r/blueteamsec • u/jnazario • 5h ago
r/blueteamsec • u/digicat • 2d ago
highlevel summary|strategy (maybe technical) CTO at NCSC Summary: week ending August 30th
ctoatncsc.substack.comr/blueteamsec • u/digicat • Mar 09 '26
highlevel summary|strategy (maybe technical) Daily BlueTeamSec Briefing Archive - daily AI generated podcast of the last 24hours of posts
briefing.workshop1.netr/blueteamsec • u/digicat • 7h ago
incident writeup (who and how) Malicious Packages Served from Unauthorized Registry Server - An unidentified malicious actor gained access to Coder’s Cloudflare infrastructure and added unauthorized IP addresses to the pool used for Coder’s module registry.
github.comr/blueteamsec • u/digicat • 19h ago
highlevel summary|strategy (maybe technical) I Think the Military Commissary Freezers Were Hacked - 'the Pentagon now acknowledging a “possible refrigeration disruption” at numerous DeCA commissaries'
signalandsilence.substack.comr/blueteamsec • u/jnazario • 8h ago
intelligence (threat actor activity) Anatomy of BraZetsu: How Cybercriminals Fuel the Underground Ecosystem
group-ib.comr/blueteamsec • u/jnazario • 9h ago
intelligence (threat actor activity) Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
securelist.comr/blueteamsec • u/jnazario • 6h ago
training (step-by-step) Beyond Chat: Building Multi Agent SOC Ecosystems with Claude and Google MCP
security.googlecloudcommunity.comr/blueteamsec • u/cdtrmnbaell • 6h ago
malware analysis (like butterfly collections) I built a Linux syscall monitor in C — would love some feedback
Hey everyone! I've been working on a project called SysTrace, a Linux behavioral monitoring tool built mainly to learn more about Linux internals, system calls, and cybersecurity.
It uses ptrace to trace a process and monitor different types of activity, including:
File operations
Process execution
Network-related syscalls
Memory operations
I also added a simple rule-based detection system and experimented with using collected behavioral data for ML classification.What would you improve next? I'm especially interested in opinions about the architecture and whether moving from ptrace toward eBPF would be a good next step.
r/blueteamsec • u/socradario • 14h ago
discovery (how we find bad stuff) Infostealers are targeting active Claude login sessions (MFA won't save you if your PC is infected)
Anthropic warned users about infostealer malware stealing active browser session tokens. Since the session is already logged in, attackers gain access without triggering 2FA or needing a password.
This isn't a flaw in Claude's infrastructure, but it highlights why revoking active sessions and securing developer endpoints is critical when dealing with AI tools containing sensitive chats/code.
r/blueteamsec • u/Dear-Jello-6693 • 20h ago
low level tools|techniques|knowledge (work aids) Honeypot-Auditor: Open-source CLI for blue/purple teams to audit and fingerprint deceptive infrastructure
Context & Use Case Deception technology relies heavily on believability. If a low-interaction decoy exposes static banners, uniform error codes, or anomalous TCP/FSM behavior, sophisticated adversaries will fingerprint and bypass it.
I developed Honeypot-Auditor as a Python-based utility to help blue and purple teams test their own honeypots, identify fingerprinting leaks, and validate decoy believability before deploying them into production environments.
How It Works
- Multi-Protocol Fingerprinting: Runs non-destructive behavioral probes across 16 protocols (SSH, SMB, Redis, MySQL, Postgres, Telnet, HTTP, etc.).
- Behavioral Honeyscore (0–100%): Evaluates host behavior rather than relying on static product-name string matches (arbitrary authentication acceptances, FSM tells, multi-protocol co-tenancy corroboration).
- Deep Mode & Signatures: Inspects shell semantics, HASSH/TCP stack characteristics, and known signatures for common decoy frameworks (e.g., uniform FTP 500 responses, MySQL SSL drop quirks).
- Output: Generates CLI reports and structured JSON for SIEM/automation pipeline ingestion.
Installation & Quick Start
pip install honeypot-auditor
honeypot-auditor --target <DECOY_IP> -v
Links & Documentation
- Cool Style Web Interface:https://mziqudhd92.github.io/honeypot-auditor/
- GitHub Repository:https://github.com/mziqudhd92/honeypot-auditor
- PyPI Package:https://pypi.org/project/honeypot-auditor/
Interested in feedback from deception engineers and blue teams:
Are there specific behavioral tells or signatures from modern decoys you'd like added to the rule engine? Pull requests and feedback are welcome!
r/blueteamsec • u/digicat • 12h ago
research|capability (we need to defend against) Enclave: We Raced Seven AI Models to RCE
enclave.air/blueteamsec • u/digicat • 8h ago
incident writeup (who and how) The August 2026 Virtualizor Incident in BGPHorizon
bgphorizon.comr/blueteamsec • u/digicat • 19h ago
vulnerability (attack surface) OEMpocalypse Now: A Generic Exploitation Strategy from Android untrusted app to root
calif.ior/blueteamsec • u/campuscodi • 1d ago
intelligence (threat actor activity) Fire Ant Evolves: From Hypervisors to Trusted Infrastructure
sygnia.cor/blueteamsec • u/digicat • 18h ago
low level tools|techniques|knowledge (work aids) /vhf-morse-transmitter-monitor: Set your radio to 148.500 MHz, select FM, USB, or CW mode, and set the squelch to 0 or 1. Then, extend your radio's antenna toward the monitor's HDMI port, and congratulations—you can now transmit in Morse code directly from your monitor!
github.comr/blueteamsec • u/digicat • 18h ago
secure by design/default (doing it right) Good news about the Pixel 11. It still has at least bare minimum support for MTE at a hardware level - but disabled in Android firmware
x.comr/blueteamsec • u/digicat • 18h ago
low level tools|techniques|knowledge (work aids) cavium-cn6640-snic10e-octeon-ii-nic: Out-of-tree Linux driver stack and boot tooling for the Cavium CN6640-SNIC10E (Octeon II, PCI 177d:0092), exposing the card as two independent 10 GbE interfaces (oct0/oct1) over a reverse-engineered PCIe BAR2 shared-memory datapath
github.comr/blueteamsec • u/digicat • 19h ago
vulnerability (attack surface) Qualcomm BootROM code signing bypass CVE-2026-25262 - needs hardware replacements
i.blackhat.comr/blueteamsec • u/digicat • 19h ago
highlevel summary|strategy (maybe technical) Improving our alignment and security practices - 'By default, all cyber evaluations should run inside a hardened sandbox (an isolated computing environment) with no internet access'
anthropic.comr/blueteamsec • u/digicat • 1d ago
highlevel summary|strategy (maybe technical) Russian-speaking cybercriminals used SpaceX’s Cursor AI tool to hack seven companies
reuters.comr/blueteamsec • u/digicat • 1d ago
incident writeup (who and how) Virtualizor Compromised (31st AUG): Virtualizor has been compromised, their BGP hijack a few days ago seems to have a deployed a malicious package.
lowendtalk.comr/blueteamsec • u/digicat • 1d ago
incident writeup (who and how) How the Russians Got Inside My Phone
spytalk.cor/blueteamsec • u/jnazario • 1d ago