Authentication Bypass — Cybersecurity News

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph is an open-source network investigation and threat hunting tool that transforms packet cap...

Open-Source Network Discovery & Topology Mapping

Open-Source Network Discovery & Topology Mapping

RedSide Security has open-sourced NETMAPPER, a network discovery and visualization tool designed to ...

 RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

When an incident unfolds and all you have left are Windows event logs, understanding attacker moveme...

Latest Posts

Palo Alto PAN-OS Authentication Bypass Exploited to Deploy Qilin Ransomware

Palo Alto PAN-OS Authentication Bypass Exploited to Deploy Qilin Ransomware

RedSide Security July 21, 2026 Cybercrime 94 views

Threat actors are exploiting CVE-2026-0257 in Palo Alto PAN-OS GlobalProtect to bypass authentication, gain VPN access, steal Active Directory credentials, and deploy Qilin ransomware. Security teams should patch immediately and rotate credentials if compromise is suspected.

Continue reading: Palo Alto PAN-OS Authentication Bypass Exploited t…
Critical Fast-MCP-Telegram Vulnerability Allows Authentication Bypass via Path Traversal

Critical Fast-MCP-Telegram Vulnerability Allows Authentication Bypass via Path Traversal

RedSide Security July 07, 2026 Vulnerability 85 views

A critical authentication bypass vulnerability (**CVE-2026-52830**) in Fast-MCP-Telegram allows attackers to exploit path traversal flaws in Bearer token validation and gain unauthorized access to Telegram sessions. Users are strongly advised to upgrade to version 0.19.1 immediately.

Continue reading: Critical Fast-MCP-Telegram Vulnerability Allows Au…
Critical SimpleHelp Flaw Actively Exploited to Deploy TaskWeaver Loader and Djinn Stealer

Critical SimpleHelp Flaw Actively Exploited to Deploy TaskWeaver Loader and Djinn Stealer

RedSide Security June 30, 2026 Cybersecurity 68 views

Threat actors are actively exploiting CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp RMM software, to deploy the TaskWeaver loader and Djinn Stealer. The malware targets cloud credentials, developer tools, AI platforms, cryptocurrency wallets, and enterprise infrastructure across Windows, macOS, and Linux systems.

Continue reading: Critical SimpleHelp Flaw Actively Exploited to Dep…
curl Patches 18 Vulnerabilities, Including a 25-Year-Old Security Flaw

curl Patches 18 Vulnerabilities, Including a 25-Year-Old Security Flaw

RedSide Security June 29, 2026 Vulnerability 103 views

curl has released a security update fixing 18 vulnerabilities, including a 25-year-old flaw dating back to 2001. The vulnerabilities affect curl and libcurl components used by billions of devices worldwide, highlighting the ongoing importance of security auditing even in mature open-source projects.

Continue reading: curl Patches 18 Vulnerabilities, Including a 25-Ye…