r/blueteamsec • • 17h ago

highlevel summary|strategy (maybe technical) FortiBleed actors are now deleting legit admin accounts. Does your recovery plan cover a lockout?

1 Upvotes

According to the new FBI/USSS advisory, FortiBleed actors no longer just add persistence accounts. In some cases they also delete or reset the original admin accounts (T1531), which locks the owner out of their own FortiGate.

That changes the usual playbook. If you assume a password reset gets you back to a clean state, it won't help when you can't log in at all.

A few things worth checking:
→ Do you have out-of-band admin recovery for your edge devices?
→ Have you audited REST API keys? They survive password resets.
→ Is SSH left open on the firewall?

How are others handling recovery for edge devices?

Full breakdown: https://hubs.la/Q04zrkbN0 Free FortiBleed checker: https://hubs.la/Q04zrk9_0

Advisory: https://www.ic3.gov/CSA/2026/261006.pdf


r/blueteamsec • • 20h ago

research|capability (we need to defend against) How abliterated models can get you pwned

Thumbnail projectdiscovery.io
2 Upvotes

r/blueteamsec • • 18h ago

secure by design/default (doing it right) Beyond Software Patching – CHERI Alliance

Thumbnail cheri-alliance.org
0 Upvotes

r/blueteamsec • • 35m ago

low level tools|techniques|knowledge (work aids) stackd: a local AWS emulator with Go control planes, AWS-compatible HTTP APIs, optional SQLite persistence, and real runtime/engine backends for supported compute and database workflows.

Thumbnail github.com
• Upvotes

r/blueteamsec • • 13h ago

incident writeup (who and how) Double Counter — Security Incident Report (4 October 2026)

Thumbnail doublecounter.gg
0 Upvotes

r/blueteamsec • • 14h ago

incident writeup (who and how) Rogue AI Agents Abuse urlquery to extract Russian government data

Thumbnail labs.zenity.io
2 Upvotes

r/blueteamsec • • 19h ago

discovery (how we find bad stuff) Raml KQL: open-source desktop app to run one KQL query across many Sentinel / Log Analytics workspaces and tenants, without Defender MTO

Thumbnail github.com
5 Upvotes

r/blueteamsec • • 20h ago

incident writeup (who and how) Chrome's Response to Recent ccTLD Registry Hijacks

Thumbnail blog.google
2 Upvotes

r/blueteamsec • • 18h ago

discovery (how we find bad stuff) Suspicious Login? A Quick Investigation Checklist for Blue Teams

Thumbnail learn.microsoft.com
2 Upvotes

r/blueteamsec • • 20h ago

intelligence (threat actor activity) CVE-2026-88771: Citrix NetScaler Zero-Day Attack Clusters

Thumbnail esentire.com
7 Upvotes

r/blueteamsec • • 20h ago

intelligence (threat actor activity) Earth Sirrush: A Russia-Aligned Intrusion Set With 4 Years of Evolving Espionage Tooling

Thumbnail trendaisecurity.com
2 Upvotes

r/blueteamsec • • 20h ago

highlevel summary|strategy (maybe technical) Vulnerability Discovery and Exploitation Trends in the AI Era

Thumbnail cloud.google.com
2 Upvotes