Skip to main content
Go to side pane
Nord.pub
Communities
Explore
Donate
Log in
Register
Home
Topics
Technology
blueteamsec@infosec.pub
blueteamsec
!blueteamsec@infosec.pub
Sort
Hot
New
Old
Active
Top 12 hours
Top Day
Top Week
Top Month
Top Year
Top All Time
Hot
Top
12 hours
Day
Week
Month
Year
All Time
New
Old
Active
Options
Join
Layout
List
Tile
Wide tile
Content type
Posts
Comments
Apply filters
Create post
Invite people to join
Search
About community
Hot
Top
12 hours
Day
Week
Month
Year
All Time
New
Old
Active
Posts
Comments
List
Tile
Wide tile
CTO at NCSC Summary: week ending August 30th
(
ctoatncsc.substack.com
)
by
digicat
@infosec.pub
6 days ago
0
comments
4
Daily BlueTeamSec Briefing Archive - daily AI generated podcast of the last 24hours of posts
(
briefing.workshop1.net
)
by
digicat
@infosec.pub
6 months ago
0
comments
0
Peeling the Sentinel: A Market-Leading EDR Comes Apart With Undergraduate Tools
(
blog.nullze.net
)
by
digicat
@infosec.pub
3 hours ago
0
comments
4
CVE-2026-9586: Sangoma Switchvox RCE
(
horizon3.ai
)
by
digicat
@infosec.pub
8 hours ago
0
comments
4
From Patch to Exploit; Using Claude Code to reverse engineer a zero-day in Papercut NG
(
techanarchy.net
)
by
digicat
@infosec.pub
8 hours ago
0
comments
3
Malicious Cyber Actors Gain Access to Victim Accounts Through Consent Phishing
(
ic3.gov
)
by
digicat
@infosec.pub
5 hours ago
0
comments
2
How to get a free .arpa domain
(
hawksley.dev
)
by
digicat
@infosec.pub
17 hours ago
1
comment
13
APT-C-56(透明部落)近期攻击活动分析 -Analysis of Recent Attack Activities by APT-C-56 (Transparent Tribe)
(
mp.weixin.qq.com
)
by
digicat
@infosec.pub
10 hours ago
0
comments
3
pstrings: pstrings - Parallel strings extractor for very large files
(
github.com
)
by
digicat
@infosec.pub
17 hours ago
0
comments
8
Password spraying campaign targets AWS root user accounts across 150+ organizations
(
securitylabs.datadoghq.com
)
by
digicat
@infosec.pub
16 hours ago
0
comments
6
Incident response guide for AWS CloudTrail investigations – Part 2
(
aws.amazon.com
)
by
digicat
@infosec.pub
7 hours ago
0
comments
1
Incident response guide for AWS CloudTrail investigations – Part 1
(
aws.amazon.com
)
by
digicat
@infosec.pub
7 hours ago
0
comments
1
Daisy-Chaining Trust: Investigating Faronics Deploy Abuse
(
huntress.com
)
by
digicat
@infosec.pub
14 hours ago
0
comments
3
1
Kim Sooki again? This time, disguised as a seafood purchase request.
(
asec.ahnlab.com
)
by
digicat
@infosec.pub
17 hours ago
0
comments
4
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
(
rapid7.com
)
by
digicat
@infosec.pub
17 hours ago
0
comments
4
Windows 365 - Placing a Cloud PC Under Review
(
ccmexec.com
)
by
digicat
@infosec.pub
14 hours ago
0
comments
2
New Entra role - Entra SOC Identity Responder
(
learn.microsoft.com
)
by
digicat
@infosec.pub
14 hours ago
0
comments
2
Linux Detection Engineering - Fileless Execution
(
elastic.co
)
by
digicat
@infosec.pub
17 hours ago
0
comments
3
UK Cybercrime Journal: ExfilSquad Emerges
(
blog.bushidotoken.net
)
by
digicat
@infosec.pub
17 hours ago
0
comments
3
New backdoors from Toy Ghouls
(
securelist.com
)
by
digicat
@infosec.pub
17 hours ago
0
comments
3
Malicious code executed on clone between 2026-08-29 and 2026-09-02
(
github.com
)
by
digicat
@infosec.pub
17 hours ago
0
comments
3
CouchPotato: another PrivEsc potato - Patches ETW & AMSI and uses indirect syscall to abuse SeImpersonatePrivilege.
