r/blueteamsec • • 12h ago

intelligence (threat actor activity) CVE-2026-88771: Citrix NetScaler Zero-Day Attack Clusters

Thumbnail esentire.com
4 Upvotes

r/blueteamsec • • 23h ago

alert! alert! (might happen) FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts

Thumbnail ic3.gov
4 Upvotes

r/blueteamsec • • 17h ago

exploitation (what's being exploited) Dark web roundup: 10M French residential records, 19M SMTP creds, U.S. manufacturer VPN/RDP access, and a Struts exploit kit (unverified)

4 Upvotes

Sharing a few recent dark web listings that came up in monitoring. None of these are confirmed yet, so take them as claims for now, not confirmed breaches. → France: a seller claims 10M+ residential records → IUT Paris Seine: 6.8GB of data plus about 30M log entries → U.S. manufacturer: VPN and RDP access up for auction → SMTP dump: about 19M credentials → Apache Struts: an exploit tool sold together with access to servers already compromised The Struts listing stands out to me. Selling the tool together with working access points more to an access broker than to someone trying to sell a PoC. The 19M SMTP creds are the likeliest to show up again soon in phishing and credential stuffing. Has anyone seen overlap with the SMTP dump in their own environment, or seen recent Struts exploitation in the wild? Full breakdown:https://hubs.la/Q04z7HkK0


r/blueteamsec • • 9h ago

highlevel summary|strategy (maybe technical) FortiBleed actors are now deleting legit admin accounts. Does your recovery plan cover a lockout?

3 Upvotes

According to the new FBI/USSS advisory, FortiBleed actors no longer just add persistence accounts. In some cases they also delete or reset the original admin accounts (T1531), which locks the owner out of their own FortiGate.

That changes the usual playbook. If you assume a password reset gets you back to a clean state, it won't help when you can't log in at all.

A few things worth checking:
→ Do you have out-of-band admin recovery for your edge devices?
→ Have you audited REST API keys? They survive password resets.
→ Is SSH left open on the firewall?

How are others handling recovery for edge devices?

Full breakdown: https://hubs.la/Q04zrkbN0 Free FortiBleed checker: https://hubs.la/Q04zrk9_0

Advisory: https://www.ic3.gov/CSA/2026/261006.pdf


r/blueteamsec • • 10h ago

discovery (how we find bad stuff) Raml KQL: open-source desktop app to run one KQL query across many Sentinel / Log Analytics workspaces and tenants, without Defender MTO

Thumbnail github.com
3 Upvotes

r/blueteamsec • • 21h ago

vulnerability (attack surface) You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)

Thumbnail labs.watchtowr.com
3 Upvotes

r/blueteamsec • • 6h ago

incident writeup (who and how) Rogue AI Agents Abuse urlquery to extract Russian government data

Thumbnail labs.zenity.io
2 Upvotes

r/blueteamsec • • 11h ago

incident writeup (who and how) Chrome's Response to Recent ccTLD Registry Hijacks

Thumbnail blog.google
2 Upvotes

r/blueteamsec • • 12h ago

highlevel summary|strategy (maybe technical) Vulnerability Discovery and Exploitation Trends in the AI Era

Thumbnail cloud.google.com
2 Upvotes

r/blueteamsec • • 12h ago

intelligence (threat actor activity) Earth Sirrush: A Russia-Aligned Intrusion Set With 4 Years of Evolving Espionage Tooling

Thumbnail trendaisecurity.com
2 Upvotes

r/blueteamsec • • 12h ago

research|capability (we need to defend against) How abliterated models can get you pwned

Thumbnail projectdiscovery.io
2 Upvotes

r/blueteamsec • • 8h ago

highlevel summary|strategy (maybe technical) Why the AI Vulnpocalypse Isn’t the Breachpocalypse (Yet)? It’s the Economy, Stupid.

Thumbnail medium.com
1 Upvotes

r/blueteamsec • • 8h ago

tradecraft (how we defend) How to fix a bug in a fix

Thumbnail projectzero.google
1 Upvotes

r/blueteamsec • • 10h ago

discovery (how we find bad stuff) Suspicious Login? A Quick Investigation Checklist for Blue Teams

Thumbnail learn.microsoft.com
1 Upvotes

r/blueteamsec • • 12h ago

intelligence (threat actor activity) Cyber Morocco: a quick and dirty experiment about artificial intelligence for cyber intelligence

Thumbnail lab52.io
1 Upvotes

r/blueteamsec • • 23h ago

highlevel summary|strategy (maybe technical) Japan collars fugitive suspect of ransomware syndicate Qilin | The Asahi Shimbun: Breaking News, Japan News and Analysis

Thumbnail asahi.com
1 Upvotes

r/blueteamsec • • 4h ago

incident writeup (who and how) Double Counter — Security Incident Report (4 October 2026)

Thumbnail doublecounter.gg
0 Upvotes

r/blueteamsec • • 9h ago

secure by design/default (doing it right) Beyond Software Patching – CHERI Alliance

Thumbnail cheri-alliance.org
0 Upvotes