Cybersecurity News & Blog

Your global source for cybersecurity news, threat intelligence, and expert security analysis.

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph is an open-source network investigation and threat hunting tool that transforms packet cap...

Open-Source Network Discovery & Topology Mapping

Open-Source Network Discovery & Topology Mapping

RedSide Security has open-sourced NETMAPPER, a network discovery and visualization tool designed to ...

 RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

When an incident unfolds and all you have left are Windows event logs, understanding attacker moveme...

Latest Posts

 RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

RedSide Security June 03, 2026 Tools & Technology 162 views

When an incident unfolds and all you have left are Windows event logs, understanding attacker movement becomes a slow and painful process. RDPGraph transforms raw `.evtx` files into an interactive BloodHound-style graph, allowing responders to quickly visualize RDP activity, identify lateral movement, and investigate compromised systems in minutes instead of hours.

Continue reading: RDPGraph: Turn Windows Event Logs into an Interac…
PoC Exploit Released for 20-Year Old PostgreSQL RCE Vulnerability

PoC Exploit Released for 20-Year Old PostgreSQL RCE Vulnerability

RedSide Security May 20, 2026 Vulnerability 231 views

A public proof-of-concept (PoC) exploit has been released for **CVE-2026-2005**, a critical remote code execution vulnerability in PostgreSQL’s **pgcrypto extension**. The flaw stems from a long-standing heap-based buffer overflow in PGP session key parsing and can allow attackers to escalate privileges to PostgreSQL superuser and execute operating system commands under certain conditions.

Continue reading: PoC Exploit Released for 20-Year Old PostgreSQL RC…
GitHub Breached - Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos

GitHub Breached - Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos

RedSide Security May 20, 2026 Data Leaks & Breaches 193 views

GitHub is investigating unauthorized access to its internal repositories following a supply chain attack linked to the threat actor **TeamPCP**, who reportedly listed GitHub source code and internal data for sale on a cybercrime forum. The incident is part of an ongoing malware campaign targeting open-source ecosystems, including a compromised Microsoft Python package and a self-replicating infostealer known as Mini Shai-Hulud.

Continue reading: GitHub Breached - Employee Device Hack Led to Exfi…
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE

NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE

RedSide Security May 17, 2026 CVE 177 views

A critical NGINX vulnerability tracked as CVE-2026-42945 is now being actively exploited in the wild, just days after public disclosure. The flaw allows attackers to crash NGINX worker processes and potentially achieve remote code execution under specific conditions. At the same time, threat actors have also begun weaponizing multiple critical vulnerabilities in openDCIM to deploy PHP web shells and gain remote access to exposed systems.

Continue reading: NGINX CVE-2026-42945 Exploited in the Wild, Causin…
First Public macOS Kernel Exploit on Apple M5 Prepared Using Mythos Preview in Five Days

First Public macOS Kernel Exploit on Apple M5 Prepared Using Mythos Preview in Five Days

RedSide Security May 17, 2026 Vulnerability 267 views

Security researchers have reportedly developed the first public macOS kernel exploit targeting Apple’s new M5 silicon, successfully bypassing the company’s hardware-based Memory Integrity Enforcement (MIE) protections. The exploit chain achieves full root access on macOS 26.4.1 using only standard system calls from an unprivileged local account, highlighting the growing impact of AI-assisted offensive security research.

Continue reading: First Public macOS Kernel Exploit on Apple M5 Prep…
TeamPCP and BreachForums Launch $1,000 Contest to Drive Open-Source Supply Chain Attacks

TeamPCP and BreachForums Launch $1,000 Contest to Drive Open-Source Supply Chain Attacks

RedSide Security May 14, 2026 Cybersecurity 172 views

Cybercrime groups **TeamPCP** and **BreachForums** are reportedly running a coordinated contest offering a $1,000 Monero prize for supply chain attacks targeting open-source ecosystems. The competition incentivizes participants to compromise software packages and CI/CD pipelines using a malicious tool called “Shai-Hulud,” raising serious concerns about large-scale, crowdsourced software supply chain compromise.

Continue reading: TeamPCP and BreachForums Launch $1,000 Contest to …
New BitUnlocker Downgrade Attack on Windows 11 Allows Access to Encrypted Disks in 5 Minutes

New BitUnlocker Downgrade Attack on Windows 11 Allows Access to Encrypted Disks in 5 Minutes

RedSide Security May 13, 2026 Vulnerability 215 views

Researchers have unveiled BitUnlocker, a new downgrade attack capable of bypassing Microsoft BitLocker encryption on patched Windows 11 systems in under five minutes. The attack abuses a flaw in the Windows Recovery Environment (WinRE) and a trusted legacy Secure Boot certificate to boot vulnerable components, allowing attackers with physical access to decrypt protected drives without triggering security alerts.

Continue reading: New BitUnlocker Downgrade Attack on Windows 11 All…
Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions

Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions

RedSide Security May 10, 2026 CVE 134 views

A newly disclosed Linux kernel vulnerability chain, dubbed **Dirty Frag**, enables unprivileged local users to gain root access across major Linux distributions. The flaw combines two page-cache write issues in the xfrm-ESP and RxRPC subsystems, creating a deterministic and highly reliable privilege escalation method. Limited in-the-wild exploitation has already been observed, with attackers using it in post-SSH compromise scenarios.

Continue reading: Linux Kernel Dirty Frag LPE Exploit Enables Root A…
Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloads

Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloads

RedSide Security May 10, 2026 Cybercrime 131 views

Researchers uncovered 28 fraudulent Android apps on the Google Play Store that falsely claimed to provide access to call histories and WhatsApp logs for any phone number. The apps amassed over 7.3 million downloads before removal and tricked victims into paying subscriptions for completely fabricated data.

Continue reading: Fake Call History Apps Stole Payments From Users A…