r/blueteamsec 2d ago

highlevel summary|strategy (maybe technical) CTO at NCSC Summary: week ending August 30th

Thumbnail ctoatncsc.substack.com
1 Upvotes

r/blueteamsec Mar 09 '26

highlevel summary|strategy (maybe technical) Daily BlueTeamSec Briefing Archive - daily AI generated podcast of the last 24hours of posts

Thumbnail briefing.workshop1.net
3 Upvotes

r/blueteamsec 5h ago

incident writeup (who and how) [Softaculous] Security Incident – BGP Hijacking

Thumbnail virtualizor.com
7 Upvotes

r/blueteamsec 7h ago

incident writeup (who and how) Malicious Packages Served from Unauthorized Registry Server - An unidentified malicious actor gained access to Coder’s Cloudflare infrastructure and added unauthorized IP addresses to the pool used for Coder’s module registry.

Thumbnail github.com
3 Upvotes

r/blueteamsec 19h ago

highlevel summary|strategy (maybe technical) I Think the Military Commissary Freezers Were Hacked - 'the Pentagon now acknowledging a “possible refrigeration disruption” at numerous DeCA commissaries'

Thumbnail signalandsilence.substack.com
21 Upvotes

r/blueteamsec 8h ago

intelligence (threat actor activity) Anatomy of BraZetsu: How Cybercriminals Fuel the Underground Ecosystem

Thumbnail group-ib.com
2 Upvotes

r/blueteamsec 9h ago

intelligence (threat actor activity) Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

Thumbnail securelist.com
2 Upvotes

r/blueteamsec 6h ago

training (step-by-step) Beyond Chat: Building Multi Agent SOC Ecosystems with Claude and Google MCP

Thumbnail security.googlecloudcommunity.com
1 Upvotes

r/blueteamsec 6h ago

malware analysis (like butterfly collections) I built a Linux syscall monitor in C — would love some feedback

0 Upvotes

Hey everyone! I've been working on a project called SysTrace, a Linux behavioral monitoring tool built mainly to learn more about Linux internals, system calls, and cybersecurity.

It uses ptrace to trace a process and monitor different types of activity, including:

File operations

Process execution

Network-related syscalls

Memory operations

I also added a simple rule-based detection system and experimented with using collected behavioral data for ML classification.What would you improve next? I'm especially interested in opinions about the architecture and whether moving from ptrace toward eBPF would be a good next step.

github


r/blueteamsec 14h ago

discovery (how we find bad stuff) Infostealers are targeting active Claude login sessions (MFA won't save you if your PC is infected)

4 Upvotes

Anthropic warned users about infostealer malware stealing active browser session tokens. Since the session is already logged in, attackers gain access without triggering 2FA or needing a password.

This isn't a flaw in Claude's infrastructure, but it highlights why revoking active sessions and securing developer endpoints is critical when dealing with AI tools containing sensitive chats/code.


r/blueteamsec 20h ago

low level tools|techniques|knowledge (work aids) Honeypot-Auditor: Open-source CLI for blue/purple teams to audit and fingerprint deceptive infrastructure

12 Upvotes

Context & Use Case Deception technology relies heavily on believability. If a low-interaction decoy exposes static banners, uniform error codes, or anomalous TCP/FSM behavior, sophisticated adversaries will fingerprint and bypass it.

I developed Honeypot-Auditor as a Python-based utility to help blue and purple teams test their own honeypots, identify fingerprinting leaks, and validate decoy believability before deploying them into production environments.

How It Works

  • Multi-Protocol Fingerprinting: Runs non-destructive behavioral probes across 16 protocols (SSH, SMB, Redis, MySQL, Postgres, Telnet, HTTP, etc.).
  • Behavioral Honeyscore (0–100%): Evaluates host behavior rather than relying on static product-name string matches (arbitrary authentication acceptances, FSM tells, multi-protocol co-tenancy corroboration).
  • Deep Mode & Signatures: Inspects shell semantics, HASSH/TCP stack characteristics, and known signatures for common decoy frameworks (e.g., uniform FTP 500 responses, MySQL SSL drop quirks).
  • Output: Generates CLI reports and structured JSON for SIEM/automation pipeline ingestion.

