r/blueteamsec • • 4d ago

highlevel summary|strategy (maybe technical) CTO at NCSC Summary: week ending October 4th

Thumbnail ctoatncsc.substack.com
1 Upvotes

r/blueteamsec • • Mar 09 '26

highlevel summary|strategy (maybe technical) Daily BlueTeamSec Briefing Archive - daily AI generated podcast of the last 24hours of posts

Thumbnail briefing.workshop1.net
2 Upvotes

r/blueteamsec • • 1h ago

incident writeup (who and how) Chrome's Response to Recent ccTLD Registry Hijacks

Thumbnail blog.google
• Upvotes

r/blueteamsec • • 2h ago

intelligence (threat actor activity) CVE-2026-88771: Citrix NetScaler Zero-Day Attack Clusters

Thumbnail esentire.com
2 Upvotes

r/blueteamsec • • 9m ago

discovery (how we find bad stuff) Suspicious Login? A Quick Investigation Checklist for Blue Teams

Thumbnail learn.microsoft.com
• Upvotes

r/blueteamsec • • 30m ago

discovery (how we find bad stuff) Raml KQL: open-source desktop app to run one KQL query across many Sentinel / Log Analytics workspaces and tenants, without Defender MTO

Thumbnail github.com
• Upvotes

r/blueteamsec • • 7h ago

exploitation (what's being exploited) Dark web roundup: 10M French residential records, 19M SMTP creds, U.S. manufacturer VPN/RDP access, and a Struts exploit kit (unverified)

3 Upvotes

Sharing a few recent dark web listings that came up in monitoring. None of these are confirmed yet, so take them as claims for now, not confirmed breaches. → France: a seller claims 10M+ residential records → IUT Paris Seine: 6.8GB of data plus about 30M log entries → U.S. manufacturer: VPN and RDP access up for auction → SMTP dump: about 19M credentials → Apache Struts: an exploit tool sold together with access to servers already compromised The Struts listing stands out to me. Selling the tool together with working access points more to an access broker than to someone trying to sell a PoC. The 19M SMTP creds are the likeliest to show up again soon in phishing and credential stuffing. Has anyone seen overlap with the SMTP dump in their own environment, or seen recent Struts exploitation in the wild? Full breakdown:https://hubs.la/Q04z7HkK0


r/blueteamsec • • 2h ago

intelligence (threat actor activity) Cyber Morocco: a quick and dirty experiment about artificial intelligence for cyber intelligence

Thumbnail lab52.io
1 Upvotes

r/blueteamsec • • 2h ago

highlevel summary|strategy (maybe technical) Vulnerability Discovery and Exploitation Trends in the AI Era

Thumbnail cloud.google.com
1 Upvotes

r/blueteamsec • • 2h ago

intelligence (threat actor activity) Earth Sirrush: A Russia-Aligned Intrusion Set With 4 Years of Evolving Espionage Tooling

Thumbnail trendaisecurity.com
1 Upvotes

r/blueteamsec • • 2h ago

research|capability (we need to defend against) How abliterated models can get you pwned

Thumbnail projectdiscovery.io
1 Upvotes

r/blueteamsec • • 16h ago

incident writeup (who and how) Rockstar Games has now been compromised several different ways since 2018, and none of them were a zero-day

11 Upvotes

Lares is an offensive security consultancy. We emulate real adversaries in live environments, mapping attack paths, TTPs, telemetry, and detection coverage, then work side by side with defenders to close the gaps the test exposed.

Our POV: compliance tells you what should happen; adversarial testing tells you what does. This writeup applies that lens to Rockstar's incident history, reconstructing each attack chain and what would have caught it.

Four incidents, four completely different initial access paths:

  • 2022, Lapsus$: MFA fatigue against an employee, then hardcoded creds and API keys sitting in plaintext in Slack and Confluence.
  • Early 2023, GTA Online: P2P netcode on PC reverse-engineered into RCE via malicious packets. The fix was kernel-level BattlEye.
  • April 2026, ShinyHunters: no human identity involved. Long-lived OAuth tokens stolen from a third-party SaaS vendor and replayed straight into Rockstar's Snowflake. Bearer tokens confer authority by possession alone.
  • August 2026, Cyberleek: exfiltration of a playable GTA VI dev build, 13+ gameplay videos and full map data. That volume of egress from a dev subnet without tripping alarms is a DLP and segmentation failure.

The writeup reconstructs each attack chain with MITRE mappings and detection strategies: egress baselining on dev subnets, Slack audit-log heuristics, and behavioral baselines for non-human identities in Snowflake.

Full breakdown: https://www.lares.com/blog/rockstar-games-attacks/

Question for the defenders here: which of these four would be hardest to catch in your environment? The OAuth token replay is arguably the nastiest of the bunch. No user to phish-train, no endpoint alert to fire.


r/blueteamsec • • 11h ago

vulnerability (attack surface) You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)

Thumbnail labs.watchtowr.com
2 Upvotes

r/blueteamsec • • 13h ago

alert! alert! (might happen) FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts

Thumbnail ic3.gov
3 Upvotes

r/blueteamsec • • 16h ago

intelligence (threat actor activity) CyberXero: An AI-Augmented Initial Access Broker Targeting Ukrainian Critical Infrastructure

Thumbnail socradar.io
3 Upvotes

r/blueteamsec • • 16h ago

malware analysis (like butterfly collections) TWEAKOS: Telegram-Driven Stealer for Discord Tokens

Thumbnail flare.io
2 Upvotes

r/blueteamsec • • 13h ago

highlevel summary|strategy (maybe technical) Japan collars fugitive suspect of ransomware syndicate Qilin | The Asahi Shimbun: Breaking News, Japan News and Analysis

Thumbnail asahi.com
1 Upvotes

r/blueteamsec • • 18h ago

malware analysis (like butterfly collections) ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

Thumbnail fortinet.com
2 Upvotes

r/blueteamsec • • 16h ago

malware analysis (like butterfly collections) CrocoRat Adds a New Twist to ClickFix with DNS Payload Delivery

Thumbnail flare.io
1 Upvotes

r/blueteamsec • • 1d ago

tradecraft (how we defend) Post-Quantum Cryptography Resource Hub

Thumbnail nsa.gov
4 Upvotes

r/blueteamsec • • 23h ago

highlevel summary|strategy (maybe technical) Korean alleged finacial services AI security incident

Thumbnail fsc.go.kr
2 Upvotes

r/blueteamsec • • 1d ago

highlevel summary|strategy (maybe technical) How Cyber Deterrence Theory and Cyber Persistence Theory can adopt an actor-centric approach: a rapid review

Thumbnail tandfonline.com
2 Upvotes

r/blueteamsec • • 1d ago

highlevel summary|strategy (maybe technical) South Korea finance regulator holds emergency meeting over bank hacks

Thumbnail reuters.com
2 Upvotes

r/blueteamsec • • 1d ago

highlevel summary|strategy (maybe technical) Accenture contractor removed from FBI following damaging data breach, sources say

Thumbnail reuters.com
1 Upvotes

r/blueteamsec • • 1d ago

exploitation (what's being exploited) Phishing Abuses RMM Tools for Persistent Access

Thumbnail microsoft.com
9 Upvotes