3Threat Hunts for Shell Command Obfuscation on VMware ESX crowdstrike.comc/blueteamsec · by digicat@infosec.pub · 17h · 0 comments
10Technical Analysis of the Geedge Networks Firewall Source Code Leak usenix.orgc/blueteamsec · by digicat@infosec.pub · 18h · 0 comments
3windbg-bridge: windbg-bridge connects a live WinDbg session to AI agents like Claude Code or Codex through a named pipe. The agent can run debugger commands, read your command history, and watch outpu github.comc/blueteamsec · by digicat@infosec.pub · 18h · 0 comments
2Release IRFlow Timeline 1.0.10 · adds ChatGPT Computer History as a new forensic artifact family, github.comc/blueteamsec · by digicat@infosec.pub · 18h · 0 comments
6ExfilSquad: New Data Extortion Group Leaks Microsoft D365 Data, Likely Linked to Misconfigured Power Pages fortra.comc/blueteamsec · by digicat@infosec.pub · 20h · 0 comments
3ETSI launches approval process for 17 European Standards supporting the Cyber Resilience Act etsi.orgc/blueteamsec · by digicat@infosec.pub · 20h · 0 comments
4Signed, sealed, injected: The mechanics of DCRat in 2026 trellix.comc/blueteamsec · by digicat@infosec.pub · 1d · 0 comments
2Dragon Breath (APT-Q-27): RONINGLOADER and Gh0st RAT Explained picussecurity.comc/blueteamsec · by digicat@infosec.pub · 1d · 0 comments
3WS-Trust Autologon Endpoint: Password Spray Without Smart Lockout Blocking varonis.comc/blueteamsec · by digicat@infosec.pub · 1d · 0 comments
2Deleting the Defenders: A Commodity BYOVD Toolkit That Erases Host Safeguards vmray.comc/blueteamsec · by digicat@infosec.pub · 1d · 0 comments
2Detecting macOS Gatekeeper Quarantine Attribute Removal with Sigma systemweakness.comc/blueteamsec · by digicat@infosec.pub · 1d · 0 comments
2The Mac With No Malware On It: When Consent Is the Attack Path ridgelinecyber.comc/blueteamsec · by digicat@infosec.pub · 1d · 0 comments
1How browser attacks are evolving in 2026 so far pushsecurity.comc/blueteamsec · by digicat@infosec.pub · 1d · 0 comments
3Device Roles in Microsoft Defender XDR: Better Context for Threat Hunting and Detection Engineering academy.bluraven.ioc/blueteamsec · by digicat@infosec.pub · 1d · 0 comments
3The phishing link that died on purpose gendigital.comc/blueteamsec · by digicat@infosec.pub · 1d · 0 comments
3Pulling the Thread: APT should not usurp the identity of Leroy Merlin or there will be consequences plausible-deniability.coc/blueteamsec · by digicat@infosec.pub · 1d · 0 comments
2Consensual Forensics with Android Intrusion Logging stark4n6.comc/blueteamsec · by digicat@infosec.pub · 1d · 0 comments
5NIST Digital Forensics Artifact Catalog: Where Digital Evidence Becomes Forensic Science cke-ltd.comc/blueteamsec · by digicat@infosec.pub · 1d · 0 comments
-3UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026 blog.bushidotoken.netc/blueteamsec · by digicat@infosec.pub · 1d · 1 comments
3Quantum Computers Are Not a Threat to 128-bit Symmetric Keys words.filippo.ioc/blueteamsec · by digicat@infosec.pub · 1d · 0 comments
on CTO at NCSC Summary: week ending June 28th · c/blueteamsec · 1 pts · 50dNo idea - the link is - https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-june-9ec
on VSMEx: A Collection Tool and a Dataset of Malicious VS Code Extensions: Data/Toolset Paper · c/blueteamsec · 1 pts · 61dhttps://github.com/kalachkar/vsmex
on ssh-keysign-pwn: Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels. · c/blueteamsec · 1 pts · 93dmitigations discussion: https://www.openwall.com/lists/oss-security/2026/05/15/3
on Agentic Malware Analysis: From Task Automation to Deep Analysis · c/blueteamsec · 1 pts · 107dRecording: https://www.youtube.com/watch?v=azej1P17w9E
on toastfix-demo: Proof-of-concept security demo illustrating how PowerShell can create trusted-looking Windows toast notifications chained together with ClickFix-style lure · c/blueteamsec · 1 pts · 121dhttps://0xh4lpy.medium.com/toastfix-chaining-a-clickfix-attack-with-toast-notifications-72082694fef9
