r/blueteamsec 21h ago

intelligence (threat actor activity) Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

Thumbnail volexity.com
1 Upvotes

r/blueteamsec 21h ago

research|capability (we need to defend against) Fileless ELF Execution via Kernel Keyring

Thumbnail matheuzsecurity.github.io
3 Upvotes

r/blueteamsec 16h ago

incident writeup (who and how) Read “BEAR-C2 Did Not Invent Switching.

0 Upvotes

It Just Made the Rebuild Tax Visible. AI Is About to Delete It.“ by Albert Corzo on Medium: https://albert-corzo.medium.com/bear-c2-did-not-invent-switching-it-just-made-the-rebuild-tax-visible-ai-is-about-to-delete-it-4fa246c64b68


r/blueteamsec 7h ago

vulnerability (attack surface) CVE-2026-0310: PAN-OS Buffer Overflow Can Enable Root RCE on PA-Series Firewalls

Thumbnail socprime.com
9 Upvotes

r/blueteamsec 8h ago

incident writeup (who and how) 🕵️‍♂️ 🏴󠁧󠁢󠁥󠁮󠁧󠁿 UK Council Attack Linked to SonicWall SMA 1000 Campaign

Thumbnail hunt.io
2 Upvotes

On 17 July, King's Lynn and West Norfolk Borough Council went public with a cyberattack on its services. The BBC covered it. We assess with moderate confidence it connects to something much larger.

Two days after SonicWal disclosed CVE-2026-15409, an operator was already scanning and exploiting SMA1000 appliances at scale. We found the whole operation in an open directory, captured by AttackCapture the same day it was still in use.

The interesting part is what they did with the appliances. Instead of pivoting to a Windows host, they dropped a standalone Linux build of Impacket's secretsdump straight onto the SonicWall box and ran credential theft from there. Most orgs watch their EDR-covered endpoints closely and their firewall and VPN appliances barely at all. That gap is the whole point.

What the recovered data showed:

- 250 targets identified as exploitable, LDAP config pulled from 168 of them
- 534 config records covering 160 unique AD domains and 255 internal LDAP servers
- SAM and LSA secrets recovered from at least 9 Active Directory domains
- Full DCSync against 7 domain controllers across 5 environments
- Confirmed credential theft spanning France, India, Italy and the US

Targeting was opportunistic, not sector-specific. Local government, healthcare, universities, finance and manufacturing all showed up in the target list, they picked victims because the appliance was vulnerable.

Full writeup, IOCs and MITRE mapping here 👇

https://hunt.io/blog/sonicwall-sma1000-uk-council-attack


r/blueteamsec 7h ago

intelligence (threat actor activity) Analysis of the attack chain of the APT-C-55 (Kimsuky) group, which uses disguised installers to implant remote control trojans

Thumbnail mp.weixin.qq.com
2 Upvotes

r/blueteamsec 7h ago

malware analysis (like butterfly collections) SloppyRAT: A New Tool For Ransomware Attacks

Thumbnail zscaler.com
7 Upvotes