Linux Security — Cybersecurity News

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph is an open-source network investigation and threat hunting tool that transforms packet cap...

Open-Source Network Discovery & Topology Mapping

Open-Source Network Discovery & Topology Mapping

RedSide Security has open-sourced NETMAPPER, a network discovery and visualization tool designed to ...

 RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

When an incident unfolds and all you have left are Windows event logs, understanding attacker moveme...

Latest Posts

15-Year-Old NGINX Vulnerability (CVE-2026-42533) Enables Pre-Auth Remote Code Execution

15-Year-Old NGINX Vulnerability (CVE-2026-42533) Enables Pre-Auth Remote Code Execution

RedSide Security July 20, 2026 CVE 88 views

A newly disclosed NGINX vulnerability, CVE-2026-42533, has reportedly been exploitable since 2011 and allows unauthenticated attackers to achieve remote code execution through a flaw in the NGINX script engine. The bug affects both NGINX Open Source and NGINX Plus and has now been patched in versions 1.30.4 and 1.31.3.

Continue reading: 15-Year-Old NGINX Vulnerability (CVE-2026-42533) E…
GuardFall Bypass Lets Attackers Evade AI Coding Agent Safety Checks Using Decades-Old Shell Tricks

GuardFall Bypass Lets Attackers Evade AI Coding Agent Safety Checks Using Decades-Old Shell Tricks

RedSide Security June 30, 2026 Cybersecurity 105 views

Researchers have disclosed GuardFall, a shell command bypass technique that defeats safety protections in 10 popular AI coding agents. The flaw allows malicious commands to evade text-based filters and execute with user privileges, potentially exposing credentials, source code, and cloud infrastructure.

Continue reading: GuardFall Bypass Lets Attackers Evade AI Coding Ag…
Critical SimpleHelp Flaw Actively Exploited to Deploy TaskWeaver Loader and Djinn Stealer

Critical SimpleHelp Flaw Actively Exploited to Deploy TaskWeaver Loader and Djinn Stealer

RedSide Security June 30, 2026 Cybersecurity 68 views

Threat actors are actively exploiting CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp RMM software, to deploy the TaskWeaver loader and Djinn Stealer. The malware targets cloud credentials, developer tools, AI platforms, cryptocurrency wallets, and enterprise infrastructure across Windows, macOS, and Linux systems.

Continue reading: Critical SimpleHelp Flaw Actively Exploited to Dep…
DirtyClone Linux Kernel Vulnerability Enables Root Privilege Escalation

DirtyClone Linux Kernel Vulnerability Enables Root Privilege Escalation

RedSide Security June 29, 2026 Vulnerability 92 views

DirtyClone (CVE-2026-43503) is a newly disclosed Linux kernel privilege escalation vulnerability that allows local attackers to gain root access by abusing packet cloning and page-cache corruption. Researchers have released a working exploit, making immediate patching essential for affected Linux systems.

Continue reading: DirtyClone Linux Kernel Vulnerability Enables Root…