Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Rishi

@rxerium@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Senior Security Researcher // rxerium.com

16 Followers
7 Following
26 Posts
Joined October 29, 2024
Website:
https://rxerium.com
Open post
Rishi @rxerium@infosec.exchange
· 2mo ago
🚨 Two actively exploited zero-days affecting SonicWall SMA1000 appliances: CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2) I’ve created vulnerability detection templates here (with confidence levels): CVE-2026-15409: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-15409.yaml CVE-2026-15410: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-15410.yaml CVE-2026-15409 is remotely exploitable without authentication, while CVE-2026-15410 requires an authenticated administrator.
github.com
2
1
1
0
Open post
Rishi @rxerium@infosec.exchange
· 2mo ago
RE: https://infosec.exchange/@BSidesLV/116925530810107821 See you in Vegas 🤘
Open quoted post
Quoting
BSides Las Vegas
@BSidesLV@infosec.exchange
DPRK-attributed campaigns placed fake personas inside real companies. They passed interviews, collected paychecks, and accessed sensitive systems. How to spot them before you hire. See Michael Reimsbach and Rishi (@rxerium@infosec.exchange) @ Common Ground during #BSidesLV on Tue Aug 4 @ 15:00.
Open quoted post
infosec.exchange
1
0
0
0
Open post
Rishi @rxerium@infosec.exchange
· 5mo ago

RE: @BSidesLuxembourg@infosec.exchange

looking forward to presenting, see you in a few weeks 👋🇱🇺

infosec.exchange
3
0
2
0
Open post
Rishi @rxerium@infosec.exchange
· 3mo ago

Excited to share that I'll be presenting at DEF CON once again this year - always an honour to be back.

I'm also thrilled to be taking the stage alongside Michael Reimsbach at BSides Las Vegas.

Full details coming soon.

See you there! 🚀

1
0
1
0
Open post
Rishi @rxerium@infosec.exchange
· 5mo ago

🚨 Fortinet just disclosed CVE-2026-39808 and CVE-2026-39813 - 2 critical vulnerabilities affecting FortiSandbox. No active exploitation itw reported as of yet.

Scan your infrastructure to find vulnerable instances:
CVE-2026-39808: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-39808.yaml
CVE-2026-39813: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-39813.yaml

CVE-2026-39808 (CVSS 9.1):
An Improper Neutralization of Special Elements used in an OS Command ('OS command injection') vulnerability [CWE-78] in FortiSandbox may allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

CVE-2026-39813 (CVSS 9.1):
A Path Traversal vulnerability [CWE-24] in FortiSandbox JRPC API may allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests.

Patches are available as per vendor advisories:
https://fortiguard.fortinet.com/psirt/FG-IR-26-112
https://fortiguard.fortinet.com/psirt/FG-IR-26-100

github.com
1
0
1
0
Open post
Rishi @rxerium@infosec.exchange
· 6mo ago
Replying to
Note: these queries only surface public repos that explicitly committed the affected versions. The impact is far wider.
0
0
0
0
Open post
Rishi @rxerium@infosec.exchange
· 5mo ago

🚨 Pre-Auth RCE vuln tagged as CVE-2026-39987 (CVSS 9.3) seeing active exploitation in the wild as reported by Vulncheck and Bleeping Computer.

Passively scan infrastructure to find potentially vulnerable instances:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-39987.yaml

An unauthenticated attacker can obtain a full interactive root shell on the server via a single WebSocket connection. No user interaction or authentication token is required, even when authentication is enabled on the marimo instance
https://github.com/marimo-team/marimo/security/advisories/GHSA-2679-6mx9-h9xc

github.com
0
0
0
0
Open post
Rishi @rxerium@infosec.exchange
· 6mo ago

🚨 Forticlient EMS Zero Day disclosed minutes ago actively being exploited in the wild as being report by @DefusedCyber & @fortinet@infosec.exchange

I've created a vulnerability detection script to check for vulnerable instances:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-35616.yaml

Fortinet recommends that you install hotfixes for EMS 7.4.5 / 7.4.6 as per their advisory:
https://www.fortiguard.com/psirt/FG-IR-26-099

github.com
0
0
2
0
Open post
Rishi @rxerium@infosec.exchange
· 6mo ago

🚨 CVE-2026-21643 an SQL Injection vulnerability (CVSS 9.8) is seeing active exploitation in the wild as reported by @DefusedCyber

Vulnerability detection script available here:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-21643.yaml

This vulnerability currently only affects FortiClientEMS 7.4.4 and it is recommended that you upgrade to 7.4.5 or later as reported by Fortinet:
https://fortiguard.fortinet.com/psirt/FG-IR-25-1142

github.com
0
0
0
0
Open post
Rishi @rxerium@infosec.exchange
· 6mo ago

🚨 CVE-2026-3055 (CVSS 9.3), a unauth memory overread vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances that could see active exploitation itw

Vulnerability detection script available here:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-3055.yaml

Patches are available as per Citrix's advisory:
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300

github.com
0
0
1
0
Open post
Rishi @rxerium@infosec.exchange
· 7mo ago

🚨 Mandiant have identified zero-day exploitation of a high-risk vulnerability in Dell RecoverPoint for Virtual Machines, tracked as CVE-2026-22769.

RecoverPoint can be detected using this Nuclei template:
https://github.com/projectdiscovery/nuclei-templates/pull/15377/changes

Very limited exposure to the internet.

Dell recommends upgrading to version 6.0.3.1 HF1 or later. Mitigations are also available.

