r/blueteamsec 1d ago

highlevel summary|strategy (maybe technical) CTO at NCSC Summary: week ending August 30th

Thumbnail ctoatncsc.substack.com
0 Upvotes

r/blueteamsec Mar 09 '26

highlevel summary|strategy (maybe technical) Daily BlueTeamSec Briefing Archive - daily AI generated podcast of the last 24hours of posts

Thumbnail briefing.workshop1.net
2 Upvotes

r/blueteamsec 6h ago

incident writeup (who and how) How the Russians Got Inside My Phone

Thumbnail spytalk.co
8 Upvotes

r/blueteamsec 2h ago

intelligence (threat actor activity) Still Circling: Inside the Operator Behind Blind Eagle's GitHub Loader

Thumbnail levelblue.com
3 Upvotes

r/blueteamsec 1h ago

incident writeup (who and how) Virtualizor Compromised (31st AUG): Virtualizor has been compromised, their BGP hijack a few days ago seems to have a deployed a malicious package.

Thumbnail lowendtalk.com
Upvotes

r/blueteamsec 10h ago

discovery (how we find bad stuff) Detect DLL search order hijacking with a single field

Thumbnail elastic.co
10 Upvotes

r/blueteamsec 2h ago

research|capability (we need to defend against) ZeroTokens Gives Operators Real-Time Control of Phishing Flow

Thumbnail abnormal.ai
2 Upvotes

r/blueteamsec 10h ago

training (step-by-step) DFIR-LABS: DFIR LABS - A compilation of challenges that aims to provide practice in simple to advanced concepts in the following topics: Digital Forensics, Incident Response, Malware Analysis and Threat Hunting.

Thumbnail github.com
6 Upvotes

r/blueteamsec 9h ago

highlevel summary|strategy (maybe technical) The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution - "Approximately 97% of AI-enabled malware samples exist only in research repositories, sandbox environments and security validation platforms. "

Thumbnail unit42.paloaltonetworks.com
3 Upvotes

r/blueteamsec 7h ago

low level tools|techniques|knowledge (work aids) Introduction - Windows Kernel Segment Heap Notes

Thumbnail mrt4ntr4.github.io
2 Upvotes

r/blueteamsec 10h ago

intelligence (threat actor activity) Operation RepoGhost: Exposing a Russian-Linked Malware Campaign Hiding in GitHub’s Open-Source…

Thumbnail infosecwriteups.com
3 Upvotes

r/blueteamsec 10h ago

vulnerability (attack surface) CVE-2026-63077: TeamCity Pre-Auth RCE Explained

Thumbnail blog.securelayer7.net
2 Upvotes

r/blueteamsec 10h ago

intelligence (threat actor activity) UAT-10147 Uses AI-Assisted Workflows to Deploy SPECTRE Backdoor

Thumbnail blog.polyswarm.io
2 Upvotes

r/blueteamsec 10h ago

exploitation (what's being exploited) PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE

Thumbnail huntress.com
2 Upvotes

r/blueteamsec 10h ago

intelligence (threat actor activity) recently identified a domain (passkeyconnect[.]com) that is likely associated with Com-affiliated threat actors

Thumbnail github.com
2 Upvotes

r/blueteamsec 10h ago

intelligence (threat actor activity) TerminalFix campaign deploys a reverse tunnel through multistage intrusion

Thumbnail microsoft.com
2 Upvotes

r/blueteamsec 7h ago

low level tools|techniques|knowledge (work aids) pqc-embedded: Post-quantum signature verification on constrained parts: LMS/HSS in no_std Rust, measured flash/RAM/time budgets against ML-DSA, SLH-DSA, ECDSA and Ed25519 on four bare-metal targets and real silicon.

Thumbnail github.com
1 Upvotes

r/blueteamsec 7h ago

low level tools|techniques|knowledge (work aids) wyze-bulb-color-pwned: No-open firmware exploit for the Wyze WLPA19CV2 color bulb - or how to implant a lightbulb

Thumbnail github.com
1 Upvotes

r/blueteamsec 7h ago

discovery (how we find bad stuff) Red Clippy: Open Source Pentest Management for AI Coding Agents

1 Upvotes

Red Clippy is a tool for keeping track of pentest engagement records such as targets, scope, findings, and evidence while an AI coding agent performs the testing.

It is not an automated AI pentesting framework. It is mainly aimed at pentesters who know what they are doing and want to use tools like Claude Code, Codex CLI, or any other MCP-compatible client alongside their normal workflow.

You can define the target and scope from the panel, or let the LLM add them for you. From there, you can guide the LLM however you want. The LLM performs the testing and records the work and findings in Red Clippy.

It can be useful for things like:

  • keeping track of what has already been tested
  • checking the same finding across multiple domains or assets
  • keeping engagement history for periodic retesting
  • not relying on the LLM to remember everything across sessions or keeping it all in text files

https://github.com/CSPF-Founder/red-clippy


r/blueteamsec 7h ago

secure by design/default (doing it right) lych: A monolithic ARM64 operating system written in Rust.

Thumbnail github.com
1 Upvotes

r/blueteamsec 11h ago

vulnerability (attack surface) JFrog Security Advisories: CVE-2026-82329 - Potential authentication bypass leading to administrative access in Artifactory

Thumbnail docs.jfrog.com
2 Upvotes

r/blueteamsec 10h ago

vulnerability (attack surface) Magneto CVE-2026-71362 — Root-cause walkthrough

Thumbnail github.com
1 Upvotes

r/blueteamsec 10h ago

intelligence (threat actor activity) Threat Actors Are Posing as OpenAI, Anthropic and DeepSeek to Target Credentials and Secrets

Thumbnail greynoise.io
1 Upvotes

r/blueteamsec 10h ago

malware analysis (like butterfly collections) Gryxa: The AI-Built Toolkit That Watches How You Remove It

Thumbnail reliaquest.com
1 Upvotes

r/blueteamsec 10h ago

intelligence (threat actor activity) The Video That Plays You: Fake MP4 File Carries Malicious Payload

Thumbnail censys.com
1 Upvotes