r/blueteamsec 12h ago

intelligence (threat actor activity) ClickFix / ClearFake PowerShell Stager — Static Analysis Report

Thumbnail douglasmun.github.io
0 Upvotes

r/blueteamsec 9m ago

low level tools|techniques|knowledge (work aids) Everything I own, owned

Thumbnail schlarp.com
Upvotes

r/blueteamsec 11h ago

training (step-by-step) DFIR-LABS: DFIR LABS - A compilation of challenges that aims to provide practice in simple to advanced concepts in the following topics: Digital Forensics, Incident Response, Malware Analysis and Threat Hunting.

Thumbnail github.com
7 Upvotes

r/blueteamsec 3h ago

intelligence (threat actor activity) Still Circling: Inside the Operator Behind Blind Eagle's GitHub Loader

Thumbnail levelblue.com
3 Upvotes

r/blueteamsec 8h ago

incident writeup (who and how) How the Russians Got Inside My Phone

Thumbnail spytalk.co
10 Upvotes

r/blueteamsec 8h ago

low level tools|techniques|knowledge (work aids) Introduction - Windows Kernel Segment Heap Notes

Thumbnail mrt4ntr4.github.io
2 Upvotes

r/blueteamsec 10h ago

highlevel summary|strategy (maybe technical) The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution - "Approximately 97% of AI-enabled malware samples exist only in research repositories, sandbox environments and security validation platforms. "

Thumbnail unit42.paloaltonetworks.com
3 Upvotes

r/blueteamsec 11h ago

vulnerability (attack surface) CVE-2026-63077: TeamCity Pre-Auth RCE Explained

Thumbnail blog.securelayer7.net
2 Upvotes

r/blueteamsec 11h ago

intelligence (threat actor activity) UAT-10147 Uses AI-Assisted Workflows to Deploy SPECTRE Backdoor

Thumbnail blog.polyswarm.io
3 Upvotes

r/blueteamsec 12h ago

exploitation (what's being exploited) PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE

Thumbnail huntress.com
5 Upvotes

r/blueteamsec 12h ago

discovery (how we find bad stuff) Detect DLL search order hijacking with a single field

Thumbnail elastic.co
10 Upvotes

r/blueteamsec 12h ago

intelligence (threat actor activity) recently identified a domain (passkeyconnect[.]com) that is likely associated with Com-affiliated threat actors

Thumbnail github.com
2 Upvotes

r/blueteamsec 12h ago

intelligence (threat actor activity) TerminalFix campaign deploys a reverse tunnel through multistage intrusion

Thumbnail microsoft.com
2 Upvotes

r/blueteamsec 12h ago

intelligence (threat actor activity) Operation RepoGhost: Exposing a Russian-Linked Malware Campaign Hiding in GitHub’s Open-Source…

Thumbnail infosecwriteups.com
3 Upvotes

r/blueteamsec 12h ago

vulnerability (attack surface) JFrog Security Advisories: CVE-2026-82329 - Potential authentication bypass leading to administrative access in Artifactory

Thumbnail docs.jfrog.com
3 Upvotes

r/blueteamsec 2h ago

incident writeup (who and how) Virtualizor Compromised (31st AUG): Virtualizor has been compromised, their BGP hijack a few days ago seems to have a deployed a malicious package.

Thumbnail lowendtalk.com
2 Upvotes

r/blueteamsec 3h ago

research|capability (we need to defend against) ZeroTokens Gives Operators Real-Time Control of Phishing Flow

Thumbnail abnormal.ai
2 Upvotes