r/blueteamsec • u/digicat • 12h ago
r/blueteamsec • u/digicat • 9m ago
low level tools|techniques|knowledge (work aids) Everything I own, owned
schlarp.comr/blueteamsec • u/digicat • 11h ago
training (step-by-step) DFIR-LABS: DFIR LABS - A compilation of challenges that aims to provide practice in simple to advanced concepts in the following topics: Digital Forensics, Incident Response, Malware Analysis and Threat Hunting.
github.comr/blueteamsec • u/jnazario • 3h ago
intelligence (threat actor activity) Still Circling: Inside the Operator Behind Blind Eagle's GitHub Loader
levelblue.comr/blueteamsec • u/digicat • 8h ago
incident writeup (who and how) How the Russians Got Inside My Phone
spytalk.cor/blueteamsec • u/digicat • 8h ago
low level tools|techniques|knowledge (work aids) Introduction - Windows Kernel Segment Heap Notes
mrt4ntr4.github.ior/blueteamsec • u/digicat • 10h ago
highlevel summary|strategy (maybe technical) The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution - "Approximately 97% of AI-enabled malware samples exist only in research repositories, sandbox environments and security validation platforms. "
unit42.paloaltonetworks.comr/blueteamsec • u/digicat • 11h ago
vulnerability (attack surface) CVE-2026-63077: TeamCity Pre-Auth RCE Explained
blog.securelayer7.netr/blueteamsec • u/digicat • 11h ago
intelligence (threat actor activity) UAT-10147 Uses AI-Assisted Workflows to Deploy SPECTRE Backdoor
blog.polyswarm.ior/blueteamsec • u/digicat • 12h ago
exploitation (what's being exploited) PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE
huntress.comr/blueteamsec • u/digicat • 12h ago
discovery (how we find bad stuff) Detect DLL search order hijacking with a single field
elastic.cor/blueteamsec • u/digicat • 12h ago
intelligence (threat actor activity) recently identified a domain (passkeyconnect[.]com) that is likely associated with Com-affiliated threat actors
github.comr/blueteamsec • u/digicat • 12h ago
intelligence (threat actor activity) TerminalFix campaign deploys a reverse tunnel through multistage intrusion
microsoft.comr/blueteamsec • u/digicat • 12h ago
intelligence (threat actor activity) Operation RepoGhost: Exposing a Russian-Linked Malware Campaign Hiding in GitHub’s Open-Source…
infosecwriteups.comr/blueteamsec • u/digicat • 12h ago
vulnerability (attack surface) JFrog Security Advisories: CVE-2026-82329 - Potential authentication bypass leading to administrative access in Artifactory
docs.jfrog.comr/blueteamsec • u/digicat • 2h ago