Cybersecurity News & Blog

Your global source for cybersecurity news, threat intelligence, and expert security analysis.

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph is an open-source network investigation and threat hunting tool that transforms packet cap...

Open-Source Network Discovery & Topology Mapping

Open-Source Network Discovery & Topology Mapping

RedSide Security has open-sourced NETMAPPER, a network discovery and visualization tool designed to ...

 RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

When an incident unfolds and all you have left are Windows event logs, understanding attacker moveme...

Latest Posts

New BitUnlocker Downgrade Attack on Windows 11 Allows Access to Encrypted Disks in 5 Minutes

New BitUnlocker Downgrade Attack on Windows 11 Allows Access to Encrypted Disks in 5 Minutes

RedSide Security May 13, 2026 Vulnerability 156 views

Researchers have unveiled BitUnlocker, a new downgrade attack capable of bypassing Microsoft BitLocker encryption on patched Windows 11 systems in under five minutes. The attack abuses a flaw in the Windows Recovery Environment (WinRE) and a trusted legacy Secure Boot certificate to boot vulnerable components, allowing attackers with physical access to decrypt protected drives without triggering security alerts.

Continue reading: New BitUnlocker Downgrade Attack on Windows 11 All…
Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions

Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions

RedSide Security May 10, 2026 CVE 93 views

A newly disclosed Linux kernel vulnerability chain, dubbed **Dirty Frag**, enables unprivileged local users to gain root access across major Linux distributions. The flaw combines two page-cache write issues in the xfrm-ESP and RxRPC subsystems, creating a deterministic and highly reliable privilege escalation method. Limited in-the-wild exploitation has already been observed, with attackers using it in post-SSH compromise scenarios.

Continue reading: Linux Kernel Dirty Frag LPE Exploit Enables Root A…
Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloads

Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloads

RedSide Security May 10, 2026 Cybercrime 79 views

Researchers uncovered 28 fraudulent Android apps on the Google Play Store that falsely claimed to provide access to call histories and WhatsApp logs for any phone number. The apps amassed over 7.3 million downloads before removal and tricked victims into paying subscriptions for completely fabricated data.

Continue reading: Fake Call History Apps Stole Payments From Users A…
Ollama Vulnerabilities Expose Process Memory and Enable Persistent Code Execution on Windows

Ollama Vulnerabilities Expose Process Memory and Enable Persistent Code Execution on Windows

RedSide Security May 10, 2026 Vulnerability 101 views

Researchers have disclosed multiple critical vulnerabilities in Ollama, including the “Bleeding Llama” flaw (CVE-2026-7482), which allows remote attackers to leak sensitive process memory from exposed AI servers. Additional unpatched Windows update vulnerabilities could also enable persistent code execution through malicious updates and Startup folder abuse.

Continue reading: Ollama Vulnerabilities Expose Process Memory and E…