Sign in

r/blueteamsec bot

@r-blueteamsec.bsky.social
251 followers 4 following 5.9K posts

Mirrors r/blueteamsec, "intelligence, research and engineering to help operational [blue|purple] teams defend their estates." Unofficial. Operated by @tweedge.net, open source @ github.com/tweedge/xpost-reddit-to-…

PostsRepliesMedia
r/blueteamsec bot @r-blueteamsec.bsky.social · 2h
Accenture contractor removed from FBI following damaging data breach, sources say
reuters.com
Accenture contractor removed from FBI following damaging data breach, sources say
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 3h
Raml KQL: open-source desktop app to run one KQL query across many Sentinel / Log Analytics workspaces and tenants, without Defender MTO
github.com
Raml KQL: open-source desktop app to run one KQL query across many Sentinel / Log Analytics workspaces and tenants, without Defender MTO
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 4h
CVE-2026-88771: Citrix NetScaler Zero-Day Attack Clusters
esentire.com
CVE-2026-88771: Citrix NetScaler Zero-Day Attack Clusters
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 4h
Chrome's Response to Recent ccTLD Registry Hijacks
blog.google
Chrome's Response to Recent ccTLD Registry Hijacks
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 5h
How abliterated models can get you pwned
projectdiscovery.io
How abliterated models can get you pwned
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 12h
You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)
labs.watchtowr.com
You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 13h
TWEAKOS: Telegram-Driven Stealer for Discord Tokens
flare.io
TWEAKOS: Telegram-Driven Stealer for Discord Tokens
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 13h
CyberXero: An AI-Augmented Initial Access Broker Targeting Ukrainian Critical Infrastructure
socradar.io
CyberXero: An AI-Augmented Initial Access Broker Targeting Ukrainian Critical Infrastructure
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 16h
FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts
ic3.gov
FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 17h
ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure
fortinet.com
ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 22h
Post-Quantum Cryptography Resource Hub
nsa.gov
Post-Quantum Cryptography Resource Hub
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 06/10/2026
How Cyber Deterrence Theory and Cyber Persistence Theory can adopt an actor-centric approach: a rapid review
tandfonline.com
How Cyber Deterrence Theory and Cyber Persistence Theory can adopt an actor-centric approach: a rapid review
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 06/10/2026
Korean alleged finacial services AI security incident
fsc.go.kr
Korean alleged finacial services AI security incident
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 06/10/2026
South Korea finance regulator holds emergency meeting over bank hacks
reuters.com
South Korea finance regulator holds emergency meeting over bank hacks
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 05/10/2026
Phishing Abuses RMM Tools for Persistent Access
microsoft.com
Phishing Abuses RMM Tools for Persistent Access
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 05/10/2026
SMTP is the key: BPFDoor and AVERAT hitting the network edge
rapid7.com
SMTP is the key: BPFDoor and AVERAT hitting the network edge
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 05/10/2026
Android-Projector-C2-Malware: Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis
github.com
Android-Projector-C2-Malware: Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis
010
r/blueteamsec bot @r-blueteamsec.bsky.social · 04/10/2026
DeepSeek-Reasonix: How a poisoned config can hijack an AI coding agent
about.gitlab.com
DeepSeek-Reasonix: How a poisoned config can hijack an AI coding agent
010
r/blueteamsec bot @r-blueteamsec.bsky.social · 04/10/2026
Every Iranian Strike on UAE Ports and Refineries Was Paired With a Cyberattack
wired.me
Every Iranian Strike on UAE Ports and Refineries Was Paired With a Cyberattack
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 04/10/2026
netscaler-ctx697096-checker: Am I fixed? Was I hacked? Read-only checker for Citrix NetScaler CTX697096 (CVE-2026-88771–88778): build, all 8 CVE preconditions, Enhanced ISN, upgrade risks, SAML status, plus --ioc sweep with every public IoC (webshells, implants, backdoor ad
github.com
netscaler-ctx697096-checker: Am I fixed? Was I hacked? Read-only checker for Citrix NetScaler CTX697096 (CVE-2026-88771–88778): build, all 8 CVE preconditions, Enhanced ISN, upgrade risks, SAML status, plus --ioc sweep with every public IoC (webshells, implants, backdoor ad
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 04/10/2026
adm-zip_LPE-PoC: CVE-2026-102282: Local Privilege Escalation via SUID/SGID preservation during archive extraction
github.com
adm-zip_LPE-PoC: CVE-2026-102282: Local Privilege Escalation via SUID/SGID preservation during archive extraction
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 04/10/2026
Debian alert DSA-6528-1 - ~1,000 CVEs patched
lwn.net
Debian alert DSA-6528-1 - ~1,000 CVEs patched
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 04/10/2026
AI Ate My Velociraptor
labs.infoguard.ch
AI Ate My Velociraptor
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 04/10/2026
N0xis: AI-first reverse-engineering toolkit: static analysis, SSA decompiler, live memory, provenance. Source-available (PolyForm Noncommercial).
github.com
N0xis: AI-first reverse-engineering toolkit: static analysis, SSA decompiler, live memory, provenance. Source-available (PolyForm Noncommercial).
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 04/10/2026
lockjaw: Rust based C2 Framework
github.com
lockjaw: Rust based C2 Framework
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 04/10/2026
UnifiedThreatHunting: A threat hunting process
github.com
UnifiedThreatHunting: A threat hunting process
010
r/blueteamsec bot @r-blueteamsec.bsky.social · 04/10/2026
prompt-injection-email-samples: Open test set of .eml emails for checking how email security controls and AI mailbox assistants handle indirect prompt injection. It crosses three intents (system-prompt disclosure, data exfiltration, tool discovery) with three delivery methods
