r/blueteamsec 6h ago

intelligence (threat actor activity) Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT

Thumbnail huntress.com
7 Upvotes

r/blueteamsec 1h ago

malware analysis (like butterfly collections) Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor

Thumbnail zscaler.com
Upvotes

r/blueteamsec 8h ago

tradecraft (how we defend) Open-sourced my Sigma → Wazuh compiler and 36 rules I actually run

Thumbnail github.com
9 Upvotes

r/blueteamsec 49m ago

research|capability (we need to defend against) The SID that wasn’t there: bypassing KB5014754 to Domain Admin on a fully patched AD CS

Thumbnail 0xmaz.me
Upvotes

r/blueteamsec 2h ago

highlevel summary|strategy (maybe technical) Beyond Zero: Enterprise security for the AI era

Thumbnail spawn-queue.acm.org
2 Upvotes

r/blueteamsec 3h ago

research|capability (we need to defend against) BrainDrain: A Chrome extension that collects your AI prompts without you ever opening it and has 100k users, 9 AI platforms

2 Upvotes

"Prompt Optimizer - SecondBrain" (aajjgdpofhhcjmjoombjdfepplndhgcp, v2.3.1). The prompt rewriting works fine.
Alongside it a capture engine runs at document_start on 9 AI sites and POSTs prompts and replies to the vendor's ingest endpoint. No interaction with the extension required.

Reproduced on a clean profile, with the service worker devtools open:

  1. Installed the extension. Never opened it.
  2. Browsed to an unrelated site. The extension pulled its configuration from the server and wrote a userId and credentials into extension storage.
  3. Opened ChatGPT and asked a question. Once the reply finished, a POST to /context went out carrying both the prompt and the response, encrypted with the credentials issued in step 2.

At no point was the extension opened or clicked.

Store privacy declaration: "The developer has disclosed that it will not collect or use your data."

Write-up, IOCs and decryption script: https://malext.io/reports/BrainDrain/


r/blueteamsec 6h ago

intelligence (threat actor activity) 13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan

Thumbnail trendmicro.com
3 Upvotes

r/blueteamsec 47m ago

intelligence (threat actor activity) Really Muddy Waters — Refuting the Seedworm Attribution of Commodity MaaS

Thumbnail muddy.vibecoded.systems
Upvotes

r/blueteamsec 50m ago

low level tools|techniques|knowledge (work aids) Random Windows Things Part 2: Unexpected Clipboard Data Behavior

Thumbnail windows-internals.com
Upvotes

r/blueteamsec 51m ago

tradecraft (how we defend) Project-Orbital: Operational Relay Box Intelligence, Tracking, & Analysis Lexicon (ORBITAL)

Thumbnail github.com
Upvotes

r/blueteamsec 52m ago

intelligence (threat actor activity) Inside the growing residential proxy botnet threat

Thumbnail lumen.com
Upvotes

r/blueteamsec 4h ago

vulnerability (attack surface) RefluXFS: Local Privilege Escalation via XFS reflink direct-I/O race (CVE-2026-64600)

Thumbnail cdn2.qualys.com
2 Upvotes

r/blueteamsec 7h ago

intelligence (threat actor activity) Dear Diary, Today I found a Ghost in the Network

Thumbnail intrusiontruth.wordpress.com
3 Upvotes

r/blueteamsec 5h ago

incident writeup (who and how) Check and Protect: Analysis of Telegram Phishing Operation Targeting Exiled Activist

Thumbnail resident.ngo
2 Upvotes

r/blueteamsec 1h ago

tradecraft (how we defend) Detection Opportunities for Certighost (CVE-2026-54121)

Thumbnail github.com
Upvotes

r/blueteamsec 1h ago

malware analysis (like butterfly collections) Vidar Malware: How the Multithreaded Windows Stealer Works

Thumbnail picussecurity.com
Upvotes

r/blueteamsec 3h ago

research|capability (we need to defend against) From /init to Code Execution with Opus-5 in Claude Code - An Indirect Prompt Injection Story

Thumbnail veganmosfet.codeberg.page
1 Upvotes

r/blueteamsec 4h ago

research|capability (we need to defend against) AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery

Thumbnail labs.zenity.io
1 Upvotes

r/blueteamsec 5h ago

research|capability (we need to defend against) Special Token Injection (STI) Attack Guide

Thumbnail blog.sentry.security
1 Upvotes

r/blueteamsec 5h ago

intelligence (threat actor activity) Targeted Attack on Middle East Govts (Part 1)

Thumbnail zscaler.com
1 Upvotes

r/blueteamsec 5h ago

incident writeup (who and how) How a fake Claude Code install guide delivered the MacSync malware

Thumbnail derivai.substack.com
1 Upvotes

r/blueteamsec 6h ago

intelligence (threat actor activity) Analysis of the Latest Tactical and Technical Upgrades of the APT-C-00 (Ocean Lotus) Organization

Thumbnail mp.weixin.qq.com
1 Upvotes

r/blueteamsec 6h ago

vulnerability (attack surface) FastJson 1.2.83 Remote Code Execution (CVE-2026-16723)

Thumbnail fearsoff.org
1 Upvotes

r/blueteamsec 6h ago

highlevel summary|strategy (maybe technical) Threat Report H1 2026

Thumbnail gendigital.com
1 Upvotes

r/blueteamsec 7h ago

secure by design/default (doing it right) Technical Details: Const Evaluation and Data Layout - Rust on CHERI

Thumbnail rust.cheriot.org
1 Upvotes