Mandiant report:
https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day

github.com
0
0
0
0
Open post
Rishi @rxerium@infosec.exchange
· 8mo ago

Yet another critical vulnerability in n8n - CVE-2026-25049 (CVSS 9.4).

Vulnerability detection script here:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-25049.yaml

Patched versions are 1.123.17 / 2.5.2 as per:
https://github.com/n8n-io/n8n/security/advisories/GHSA-6cqr-8cfr-67f8

github.com
0
0
0
0
Open post
Rishi @rxerium@infosec.exchange
· 8mo ago

🚨 2 new vulnerability scripts created for the n8n vulnerabilities disclosed today:

CVE-2026-1470:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-1470.yaml

CVE-2026-0863:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-0863.yaml

Happy hunting.

github.com
0
0
0
0
Open post
Rishi @rxerium@infosec.exchange
· 8mo ago

🚨 2 critical authentication bypass and remote command execution vulnerabilities in Solarwinds WHD have been disclosed.

Vulnerability detection scripts can be found below:
CVE-2025-40552:
https://github.com/rxerium/rxerium-templates/blob/main/2025/CVE-2025-40552.yaml

CVE-2025-40554:
https://github.com/rxerium/rxerium-templates/blob/main/2025/CVE-2025-40554.yaml

At the time of writing there are no signs of active exploitation in the wild but it is strongly recommended that you patch as per Solarwind's security advisory:
https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm

github.com
0
0
0
0
Open post
Rishi @rxerium@infosec.exchange
· 8mo ago

🔎 With all the recent buzz around Clawdbot, I've created a Nuclei template to fingerprint and detect this product:
https://github.com/projectdiscovery/nuclei-templates/pull/15055

Currently, there are 240 exposed instances (via Shodan) accessible on the internet at the time of posting, but I expect that number to grow:
https://www.shodan.io/search?query=clawdbot-gw

github.com
0
0
0
0
Open post
Rishi @rxerium@infosec.exchange
· 5mo ago

🇨🇿 In Prague this week for BSides Prague - if you’re around, it would be great to catch up! Drop me a DM 👋

0
0
0
0
Open post
Rishi @rxerium@infosec.exchange
· 2mo ago
Grateful to ProjectDiscovery for featuring me in its latest Community Spotlight. We spoke about Nuclei, OSINT, detection engineering and the lessons I’ve learnt from contributing more than 500 templates. The milestone is humbling, but the community feedback and real-world impact have always mattered most. “Open source isn’t about perfection; it’s about putting an idea forward and improving it together as a community.” Full interview: https://projectdiscovery.io/blog/community-spotlight-rishi-rxerium
projectdiscovery.io
0
0
0
0
Open post
Rishi @rxerium@infosec.exchange
· 2mo ago

🚨 Progress is warning ShareFile customers to shut down their Storage Zone Controller servers after identifying a "credible external security threat" targeting the on-prem side of the file sharing platform

Progress has cut cloud access for affected accounts and says customers must also manually power off the Windows servers hosting the controllers. No indication of unauthorised access so far, with another update promised within 24 hours.

Live status:
https://status.sharefile.com/

status.sharefile.com
0
1
0
0
Open post
Rishi @rxerium@infosec.exchange
· 3mo ago

🚨🇦🇺 ACSC warns of a large-scale campaign exploiting CMS devices worldwide - actors are mass-scanning for unauth file upload, RCE, SSRF and deserialisation bugs to drop webshells.

The hit list is wide: a stack of WordPress plugins + Craft CMS, MaxSite CMS, MetInfo CMS and Joomla JCE.

A list of Nuclei templates to help detect exposure to these CVEs:
https://github.com/rxerium/cms-exploitation-campaign

Advisory can be found below:
https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/large-scale-exploitation-campaign-targeting-website-content-management-systems-cms

github.com
0
0
0
0
Open post
Rishi @rxerium@infosec.exchange
· 3mo ago

🚨 New critical improper access control vulnerability tagged CVE-2026-48907, affecting Widget Factory Joomla Content Editor is seeing active exploitation in the wild as reported by CISA.

Vulnerability detection script available below:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-48907.yaml

Patches and mitigations are available:
https://www.sentinelone.com/vulnerability-database/cve-2026-48907/

github.com
0
0
0
0
Open post
Rishi @rxerium@infosec.exchange
· 3mo ago

It's been a year since I last had the chance to fix the template notifier feed, but it's now up and running again.

Subscribe to get notified when a new detection script goes live:
https://rxerium.com/templates-feed/

rxerium.com
0
0
0
0
Open post
Rishi @rxerium@infosec.exchange
· 3mo ago

🚨 CVE-2026-53435, a high severity (CVSS 8.8) deserialization vulnerability in Jenkins is now seeing active exploitation as per Defused

Scan your infrastructure: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-53435.yaml

Patches are available per the vendor advisory: https://jenkins.io/security/advisory/2026-06-10/

github.com
0
0
0
0
Open post
Rishi @rxerium@infosec.exchange
· 3mo ago

🚨 CVE-2026-10520, a critical (CVSS 10.0) OS Command Injection vulnerability in Ivanti Sentry is now under active exploitation as reported by Defused

Scan infrastructure to see if you're vulnerable:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-10520.yaml

Patches are available as per Ivanti's advisory:
https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US

github.com
0
0
0
0
Open post
Rishi @rxerium@infosec.exchange
· 8mo ago
Replying to
@securestep9@infosec.exchange @OWASPLondon@infosec.exchange Thank you Sam 🙏
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:36:59 UTC