on smokedmeat: A CI/CD Red Team Framework for demonstrating Build Pipeline security risks. · c/blueteamsec · 1 pts · 121dhttps://labs.boostsecurity.io/articles/introducing-smokedmeat/
on MAD Bugs: Feeding Claude Phrack Articles for Fun and Profit · c/blueteamsec · 2 pts · 129dhttps://blog.calif.io/p/mad-bugs-feeding-claude-phrack-articles
on jailer: Jailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. It tracks processes using BPF task_storage maps and enforces role-based policies · c/blueteamsec · 1 pts · 165d
on Predator Spyware Bypasses iOS Recording Indicators · c/blueteamsec · 1 pts · 196darchive - https://archive.ph/ni8Dl
on Paper page - A unified framework for detecting point and collective anomalies in operating system logs via collaborative transformers · c/blueteamsec · 1 pts · 225dGitHub repo is here: https://github.com/NasirzadehMoh/CoLog
on Agentic-SOC-Simulation: AI 驱动的 SOC 仿真平台 - "integrating the DeepSeek inference model , multi-agent collaboration, and the MCP (Model Context Protocol) standard, we have built a virtual SOC team. · c/blueteamsec · 1 pts · 228dhttps://mp.weixin.qq.com/s/llgko171hBvEaZ2gYbQg6A
on TokenFlare: Serverless AITM Simulation Framework for Entra ID and M365 · c/blueteamsec · 1 pts · 238dhttps://labs.jumpsec.com/tokenflare-serverless-AiTM-phishing-in-under-60-seconds/
on Vulnhalla: Picking the true vulnerabilities from the CodeQL haystack · c/blueteamsec · 1 pts · 246dhttps://github.com/cyberark/Vulnhalla
on wirebrowser: Wirebrowser is a debugging, interception, and memory-inspection toolkit powered by the Chrome DevTools Protocol (CDP). It unifies network manipulation, API testing, automation scripting, · c/blueteamsec · 1 pts · 247dhttps://fcavallarin.github.io/wirebrowser/BDHS-Origin-Trace
on Start using Windows Autopatch · c/blueteamsec · 1 pts · 268dRelated - https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-autopatch-%E2%80%94-elevate-your-update-experience-for-modern-work/4468111
on Exclusive: Full Student Database of MOIS-Affiliated Ravin Academy Leaked · c/blueteamsec · 1 pts · 294dhttps://ravin-academy.com/
on Malicious Teams Installers Drop Oyster Malware - abusing SEO poisoning and malvertising to lure users into downloading a fake Microsoft Teams installer. · c/blueteamsec · 1 pts · 323dRelated - https://conscia.com/blog/from-seo-poisoning-to-malware-deployment-malvertising-campaign-uncovered/
on Domain Fronting is Dead. Long Live Domain Fronting! · c/blueteamsec · 2 pts · 330dThe observant observer
on Behind the Curtain: Detecting Remote Employment Fraud Inside Your Organization · c/blueteamsec · 2 pts · 338dThx for the share
No idea - the link is - https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-june-9ec
https://github.com/kalachkar/vsmex
mitigations discussion: https://www.openwall.com/lists/oss-security/2026/05/15/3
Recording: https://www.youtube.com/watch?v=azej1P17w9E
yep, still working
https://0xh4lpy.medium.com/toastfix-chaining-a-clickfix-attack-with-toast-notifications-72082694fef9
https://labs.boostsecurity.io/articles/introducing-smokedmeat/
https://blog.calif.io/p/mad-bugs-feeding-claude-phrack-articles
archive - https://archive.ph/ni8Dl
GitHub repo is here: https://github.com/NasirzadehMoh/CoLog
https://mp.weixin.qq.com/s/llgko171hBvEaZ2gYbQg6A
https://labs.jumpsec.com/tokenflare-serverless-AiTM-phishing-in-under-60-seconds/
https://github.com/cyberark/Vulnhalla
https://fcavallarin.github.io/wirebrowser/BDHS-Origin-Trace
Related - https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-autopatch-%E2%80%94-elevate-your-update-experience-for-modern-work/4468111
https://ravin-academy.com/
Related - https://conscia.com/blog/from-seo-poisoning-to-malware-deployment-malvertising-campaign-uncovered/
The observant observer
Thx for the share