Microsoft Security — Cybersecurity News

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph is an open-source network investigation and threat hunting tool that transforms packet cap...

Open-Source Network Discovery & Topology Mapping

Open-Source Network Discovery & Topology Mapping

RedSide Security has open-sourced NETMAPPER, a network discovery and visualization tool designed to ...

 RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

When an incident unfolds and all you have left are Windows event logs, understanding attacker moveme...

Latest Posts

ShieldBreak: Microsoft Defender Zero-Day and RoguePlanet Patch Bypass

ShieldBreak: Microsoft Defender Zero-Day and RoguePlanet Patch Bypass

RedSide Security September 17, 2026 Vulnerability 89 views

ShieldBreak (CVE-2026-69414) is a Microsoft Defender elevation-of-privilege vulnerability linked to research on bypassing mitigations for RoguePlanet (CVE-2026-50656). Explore the technical research, affected components, and defensive detection opportunities.

Continue reading: ShieldBreak: Microsoft Defender Zero-Day and Rogue…
Microsoft SCCM Vulnerability Chain Could Enable Remote SYSTEM-Level Code Execution

Microsoft SCCM Vulnerability Chain Could Enable Remote SYSTEM-Level Code Execution

RedSide Security August 17, 2026 Vulnerability 207 views

Security researchers have disclosed an attack chain affecting Microsoft System Center Configuration Manager (SCCM) that could allow standard Active Directory users to ultimately execute malicious code with SYSTEM privileges on an SCCM primary site server. The chain combines an AdminService authorization flaw, weak signature validation, CAB path traversal, and unsafe DLL loading.

Continue reading: Microsoft SCCM Vulnerability Chain Could Enable Re…
PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability

PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability

RedSide Security July 08, 2026 Vulnerability 131 views

Researchers have released a working proof-of-concept exploit for CVE-2025-53770, a critical SharePoint Server remote code execution vulnerability. The flaw abuses XML schema imports and .NET deserialization gadgets to achieve code execution on vulnerable on-premises SharePoint deployments, increasing the risk of large-scale exploitation.

Continue reading: PoC and Technical Details Released for SharePoint …