Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Rishi

@rxerium@infosec.exchange
  • Open on infosec.exchange

Senior Security Researcher // rxerium.com

0 Followers
0 Following
26 Posts
Joined October 29, 2024
Website:
https://rxerium.com

Posts

Open post
rxerium
Rishi @rxerium@infosec.exchange · Jul 21, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange
Grateful to ProjectDiscovery for featuring me in its latest Community Spotlight. We spoke about Nuclei, OSINT, detection engineering and the lessons I’ve learnt from contributing more than 500 templates. The milestone is humbling, but the community feedback and real-world impact have always mattered most. “Open source isn’t about perfection; it’s about putting an idea forward and improving it together as a community.” Full interview: https://projectdiscovery.io/blog/community-spotlight-rishi-rxerium
0
0
0
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Jul 15, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange
RE: https://infosec.exchange/@BSidesLV/116925530810107821 See you in Vegas 🤘
Quoting
BSides Las Vegas @BSidesLV@infosec.exchange
DPRK-attributed campaigns placed fake personas inside real companies. They passed interviews, collected paychecks, and accessed sensitive systems. How to spot them before you hire. See Michael Reimsbach and Rishi (@rxerium@infosec.exchange) @ Common Ground during #BSidesLV on Tue Aug 4 @ 15:00.
Open quoted post
1
0
0
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Jul 15, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange
Replying to @rxerium@infosec.exchange
Platform hotfixes are available through SonicWall’s security advisory: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
0
0
0
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Jul 15, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange
🚨 Two actively exploited zero-days affecting SonicWall SMA1000 appliances: CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2) I’ve created vulnerability detection templates here (with confidence levels): CVE-2026-15409: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-15409.yaml CVE-2026-15410: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-15410.yaml CVE-2026-15409 is remotely exploitable without authentication, while CVE-2026-15410 requires an authenticated administrator.
2
1
1
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Jul 10, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange

🚨 Progress is warning ShareFile customers to shut down their Storage Zone Controller servers after identifying a "credible external security threat" targeting the on-prem side of the file sharing platform

Progress has cut cloud access for affected accounts and says customers must also manually power off the Windows servers hosting the controllers. No indication of unauthorised access so far, with another update promised within 24 hours.

Live status:
https://status.sharefile.com/

0
1
0
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Jul 09, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange

🚨🇦🇺 ACSC warns of a large-scale campaign exploiting CMS devices worldwide - actors are mass-scanning for unauth file upload, RCE, SSRF and deserialisation bugs to drop webshells.

The hit list is wide: a stack of WordPress plugins + Craft CMS, MaxSite CMS, MetInfo CMS and Joomla JCE.

A list of Nuclei templates to help detect exposure to these CVEs:
https://github.com/rxerium/cms-exploitation-campaign

Advisory can be found below:
https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/large-scale-exploitation-campaign-targeting-website-content-management-systems-cms

0
0
0
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Jun 29, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange

Excited to share that I'll be presenting at DEF CON once again this year - always an honour to be back.

I'm also thrilled to be taking the stage alongside Michael Reimsbach at BSides Las Vegas.

Full details coming soon.

See you there! 🚀

1
0
1
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Jun 17, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange

🚨 New critical improper access control vulnerability tagged CVE-2026-48907, affecting Widget Factory Joomla Content Editor is seeing active exploitation in the wild as reported by CISA.

Vulnerability detection script available below:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-48907.yaml

Patches and mitigations are available:
https://www.sentinelone.com/vulnerability-database/cve-2026-48907/

0
0
0
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Jun 17, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange

It's been a year since I last had the chance to fix the template notifier feed, but it's now up and running again.

Subscribe to get notified when a new detection script goes live:
https://rxerium.com/templates-feed/

0
0
0
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Jun 16, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange

🚨 CVE-2026-53435, a high severity (CVSS 8.8) deserialization vulnerability in Jenkins is now seeing active exploitation as per Defused

Scan your infrastructure: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-53435.yaml

Patches are available per the vendor advisory: https://jenkins.io/security/advisory/2026-06-10/

0
0
0
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Jun 10, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange

🚨 CVE-2026-10520, a critical (CVSS 10.0) OS Command Injection vulnerability in Ivanti Sentry is now under active exploitation as reported by Defused

Scan infrastructure to see if you're vulnerable:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-10520.yaml

Patches are available as per Ivanti's advisory:
https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US

0
0
0
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Apr 21, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange

🇨🇿 In Prague this week for BSides Prague - if you’re around, it would be great to catch up! Drop me a DM 👋

0
0
0
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Apr 17, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange

RE: @BSidesLuxembourg@infosec.exchange

looking forward to presenting, see you in a few weeks 👋🇱🇺

3
0
2
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Apr 14, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange

🚨 Fortinet just disclosed CVE-2026-39808 and CVE-2026-39813 - 2 critical vulnerabilities affecting FortiSandbox. No active exploitation itw reported as of yet.

Scan your infrastructure to find vulnerable instances:
CVE-2026-39808: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-39808.yaml
CVE-2026-39813: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-39813.yaml

CVE-2026-39808 (CVSS 9.1):
An Improper Neutralization of Special Elements used in an OS Command ('OS command injection') vulnerability [CWE-78] in FortiSandbox may allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

CVE-2026-39813 (CVSS 9.1):
A Path Traversal vulnerability [CWE-24] in FortiSandbox JRPC API may allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests.

Patches are available as per vendor advisories:
https://fortiguard.fortinet.com/psirt/FG-IR-26-112
https://fortiguard.fortinet.com/psirt/FG-IR-26-100

1
0
1
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Apr 12, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange

🚨 Pre-Auth RCE vuln tagged as CVE-2026-39987 (CVSS 9.3) seeing active exploitation in the wild as reported by Vulncheck and Bleeping Computer.

