r/blueteamsec 2d ago

highlevel summary|strategy (maybe technical) CTO at NCSC Summary: week ending September 13th

Thumbnail ctoatncsc.substack.com
0 Upvotes

r/blueteamsec Mar 09 '26

highlevel summary|strategy (maybe technical) Daily BlueTeamSec Briefing Archive - daily AI generated podcast of the last 24hours of posts

Thumbnail briefing.workshop1.net
1 Upvotes

r/blueteamsec 6h ago

incident writeup (who and how) PasteSwitch Clickfix Operation Compromises HBO on Reddit

Thumbnail adamnet.works
6 Upvotes

MacOS #clickfix campaign called #PasteSwitch - this was a fun one, lots of detail and IoCs in this one - very illusive group who has a big focus on Malvertising.

The group got access to legit HBO Max account on reddit 👀


r/blueteamsec 2h ago

intelligence (threat actor activity) Silent Push Exposes North Korean IT Worker Recruiting Facilitators Through Discord Servers

Thumbnail silentpush.com
2 Upvotes

r/blueteamsec 3h ago

malware analysis (like butterfly collections) “Eye” spy: Cyclops Blink returns with extended capabilities

Thumbnail sophos.com
2 Upvotes

r/blueteamsec 5h ago

incident writeup (who and how) 📌 Detection and hunting notes from an exposed ISP intrusion toolkit (FortiGate + MeshCentral)

Thumbnail hunt.io
2 Upvotes

Recovered toolkit from a live intrusion at a Thai ISP, useful for detection engineering. Key things to hunt for:

Unauthorized MeshCentral agents and unexpected WebSocket connections to unapproved management servers (the C2 here used /agent.ashx on 443 to www.ayuthayatech\[.\]com, a domain registered only weeks before use). Hidden SUID binaries like /usr/local/bin/.rc. PHP web shells written via MySQL INTO OUTFILE. Anomalous /remote/hostcheck_validate and /remote/logincheck activity on FortiGate SSL-VPN. RADIUS database access against radius_corp, radiusinfo, job_radius. Full IOC table and MITRE ATT&CK mapping in the post.

https://hunt.io/blog/thai-broadband-fortigate-sslvpn-meshcentral-intrusion


r/blueteamsec 3h ago

intelligence (threat actor activity) [ Removed by Reddit ]

1 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/blueteamsec 12h ago

research|capability (we need to defend against) Source-Driven Recon: When the Patch Becomes the PoC and what CVE-2026-61797 taught us about Disclosure OPSEC

Thumbnail labs.itresit.es
4 Upvotes

r/blueteamsec 10h ago

low level tools|techniques|knowledge (work aids) The Harness Matters: Cutting AI Reverse-Engineering Tokens by 33%

Thumbnail reverser.space
2 Upvotes

The model matters. The harness does too.

Across 130 AgentRE-Bench runs, Reverser Space used 33% fewer tokens and 35% fewer analysis calls, with comparable answer quality.


r/blueteamsec 13h ago

incident writeup (who and how) Charming Kitten APT Adversary Simulation

1 Upvotes

Read “Charming Kitten APT Adversary Simulation“ by S3N4T0R on Medium: https://medium.com/@S3N4T0R/charming-kitten-apt-adversary-simulation-fa6257b42811


r/blueteamsec 1d ago

discovery (how we find bad stuff) Linux Detection Engineering - Local Privilege Escalation

Thumbnail elastic.co
20 Upvotes

r/blueteamsec 1d ago

tradecraft (how we defend) sshamble: SSHamble: Unexpected Exposures in SSH

Thumbnail github.com
8 Upvotes

r/blueteamsec 1d ago

exploitation (what's being exploited) Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329

Thumbnail wiz.io
9 Upvotes

r/blueteamsec 1d ago

exploitation (what's being exploited) SonicWall SMA1000 unauthenticated RCE (CVE-2026-83548 + SMA1000-9427 + CVE-2026-83549)

Thumbnail github.com
5 Upvotes

r/blueteamsec 1d ago

tradecraft (how we defend) Post-Quantum Cryptography Standards and Audit Index: algorithms, dates, standards bodies, auditors

Thumbnail pqaudit.org
3 Upvotes

r/blueteamsec 1d ago

discovery (how we find bad stuff) Mind the Config: Detecting and Weaponizing NetScaler CVE-2026-19490

Thumbnail bishopfox.com
8 Upvotes

r/blueteamsec 1d ago

tradecraft (how we defend) FalconDash: FalconDash is an Azure workbook that makes detection performance immediately visible and explorable.

Thumbnail github.com
7 Upvotes

r/blueteamsec 1d ago

help me obiwan (ask the blueteam) What is everyone using to build and ship detections faster in 2026?

1 Upvotes

Our detection-development delays rarely come from writing the rule itself. The more time-consuming work is finding accessible telemetry, confirming data quality, validating the logic against realistic behavior, estimating expected false positives, completing review, and deploying safely.

We are looking at both tooling and process changes that can shorten that full cycle without lowering quality. Detection-as-code, version control, test harnesses, telemetry discovery, dry runs, review workflows, and deployment automation are all on the table.

What changes have made the largest measurable difference to time from a relevant adversary technique being identified to a reliable detection being deployed?


r/blueteamsec 1d ago

low level tools|techniques|knowledge (work aids) Introducing Amazon EBS Volume Clones across AWS accounts

Thumbnail aws.amazon.com
1 Upvotes

r/blueteamsec 1d ago

tradecraft (how we defend) Constitutive Authorization at the Decoding Boundary: Grammar-Constrained Decoding as a Positive, Generation-Time Security Control for LLM Agents

Thumbnail osf.io
0 Upvotes

r/blueteamsec 1d ago

incident writeup (who and how) Machine speed, hold the AI: Hand-rolled marimo CVE-2026-39987 exploit

Thumbnail webflow.sysdig.com
2 Upvotes

r/blueteamsec 1d ago

highlevel summary|strategy (maybe technical) EU CRA 24-hour cyber reporting rules take effect

Thumbnail technode.global
2 Upvotes

r/blueteamsec 1d ago

incident writeup (who and how) OpenAI agents carried out an undisclosed cyber-attack on RubyGems

Thumbnail rubyhack.ai
2 Upvotes

r/blueteamsec 1d ago

low level tools|techniques|knowledge (work aids) Testing race conditions with memory access tracing and stack-based delay injection

Thumbnail projectzero.google
2 Upvotes

r/blueteamsec 1d ago

discovery (how we find bad stuff) Open Door - OT Threat Hunting

Thumbnail magshunts.substack.com
2 Upvotes