Active Directory — Cybersecurity News

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph is an open-source network investigation and threat hunting tool that transforms packet cap...

Open-Source Network Discovery & Topology Mapping

Open-Source Network Discovery & Topology Mapping

RedSide Security has open-sourced NETMAPPER, a network discovery and visualization tool designed to ...

 RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

When an incident unfolds and all you have left are Windows event logs, understanding attacker moveme...

Latest Posts

Microsoft SCCM Vulnerability Chain Could Enable Remote SYSTEM-Level Code Execution

Microsoft SCCM Vulnerability Chain Could Enable Remote SYSTEM-Level Code Execution

RedSide Security August 17, 2026 Vulnerability 98 views

Security researchers have disclosed an attack chain affecting Microsoft System Center Configuration Manager (SCCM) that could allow standard Active Directory users to ultimately execute malicious code with SYSTEM privileges on an SCCM primary site server. The chain combines an AdminService authorization flaw, weak signature validation, CAB path traversal, and unsafe DLL loading.

Continue reading: Microsoft SCCM Vulnerability Chain Could Enable Re…
Palo Alto PAN-OS Authentication Bypass Exploited to Deploy Qilin Ransomware

Palo Alto PAN-OS Authentication Bypass Exploited to Deploy Qilin Ransomware

RedSide Security July 21, 2026 Cybercrime 142 views

Threat actors are exploiting CVE-2026-0257 in Palo Alto PAN-OS GlobalProtect to bypass authentication, gain VPN access, steal Active Directory credentials, and deploy Qilin ransomware. Security teams should patch immediately and rotate credentials if compromise is suspected.

Continue reading: Palo Alto PAN-OS Authentication Bypass Exploited t…