Rhino Security Labs

Strategic & Technical Blog

CVE-2025-26147: Authenticated RCE In Denodo Scheduler 

John De Armas
May 21, 2025

Denodo provides a range of logical data management software.
This blog focuses on one such software, called “Scheduler”. Denodo Scheduler allows the scheduling and execution of data extraction and integration jobs…

New Pacu Module:
Secret Enumeration in Elastic Beanstalk

CVE-2024-55963: Unauthenticated RCE in Default-Install of Appsmith

CVE-2025-0693: AWS IAM User Enumeration

Nate Wilson

Username enumeration vulnerabilities can allow attackers to identify valid users, which is the first step in many attacks.  During a recent pentest, we discovered two username enumeration vulnerabilities in the AWS Web Console. These…