Cybersecurity News & Blog

Your global source for cybersecurity news, threat intelligence, and expert security analysis.

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph is an open-source network investigation and threat hunting tool that transforms packet cap...

Open-Source Network Discovery & Topology Mapping

Open-Source Network Discovery & Topology Mapping

RedSide Security has open-sourced NETMAPPER, a network discovery and visualization tool designed to ...

 RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

When an incident unfolds and all you have left are Windows event logs, understanding attacker moveme...

Latest Posts

PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability

PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability

RedSide Security July 08, 2026 Vulnerability 43 views

Researchers have released a working proof-of-concept exploit for CVE-2025-53770, a critical SharePoint Server remote code execution vulnerability. The flaw abuses XML schema imports and .NET deserialization gadgets to achieve code execution on vulnerable on-premises SharePoint deployments, increasing the risk of large-scale exploitation.

Continue reading: PoC and Technical Details Released for SharePoint …
Critical Fast-MCP-Telegram Vulnerability Allows Authentication Bypass via Path Traversal

Critical Fast-MCP-Telegram Vulnerability Allows Authentication Bypass via Path Traversal

RedSide Security July 07, 2026 Vulnerability 53 views

A critical authentication bypass vulnerability (**CVE-2026-52830**) in Fast-MCP-Telegram allows attackers to exploit path traversal flaws in Bearer token validation and gain unauthorized access to Telegram sessions. Users are strongly advised to upgrade to version 0.19.1 immediately.

Continue reading: Critical Fast-MCP-Telegram Vulnerability Allows Au…
Bad Epoll Linux Kernel Flaw Lets Attackers Gain Root Access on Linux and Android

Bad Epoll Linux Kernel Flaw Lets Attackers Gain Root Access on Linux and Android

RedSide Security July 04, 2026 Vulnerability 92 views

A newly disclosed Linux kernel vulnerability, Bad Epoll (CVE-2026-46242), allows unprivileged users to gain root access on Linux and Android systems through a race condition and use-after-free flaw in the epoll subsystem. With no workaround available, organizations are urged to deploy kernel patches as soon as they become available.

Continue reading: Bad Epoll Linux Kernel Flaw Lets Attackers Gain Ro…
Introducing AnyStix: Automated Country-Based Threat Intelligence for OpenCTI

Introducing AnyStix: Automated Country-Based Threat Intelligence for OpenCTI

RedSide Security July 02, 2026 Tools & Technology 61 views

AnyStix is an open-source threat intelligence tool that collects country-specific malicious submissions from ANY.RUN, enriches them with indicators, converts them into STIX 2.1 format, and automatically imports them into OpenCTI. The platform enables continuous, region-focused threat intelligence collection using publicly available sandbox data.

Continue reading: Introducing AnyStix: Automated Country-Based Threa…
Introducing CVEAlertor: Now With Public PoC & Exploit Monitoring

Introducing CVEAlertor: Now With Public PoC & Exploit Monitoring

RedSide Security July 02, 2026 Tools & Technology 65 views

CVEAlertor now monitors GitHub for newly released proof-of-concept exploits tied to tracked vulnerabilities. Security teams receive instant Telegram alerts when new CVEs are published and when public exploit code becomes available, helping prioritize patching before attackers strike.

Continue reading: Introducing CVEAlertor: Now With Public PoC & Expl…
Critical Cursor IDE Flaws Enable Full Sandbox Escape and Remote Code Execution

Critical Cursor IDE Flaws Enable Full Sandbox Escape and Remote Code Execution

RedSide Security July 01, 2026 Vulnerability 60 views

Two critical vulnerabilities in Cursor IDE, tracked as CVE-2026-50548 and CVE-2026-50549, allow attackers to escape the platform's sandbox and achieve full remote code execution through prompt injection. The flaws demonstrate how AI-driven coding agents can expose traditional software attack surfaces, leading to system compromise without user approval.

Continue reading: Critical Cursor IDE Flaws Enable Full Sandbox Esca…
Top 10 Cybersecurity Tips for Small Businesses

Top 10 Cybersecurity Tips for Small Businesses

RedSide Security June 30, 2026 RedSide Security News 49 views

Small businesses are increasingly targeted by cybercriminals due to limited security resources and weaker defenses. Learn the top 10 cybersecurity tips that can help protect your organization from phishing, ransomware, credential theft, and other common cyber threats.

Continue reading: Top 10 Cybersecurity Tips for Small Businesses
Researchers Find 282 iPhone AI Apps Exposing Paid AI Access Through Leaked API Credentials

Researchers Find 282 iPhone AI Apps Exposing Paid AI Access Through Leaked API Credentials

RedSide Security June 30, 2026 Vulnerability 48 views

Researchers analyzing 444 AI chatbot apps on iPhone found that 282 applications exposed paid AI access through leaked API keys, reusable tokens, or unsecured backend services. The findings highlight growing risks of LLMJacking attacks, where threat actors abuse stolen AI credentials to generate costly unauthorized model usage.

Continue reading: Researchers Find 282 iPhone AI Apps Exposing Paid …
GuardFall Bypass Lets Attackers Evade AI Coding Agent Safety Checks Using Decades-Old Shell Tricks

GuardFall Bypass Lets Attackers Evade AI Coding Agent Safety Checks Using Decades-Old Shell Tricks

RedSide Security June 30, 2026 Cybersecurity 62 views

Researchers have disclosed GuardFall, a shell command bypass technique that defeats safety protections in 10 popular AI coding agents. The flaw allows malicious commands to evade text-based filters and execute with user privileges, potentially exposing credentials, source code, and cloud infrastructure.

Continue reading: GuardFall Bypass Lets Attackers Evade AI Coding Ag…
Critical SimpleHelp Flaw Actively Exploited to Deploy TaskWeaver Loader and Djinn Stealer

Critical SimpleHelp Flaw Actively Exploited to Deploy TaskWeaver Loader and Djinn Stealer

RedSide Security June 30, 2026 Cybersecurity 43 views

Threat actors are actively exploiting CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp RMM software, to deploy the TaskWeaver loader and Djinn Stealer. The malware targets cloud credentials, developer tools, AI platforms, cryptocurrency wallets, and enterprise infrastructure across Windows, macOS, and Linux systems.

Continue reading: Critical SimpleHelp Flaw Actively Exploited to Dep…