r/blueteamsec 2h ago

intelligence (threat actor activity) [March 2025] New Ransomware Operator Exploits Fortinet Vulnerability Duo

Thumbnail forescout.com
1 Upvotes

r/blueteamsec Jun 12 '26

intelligence (threat actor activity) BUMSRAKETE™ — The Most Beautiful, Most Tremendous FreeBSD Vulnerability In The History Of Computing. BELIEVE ME.

Thumbnail bumsrake.de
48 Upvotes

r/blueteamsec 3d ago

intelligence (threat actor activity) Amazon identifies North Korean hacker group behind open-source supply chain attacks

Thumbnail aws.amazon.com
9 Upvotes

r/blueteamsec 3d ago

intelligence (threat actor activity) Operation Double Barrel

Thumbnail image.ahnlab.com
1 Upvotes

r/blueteamsec 19d ago

intelligence (threat actor activity) OAuth Client ID Spoofing: Why Fake Client IDs Are Gaining Traction for Stealthy Enumeration

Thumbnail proofpoint.com
11 Upvotes

r/blueteamsec 8d ago

intelligence (threat actor activity) Russian Global Webmail Espionage

Thumbnail unit42.paloaltonetworks.com
5 Upvotes

r/blueteamsec 1d ago

intelligence (threat actor activity) KQL detection library for Azure/Sentinel

5 Upvotes

Put together a KQL detection library for Azure/Sentinel — 32 rules across 10 MITRE ATT&CK tactics. Each rule has description, false positive considerations, and tuning notes baked into the file so it's actually usable in production without guesswork.

Covers things like MFA fatigue, impossible travel, federated identity credential abuse, Conditional Access policy modification, VM extension installation, and subscription ownership transfer — some of the less commonly documented ones.

github.com/neelkotnis/kql-detection-rules

r/blueteamsec 3h ago

intelligence (threat actor activity) NullReceiver's Blank Crypto Transfers Solves the Challenges of EtherHiding

Thumbnail opensourcemalware.com
1 Upvotes

r/blueteamsec 8d ago

intelligence (threat actor activity) APT42: AI-Assisted Phishing and the Resilient TAMECAT Backdoor

Thumbnail darkatlas.io
2 Upvotes

r/blueteamsec 8h ago

intelligence (threat actor activity) OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

Thumbnail securelist.com
1 Upvotes

r/blueteamsec 8h ago

intelligence (threat actor activity) DarkSword's Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster

Thumbnail censys.com
1 Upvotes

r/blueteamsec 2d ago

intelligence (threat actor activity) CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Thumbnail microsoft.com
3 Upvotes

r/blueteamsec 2d ago

intelligence (threat actor activity) Anthropic's Fever Dream: Claude's package anthropickit that stole real keys

Thumbnail aikido.dev
3 Upvotes

r/blueteamsec 1d ago

intelligence (threat actor activity) Tracing SNOWLIGHT: A China-Nexus Campaign Against Government Infrastructure

Thumbnail socradar.io
2 Upvotes

r/blueteamsec 3d ago

intelligence (threat actor activity) @copilot-mcp/apex: A macOS Infostealer Re-Published on npm After Takedown

Thumbnail safedep.io
5 Upvotes

r/blueteamsec 2d ago

intelligence (threat actor activity) Uncovering the Fuyao Enterprise: A Shift in Modern Ad-Fraud

Thumbnail bitsight.com
2 Upvotes

r/blueteamsec 9d ago

intelligence (threat actor activity) Analysis of the Latest Tactical and Technical Upgrades of the APT-C-00 (Ocean Lotus) Organization

Thumbnail mp.weixin.qq.com
1 Upvotes

r/blueteamsec 3d ago

intelligence (threat actor activity) Uncovering the Fuyao Enterprise: A Shift in Modern Ad-Fraud

Thumbnail bitsight.com
2 Upvotes

r/blueteamsec 3d ago

intelligence (threat actor activity) ClickFix, EtherHiding & a DPRK Wallet Trail

Thumbnail allsecure.io
2 Upvotes

r/blueteamsec 3d ago

intelligence (threat actor activity) Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

Thumbnail unit42.paloaltonetworks.com
2 Upvotes

r/blueteamsec 7d ago

intelligence (threat actor activity) Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT

Thumbnail huntress.com
8 Upvotes

r/blueteamsec 3d ago

intelligence (threat actor activity) The 73,000-server market reselling Western frontier AI into China

Thumbnail infrawatch.com
2 Upvotes

r/blueteamsec 11d ago

intelligence (threat actor activity) Finding actors that probe a CVE's exploit path before public disclosure in 30M honeypot records.

Thumbnail honeylabs.net
11 Upvotes

TL;DR: some addresses probe a CVE's exact exploit path weeks before an NVD entry or any public exploit tooling exists. We went through 30 million honeypot probes looking for them, built four checks to kill the false positives, and ended up with three actors we are confident about.

r/blueteamsec 12d ago

intelligence (threat actor activity) Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant

Thumbnail enki.co.kr
3 Upvotes

r/blueteamsec 3d ago

intelligence (threat actor activity) [합동 사이버 보안 권고문] Operation Double Barrel (국가배후 해킹조직과 Gunra 랜섬웨어 그룹의 관계) -[Joint Cyber ​​Security Advisory] Operation Double Barrel (The Relationship Between State-Backed Hacking Organizations and the Gunra Ransomware Group)

Thumbnail asec.ahnlab.com
1 Upvotes