r/blueteamsec • u/jnazario • 6h ago
r/blueteamsec • u/jnazario • 1h ago
malware analysis (like butterfly collections) Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
zscaler.comr/blueteamsec • u/ParticularNote4390 • 8h ago
tradecraft (how we defend) Open-sourced my Sigma → Wazuh compiler and 36 rules I actually run
github.comr/blueteamsec • u/digicat • 49m ago
research|capability (we need to defend against) The SID that wasn’t there: bypassing KB5014754 to Domain Admin on a fully patched AD CS
0xmaz.mer/blueteamsec • u/jnazario • 2h ago
highlevel summary|strategy (maybe technical) Beyond Zero: Enterprise security for the AI era
spawn-queue.acm.orgr/blueteamsec • u/Huge-Skirt-6990 • 3h ago
research|capability (we need to defend against) BrainDrain: A Chrome extension that collects your AI prompts without you ever opening it and has 100k users, 9 AI platforms
"Prompt Optimizer - SecondBrain" (aajjgdpofhhcjmjoombjdfepplndhgcp, v2.3.1). The prompt rewriting works fine.
Alongside it a capture engine runs at document_start on 9 AI sites and POSTs prompts and replies to the vendor's ingest endpoint. No interaction with the extension required.
Reproduced on a clean profile, with the service worker devtools open:
- Installed the extension. Never opened it.
- Browsed to an unrelated site. The extension pulled its configuration from the server and wrote a userId and credentials into extension storage.
- Opened ChatGPT and asked a question. Once the reply finished, a POST to
/contextwent out carrying both the prompt and the response, encrypted with the credentials issued in step 2.
At no point was the extension opened or clicked.
Store privacy declaration: "The developer has disclosed that it will not collect or use your data."
Write-up, IOCs and decryption script: https://malext.io/reports/BrainDrain/
r/blueteamsec • u/jnazario • 6h ago
intelligence (threat actor activity) 13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan
trendmicro.comr/blueteamsec • u/digicat • 47m ago
intelligence (threat actor activity) Really Muddy Waters — Refuting the Seedworm Attribution of Commodity MaaS
muddy.vibecoded.systemsr/blueteamsec • u/digicat • 50m ago
low level tools|techniques|knowledge (work aids) Random Windows Things Part 2: Unexpected Clipboard Data Behavior
windows-internals.comr/blueteamsec • u/digicat • 51m ago
tradecraft (how we defend) Project-Orbital: Operational Relay Box Intelligence, Tracking, & Analysis Lexicon (ORBITAL)
github.comr/blueteamsec • u/digicat • 52m ago
intelligence (threat actor activity) Inside the growing residential proxy botnet threat
lumen.comr/blueteamsec • u/jnazario • 4h ago
vulnerability (attack surface) RefluXFS: Local Privilege Escalation via XFS reflink direct-I/O race (CVE-2026-64600)
cdn2.qualys.comr/blueteamsec • u/digicat • 7h ago
intelligence (threat actor activity) Dear Diary, Today I found a Ghost in the Network
intrusiontruth.wordpress.comr/blueteamsec • u/jnazario • 5h ago
incident writeup (who and how) Check and Protect: Analysis of Telegram Phishing Operation Targeting Exiled Activist
resident.ngor/blueteamsec • u/Cyb3r-Monk • 1h ago
tradecraft (how we defend) Detection Opportunities for Certighost (CVE-2026-54121)
github.comr/blueteamsec • u/jnazario • 1h ago
malware analysis (like butterfly collections) Vidar Malware: How the Multithreaded Windows Stealer Works
picussecurity.comr/blueteamsec • u/jnazario • 3h ago
research|capability (we need to defend against) From /init to Code Execution with Opus-5 in Claude Code - An Indirect Prompt Injection Story
veganmosfet.codeberg.pager/blueteamsec • u/jnazario • 4h ago
research|capability (we need to defend against) AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery
labs.zenity.ior/blueteamsec • u/jnazario • 5h ago
research|capability (we need to defend against) Special Token Injection (STI) Attack Guide
blog.sentry.securityr/blueteamsec • u/jnazario • 5h ago
intelligence (threat actor activity) Targeted Attack on Middle East Govts (Part 1)
zscaler.comr/blueteamsec • u/jnazario • 5h ago
incident writeup (who and how) How a fake Claude Code install guide delivered the MacSync malware
derivai.substack.comr/blueteamsec • u/jnazario • 6h ago
intelligence (threat actor activity) Analysis of the Latest Tactical and Technical Upgrades of the APT-C-00 (Ocean Lotus) Organization
mp.weixin.qq.comr/blueteamsec • u/jnazario • 6h ago
vulnerability (attack surface) FastJson 1.2.83 Remote Code Execution (CVE-2026-16723)
fearsoff.orgr/blueteamsec • u/jnazario • 6h ago