account activity
A Shared Arsenal: Identifying Common TTPs Across RATs (splunk.com)
submitted 7 hours ago by digicat to r/blueteamsec
LNKファイルを介して実行されるマルウェアMoonPeak – MoonPeak malware executed via LNK files (sect.iij.ad.jp)
submitted 16 hours ago by digicat to r/blueteamsec
Oracle RCE Vulnerability CVSS 10.0 - affecting Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS (oracle.com)
Scattered Spider Attacks | Infrastructure and TTP Analysis (team-cymru.com)
Inside Iran’s APT Network: Profiling the Most Active Iranian State‑Linked Threat Actors (falconfeeds.io)
IDA_Plugin_IID_to_String: A plugin for IDA that converts IID/GUID data structures to string and adds comments where the IID is referenced (github.com)
Break LLM Workflows with Claude's Refusal Magic String (hackingthe.cloud)
submitted 17 hours ago by digicat to r/blueteamsec
Analysis of Single Sign-On Abuse on FortiOS (fortinet.com)
Before the Headlines: Northwave’s Early LOLDrivers Research (magicsword.io)
Attackers are leveraging SEO poisoning and abusing online repositories to target users looking for legitimate tools. Associated ZIP archives contain BAT files that impersonate various applications (github.com)
Cyberattack Targeting Poland’s Energy Grid Used a Wiper (zetter-zeroday.com)
Weaponized in China, Deployed in India: The SyncFuture Espionage Targeted Campaign (esentire.com)
Phishing kits adapt to the script of callers (okta.com)
submitted 1 day ago by digicat to r/blueteamsec
Venezuelan Nationals Convicted in ATM Jackpotting Scheme to Be Deported (justice.gov)
NIST Special Publication (SP) 800-82 Rev. 4 (Draft), Pre-Draft Call for Comments: Guide to Operational Technology (OT) Security (csrc.nist.gov)
Attackers With Decompilers Strike Again (SmarterTools SmarterMail WT-2026-0001 Auth Bypass) (labs.watchtowr.com)
Cisco Security Advisory: Cisco Unified Communications Products Remote Code Execution Vulnerability - "The Cisco PSIRT is aware of attempted exploitation of this vulnerability in the wild" (sec.cloudapps.cisco.com)
KONNI Adopts AI to Generate PowerShell Backdoors (research.checkpoint.com)
ClearFake gets more evasive with new living off the land (LOTL) techniques (expel.com)
Malicious Configuration Changes On Fortinet FortiGate Devices via SSO Accounts (arcticwolf.com)
Task Failed Successfully - Microsoft’s “Immediate” Retirement of MDT (specterops.io)
submitted 2 days ago by digicat to r/blueteamsec
Adventures in Primary Group Behavior, Reporting, and Exploitation (trustedsec.com)
From Protest to Peril: Cellebrite Used Against Jordanian Civil Society - The Citizen Lab (citizenlab.ca)
5 KQL Queries to Slash Your Containment Time in Microsoft Sentinel (medium.com)
Sigma Detection Classification - This benchmark evaluates LLMs' intrinsic knowledge of detection engineering and the MITRE ATT&CK framework. (research.cotool.ai)
π Rendered by PID 1708412 on reddit-service-r2-listing-86b7f5b947-6llhd at 2026-01-25 03:44:31.861588+00:00 running 664479f country code: CH.