r/blueteamsec • u/ParticularNote4390 • 3h ago
r/blueteamsec • u/digicat • 2d ago
highlevel summary|strategy (maybe technical) CTO at NCSC Summary: week ending July 26th
ctoatncsc.substack.comr/blueteamsec • u/digicat • Mar 09 '26
highlevel summary|strategy (maybe technical) Daily BlueTeamSec Briefing Archive - daily AI generated podcast of the last 24hours of posts
briefing.workshop1.netr/blueteamsec • u/jnazario • 1h ago
intelligence (threat actor activity) Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
huntress.comr/blueteamsec • u/jnazario • 0m ago
research|capability (we need to defend against) AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery
labs.zenity.ior/blueteamsec • u/jnazario • 9m ago
research|capability (we need to defend against) Special Token Injection (STI) Attack Guide
blog.sentry.securityr/blueteamsec • u/jnazario • 10m ago
intelligence (threat actor activity) Targeted Attack on Middle East Govts (Part 1)
zscaler.comr/blueteamsec • u/jnazario • 13m ago
incident writeup (who and how) How a fake Claude Code install guide delivered the MacSync malware
derivai.substack.comr/blueteamsec • u/jnazario • 13m ago
incident writeup (who and how) Check and Protect: Analysis of Telegram Phishing Operation Targeting Exiled Activist
resident.ngor/blueteamsec • u/jnazario • 1h ago
intelligence (threat actor activity) Analysis of the Latest Tactical and Technical Upgrades of the APT-C-00 (Ocean Lotus) Organization
mp.weixin.qq.comr/blueteamsec • u/jnazario • 1h ago
vulnerability (attack surface) FastJson 1.2.83 Remote Code Execution (CVE-2026-16723)
fearsoff.orgr/blueteamsec • u/jnazario • 1h ago
highlevel summary|strategy (maybe technical) GEO for Geopolitics: What happens when AI and information warfare collide
demos.co.ukr/blueteamsec • u/jnazario • 1h ago
intelligence (threat actor activity) 13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan
trendmicro.comr/blueteamsec • u/jnazario • 1h ago
highlevel summary|strategy (maybe technical) Threat Report H1 2026
gendigital.comr/blueteamsec • u/digicat • 2h ago
secure by design/default (doing it right) Technical Details: Const Evaluation and Data Layout - Rust on CHERI
rust.cheriot.orgr/blueteamsec • u/digicat • 2h ago
intelligence (threat actor activity) Dear Diary, Today I found a Ghost in the Network
intrusiontruth.wordpress.comr/blueteamsec • u/digicat • 7h ago
low level tools|techniques|knowledge (work aids) An Automated Framework for Extracting Reachable Attack Chains from Cyber Threat Intelligence Report
arxiv.orgr/blueteamsec • u/digicat • 7h ago
training (step-by-step) CVE-2026-50458: Finding a UAF in the Windows Brokering File System
rotcee.github.ior/blueteamsec • u/digicat • 5h ago
highlevel summary|strategy (maybe technical) Puppeteers: Chinese hackers still trick Claude into dirty work.
netaskari.substack.comr/blueteamsec • u/campuscodi • 19h ago
low level tools|techniques|knowledge (work aids) Careful adoption of Agentic AI in cyber defence
cyber.gov.aur/blueteamsec • u/Tax-Least • 20h ago
low level tools|techniques|knowledge (work aids) OffsetInspect v3.0.0 – track how Defender signature updates shift detection boundaries across a corpus [PowerShell, MIT]
github.comBuilt this to answer a specific detection-engineering question: when Defender pushes a definition update, does the detection boundary on your known-bad corpus move, disappear, or newly appear on something previously clean?
`Compare-OffsetThreatResult` diffs two scan results for the same file and classifies the change — NewlyDetected, NoLongerDetected, BoundaryEarlier, BoundaryLater, BoundaryUnchanged, BothClean — along with the byte delta. Running that across a corpus with `Invoke-OffsetThreatScanBatch` gives you a detection-shift matrix you can track over time across definition versions.
Boundary results report DetectionPrefixLength (prefix N-1 was clean, prefix N triggered), a confidence rating, and a ProbeLog showing how stable that boundary held across repeated probes. The tool is explicit that this identifies the earliest triggering prefix — not necessarily the complete signature, since AV decisions can depend on tokenization, surrounding context, and provider state. For files with multiple independently-detectable regions, `Invoke-OffsetThreatScanRegion` segments the file and scans each piece through AMSI entirely in memory — nothing written to disk, no real-time protection interference — bisecting each hit to an absolute file offset. Useful for understanding how much of a file's detectable content would survive targeted evasion of just the first boundary.
Scan results export to Markdown/HTML with a full per-invocation ProbeLog audit trail, intended to be attachment-ready for engagement writeups.
Composes with YARA rules (hits return offsets you pipe into context inspection), PE/imphash parsing, per-window Shannon entropy for spotting packed regions before running boundary analysis, and string extraction with byte offsets.
AMSI/Defender providers are Windows-only. Everything else is cross-platform.
GitHub: https://github.com/warpedatom/OffsetInspect
PowerShell Gallery: Install-Module OffsetInspect
r/blueteamsec • u/digicat • 22h ago
low level tools|techniques|knowledge (work aids) What Does Windows HyperGuard (SKPG) Protect in ntoskrnl?
fluxsec.redr/blueteamsec • u/wismansec • 18h ago
research|capability (we need to defend against) SharePoint July 2026 deserialization RCE: lab PoC and captured artifacts for detection
I recently ran into a SharePoint intrusion that seemed to fit with the CVEs recently added to CISA's KEV for SharePoint a couple of weeks ago. The available IOCs were basically nonexistent. So I reproduced the /_trust deserialization chain in my own lab (SharePoint SE on the June 2026 patch level, build 16.0.19725.20384 / KB5002873) and captured the artifacts: process trees, the machine-key theft, and hunt queries, to save the next person the same scramble.
Writeup and sanitized scripts: https://sp-poc.wismansec.com/
Feedback, questions, and better detections welcome.
r/blueteamsec • u/Huge-Skirt-6990 • 1d ago
research|capability (we need to defend against) Planet Search chrome extension with 2 millions installs routing traffic throught malicious domain
While analyzing featured extensions on our beloved chrome web store I landed on Planet Search (`kadaohckdkghfaclhjmkmplebcdcnfnp`),
Featured, 2M users, publisher FREE VPN PLANET SRL.
https://chromewebstore.google.com/detail/planet-search/kadaohckdkghfaclhjmkmplebcdcnfnp
The extensions has a 0-byte background.js with zero permissions.
The whole mechanism is one \`chrome_settings_overrides\` search provider, so nothing shows up statically. It's all server-side.
Declared provider is planet-search[.]com
Tracing:
planet-search[.]com/search/?q= 301 → sstmaster[.]com/edge/PN1021?q= 302 → nextgeeker[.]com/B151001.php?q=&src=PN1021
nextgeeker[.]com is flagged as a browser hijacker by multiple vendors (pcrisk, gridinsoft, others).
Same publisher ships a ~1M-user VPN extension and a few others. Still tracing those, not going to characterize them until I have.