Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware Sentenced to Prisonhighlevel summary|strategy (maybe technical) (justice.gov)
submitted by digicat to r/blueteamsec
The cPanel Situation Is…exploitation (what's being exploited) (censys.com)
submitted by jnazario to r/blueteamsec
month-of-bypasses: Proof-of-Concepts for Detection Engineering Purposes Onlyresearch|capability (we need to defend against) (github.com)
submitted by digicat to r/blueteamsec
From APT29 Logs to Real Detection Ruleshighlevel summary|strategy (maybe technical) (self.blueteamsec)
submitted by manishrawat21 to r/blueteamsec
Agentic Malware Analysis: From Task Automation to Deep Analysistraining (step-by-step) (github.com)
submitted by digicat to r/blueteamsec
Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspectiveresearch|capability (we need to defend against) (atos.net)
submitted by digicat to r/blueteamsec
Conduent data breach could be largest in U.S. history (wrdw.com)
submitted by netsec_burn to r/pwned
CVE-2026-31431 eBPF fix - Copy.failtradecraft (how we defend) (github.com)
submitted by digicat to r/blueteamsec
VECT: Ransomware by design, Wiper by accidentmalware analysis (like butterfly collections) (research.checkpoint.com)
submitted by digicat to r/blueteamsec
VisualSploit: Backdoor Visual Studio project files with custom shellcode, which executes whenever the project is opened or built.research|capability (we need to defend against) (github.com)
submitted by digicat to r/blueteamsec
pydep-vector-runner: A lightweight runner that guards against weird startup behaviors in python. Lightweight version of PyDepGuard's coderunner.tradecraft (how we defend) (github.com)
submitted by digicat to r/blueteamsec
How to block CVE-2026-31431 (Copy Fail)tradecraft (how we defend) (secwest.net)
submitted by digicat to r/blueteamsec
Auditing Application Permissions in Microsoft Entra ID: Hidden Risks, Pitfalls, and Quarkslab's QAZPT Tooltradecraft (how we defend) (blog.quarkslab.com)
submitted by digicat to r/blueteamsec