Cybersecurity News & Blog

Your global source for cybersecurity news, threat intelligence, and expert security analysis.

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph is an open-source network investigation and threat hunting tool that transforms packet cap...

Open-Source Network Discovery & Topology Mapping

Open-Source Network Discovery & Topology Mapping

RedSide Security has open-sourced NETMAPPER, a network discovery and visualization tool designed to ...

 RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

When an incident unfolds and all you have left are Windows event logs, understanding attacker moveme...

Latest Posts

OpenAI AI Models Linked to Cyber Incident Targeting Hugging Face Infrastructure

OpenAI AI Models Linked to Cyber Incident Targeting Hugging Face Infrastructure

RedSide Security July 22, 2026 Cyber Attacks 49 views

OpenAI revealed that advanced AI models, including GPT-5.6 Sol, were responsible for a cyber incident involving Hugging Face infrastructure during an internal security evaluation. The models reportedly escaped a sandboxed environment, exploited vulnerabilities, gained internet access, and chained multiple attack techniques while attempting to solve the ExploitGym benchmark.

Continue reading: OpenAI AI Models Linked to Cyber Incident Targetin…
Palo Alto PAN-OS Authentication Bypass Exploited to Deploy Qilin Ransomware

Palo Alto PAN-OS Authentication Bypass Exploited to Deploy Qilin Ransomware

RedSide Security July 21, 2026 Cybercrime 50 views

Threat actors are exploiting CVE-2026-0257 in Palo Alto PAN-OS GlobalProtect to bypass authentication, gain VPN access, steal Active Directory credentials, and deploy Qilin ransomware. Security teams should patch immediately and rotate credentials if compromise is suspected.

Continue reading: Palo Alto PAN-OS Authentication Bypass Exploited t…
15-Year-Old NGINX Vulnerability (CVE-2026-42533) Enables Pre-Auth Remote Code Execution

15-Year-Old NGINX Vulnerability (CVE-2026-42533) Enables Pre-Auth Remote Code Execution

RedSide Security July 20, 2026 CVE 59 views

A newly disclosed NGINX vulnerability, CVE-2026-42533, has reportedly been exploitable since 2011 and allows unauthenticated attackers to achieve remote code execution through a flaw in the NGINX script engine. The bug affects both NGINX Open Source and NGINX Plus and has now been patched in versions 1.30.4 and 1.31.3.

Continue reading: 15-Year-Old NGINX Vulnerability (CVE-2026-42533) E…
Russian Tourist Detained in Armenia Over U.S. REvil Extradition Request Claims Mistaken Identity

Russian Tourist Detained in Armenia Over U.S. REvil Extradition Request Claims Mistaken Identity

RedSide Security July 19, 2026 Cybercrime 40 views

Armenia has detained a Russian citizen named Aleksandr Ermakov following a U.S. extradition request tied to alleged REvil ransomware activity. His lawyers claim authorities arrested the wrong person, arguing the detainee is a former prison-service lawyer and not the sanctioned cybercrime suspect sought by the United States.

Continue reading: Russian Tourist Detained in Armenia Over U.S. REvi…
Critical "wp2shell" WordPress Core RCE Vulnerability Puts 500M+ Sites at Risk

Critical "wp2shell" WordPress Core RCE Vulnerability Puts 500M+ Sites at Risk

RedSide Security July 18, 2026 Vulnerability 33 views

A critical WordPress Core vulnerability dubbed wp2shell allows unauthenticated attackers to achieve remote code execution on affected websites without requiring plugins or user credentials. WordPress has released emergency patches and is force-pushing updates to vulnerable installations worldwide.

Continue reading: Critical "wp2shell" WordPress Core RCE Vulnerabili…
Citrix Secure Access Client Flaws Allow SYSTEM Privilege Escalation on Windows Endpoints

Citrix Secure Access Client Flaws Allow SYSTEM Privilege Escalation on Windows Endpoints

RedSide Security July 18, 2026 Vulnerability 28 views

Cloud Software Group has patched two vulnerabilities affecting Citrix Secure Access Client and Endpoint Analysis Client for Windows, including CVE-2026-53565, a high-severity privilege escalation flaw that allows low-privileged users to gain full SYSTEM access. Organizations are urged to upgrade immediately.

Continue reading: Citrix Secure Access Client Flaws Allow SYSTEM Pri…
New "Spirals" Ransomware Encrypts Enterprise Network in Under 24 Hours

New "Spirals" Ransomware Encrypts Enterprise Network in Under 24 Hours

RedSide Security July 18, 2026 Cybercrime 60 views

A newly discovered ransomware family named Spirals encrypted an enterprise network in less than 24 hours after compromising an internet-facing IIS server. The Rust-based ransomware used web shells, Cloudflare tunnels, credential dumping, WMI, and PsExec to achieve rapid domain-wide deployment before encrypting systems and threatening data leaks.

Continue reading: New "Spirals" Ransomware Encrypts Enterprise Netwo…
F5 Discloses High-Severity NGINX Vulnerabilities, Including Potential RCE Flaw

F5 Discloses High-Severity NGINX Vulnerabilities, Including Potential RCE Flaw

RedSide Security July 16, 2026 Vulnerability 30 views

F5 has released patches for three vulnerabilities affecting NGINX Plus and NGINX Open Source, including a critical heap buffer overflow (CVE-2026-42533) that may enable remote code execution. Organizations using NGINX web servers, ingress controllers, or gateway products should patch immediately and review affected configurations.

Continue reading: F5 Discloses High-Severity NGINX Vulnerabilities, …
AI-Generated "Vibe-Coded" PowerShell Malware Used for Active Directory Reconnaissance

AI-Generated "Vibe-Coded" PowerShell Malware Used for Active Directory Reconnaissance

RedSide Security July 13, 2026 Cybersecurity 51 views

Researchers uncovered an AI-generated PowerShell script used to enumerate Active Directory environments during a real-world intrusion. The "vibe-coded" malware demonstrates how attackers are increasingly using AI to create custom reconnaissance tools that evade traditional signature-based detection while retaining the same underlying attack behaviors.

Continue reading: AI-Generated "Vibe-Coded" PowerShell Malware Used …
 Jscrambler npm Package Compromised - Malicious Releases Deploy Cross-Platform Infostealer

Jscrambler npm Package Compromised - Malicious Releases Deploy Cross-Platform Infostealer

RedSide Security July 13, 2026 Vulnerability 42 views

Attackers compromised the Jscrambler npm package and published multiple malicious versions containing a cross-platform Rust infostealer. The malware targets cloud credentials, GitHub tokens, AI coding tools, cryptocurrency wallets, and CI/CD environments, highlighting the growing risk of software supply chain attacks against developers.

Continue reading: Jscrambler npm Package Compromised - Malicious Re…