Passively scan infrastructure to find potentially vulnerable instances:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-39987.yaml

An unauthenticated attacker can obtain a full interactive root shell on the server via a single WebSocket connection. No user interaction or authentication token is required, even when authentication is enabled on the marimo instance
https://github.com/marimo-team/marimo/security/advisories/GHSA-2679-6mx9-h9xc

0
0
0
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Apr 04, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange

🚨 Forticlient EMS Zero Day disclosed minutes ago actively being exploited in the wild as being report by @DefusedCyber & @fortinet@infosec.exchange

I've created a vulnerability detection script to check for vulnerable instances:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-35616.yaml

Fortinet recommends that you install hotfixes for EMS 7.4.5 / 7.4.6 as per their advisory:
https://www.fortiguard.com/psirt/FG-IR-26-099

0
0
2
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Mar 31, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange
Replying to @rxerium@infosec.exchange
Note: these queries only surface public repos that explicitly committed the affected versions. The impact is far wider.
0
0
0
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Mar 31, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange

🚨 Axios was hit by a supply chain attack as of the early hours of this morning.

I'm currently hunting affected repos on GitHub, here is what I have so far:

Vulnerable versions (via package.json):
https://github.com/search?q=%2F%5C%22axios%5C%22%3A%5Cs*%5C%22%281%5C.14%5C.1%7C0%5C.30%5C.4%29%5C%22%2F+path%3Apackage.json&type=code

Presence of plain-crypto-js:
https://github.com/search?q=plain-crypto-js+path%3Apackage-lock.json&type=code

Full technical analysis from StepSecurity:
https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan

0
1
0
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Mar 30, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange

🚨 CVE-2026-21643 an SQL Injection vulnerability (CVSS 9.8) is seeing active exploitation in the wild as reported by @DefusedCyber

Vulnerability detection script available here:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-21643.yaml

This vulnerability currently only affects FortiClientEMS 7.4.4 and it is recommended that you upgrade to 7.4.5 or later as reported by Fortinet:
https://fortiguard.fortinet.com/psirt/FG-IR-25-1142

0
0
0
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Mar 23, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange

🚨 CVE-2026-3055 (CVSS 9.3), a unauth memory overread vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances that could see active exploitation itw

Vulnerability detection script available here:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-3055.yaml

Patches are available as per Citrix's advisory:
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300

GitHub

rxerium-templates/2026/CVE-2026-3055.yaml at main · rxerium/rxerium-templates

Nuclei scripts created by @rxerium for zero days / actively exploited vulnerabilities. - rxerium/rxerium-templates

0
0
1
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Feb 18, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange

🚨 Mandiant have identified zero-day exploitation of a high-risk vulnerability in Dell RecoverPoint for Virtual Machines, tracked as CVE-2026-22769.

RecoverPoint can be detected using this Nuclei template:
https://github.com/projectdiscovery/nuclei-templates/pull/15377/changes

Very limited exposure to the internet.

Dell recommends upgrading to version 6.0.3.1 HF1 or later. Mitigations are also available.

Mandiant report:
https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day

0
0
0
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Feb 05, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange

Yet another critical vulnerability in n8n - CVE-2026-25049 (CVSS 9.4).

Vulnerability detection script here:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-25049.yaml

Patched versions are 1.123.17 / 2.5.2 as per:
https://github.com/n8n-io/n8n/security/advisories/GHSA-6cqr-8cfr-67f8

GitHub

rxerium-templates/2026/CVE-2026-25049.yaml at main · rxerium/rxerium-templates

Nuclei scripts created by @rxerium for zero days / actively exploited vulnerabilities. - rxerium/rxerium-templates

0
0
0
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Jan 29, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange

🚨 2 new vulnerability scripts created for the n8n vulnerabilities disclosed today:

CVE-2026-1470:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-1470.yaml

CVE-2026-0863:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-0863.yaml

Happy hunting.

GitHub

rxerium-templates/2026/CVE-2026-1470.yaml at main · rxerium/rxerium-templates

Nuclei scripts created by @rxerium for zero days / actively exploited vulnerabilities. - rxerium/rxerium-templates

0
0
0
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Jan 29, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange

🚨 2 critical authentication bypass and remote command execution vulnerabilities in Solarwinds WHD have been disclosed.

Vulnerability detection scripts can be found below:
CVE-2025-40552:
https://github.com/rxerium/rxerium-templates/blob/main/2025/CVE-2025-40552.yaml

CVE-2025-40554:
https://github.com/rxerium/rxerium-templates/blob/main/2025/CVE-2025-40554.yaml

At the time of writing there are no signs of active exploitation in the wild but it is strongly recommended that you patch as per Solarwind's security advisory:
https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm

0
0
0
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Jan 26, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange

🔎 With all the recent buzz around Clawdbot, I've created a Nuclei template to fingerprint and detect this product:
https://github.com/projectdiscovery/nuclei-templates/pull/15055

Currently, there are 240 exposed instances (via Shodan) accessible on the internet at the time of posting, but I expect that number to grow:
https://www.shodan.io/search?query=clawdbot-gw

0
0
0
0
Open post
rxerium
Rishi @rxerium@infosec.exchange · Jan 21, 2026
Rishi
@rxerium@infosec.exchange

Senior Security Researcher // rxerium.com

infosec.exchange
Replying to @securestep9@infosec.exchange
@securestep9@infosec.exchange @OWASPLondon@infosec.exchange Thank you Sam 🙏
0
0
0
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 00:32:09 UTC