(
github.com
)
by
digicat
@infosec.pub
18 hours ago
0
comments
3
Simulating legitimate Active Directory services on the network: the case of GPO exploitation
(
synacktiv.com
)
by
digicat
@infosec.pub
18 hours ago
0
comments
3
mythic_ornn: LLM-driven generator for Mythic Agents, Payload-Type and C2 Profiles.
(
github.com
)
by
digicat
@infosec.pub
18 hours ago
0
comments
3
How Forza Horizon 6 Breaks Your IDA
(
iretq.com
)
by
digicat
@infosec.pub
18 hours ago
0
comments
3
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access | Microsoft Security Blog
(
microsoft.com
)
by
digicat
@infosec.pub
18 hours ago
0
comments
3
Modern Adventures in Azure Privilege Escalation
(
netspi.com
)
by
digicat
@infosec.pub
18 hours ago
0
comments
3
Getting Agents to tell on themselves
(
blog.thinkst.com
)
by
digicat
@infosec.pub
1 day ago
0
comments
3
Pegasus Spyware Infection of Serbian Pro-Democracy Student Activist - The Citizen Lab
(
citizenlab.ca
)
by
digicat
@infosec.pub
1 day ago
0
comments
8
1
Malicious Packages Served from Unauthorized Registry Server
(
github.com
)
by
digicat
@infosec.pub
1 day ago
0
comments
4
Russian National Indicted For Exploiting Online Platform Used For Freelance Employment And Distributing Malware To Thousands Of Victim Users Worldwide For Financial Gain
(
justice.gov
)
by
digicat
@infosec.pub
1 day ago
0
comments
3
Communicating under pressure: Best practices for service providers
(
cyber.gov.au
)
by
digicat
@infosec.pub
1 day ago
0
comments
2
1
Amir Yaryab – Rewards For Justice - a senior official in Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC). Yaryab leads the IRGC-CEC’s Cyber Operations Command.
(
rewardsforjustice.net
)
by
digicat
@infosec.pub
1 day ago
0
comments
2
Node.js: Old Technique Makes a Comeback
(
security.com
)
by
digicat
@infosec.pub
1 day ago
0
comments
2
Communicating under pressure: Best practices for service providers
(
cyber.gov.au
)
by
digicat
@infosec.pub
1 day ago
0
comments
1
1
Prince of Persia: Detecting the Next C2
(
whisper.security
)
by
digicat
@infosec.pub
1 day ago
0
comments
1
Sality Malware Disrupted in International Cyber Takedown
(
justice.gov
)
by
digicat
@infosec.pub
2 days ago
0
comments
2
Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
(
huntress.com
)
by
digicat
@infosec.pub
2 days ago
0
comments
1
ephemora-cell: Ephemora Cell — The execution layer for untrusted AI-generated code. Fast, capability-based WASM execution with explicit CPU, memory, time, I/O, and filesystem limits.
(
github.com
)
by
digicat
@infosec.pub
2 days ago
0
comments
0
FalconFlank: Crowdstrike Falcon 0day Privilege Escalation Vulnerability
(
github.com
)
by
digicat
@infosec.pub
2 days ago
0
comments
5
Persistent Engagement and the Illusion of Cyber Equilibrium
(
lawfaremedia.org
)
by
digicat
@infosec.pub
3 days ago
1
comment
2
1
SuperProxy: How Residential Proxy Networks Have Become Malware Delivery Platforms
(
plume.com
)
by
digicat
@infosec.pub
3 days ago
0
comments
4
FBI investigation leads to five Venezuelan nationals pleading guilty to attempting to jackpot Kansas ATMs
(
justice.gov
)
by
digicat
@infosec.pub
3 days ago
0
comments
2
Update on Security at METR
(
metr.org
)
by
digicat
@infosec.pub
3 days ago
0
comments
2
1
Daisy-Chaining Trust: Investigating Faronics Deploy Abuse
(
huntress.com
)
by
digicat
@infosec.pub
3 days ago
0
comments
1
1
Financially Motivated Threat Actor BREEZE COMET Targets Brazil
(
cloud.google.com
)
by
digicat
@infosec.pub
3 days ago
0
comments
1
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
(
unit42.paloaltonetworks.com
)
by
digicat
@infosec.pub
3 days ago
0
comments
1
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
(
microsoft.com
)
by
digicat
@infosec.pub
3 days ago
0
comments
1
Malicious Packages Served from Unauthorized Registry Server - An unidentified malicious actor gained access to Coder’s Cloudflare infrastructure and added unauthorized IP addresses to the pool
by
digicat
@infosec.pub
4 days ago
1
comment
2
The August 2026 Virtualizor Incident in BGPHorizon
(
bgphorizon.com
)
by
digicat
@infosec.pub
4 days ago
0
comments
2
Mirage Kitten switches to Node.js and JavaScript malware
(
securelist.com
)
by
digicat
@infosec.pub
4 days ago
0
comments
2
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode
(
research.checkpoint.com
)
by
digicat
@infosec.pub
3 days ago
0
comments
-5
I Think the Military Commissary Freezers Were Hacked - 'the Pentagon now acknowledging a “possible refrigeration disruption” at numerous DeCA commissaries.'
