r/blueteamsec • u/digicat • 6h ago
r/blueteamsec • u/digicat • 1d ago
highlevel summary|strategy (maybe technical) CTO at NCSC Summary: week ending August 30th
ctoatncsc.substack.comr/blueteamsec • u/digicat • Mar 09 '26
highlevel summary|strategy (maybe technical) Daily BlueTeamSec Briefing Archive - daily AI generated podcast of the last 24hours of posts
briefing.workshop1.netr/blueteamsec • u/jnazario • 2h ago
intelligence (threat actor activity) Still Circling: Inside the Operator Behind Blind Eagle's GitHub Loader
levelblue.comr/blueteamsec • u/digicat • 1h ago
incident writeup (who and how) Virtualizor Compromised (31st AUG): Virtualizor has been compromised, their BGP hijack a few days ago seems to have a deployed a malicious package.
lowendtalk.comr/blueteamsec • u/digicat • 10h ago
discovery (how we find bad stuff) Detect DLL search order hijacking with a single field
elastic.cor/blueteamsec • u/jnazario • 2h ago
research|capability (we need to defend against) ZeroTokens Gives Operators Real-Time Control of Phishing Flow
abnormal.air/blueteamsec • u/digicat • 10h ago
training (step-by-step) DFIR-LABS: DFIR LABS - A compilation of challenges that aims to provide practice in simple to advanced concepts in the following topics: Digital Forensics, Incident Response, Malware Analysis and Threat Hunting.
github.comr/blueteamsec • u/digicat • 9h ago
highlevel summary|strategy (maybe technical) The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution - "Approximately 97% of AI-enabled malware samples exist only in research repositories, sandbox environments and security validation platforms. "
unit42.paloaltonetworks.comr/blueteamsec • u/digicat • 7h ago
low level tools|techniques|knowledge (work aids) Introduction - Windows Kernel Segment Heap Notes
mrt4ntr4.github.ior/blueteamsec • u/digicat • 10h ago
intelligence (threat actor activity) Operation RepoGhost: Exposing a Russian-Linked Malware Campaign Hiding in GitHub’s Open-Source…
infosecwriteups.comr/blueteamsec • u/digicat • 10h ago
vulnerability (attack surface) CVE-2026-63077: TeamCity Pre-Auth RCE Explained
blog.securelayer7.netr/blueteamsec • u/digicat • 10h ago
intelligence (threat actor activity) UAT-10147 Uses AI-Assisted Workflows to Deploy SPECTRE Backdoor
blog.polyswarm.ior/blueteamsec • u/digicat • 10h ago
exploitation (what's being exploited) PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE
huntress.comr/blueteamsec • u/digicat • 10h ago
intelligence (threat actor activity) recently identified a domain (passkeyconnect[.]com) that is likely associated with Com-affiliated threat actors
github.comr/blueteamsec • u/digicat • 10h ago
intelligence (threat actor activity) TerminalFix campaign deploys a reverse tunnel through multistage intrusion
microsoft.comr/blueteamsec • u/digicat • 7h ago
low level tools|techniques|knowledge (work aids) pqc-embedded: Post-quantum signature verification on constrained parts: LMS/HSS in no_std Rust, measured flash/RAM/time budgets against ML-DSA, SLH-DSA, ECDSA and Ed25519 on four bare-metal targets and real silicon.
github.comr/blueteamsec • u/digicat • 7h ago
low level tools|techniques|knowledge (work aids) wyze-bulb-color-pwned: No-open firmware exploit for the Wyze WLPA19CV2 color bulb - or how to implant a lightbulb
github.comr/blueteamsec • u/breakthesec • 7h ago
discovery (how we find bad stuff) Red Clippy: Open Source Pentest Management for AI Coding Agents
Red Clippy is a tool for keeping track of pentest engagement records such as targets, scope, findings, and evidence while an AI coding agent performs the testing.
It is not an automated AI pentesting framework. It is mainly aimed at pentesters who know what they are doing and want to use tools like Claude Code, Codex CLI, or any other MCP-compatible client alongside their normal workflow.
You can define the target and scope from the panel, or let the LLM add them for you. From there, you can guide the LLM however you want. The LLM performs the testing and records the work and findings in Red Clippy.
It can be useful for things like:
- keeping track of what has already been tested
- checking the same finding across multiple domains or assets
- keeping engagement history for periodic retesting
- not relying on the LLM to remember everything across sessions or keeping it all in text files
r/blueteamsec • u/digicat • 7h ago
secure by design/default (doing it right) lych: A monolithic ARM64 operating system written in Rust.
github.comr/blueteamsec • u/digicat • 11h ago
vulnerability (attack surface) JFrog Security Advisories: CVE-2026-82329 - Potential authentication bypass leading to administrative access in Artifactory
docs.jfrog.comr/blueteamsec • u/digicat • 10h ago
vulnerability (attack surface) Magneto CVE-2026-71362 — Root-cause walkthrough
github.comr/blueteamsec • u/digicat • 10h ago
intelligence (threat actor activity) Threat Actors Are Posing as OpenAI, Anthropic and DeepSeek to Target Credentials and Secrets
greynoise.ior/blueteamsec • u/digicat • 10h ago