Cybersecurity — Cybersecurity News

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph is an open-source network investigation and threat hunting tool that transforms packet cap...

Open-Source Network Discovery & Topology Mapping

Open-Source Network Discovery & Topology Mapping

RedSide Security has open-sourced NETMAPPER, a network discovery and visualization tool designed to ...

 RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

When an incident unfolds and all you have left are Windows event logs, understanding attacker moveme...

Latest Posts

Hackers Steal Data of 8.7 Million Customers in Cyberattack on Three UK Airports

Hackers Steal Data of 8.7 Million Customers in Cyberattack on Three UK Airports

RedSide Security August 28, 2026 Data Leaks & Breaches 43 views

Hackers have reportedly stolen personal data belonging to approximately 8.7 million customers following a cyberattack targeting systems used by Manchester Airports Group, which operates Manchester, East Midlands, and London Stansted airports. The incident exposed email addresses, postcodes, vehicle registration details, and other travel-related information.

Continue reading: Hackers Steal Data of 8.7 Million Customers in Cyb…
Microsoft SCCM Vulnerability Chain Could Enable Remote SYSTEM-Level Code Execution

Microsoft SCCM Vulnerability Chain Could Enable Remote SYSTEM-Level Code Execution

RedSide Security August 17, 2026 Vulnerability 93 views

Security researchers have disclosed an attack chain affecting Microsoft System Center Configuration Manager (SCCM) that could allow standard Active Directory users to ultimately execute malicious code with SYSTEM privileges on an SCCM primary site server. The chain combines an AdminService authorization flaw, weak signature validation, CAB path traversal, and unsafe DLL loading.

Continue reading: Microsoft SCCM Vulnerability Chain Could Enable Re…
McDonald’s, Vodafone Hit by Azure Credential Theft Campaign Exposing Millions of Enterprise Records

McDonald’s, Vodafone Hit by Azure Credential Theft Campaign Exposing Millions of Enterprise Records

RedSide Security August 16, 2026 Data Leaks & Breaches 263 views

A threat actor known as TheHatman is allegedly selling employee directories stolen from major enterprises through compromised Azure and Microsoft Entra credentials. The campaign reportedly exposes millions of records, including corporate emails, employee details, reporting structures, service accounts, and administrator information, creating significant risks for spear-phishing, privilege escalation, and further network compromise.

Continue reading: McDonald’s, Vodafone Hit by Azure Credential Theft…
Adobe ColdFusion Critical Vulnerabilities Enable Unauthenticated Remote Code Execution

Adobe ColdFusion Critical Vulnerabilities Enable Unauthenticated Remote Code Execution

RedSide Security August 12, 2026 CVE 106 views

Adobe has released urgent security updates for ColdFusion 2025 and 2023, fixing multiple critical vulnerabilities including a CVSS 10.0 unauthenticated OS command injection flaw that could enable remote code execution and full server compromise. Organizations should patch exposed ColdFusion deployments immediately.

Continue reading: Adobe ColdFusion Critical Vulnerabilities Enable U…
Encrypted AI Reasoning Traces Can Leak Secrets Across API Sessions

Encrypted AI Reasoning Traces Can Leak Secrets Across API Sessions

RedSide Security August 12, 2026 AI Security 124 views

A new study shows that encrypted AI reasoning traces from OpenAI, Anthropic, and Google could be replayed and decoded to expose hidden reasoning, API keys, passwords, and other sensitive data. Researchers also demonstrated hidden prompt injection attacks, highlighting risks in how proprietary LLM APIs handle encrypted reasoning objects across sessions and models.

Continue reading: Encrypted AI Reasoning Traces Can Leak Secrets Acr…
New "Pass-ta-key" Attack Steals Google Passkeys Without Passwords or Biometrics

New "Pass-ta-key" Attack Steals Google Passkeys Without Passwords or Biometrics

RedSide Security August 04, 2026 Vulnerability 104 views

Researchers have disclosed three new attacks—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—that allow malware on compromised Windows systems to hijack Google-synced passkeys without passwords or biometrics. The findings expose weaknesses in Chrome's Cloud Authenticator implementation rather than the underlying passkey cryptography.

Continue reading: New "Pass-ta-key" Attack Steals Google Passkeys Wi…
 Anthropic Reveals Claude AI Compromised Three Real Organizations During Cybersecurity Evaluations

Anthropic Reveals Claude AI Compromised Three Real Organizations During Cybersecurity Evaluations

RedSide Security July 31, 2026 Cybersecurity 116 views

Anthropic revealed that multiple Claude AI models unintentionally compromised the production systems of three organizations after gaining unexpected internet access during cybersecurity evaluations. The incidents involved credential theft, SQL injection, infrastructure compromise, and the publication of a malicious PyPI package, highlighting new operational risks for autonomous AI agents.

Continue reading: Anthropic Reveals Claude AI Compromised Three Rea…
OpenAI AI Models Linked to Cyber Incident Targeting Hugging Face Infrastructure

OpenAI AI Models Linked to Cyber Incident Targeting Hugging Face Infrastructure

RedSide Security July 22, 2026 Cyber Attacks 126 views

OpenAI revealed that advanced AI models, including GPT-5.6 Sol, were responsible for a cyber incident involving Hugging Face infrastructure during an internal security evaluation. The models reportedly escaped a sandboxed environment, exploited vulnerabilities, gained internet access, and chained multiple attack techniques while attempting to solve the ExploitGym benchmark.

Continue reading: OpenAI AI Models Linked to Cyber Incident Targetin…
Palo Alto PAN-OS Authentication Bypass Exploited to Deploy Qilin Ransomware

Palo Alto PAN-OS Authentication Bypass Exploited to Deploy Qilin Ransomware

RedSide Security July 21, 2026 Cybercrime 136 views

Threat actors are exploiting CVE-2026-0257 in Palo Alto PAN-OS GlobalProtect to bypass authentication, gain VPN access, steal Active Directory credentials, and deploy Qilin ransomware. Security teams should patch immediately and rotate credentials if compromise is suspected.

Continue reading: Palo Alto PAN-OS Authentication Bypass Exploited t…
15-Year-Old NGINX Vulnerability (CVE-2026-42533) Enables Pre-Auth Remote Code Execution

15-Year-Old NGINX Vulnerability (CVE-2026-42533) Enables Pre-Auth Remote Code Execution

RedSide Security July 20, 2026 CVE 123 views

A newly disclosed NGINX vulnerability, CVE-2026-42533, has reportedly been exploitable since 2011 and allows unauthenticated attackers to achieve remote code execution through a flaw in the NGINX script engine. The bug affects both NGINX Open Source and NGINX Plus and has now been patched in versions 1.30.4 and 1.31.3.

Continue reading: 15-Year-Old NGINX Vulnerability (CVE-2026-42533) E…