#blueteam — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #blueteam, aggregated by home.social.
-
I spent the last few months building a CTF.
WATCHLIST: 24 challenges, one investigation, 24 hours.
DNS forensics. Memory analysis. A live honeypot. Disk images. OSINT.
Sep 19. Teams 1-6. $750 first place.
If you have been meaning to try CTFs but thought they were too technical, this one has entry points built for you.
ctf.xposedornot.com
-
Added
telegra.phto my PasteBin block list as it's been observed by GenDigital for C2 dead drops:https://github.com/BadSamuraiDev/bs-lists/blob/main/pastebins.txt
-
New by me: CybersecKyle Security How-To Series: Light Offensive to Think Defensively, Part 1 - Build a Safe Lab with Snapshots
-
We've uploaded 75+ production-ready scripts for #Security, #DevOps, and automation to save you hours of writing boilerplate code. Best part? We are dropping new tutorials and tools every single day!
Find your next time-saver here: https://www.valtersit.com/python #CVE #infosec #SysAdmin #cybersecurity #Linux #devops #developer #git #github #gitlab #blueteam #python #hackers #ubuntu #debian #ukraine #spain #ireland #uk #canada #finland #lithuania #ireland #hungary #denmark #norway -
We have updated https://www.valtersit.com/methodology/ with the actual information #CVE #Dokploy #infosec #SysAdmin #cybersecurity #Linux #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta
-
Three attacks this week didn't break the network trust signals a SOC leans on. They just hid inside them.
A 633-server proxy network (CanOworms) so a state actor and a card fraudster leave through the same clean IP. Midnight Blizzard on hotel Wi-Fi captive portals serving a fake M365 login. And a PoC running code on Cloudflare's own edge.
The address tells you where traffic sits, not who's driving it.
-
RE: https://infosec.exchange/@BleepingComputer/117079181932676633
Assuming you don’t need access to the Polygon blockchain from your business network, protect your systems by block the named public RPC endpoints using DNS, NGFW or web security proxy:
polygon-bor-rpc.publicnode[.]com
polygon.drpc[.]org
polygon-pokt.nodies[.]app
polygon-rpc[.]com
1rpc[.]io
polygon.meowrpc[.]com -
🛡️ HAVOC C2 — DEFENDER CHEAT SHEET
Havoc is a powerful Command & Control framework used in authorized red-team operations. 🔴⚡ Understanding how C2 infrastructure, agents and communications behave can also help defenders recognize suspicious activity and improve detection. 🔍
Learn the framework. Hunt the signals. Strengthen your defenses. 🔐
💬 Comment “HAVOC” if you want more cybersecurity cheat sheets.
-
-
Sweet little investigation to a malicious infrastructure, that was initiated with two web that turns out to be a Powershell, and digging deeper into the infrastructure.
https://malwr-analysis.com/2026/08/08/investigating-a-multi-stage-powershell-loader/
-
AI is not your biggest cyber threat.
Your shitty patching process probably is.
A slightly sarcastic take on AI hype, CISOs, security theatre, broken processes, legacy IT, SOC reality and why automation changes the speed of attacks more than the nature of the problem.
https://0ut3r.space/2026/08/08/ai-is-not-your-biggest-cyber-threat/
#cybersecurity #infosec #AI #CISO #BlueTeam #RedTeam #SOC #SecurityEngineering
-
🚨 CVE-2026-48282: una semplice Path Traversal può trasformarsi in una Remote Code Execution su Adobe ColdFusion.
Nel video spiego:
🔴 cos'è RDS
🔴 perché il CVSS è 10.0
🔴 come avviene la catena di attacco
🔴 cosa controllare dopo aver applicato la patch🎥 Guarda il video:
👉 https://youtu.be/SHYU1ag3NsQ#CyberSecurity #ColdFusion #CVE202648282 #InfoSec #BlueTeam
@sicurezza -
In #cybersecurity there's always two problem sources; a perceived source, and an actual source. The two are seldom the same but the perceived source is always the easiest to blame.
-
2026-08-05 RDP #Honeypot IOCs - 29778 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
27.71.229.97 - 29670
134.199.168.195 - 30
45.142.193.18 - 12Top ASNs:
AS38731 - 29670
AS14061 - 30
AS396982 - 27Top Accounts:
hello - 29712
Test - 18
Domain - 9Top ISPs:
VIETTEL - 29670
DigitalOcean, LLC - 30
Google LLC - 27Top Clients:
Unknown - 29778Top Software:
Unknown - 29778Top Keyboards:
Unknown - 29778Top IP Classification:
Unknown - 29679
hosting - 78
proxy - 12Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
We still have not processed 49 hours of new #cve #cvealert data due to system update and new source connection https://www.valtersit.com/cve will become much better and after that vendors is next on the list. #defcon #devops #devsecops #sysadmin #cybersecurity #redteam #blueteam #hackers #infosec #linux #python #developers #ubuntu #ethicalhacking #ethicalhacker #angular #android
-
New by me: CybersecKyle Security How-To Series: Blue Team Fundamentals, Part 3 - Vulnerability Scanning with Real Triage
#Cybersecurity #InfoSec #VulnerabilityManagement #BlueTeam #CybersecKyleHowTo
-
Palo: "Almost Half of Malware Samples Communicate Direct to IP"
Also Palo: "We don't understand why you want to Block-by-ASN."
https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/
-
Qu’est-ce qu’un WAF ? Principes et mise en pratique https://www.it-connect.fr/waf-web-application-firewall-debutant/ #Pourlesdébutants #Cybersécurité #BlueTeam #Web
-
Great write-up about security debt by Brent Huston.
https://stateofsecurity.com/security-debt-compounds-faster-than-technical-debt/
-
Rewriting all structure for migration from #SQLite to different database engine I know I will lose a bit speed, but it is minimal, but easier to maintain and backup + new #CVE sources will be added and additional information! #devsecops #devops #developer #sysadmin #cybersecurity #linux #python #redteam #blueteam https://www.valtersit.com CVE database will be more powerful
-
While others relax, the API development is ongoing! API V1 soon released to public #devsecops #devops #sysadmin #infosec #CVe #CVEalert #redteam #blueteam #git #github #gitlab #developer #developers #cybersecurity #ethicalhacker #ethicalhacking #linux #python #ubuntu
-
RE: https://infosec.exchange/@badsamurai/117016191874879106
This week in BS Lists, AI Meeting Notetakers, the Shadow AI that's siphoning sensitive data from your organization.
If not approved, block these in your web proxy, firewall, and SEG. You may be limited in what you can do in Teams/Zoom, but this will help deter and nerf their usability.
Upgrade to a ban-sledge with additional LinkedIn URLs. I also included some of the most common attendee formats to hunt in your SIEM.
But
notetakerwill get you real far.https://github.com/BadSamuraiDev/bs-lists/blob/main/ai-meeting-notetakers.md