(
signalandsilence.substack.com
)
by
digicat
@infosec.pub
4 days ago
2
comments
9
OEMpocalypse Now: A Generic Exploitation Strategy from Android untrusted app to root
(
calif.io
)
by
digicat
@infosec.pub
4 days ago
1
comment
7
Good news about the Pixel 11. It still has at least bare minimum support for MTE at a hardware level - but disabled in Android firmware
(
x.com
)
by
digicat
@infosec.pub
4 days ago
0
comments
4
Enclave: We Raced Seven AI Models to RCE
(
enclave.ai
)
by
digicat
@infosec.pub
4 days ago
0
comments
0
Qualcomm BootROM code signing bypass CVE-2026-25262 - needs hardware replacements
(
i.blackhat.com
)
by
digicat
@infosec.pub
4 days ago
0
comments
3
vhf-morse-transmitter-monitor: Set radio to 148.500 MHz, selct FM, USB, or CW, set squelch to 0 or 1. xtend your radio's antenna toward monitor's HDMI - now transmit in Morse code from your monitor!
(
github.com
)
by
digicat
@infosec.pub
4 days ago
0
comments
2
ValleyRAT is spreading disguised as adware
(
securelist.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
10
Everything I own, owned
(
schlarp.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
10
2
Out-of-tree Linux driver stack and boot tooling for the Cavium CN6640-SNIC10E (Octeon II, PCI 177d:0092), exposing as two independent 10 GbE interfaces (oct0/oct1) over a BAR2 shared-memory datapath
(
github.com
)
by
digicat
@infosec.pub
4 days ago
0
comments
1
Improving our alignment and security practices - 'By default, all cyber evaluations should run inside a hardened sandbox (an isolated computing environment) with no internet access'
(
anthropic.com
)
by
digicat
@infosec.pub
4 days ago
0
comments
0
Still Circling: Inside the Operator Behind Blind Eagle's GitHub Loader
(
levelblue.com
)
by
digicat
@infosec.pub
4 days ago
0
comments
1
JavaScript obfuscation: From party trick to phishing kit
(
blog.talosintelligence.com
)
by
digicat
@infosec.pub
4 days ago
0
comments
1
Fire Ant Evolves: From Hypervisors to Trusted Infrastructure
(
sygnia.co
)
by
digicat
@infosec.pub
4 days ago
0
comments
1
Russian-speaking cybercriminals used SpaceX’s Cursor AI tool to hack seven companies
(
reuters.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
4
Caught in 4K: The Aurora Files
(
cloudsek.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
3
Virtualizor Compromised (31st AUG): Virtualizor has been compromised, their BGP hijack a few days ago seems to have a deployed a malicious package.
(
lowendtalk.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
3
lych: A monolithic ARM64 operating system written in Rust.
(
github.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
7
wyze-bulb-color-pwned: No-open firmware exploit for the Wyze WLPA19CV2 color bulb - or how to implant a lightbulb
(
github.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
5
How the Russians Got Inside My Phone
(
spytalk.co
)
by
digicat
@infosec.pub
5 days ago
1
comment
2
pqc-embedded: Post-quantum signature verification on constrained parts: LMS/HSS in no_std Rust, measured flash/RAM/time budgets against ML-DSA, SLH-DSA, ECDSA and Ed25519
(
github.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
3
Introduction - Windows Kernel Segment Heap Notes
(
mrt4ntr4.github.io
)
by
digicat
@infosec.pub
5 days ago
0
comments
3
Gryxa: The AI-Built Toolkit That Watches How You Remove It
(
reliaquest.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
4
Operation RepoGhost: Exposing a Russian-Linked Malware Campaign Hiding in GitHub’s Open-Source…
(
infosecwriteups.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
4
GreenSection: Nvidia GreenSection Memory Corruption 0day vulnerability
(
github.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
4
Mini Shai-Hulud Strikes Again: openapi-react-query-codegen
(
safedep.io
)
by
digicat
@infosec.pub
5 days ago
0
comments
3
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution - "Approximately 97% of AI-enabled malware samples exist only in research repositories, sandbox environments and secu
(
unit42.paloaltonetworks.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
2
DFIR-LABS: DFIR LABS - A compilation of challenges that aims to provide practice in simple to advanced concepts in the following topics: DFIR, Malware Analysis and Threat Hunting.