Installation & Quick Start

pip install honeypot-auditor
honeypot-auditor --target <DECOY_IP> -v

Links & Documentation

Interested in feedback from deception engineers and blue teams:

Are there specific behavioral tells or signatures from modern decoys you'd like added to the rule engine? Pull requests and feedback are welcome!


r/blueteamsec 12h ago

research|capability (we need to defend against) Enclave: We Raced Seven AI Models to RCE

Thumbnail enclave.ai
2 Upvotes

r/blueteamsec 8h ago

incident writeup (who and how) The August 2026 Virtualizor Incident in BGPHorizon

Thumbnail bgphorizon.com
0 Upvotes

r/blueteamsec 19h ago

vulnerability (attack surface) OEMpocalypse Now: A Generic Exploitation Strategy from Android untrusted app to root

Thumbnail calif.io
3 Upvotes

r/blueteamsec 1d ago

intelligence (threat actor activity) Fire Ant Evolves: From Hypervisors to Trusted Infrastructure

Thumbnail sygnia.co
6 Upvotes

r/blueteamsec 18h ago

low level tools|techniques|knowledge (work aids) /vhf-morse-transmitter-monitor: Set your radio to 148.500 MHz, select FM, USB, or CW mode, and set the squelch to 0 or 1. Then, extend your radio's antenna toward the monitor's HDMI port, and congratulations—you can now transmit in Morse code directly from your monitor!

Thumbnail github.com
2 Upvotes

r/blueteamsec 18h ago

secure by design/default (doing it right) Good news about the Pixel 11. It still has at least bare minimum support for MTE at a hardware level - but disabled in Android firmware

Thumbnail x.com
0 Upvotes

r/blueteamsec 18h ago

low level tools|techniques|knowledge (work aids) cavium-cn6640-snic10e-octeon-ii-nic: Out-of-tree Linux driver stack and boot tooling for the Cavium CN6640-SNIC10E (Octeon II, PCI 177d:0092), exposing the card as two independent 10 GbE interfaces (oct0/oct1) over a reverse-engineered PCIe BAR2 shared-memory datapath

Thumbnail github.com
1 Upvotes

r/blueteamsec 19h ago

vulnerability (attack surface) Qualcomm BootROM code signing bypass CVE-2026-25262 - needs hardware replacements

Thumbnail i.blackhat.com
1 Upvotes

r/blueteamsec 19h ago

highlevel summary|strategy (maybe technical) Improving our alignment and security practices - 'By default, all cyber evaluations should run inside a hardened sandbox (an isolated computing environment) with no internet access'

Thumbnail anthropic.com
1 Upvotes

r/blueteamsec 1d ago

highlevel summary|strategy (maybe technical) Russian-speaking cybercriminals used SpaceX’s Cursor AI tool to hack seven companies

Thumbnail reuters.com
7 Upvotes

r/blueteamsec 1d ago

incident writeup (who and how) Virtualizor Compromised (31st AUG): Virtualizor has been compromised, their BGP hijack a few days ago seems to have a deployed a malicious package.

Thumbnail lowendtalk.com
6 Upvotes

r/blueteamsec 1d ago

incident writeup (who and how) How the Russians Got Inside My Phone

Thumbnail spytalk.co
15 Upvotes

r/blueteamsec 1d ago

tradecraft (how we defend) JavaScript obfuscation: From party trick to phishing kit

Thumbnail blog.talosintelligence.com
2 Upvotes

r/blueteamsec 1d ago

intelligence (threat actor activity) Still Circling: Inside the Operator Behind Blind Eagle's GitHub Loader

Thumbnail levelblue.com
3 Upvotes