗨𝗑𝗧 𝗧𝗒 𝗠𝗔𝗦𝗦 π——π—˜π—§π—˜π—–π—§π—œπ—’π—‘: π—ͺπ—˜π—”π—£π—’π—‘π—œπ—¦π—œπ—‘π—š π—‘π—¨π—–π—Ÿπ—˜π—œ π—”π—šπ—”π—œπ—‘π—¦π—§ π—£π—›π—œπ—¦π—›π—œπ—‘π—š – Rishi @rxerium

Phishing isn’t slowing downβ€”but your detection can scale.

This talk shows how open-source automation with Nuclei transforms phishing detection from manual investigation into a fast, proactive, and scalable process. Learn how hundreds of templates can identify malicious sites across thousands of targets in seconds.

Rishi (@rxerium) is a security researcher focused on vulnerability research, threat intelligence, and large-scale detection techniques, contributing extensively to open-source security tooling.

πŸ“… Conference Dates: 6–8 May 2026 | 09:00–18:00
πŸ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/

πŸ“… Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/

#BSidesLuxembourg2026 #Phishing #ThreatIntel #OSINT #CyberSecurity #Automation

🚨 Forticlient EMS Zero Day disclosed minutes ago actively being exploited in the wild as being report by @DefusedCyber & @fortinet

I've created a vulnerability detection script to check for vulnerable instances:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-35616.yaml

Fortinet recommends that you install hotfixes for EMS 7.4.5 / 7.4.6 as per their advisory:
https://www.fortiguard.com/psirt/FG-IR-26-099

Note: these queries only surface public repos that explicitly committed the affected versions. The impact is far wider.

🚨 Axios was hit by a supply chain attack as of the early hours of this morning.

I'm currently hunting affected repos on GitHub, here is what I have so far:

Vulnerable versions (via package.json):
https://github.com/search?q=%2F%5C%22axios%5C%22%3A%5Cs*%5C%22%281%5C.14%5C.1%7C0%5C.30%5C.4%29%5C%22%2F+path%3Apackage.json&type=code

Presence of plain-crypto-js:
https://github.com/search?q=plain-crypto-js+path%3Apackage-lock.json&type=code

Full technical analysis from StepSecurity:
https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan

Build software better, together

GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.

GitHub