Windows Security — Cybersecurity News

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph is an open-source network investigation and threat hunting tool that transforms packet cap...

Open-Source Network Discovery & Topology Mapping

Open-Source Network Discovery & Topology Mapping

RedSide Security has open-sourced NETMAPPER, a network discovery and visualization tool designed to ...

 RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

When an incident unfolds and all you have left are Windows event logs, understanding attacker moveme...

Latest Posts

ShieldBreak: Microsoft Defender Zero-Day and RoguePlanet Patch Bypass

ShieldBreak: Microsoft Defender Zero-Day and RoguePlanet Patch Bypass

RedSide Security September 17, 2026 Vulnerability 72 views

ShieldBreak (CVE-2026-69414) is a Microsoft Defender elevation-of-privilege vulnerability linked to research on bypassing mitigations for RoguePlanet (CVE-2026-50656). Explore the technical research, affected components, and defensive detection opportunities.

Continue reading: ShieldBreak: Microsoft Defender Zero-Day and Rogue…
Microsoft SCCM Vulnerability Chain Could Enable Remote SYSTEM-Level Code Execution

Microsoft SCCM Vulnerability Chain Could Enable Remote SYSTEM-Level Code Execution

RedSide Security August 17, 2026 Vulnerability 167 views

Security researchers have disclosed an attack chain affecting Microsoft System Center Configuration Manager (SCCM) that could allow standard Active Directory users to ultimately execute malicious code with SYSTEM privileges on an SCCM primary site server. The chain combines an AdminService authorization flaw, weak signature validation, CAB path traversal, and unsafe DLL loading.

Continue reading: Microsoft SCCM Vulnerability Chain Could Enable Re…
New "Pass-ta-key" Attack Steals Google Passkeys Without Passwords or Biometrics

New "Pass-ta-key" Attack Steals Google Passkeys Without Passwords or Biometrics

RedSide Security August 04, 2026 Vulnerability 139 views

Researchers have disclosed three new attacks—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—that allow malware on compromised Windows systems to hijack Google-synced passkeys without passwords or biometrics. The findings expose weaknesses in Chrome's Cloud Authenticator implementation rather than the underlying passkey cryptography.

Continue reading: New "Pass-ta-key" Attack Steals Google Passkeys Wi…
Citrix Secure Access Client Flaws Allow SYSTEM Privilege Escalation on Windows Endpoints

Citrix Secure Access Client Flaws Allow SYSTEM Privilege Escalation on Windows Endpoints

RedSide Security July 18, 2026 Vulnerability 112 views

Cloud Software Group has patched two vulnerabilities affecting Citrix Secure Access Client and Endpoint Analysis Client for Windows, including CVE-2026-53565, a high-severity privilege escalation flaw that allows low-privileged users to gain full SYSTEM access. Organizations are urged to upgrade immediately.

Continue reading: Citrix Secure Access Client Flaws Allow SYSTEM Pri…
PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability

PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability

RedSide Security July 08, 2026 Vulnerability 121 views

Researchers have released a working proof-of-concept exploit for CVE-2025-53770, a critical SharePoint Server remote code execution vulnerability. The flaw abuses XML schema imports and .NET deserialization gadgets to achieve code execution on vulnerable on-premises SharePoint deployments, increasing the risk of large-scale exploitation.

Continue reading: PoC and Technical Details Released for SharePoint …
Critical SimpleHelp Flaw Actively Exploited to Deploy TaskWeaver Loader and Djinn Stealer

Critical SimpleHelp Flaw Actively Exploited to Deploy TaskWeaver Loader and Djinn Stealer

RedSide Security June 30, 2026 Cybersecurity 117 views

Threat actors are actively exploiting CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp RMM software, to deploy the TaskWeaver loader and Djinn Stealer. The malware targets cloud credentials, developer tools, AI platforms, cryptocurrency wallets, and enterprise infrastructure across Windows, macOS, and Linux systems.

Continue reading: Critical SimpleHelp Flaw Actively Exploited to Dep…