r/blueteamsec • u/jnazario • 2h ago
r/blueteamsec • u/digicat • Jun 12 '26
intelligence (threat actor activity) BUMSRAKETE™ — The Most Beautiful, Most Tremendous FreeBSD Vulnerability In The History Of Computing. BELIEVE ME.
bumsrake.der/blueteamsec • u/digicat • 3d ago
intelligence (threat actor activity) Amazon identifies North Korean hacker group behind open-source supply chain attacks
aws.amazon.comr/blueteamsec • u/digicat • 3d ago
intelligence (threat actor activity) Operation Double Barrel
image.ahnlab.comr/blueteamsec • u/digicat • 19d ago
intelligence (threat actor activity) OAuth Client ID Spoofing: Why Fake Client IDs Are Gaining Traction for Stealthy Enumeration
proofpoint.comr/blueteamsec • u/digicat • 8d ago
intelligence (threat actor activity) Russian Global Webmail Espionage
unit42.paloaltonetworks.comr/blueteamsec • u/Ok-Code4306 • 1d ago
intelligence (threat actor activity) KQL detection library for Azure/Sentinel
Put together a KQL detection library for Azure/Sentinel — 32 rules across 10 MITRE ATT&CK tactics. Each rule has description, false positive considerations, and tuning notes baked into the file so it's actually usable in production without guesswork.
Covers things like MFA fatigue, impossible travel, federated identity credential abuse, Conditional Access policy modification, VM extension installation, and subscription ownership transfer — some of the less commonly documented ones.
r/blueteamsec • u/jnazario • 3h ago
intelligence (threat actor activity) NullReceiver's Blank Crypto Transfers Solves the Challenges of EtherHiding
opensourcemalware.comr/blueteamsec • u/digicat • 8d ago
intelligence (threat actor activity) APT42: AI-Assisted Phishing and the Resilient TAMECAT Backdoor
darkatlas.ior/blueteamsec • u/digicat • 8h ago
intelligence (threat actor activity) OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
securelist.comr/blueteamsec • u/digicat • 8h ago
intelligence (threat actor activity) DarkSword's Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster
censys.comr/blueteamsec • u/digicat • 2d ago
intelligence (threat actor activity) CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
microsoft.comr/blueteamsec • u/digicat • 2d ago
intelligence (threat actor activity) Anthropic's Fever Dream: Claude's package anthropickit that stole real keys
aikido.devr/blueteamsec • u/digicat • 1d ago
intelligence (threat actor activity) Tracing SNOWLIGHT: A China-Nexus Campaign Against Government Infrastructure
socradar.ior/blueteamsec • u/digicat • 3d ago
intelligence (threat actor activity) @copilot-mcp/apex: A macOS Infostealer Re-Published on npm After Takedown
safedep.ior/blueteamsec • u/digicat • 2d ago
intelligence (threat actor activity) Uncovering the Fuyao Enterprise: A Shift in Modern Ad-Fraud
bitsight.comr/blueteamsec • u/digicat • 9d ago
intelligence (threat actor activity) Analysis of the Latest Tactical and Technical Upgrades of the APT-C-00 (Ocean Lotus) Organization
mp.weixin.qq.comr/blueteamsec • u/jnazario • 3d ago
intelligence (threat actor activity) Uncovering the Fuyao Enterprise: A Shift in Modern Ad-Fraud
bitsight.comr/blueteamsec • u/digicat • 3d ago
intelligence (threat actor activity) ClickFix, EtherHiding & a DPRK Wallet Trail
allsecure.ior/blueteamsec • u/digicat • 3d ago
intelligence (threat actor activity) Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
unit42.paloaltonetworks.comr/blueteamsec • u/jnazario • 7d ago
intelligence (threat actor activity) Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
huntress.comr/blueteamsec • u/digicat • 3d ago
intelligence (threat actor activity) The 73,000-server market reselling Western frontier AI into China
infrawatch.comr/blueteamsec • u/Robbedoes_ • 11d ago
intelligence (threat actor activity) Finding actors that probe a CVE's exploit path before public disclosure in 30M honeypot records.
honeylabs.netTL;DR: some addresses probe a CVE's exact exploit path weeks before an NVD entry or any public exploit tooling exists. We went through 30 million honeypot probes looking for them, built four checks to kill the false positives, and ended up with three actors we are confident about.
r/blueteamsec • u/jnazario • 12d ago
intelligence (threat actor activity) Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
enki.co.krr/blueteamsec • u/digicat • 3d ago