Skip to content
View rxerium's full-sized avatar
💥
rise and grind
💥
rise and grind

Highlights

  • Pro

Organizations

@alph4-org

Block or report rxerium

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
rxerium/README.md

Rishi — vulnerability research & threat intelligence

Rishi — @rxerium

Vulnerability researcher and threat intelligence specialist in London, UK — CTI at The Shadowserver Foundation and part of the executive leadership of the UK OSINT community. Detection research recognised by governments across North America, Europe and Asia, and trusted by national cyber authorities and law enforcement.

Full profile: rxerium.com/about

📊 At a glance

🛡️ Nuclei templates 950+ authored · 530+ merged upstream · 73 covering CISA KEV
🎤 Conference talks 17 sessions across 8 countries · 2 workshops
🏛️ Gov & CERT citations 7 — NCSC (UK), CERT Polska, NIST/NVD, INCIBE (ES), CIRCL (LU), Cal-CSIC, Vietnam
🐛 CVEs disclosed 11 — 3 Critical (CVSS 9.8) · 8 High (CVSS 7.5)

🔄 Stats auto-synced weekly from rxerium.com/about — the website is the source of truth.

🛠️ Open source & projects

Project What it is
rxerium-templates ⭐ Open-source Nuclei detection templates for critical CVEs & zero-days — 950+ templates used worldwide
CISA-KEV Automated tracking of Nuclei template coverage against the CISA Known Exploited Vulnerabilities catalog
cms-exploitation-campaign Analysis of a large-scale CMS exploitation campaign (Jul 2026)
ai-bot-ip-ranges Official IP ranges for AI bot crawlers, auto-updated weekly
responsible-disclosure-email-gathering Workflow to gather responsible disclosure emails from given hosts
OWASP Amass Contributor — in-depth attack surface mapping & asset discovery

🐛 Disclosed CVEs

CVE Product Impact Severity
CVE-2026-89026 Issabel Framework / Issabel PBX Hardcoded JWT key leading to remote command execution, exploited in the wild 🔴 Critical · 9.8
CVE-2023-54399 Hongjing e-HR Unauthenticated SQL injection 🔴 Critical · 9.8
CVE-2023-54400 Fumasoft Fumeng Cloud Unauthenticated SQL injection 🔴 Critical · 9.8
CVE-2024-58388 Sharp / Toshiba Tec MFPs Local file inclusion via directory traversal 🟠 High · 7.5
CVE-2024-58387 Inspur Haiyue HCM Cloud Arbitrary file read 🟠 High · 7.5
CVE-2023-54403 Yonyou U8 CRM Arbitrary file read with authentication bypass 🟠 High · 7.5
CVE-2023-54402 iDocView SSRF leading to local file read 🟠 High · 7.5
CVE-2021-48008 Chanjet CRM Unauthenticated SQL injection 🟠 High · 7.5
CVE-2019-25776 Weaver E-cology Unauthenticated SQL injection 🟠 High · 7.5
CVE-2017-20284 Caucho Resin Path traversal file read 🟠 High · 7.5
CVE-2015-20122 Seeyon A6 OA Unauthenticated SQL injection 🟠 High · 7.5

Full details: rxerium.com/about/#cves

🎤 Speaking

Multi-time DEF CON speaker across the Red Team, Recon and Social Engineering Villages, plus the BSides circuit, OWASP London, and a briefing for the UK government & policymakers. Next up: SecTor 2026, Toronto.

Circuit Highlights
DEF CON Villages, Las Vegas Red Team Village (DNS OSINT) · Recon Village · SE Village workshops (Zero Day Hire) · Amass workshop
BSides & community Las Vegas · Cymru · Porto · Prague · Budapest (×2) · Luxembourg (×2) · Hack Glasgow · ElbSides Hamburg
Industry & policy OWASP London · SecTor Toronto · UK Parliament briefing on supply-chain risk

Full history: rxerium.com/talks

🏆 Recognition

Who What
NCSC (UK Government) Recognised detection script for GoAnywhere MFT exploitation (CVE-2025-10035)
CERT Polska Adopted detection scripts into Artemis tooling (CVE-2025-49113, CVE-2025-68461)
NIST / NVD Featured detection script on the official CVE-2023-40000 advisory
INCIBE (ES) · CIRCL (LU) · Cal-CSIC · Gov. of Vietnam Referenced/cited detection research in national guidance & advisories
BSides Las Vegas 2025 🏅 ProsVJoes CTF winner

Industry citations: SonicWall · Qualys · Censys · ReSecurity · Coalition and more. Press: GBHackers · The Hacker News · Cybersecurity News. Podcasts/newsletters: SANS Stormcast · SecurityIntel · Exploit Bulletin.

📝 Research & writing

🧰 Focus

vulnerability research · threat intelligence · detection engineering · OSINT · DNS OSINT · attack surface management · supply chain security · internet-wide scanning · phishing detection · honeypots · nuclei · amass · CVE / CVSS / EPSS · public speaking · mentoring

📫 Connect

Metrics

Pinned Loading

  1. rxerium-templates rxerium-templates Public

    Nuclei scripts created by @rxerium for zero days / actively exploited vulnerabilities.

    Python 194 35

  2. owasp-amass/amass owasp-amass/amass Public

    In-depth attack surface mapping and asset discovery

    Go 15.3k 2.2k

  3. projectdiscovery/nuclei-templates projectdiscovery/nuclei-templates Public

    Community curated list of templates for the nuclei engine to find security vulnerabilities.

    JavaScript 13.1k 3.7k

  4. bug-bounty-tools bug-bounty-tools Public

    A BASH Script to automate the installation of the most popular bug bounty tools

    Shell 27 6