EDR — Cybersecurity News

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph is an open-source network investigation and threat hunting tool that transforms packet cap...

Open-Source Network Discovery & Topology Mapping

Open-Source Network Discovery & Topology Mapping

RedSide Security has open-sourced NETMAPPER, a network discovery and visualization tool designed to ...

 RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

When an incident unfolds and all you have left are Windows event logs, understanding attacker moveme...

Latest Posts

ShieldBreak: Microsoft Defender Zero-Day and RoguePlanet Patch Bypass

ShieldBreak: Microsoft Defender Zero-Day and RoguePlanet Patch Bypass

RedSide Security September 17, 2026 Vulnerability 95 views

ShieldBreak (CVE-2026-69414) is a Microsoft Defender elevation-of-privilege vulnerability linked to research on bypassing mitigations for RoguePlanet (CVE-2026-50656). Explore the technical research, affected components, and defensive detection opportunities.

Continue reading: ShieldBreak: Microsoft Defender Zero-Day and Rogue…
AI-Generated "Vibe-Coded" PowerShell Malware Used for Active Directory Reconnaissance

AI-Generated "Vibe-Coded" PowerShell Malware Used for Active Directory Reconnaissance

RedSide Security July 13, 2026 Cybersecurity 155 views

Researchers uncovered an AI-generated PowerShell script used to enumerate Active Directory environments during a real-world intrusion. The "vibe-coded" malware demonstrates how attackers are increasingly using AI to create custom reconnaissance tools that evade traditional signature-based detection while retaining the same underlying attack behaviors.

Continue reading: AI-Generated "Vibe-Coded" PowerShell Malware Used …