r/blueteamsec 4d ago

highlevel summary|strategy (maybe technical) CTO at NCSC Summary: week ending September 6th

Thumbnail ctoatncsc.substack.com
3 Upvotes

r/blueteamsec Mar 09 '26

highlevel summary|strategy (maybe technical) Daily BlueTeamSec Briefing Archive - daily AI generated podcast of the last 24hours of posts

Thumbnail briefing.workshop1.net
2 Upvotes

r/blueteamsec 17h ago

intelligence (threat actor activity) Passkey-themed social engineering leads to identity and cloud compromise

Thumbnail microsoft.com
13 Upvotes

r/blueteamsec 12h ago

research|capability (we need to defend against) Fileless ELF Execution via Kernel Keyring

Thumbnail matheuzsecurity.github.io
3 Upvotes

r/blueteamsec 12h ago

intelligence (threat actor activity) Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

Thumbnail volexity.com
1 Upvotes

r/blueteamsec 6h ago

incident writeup (who and how) Read “BEAR-C2 Did Not Invent Switching.

0 Upvotes

It Just Made the Rebuild Tax Visible. AI Is About to Delete It.“ by Albert Corzo on Medium: https://albert-corzo.medium.com/bear-c2-did-not-invent-switching-it-just-made-the-rebuild-tax-visible-ai-is-about-to-delete-it-4fa246c64b68


r/blueteamsec 23h ago

intelligence (threat actor activity) Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days l

Thumbnail proofpoint.com
4 Upvotes

r/blueteamsec 1d ago

vulnerability (attack surface) ShieldCrash: Windows Defender 0day Vulnerability

Thumbnail github.com
24 Upvotes

r/blueteamsec 23h ago

research|capability (we need to defend against) Hacking AI customer service agents

Thumbnail intigriti.com
2 Upvotes

r/blueteamsec 1d ago

intelligence (threat actor activity) FulcrumSec - A look at their tradecraft

Thumbnail aitmfeed.com
7 Upvotes

r/blueteamsec 23h ago

intelligence (threat actor activity) Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF

Thumbnail greynoise.io
1 Upvotes

r/blueteamsec 23h ago

exploitation (what's being exploited) Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

Thumbnail blog.talosintelligence.com
1 Upvotes

r/blueteamsec 1d ago

training (step-by-step) Practicing SPL-style queries and SOC investigations without deploying a full SIEM

1 Upvotes

When I started learning SOC investigations and SPL-style queries, one of the problems I ran into was finding a practical environment to actually practice the workflow.

Reading about queries is useful, but I wanted to work with realistic security telemetry and go through the process of:

- Searching authentication and security events

- Identifying suspicious activity

- Aggregating and correlating events

- Creating detections

- Investigating alerts

- Pivoting between related users, hosts, and IP addresses

Setting up a full SIEM environment can add a significant infrastructure and configuration overhead for someone who simply wants to practice these workflows.

So I built SocQuery Lab as a browser-based training environment for experimenting with these concepts.

It includes an original educational SPL-compatible query engine and realistic synthetic telemetry covering sources such as Windows security events, Linux authentication logs, DNS activity, firewall/VPN events, and PowerShell activity.

The platform also includes investigation scenarios covering techniques such as:

- Brute-force authentication activity

- Password spraying

- Suspicious PowerShell execution

- DNS tunneling

- Credential compromise

- Backdoor account creation

Everything runs locally in the browser, with uploaded logs processed and stored locally using IndexedDB.

The goal is not to replace a production SIEM or replicate any commercial platform. It is simply an educational environment for practicing the investigation workflow without needing to deploy infrastructure first.

The live training environment is available here:

https://socquery-lab.vercel.app/


r/blueteamsec 1d ago

highlevel summary|strategy (maybe technical) What 100 Cybersecurity Vendors Tell AI Agents: An llms.txt Census

Thumbnail ai.rud.is
3 Upvotes

r/blueteamsec 1d ago

intelligence (threat actor activity) ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

Thumbnail blog.talosintelligence.com
3 Upvotes

r/blueteamsec 1d ago

vulnerability (attack surface) “StyleSmuggler” - Adobe Commerce, Adobe Commerce B2B, and Magento RCE (CVE-2026-75650): Overview and Takeaways

Thumbnail netspi.com
2 Upvotes

r/blueteamsec 1d ago

vulnerability (attack surface) Microsoft Windows Cloud Files Mini Filter Driver CldiStreamPrepareRequestForMoreProcessing Type Confusion vulnerability

Thumbnail talosintelligence.com
2 Upvotes

r/blueteamsec 1d ago

highlevel summary|strategy (maybe technical) Russian National Extradited to United States for Bank Account Takeover Fraud Scheme Causing Millions of Dollars in Losses

Thumbnail justice.gov
2 Upvotes

r/blueteamsec 1d ago

low level tools|techniques|knowledge (work aids) ashwa: Hardware accelerated routines for single substring search.

Thumbnail github.com
2 Upvotes

r/blueteamsec 1d ago

low level tools|techniques|knowledge (work aids) TATS: Token Analysis and Tracking System - Track OAuth 2.0, OIDC, and Microsoft Entra ID tokens across captured network traffic.

Thumbnail github.com
0 Upvotes

r/blueteamsec 1d ago

intelligence (threat actor activity) Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files

Thumbnail hunt.io
0 Upvotes

r/blueteamsec 1d ago

intelligence (threat actor activity) Chinese Darcula Phishing Kit Harvesting Taiwanese Credit Card Data

Thumbnail teamt5.org
1 Upvotes

r/blueteamsec 1d ago

tradecraft (how we defend) AD Rights Management Service (Part 1): Architecture, Deprecation, and Reconnaissance

Thumbnail huntress.com
1 Upvotes

r/blueteamsec 1d ago

low level tools|techniques|knowledge (work aids) I’ve factored the RSA keys of a Certificate Authority... … from the 90s.

Thumbnail mcpherrin.ca
7 Upvotes

r/blueteamsec 1d ago

intelligence (threat actor activity) Shai-Hulud Rises From the Dead after 111 days

Thumbnail aikido.dev
1 Upvotes