github.com
prompt-injection-email-samples: Open test set of .eml emails for checking how email security controls and AI mailbox assistants handle indirect prompt injection. It crosses three intents (system-prompt disclosure, data exfiltration, tool discovery) with three delivery methods
010
r/blueteamsec bot @r-blueteamsec.bsky.social · 03/10/2026
Spetsvuzavtomatika Leak Exposes an SVR Cyber Development Ecosystem
dti.domaintools.com
Spetsvuzavtomatika Leak Exposes an SVR Cyber Development Ecosystem
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 03/10/2026
We Turned On DNS Logging. Now Watch Me Walk Around It
redhand.io
We Turned On DNS Logging. Now Watch Me Walk Around It
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 03/10/2026
Three in four EU employees faced cyber threats at work, new Eurobarometer finds
digital-strategy.ec.europa.eu
Three in four EU employees faced cyber threats at work, new Eurobarometer finds
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 03/10/2026
Critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway products, several intrusions in Finland
kyberturvallisuuskeskus.fi
Critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway products, several intrusions in Finland
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 03/10/2026
aws-firmware-dump: Acquire the disks of an AMI you can already launch into a private S3 bucket. No catalog, no product list, no baked-in AMI ids. You pass the AMI id.
github.com
aws-firmware-dump: Acquire the disks of an AMI you can already launch into a private S3 bucket. No catalog, no product list, no baked-in AMI ids. You pass the AMI id.
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 03/10/2026
ShinyHunters hacker in FBI data theft detained in Jordan, cooperating with bureau, sources say
reuters.com
ShinyHunters hacker in FBI data theft detained in Jordan, cooperating with bureau, sources say
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 03/10/2026
CloudSyncD: macOS backdoor hidden in a fake Zoom installer
jamf.com
CloudSyncD: macOS backdoor hidden in a fake Zoom installer
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 03/10/2026
Updates to Full Disk Access in macOS - Latest News - Apple Developer
developer.apple.com
Updates to Full Disk Access in macOS - Latest News - Apple Developer
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 03/10/2026
knock-outd: an undetected port-knocking backdoor in the wild
virlabs.ai
knock-outd: an undetected port-knocking backdoor in the wild
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 03/10/2026
OpenAI says its review into hacks, including on Australian government sites, is costing $500,000 a day
theguardian.com
OpenAI says its review into hacks, including on Australian government sites, is costing $500,000 a day
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 03/10/2026
CVE-2026-79954: radio telecommand injection through an SDLS authentication downgrade in NASA CryptoLib
starsec.io
CVE-2026-79954: radio telecommand injection through an SDLS authentication downgrade in NASA CryptoLib
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 03/10/2026
NSA Announces Post-Quantum Cryptography Measures to Safeguard National Security Systems Against Quantum Computing Threats
nsa.gov
NSA Announces Post-Quantum Cryptography Measures to Safeguard National Security Systems Against Quantum Computing Threats
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 03/10/2026
Teenager suspected of leading KillSec ransomware group as law enforcement seizes servers and leak site – Three arrests and eight searches across four European countries in an operation targeting a group linked to some 1 000 attacks worldwide
europol.europa.eu
Teenager suspected of leading KillSec ransomware group as law enforcement seizes servers and leak site – Three arrests and eight searches across four European countries in an operation targeting a group linked to some 1 000 attacks worldwide
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 03/10/2026
CVE-2026-93355: Account Takeover in LiteLLM
ox.security
CVE-2026-93355: Account Takeover in LiteLLM
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 03/10/2026
Introducing ADE-Skills — Adversarial Detection Engineering Knowledge Base
detect.fyi
Introducing ADE-Skills — Adversarial Detection Engineering Knowledge Base
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 03/10/2026
Security Update: Guidance for NetScaler SAML Authentication Deployment
community.citrix.com
Security Update: Guidance for NetScaler SAML Authentication Deployment
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 02/10/2026
GitHub Repos Exposed 543,699 Credentials. Nobody Revoked Them.
trufflesecurity.com
GitHub Repos Exposed 543,699 Credentials. Nobody Revoked Them.
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 02/10/2026
Counteroffensive AI: Pwning AI Pentesters
troopers.de
Counteroffensive AI: Pwning AI Pentesters
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 02/10/2026
Disruptive cyber attacks – reducing their impact, reducing the risk
ncsc.gov.uk
Disruptive cyber attacks – reducing their impact, reducing the risk
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 02/10/2026
Detecting AI Attack Agents: CDN Bypass, JA3, Anti-Forensics
abstract.security
Detecting AI Attack Agents: CDN Bypass, JA3, Anti-Forensics
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 02/10/2026
ps-ppl-bypass: Process Explorer vulnerable driver PPL Bypass
github.com
ps-ppl-bypass: Process Explorer vulnerable driver PPL Bypass
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 02/10/2026
FortiMail - Improper limitation of a pathname to a restricted directory - This has been reported to be exploited in the wild
fortiguard.com
FortiMail - Improper limitation of a pathname to a restricted directory - This has been reported to be exploited in the wild
000
r/blueteamsec bot @r-blueteamsec.bsky.social · 02/10/2026
DIVD-2026-00015 - Vulnerabilities in Zammad during investigation of case DIVD-2026-00014
csirt.divd.nl
DIVD-2026-00015 - Vulnerabilities in Zammad during investigation of case DIVD-2026-00014
000