(
github.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
2
Magneto CVE-2026-71362 — Root-cause walkthrough
(
github.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
2
CVE-2026-63077: TeamCity Pre-Auth RCE Explained
(
blog.securelayer7.net
)
by
digicat
@infosec.pub
5 days ago
0
comments
2
Threat Actors Are Posing as OpenAI, Anthropic and DeepSeek to Target Credentials and Secrets
(
greynoise.io
)
by
digicat
@infosec.pub
5 days ago
0
comments
2
UAT-10147 Uses AI-Assisted Workflows to Deploy SPECTRE Backdoor
(
blog.polyswarm.io
)
by
digicat
@infosec.pub
5 days ago
0
comments
2
PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE
(
huntress.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
2
Detect DLL search order hijacking with a single field
(
elastic.co
)
by
digicat
@infosec.pub
5 days ago
0
comments
2
recently identified a domain (passkeyconnect[.]com) that is likely associated with Com-affiliated threat actors
(
github.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
2
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
(
microsoft.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
2
The Video That Plays You: Fake MP4 File Carries Malicious Payload
(
censys.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
2
ClickFix / ClearFake PowerShell Stager — Static Analysis Report
(
douglasmun.github.io
)
by
digicat
@infosec.pub
5 days ago
0
comments
2
VRIG - Fuzzillai - goal of the project was to learn more about JavaScript engine fuzzing, V8 compiler internals, and the applications of AI systems to fuzzers like Fuzzilli.
(
blog.ritsec.club
)
by
digicat
@infosec.pub
5 days ago
0
comments
2
PrettyPrague: GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability
(
github.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
2
JFrog Security Advisories: CVE-2026-82329 - Potential authentication bypass leading to administrative access in Artifactory -
(
docs.jfrog.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
2
visa-vulnerability-agentic-harness: Visa Vulnerability Agentic Harness
(
github.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
2
ClickExfil: My iteration on ClickFix and FileFix
(
catchingphish.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
2
The Hugging Face incident and the road ahead
(
openai.com
)
by
digicat
@infosec.pub
5 days ago
14
comments
1
4
logtotal-sanitizer: Framework-agnostic log sanitizer for browsers and Node.js. Redacts secrets and infrastructure identifiers with stable HMAC tokens so event correlation still works.
(
github.com
)
by
digicat
@infosec.pub
5 days ago
0
comments
2
חשיפה: ההאקר מאשקלון - עובד IT ומומחה סייבר - he was charged with violations of the Computer Law, wiretapping and invasion of privacy. As far as is known so far, the suspected hacker – who, at the sam
(
pc.co.il
)
by
digicat
@infosec.pub
5 days ago
0
comments
1
vol-rs: Volatility 3 ported to Rust. Same output, much faster.
(
github.com
)
by
digicat
@infosec.pub
6 days ago
1
comment
2
Questions about Collective action on cybersecurity
(
designingsecuresoftware.com
)
by
digicat
@infosec.pub
6 days ago
0
comments
2
Incident Timeline // TeamPCP Supply Chain Campaign
(
ramimac.me
)
by
digicat
@infosec.pub
6 days ago
0
comments
3
iwa-tools — Offensive AD tradecraft in a browser tab
(
iwa-tools.pkilla.pw
)
by
digicat
@infosec.pub
6 days ago
0
comments
3
Android Intrusion Logs - A First Look
(
iverify.com
)
by
digicat
@infosec.pub
6 days ago
0
comments
7
Next page
→
Home
Explore
Communities
Search
Login
Voting Options
Upvote (federated)
Upvote (local)
Downvote (local)
Downvote (federated)
Local votes are a bit more private.
Default mode: public.
React with an emoji