DevSecOps — Cybersecurity News

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph is an open-source network investigation and threat hunting tool that transforms packet cap...

Open-Source Network Discovery & Topology Mapping

Open-Source Network Discovery & Topology Mapping

RedSide Security has open-sourced NETMAPPER, a network discovery and visualization tool designed to ...

 RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

When an incident unfolds and all you have left are Windows event logs, understanding attacker moveme...

Latest Posts

F5 Discloses High-Severity NGINX Vulnerabilities, Including Potential RCE Flaw

F5 Discloses High-Severity NGINX Vulnerabilities, Including Potential RCE Flaw

RedSide Security July 16, 2026 Vulnerability 55 views

F5 has released patches for three vulnerabilities affecting NGINX Plus and NGINX Open Source, including a critical heap buffer overflow (CVE-2026-42533) that may enable remote code execution. Organizations using NGINX web servers, ingress controllers, or gateway products should patch immediately and review affected configurations.

Continue reading: F5 Discloses High-Severity NGINX Vulnerabilities, …
 Jscrambler npm Package Compromised - Malicious Releases Deploy Cross-Platform Infostealer

Jscrambler npm Package Compromised - Malicious Releases Deploy Cross-Platform Infostealer

RedSide Security July 13, 2026 Vulnerability 68 views

Attackers compromised the Jscrambler npm package and published multiple malicious versions containing a cross-platform Rust infostealer. The malware targets cloud credentials, GitHub tokens, AI coding tools, cryptocurrency wallets, and CI/CD environments, highlighting the growing risk of software supply chain attacks against developers.

Continue reading: Jscrambler npm Package Compromised - Malicious Re…
Introducing CVEAlertor: Now With Public PoC & Exploit Monitoring

Introducing CVEAlertor: Now With Public PoC & Exploit Monitoring

RedSide Security July 02, 2026 Tools & Technology 92 views

CVEAlertor now monitors GitHub for newly released proof-of-concept exploits tied to tracked vulnerabilities. Security teams receive instant Telegram alerts when new CVEs are published and when public exploit code becomes available, helping prioritize patching before attackers strike.

Continue reading: Introducing CVEAlertor: Now With Public PoC & Expl…
Critical Cursor IDE Flaws Enable Full Sandbox Escape and Remote Code Execution

Critical Cursor IDE Flaws Enable Full Sandbox Escape and Remote Code Execution

RedSide Security July 01, 2026 Vulnerability 94 views

Two critical vulnerabilities in Cursor IDE, tracked as CVE-2026-50548 and CVE-2026-50549, allow attackers to escape the platform's sandbox and achieve full remote code execution through prompt injection. The flaws demonstrate how AI-driven coding agents can expose traditional software attack surfaces, leading to system compromise without user approval.

Continue reading: Critical Cursor IDE Flaws Enable Full Sandbox Esca…
GuardFall Bypass Lets Attackers Evade AI Coding Agent Safety Checks Using Decades-Old Shell Tricks

GuardFall Bypass Lets Attackers Evade AI Coding Agent Safety Checks Using Decades-Old Shell Tricks

RedSide Security June 30, 2026 Cybersecurity 105 views

Researchers have disclosed GuardFall, a shell command bypass technique that defeats safety protections in 10 popular AI coding agents. The flaw allows malicious commands to evade text-based filters and execute with user privileges, potentially exposing credentials, source code, and cloud infrastructure.

Continue reading: GuardFall Bypass Lets Attackers Evade AI Coding Ag…