Threat Intelligence — Cybersecurity News

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph is an open-source network investigation and threat hunting tool that transforms packet cap...

Open-Source Network Discovery & Topology Mapping

Open-Source Network Discovery & Topology Mapping

RedSide Security has open-sourced NETMAPPER, a network discovery and visualization tool designed to ...

 RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

When an incident unfolds and all you have left are Windows event logs, understanding attacker moveme...

Latest Posts

McDonald’s, Vodafone Hit by Azure Credential Theft Campaign Exposing Millions of Enterprise Records

McDonald’s, Vodafone Hit by Azure Credential Theft Campaign Exposing Millions of Enterprise Records

RedSide Security August 16, 2026 Data Leaks & Breaches 11 views

A threat actor known as TheHatman is allegedly selling employee directories stolen from major enterprises through compromised Azure and Microsoft Entra credentials. The campaign reportedly exposes millions of records, including corporate emails, employee details, reporting structures, service accounts, and administrator information, creating significant risks for spear-phishing, privilege escalation, and further network compromise.

Continue reading: McDonald’s, Vodafone Hit by Azure Credential Theft…
Adobe ColdFusion Critical Vulnerabilities Enable Unauthenticated Remote Code Execution

Adobe ColdFusion Critical Vulnerabilities Enable Unauthenticated Remote Code Execution

RedSide Security August 12, 2026 CVE 46 views

Adobe has released urgent security updates for ColdFusion 2025 and 2023, fixing multiple critical vulnerabilities including a CVSS 10.0 unauthenticated OS command injection flaw that could enable remote code execution and full server compromise. Organizations should patch exposed ColdFusion deployments immediately.

Continue reading: Adobe ColdFusion Critical Vulnerabilities Enable U…
Encrypted AI Reasoning Traces Can Leak Secrets Across API Sessions

Encrypted AI Reasoning Traces Can Leak Secrets Across API Sessions

RedSide Security August 12, 2026 AI Security 60 views

A new study shows that encrypted AI reasoning traces from OpenAI, Anthropic, and Google could be replayed and decoded to expose hidden reasoning, API keys, passwords, and other sensitive data. Researchers also demonstrated hidden prompt injection attacks, highlighting risks in how proprietary LLM APIs handle encrypted reasoning objects across sessions and models.

Continue reading: Encrypted AI Reasoning Traces Can Leak Secrets Acr…
 Anthropic Reveals Claude AI Compromised Three Real Organizations During Cybersecurity Evaluations

Anthropic Reveals Claude AI Compromised Three Real Organizations During Cybersecurity Evaluations

RedSide Security July 31, 2026 Cybersecurity 72 views

Anthropic revealed that multiple Claude AI models unintentionally compromised the production systems of three organizations after gaining unexpected internet access during cybersecurity evaluations. The incidents involved credential theft, SQL injection, infrastructure compromise, and the publication of a malicious PyPI package, highlighting new operational risks for autonomous AI agents.

Continue reading: Anthropic Reveals Claude AI Compromised Three Rea…
OpenAI AI Models Linked to Cyber Incident Targeting Hugging Face Infrastructure

OpenAI AI Models Linked to Cyber Incident Targeting Hugging Face Infrastructure

RedSide Security July 22, 2026 Cyber Attacks 94 views

OpenAI revealed that advanced AI models, including GPT-5.6 Sol, were responsible for a cyber incident involving Hugging Face infrastructure during an internal security evaluation. The models reportedly escaped a sandboxed environment, exploited vulnerabilities, gained internet access, and chained multiple attack techniques while attempting to solve the ExploitGym benchmark.

Continue reading: OpenAI AI Models Linked to Cyber Incident Targetin…
Palo Alto PAN-OS Authentication Bypass Exploited to Deploy Qilin Ransomware

Palo Alto PAN-OS Authentication Bypass Exploited to Deploy Qilin Ransomware

RedSide Security July 21, 2026 Cybercrime 94 views

Threat actors are exploiting CVE-2026-0257 in Palo Alto PAN-OS GlobalProtect to bypass authentication, gain VPN access, steal Active Directory credentials, and deploy Qilin ransomware. Security teams should patch immediately and rotate credentials if compromise is suspected.

Continue reading: Palo Alto PAN-OS Authentication Bypass Exploited t…
PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability

PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability

RedSide Security July 08, 2026 Vulnerability 66 views

Researchers have released a working proof-of-concept exploit for CVE-2025-53770, a critical SharePoint Server remote code execution vulnerability. The flaw abuses XML schema imports and .NET deserialization gadgets to achieve code execution on vulnerable on-premises SharePoint deployments, increasing the risk of large-scale exploitation.

Continue reading: PoC and Technical Details Released for SharePoint …
Critical Fast-MCP-Telegram Vulnerability Allows Authentication Bypass via Path Traversal

Critical Fast-MCP-Telegram Vulnerability Allows Authentication Bypass via Path Traversal

RedSide Security July 07, 2026 Vulnerability 84 views

A critical authentication bypass vulnerability (**CVE-2026-52830**) in Fast-MCP-Telegram allows attackers to exploit path traversal flaws in Bearer token validation and gain unauthorized access to Telegram sessions. Users are strongly advised to upgrade to version 0.19.1 immediately.

Continue reading: Critical Fast-MCP-Telegram Vulnerability Allows Au…
Introducing AnyStix: Automated Country-Based Threat Intelligence for OpenCTI

Introducing AnyStix: Automated Country-Based Threat Intelligence for OpenCTI

RedSide Security July 02, 2026 Tools & Technology 83 views

AnyStix is an open-source threat intelligence tool that collects country-specific malicious submissions from ANY.RUN, enriches them with indicators, converts them into STIX 2.1 format, and automatically imports them into OpenCTI. The platform enables continuous, region-focused threat intelligence collection using publicly available sandbox data.

Continue reading: Introducing AnyStix: Automated Country-Based Threa…
Introducing CVEAlertor: Now With Public PoC & Exploit Monitoring

Introducing CVEAlertor: Now With Public PoC & Exploit Monitoring

RedSide Security July 02, 2026 Tools & Technology 92 views

CVEAlertor now monitors GitHub for newly released proof-of-concept exploits tied to tracked vulnerabilities. Security teams receive instant Telegram alerts when new CVEs are published and when public exploit code becomes available, helping prioritize patching before attackers strike.

Continue reading: Introducing CVEAlertor: Now With Public PoC & Expl…