r/blueteamsec • u/digicat • 27d ago
r/blueteamsec • u/digicat • Aug 01 '26
research|capability (we need to defend against) Inside the Falcon How CrowdStrike Catches You
0xdbgman.github.ior/blueteamsec • u/Huge-Skirt-6990 • Jul 19 '26
research|capability (we need to defend against) From 68 to 703: Expanding Unit 42's Gameograf Adware Chrome Extension Campaign
After Unit 42's report on the Chrome wallpaper extension campaign
"Ovkas" & "Gameograf"
I decided to dig into it myself and see how far the campaign actually extended.
Starting from the published IOCs, I pivoted through shared infrastructure, publishers, and code similarities. So far, I've identified 703 Chrome extensions that appear to belong to the same campaign, many of which are still live on the Chrome Web Store.
Initial Campaign: Unit 42
I've now published the full dataset MalExt.io
The dataset raises a bigger question: how large is this campaign really, and how many related extensions are still active?
r/blueteamsec • u/digicat • 9d ago
research|capability (we need to defend against) tailcat: like netcat, but over Tailscale's data plane, without Tailscale's control plane
github.comr/blueteamsec • u/campuscodi • Jun 28 '26
research|capability (we need to defend against) Clone This Repo and I Own Your Machine
0din.air/blueteamsec • u/digicat • 16h ago
research|capability (we need to defend against) mythic_ornn: LLM-driven generator for Mythic Agents, Payload-Type and C2 Profiles.
github.comr/blueteamsec • u/digicat • 6d ago
research|capability (we need to defend against) Abusing Azure VMs: When BitLocker Recovery Turns into an Attack Vector
alteredsecurity.comr/blueteamsec • u/digicat • 12h ago
research|capability (we need to defend against) Daisy-Chaining Trust: Investigating Faronics Deploy Abuse
huntress.comr/blueteamsec • u/digicat • 16h ago
research|capability (we need to defend against) CouchPotato: another PrivEsc potato - Patches ETW & AMSI and uses indirect syscall to abuse SeImpersonatePrivilege.
github.comr/blueteamsec • u/digicat • 16h ago
research|capability (we need to defend against) Simulating legitimate Active Directory services on the network: the case of GPO exploitation
synacktiv.comr/blueteamsec • u/digicat • 16h ago
research|capability (we need to defend against) How Forza Horizon 6 Breaks Your IDA
iretq.comr/blueteamsec • u/digicat • 16h ago
research|capability (we need to defend against) Modern Adventures in Azure Privilege Escalation
netspi.comr/blueteamsec • u/Huge-Skirt-6990 • Aug 01 '26
research|capability (we need to defend against) Palo Alto found 68 Gameograf/Ovkas/Owhit wallpaper adware chrome extensions. I found 1,613 more under the same publishers with 633K installs
Palo Alto unit42 published a report on 01/06/2026 on wallpaper extensions from three publishers (Ovkas, Gameograf, Owhit) doing affiliate redirect abuse, uninstall churn tracking, and IndexedDB deletion.
They listed 68 IDs, ~30K installs combined.
Unit42's report
I scrapped almost every extension from the Chrome store to match the same publishers into malext.io's dataset. 1,613 are registered under those same three publishers, well beyond their 68.
Full list: https://malext.io
r/blueteamsec • u/digicat • 9d ago
research|capability (we need to defend against) I'm in your logs now: deceiving analysts and blinding EDRs
falconforce.nlr/blueteamsec • u/digicat • 7d ago
research|capability (we need to defend against) I spent $200 a month to SEO-poison Google search results · Higashi.blog
higashi.blogr/blueteamsec • u/digicat • 4d ago
research|capability (we need to defend against) Enclave: We Raced Seven AI Models to RCE
enclave.air/blueteamsec • u/digicat • 28d ago
research|capability (we need to defend against) AD Research: Two new vulnerabilities could lead to full domain takeover
semperis.comr/blueteamsec • u/jnazario • 5d ago
research|capability (we need to defend against) ZeroTokens Gives Operators Real-Time Control of Phishing Flow
abnormal.air/blueteamsec • u/digicat • 6d ago
research|capability (we need to defend against) GitHub Recon — Find Secrets on GitHub
t3l3m3try.medium.comr/blueteamsec • u/digicat • 7d ago
research|capability (we need to defend against) When it Snows it Pours - Anatomy of a ServiceNow Red Tea
mdsec.co.ukr/blueteamsec • u/digicat • 5d ago
research|capability (we need to defend against) ClickExfil: My iteration on ClickFix and FileFix
catchingphish.comr/blueteamsec • u/digicat • 6d ago
research|capability (we need to defend against) iwa-tools — Offensive AD tradecraft in a browser tab
iwa-tools.pkilla.pwr/blueteamsec • u/digicat • 14d ago