home.social

#blueteam — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #blueteam, aggregated by home.social.

  1. PaperCut NG/MF hit by CRITICAL zero-days (CVE-2026-82078, CVE-2026-81578) exploited in AI-driven attacks. Remote code exec, credential theft, & domain admin escalation seen on 440+ deployments. Patch ASAP. Details: radar.offseq.com/threat/paperc #OffSeq #PaperCut #ZeroDay #BlueTeam

  2. PaperCut NG/MF hit by CRITICAL zero-days (CVE-2026-82078, CVE-2026-81578) exploited in AI-driven attacks. Remote code exec, credential theft, & domain admin escalation seen on 440+ deployments. Patch ASAP. Details: radar.offseq.com/threat/paperc #OffSeq #PaperCut #ZeroDay #BlueTeam

  3. PaperCut NG/MF hit by CRITICAL zero-days (CVE-2026-82078, CVE-2026-81578) exploited in AI-driven attacks. Remote code exec, credential theft, & domain admin escalation seen on 440+ deployments. Patch ASAP. Details: radar.offseq.com/threat/paperc #OffSeq #PaperCut #ZeroDay #BlueTeam

  4. PaperCut NG/MF hit by CRITICAL zero-days (CVE-2026-82078, CVE-2026-81578) exploited in AI-driven attacks. Remote code exec, credential theft, & domain admin escalation seen on 440+ deployments. Patch ASAP. Details: radar.offseq.com/threat/paperc #OffSeq #PaperCut #ZeroDay #BlueTeam

  5. 2026-09-10 RDP #Honeypot IOCs - 2139 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 2001
    165.22.57.45 - 18
    80.66.83.43 - 18

    Top ASNs:
    AS135905 - 2001
    AS14061 - 39
    AS396982 - 27

    Top Accounts:
    hello - 2046
    Administr - 27
    Test - 9

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 2001
    DigitalOcean, LLC - 39
    Google LLC - 27

    Top Clients:
    Unknown - 2139

    Top Software:
    Unknown - 2139

    Top Keyboards:
    Unknown - 2139

    Top IP Classification:
    Unknown - 2016
    hosting - 120
    hosting & proxy - 3

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  6. 2026-09-10 RDP #Honeypot IOCs - 2139 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 2001
    165.22.57.45 - 18
    80.66.83.43 - 18

    Top ASNs:
    AS135905 - 2001
    AS14061 - 39
    AS396982 - 27

    Top Accounts:
    hello - 2046
    Administr - 27
    Test - 9

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 2001
    DigitalOcean, LLC - 39
    Google LLC - 27

    Top Clients:
    Unknown - 2139

    Top Software:
    Unknown - 2139

    Top Keyboards:
    Unknown - 2139

    Top IP Classification:
    Unknown - 2016
    hosting - 120
    hosting & proxy - 3

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  7. 2026-09-10 RDP #Honeypot IOCs - 2139 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 2001
    165.22.57.45 - 18
    80.66.83.43 - 18

    Top ASNs:
    AS135905 - 2001
    AS14061 - 39
    AS396982 - 27

    Top Accounts:
    hello - 2046
    Administr - 27
    Test - 9

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 2001
    DigitalOcean, LLC - 39
    Google LLC - 27

    Top Clients:
    Unknown - 2139

    Top Software:
    Unknown - 2139

    Top Keyboards:
    Unknown - 2139

    Top IP Classification:
    Unknown - 2016
    hosting - 120
    hosting & proxy - 3

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  8. 2026-09-10 RDP #Honeypot IOCs - 2139 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 2001
    165.22.57.45 - 18
    80.66.83.43 - 18

    Top ASNs:
    AS135905 - 2001
    AS14061 - 39
    AS396982 - 27

    Top Accounts:
    hello - 2046
    Administr - 27
    Test - 9

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 2001
    DigitalOcean, LLC - 39
    Google LLC - 27

    Top Clients:
    Unknown - 2139

    Top Software:
    Unknown - 2139

    Top Keyboards:
    Unknown - 2139

    Top IP Classification:
    Unknown - 2016
    hosting - 120
    hosting & proxy - 3

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  9. 2026-09-10 RDP #Honeypot IOCs - 1426 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 1334
    165.22.57.45 - 12
    80.66.83.43 - 12

    Top ASNs:
    AS135905 - 1334
    AS14061 - 26
    AS396982 - 18

    Top Accounts:
    hello - 1364
    Administr - 18
    Test - 6

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 1334
    DigitalOcean, LLC - 26
    Google LLC - 18

    Top Clients:
    Unknown - 1426

    Top Software:
    Unknown - 1426

    Top Keyboards:
    Unknown - 1426

    Top IP Classification:
    Unknown - 1344
    hosting - 80
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  10. 2026-09-10 RDP #Honeypot IOCs - 1426 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 1334
    165.22.57.45 - 12
    80.66.83.43 - 12

    Top ASNs:
    AS135905 - 1334
    AS14061 - 26
    AS396982 - 18

    Top Accounts:
    hello - 1364
    Administr - 18
    Test - 6

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 1334
    DigitalOcean, LLC - 26
    Google LLC - 18

    Top Clients:
    Unknown - 1426

    Top Software:
    Unknown - 1426

    Top Keyboards:
    Unknown - 1426

    Top IP Classification:
    Unknown - 1344
    hosting - 80
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  11. 2026-09-10 RDP #Honeypot IOCs - 1426 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 1334
    165.22.57.45 - 12
    80.66.83.43 - 12

    Top ASNs:
    AS135905 - 1334
    AS14061 - 26
    AS396982 - 18

    Top Accounts:
    hello - 1364
    Administr - 18
    Test - 6

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 1334
    DigitalOcean, LLC - 26
    Google LLC - 18

    Top Clients:
    Unknown - 1426

    Top Software:
    Unknown - 1426

    Top Keyboards:
    Unknown - 1426

    Top IP Classification:
    Unknown - 1344
    hosting - 80
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  12. 2026-09-10 RDP #Honeypot IOCs - 1426 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 1334
    165.22.57.45 - 12
    80.66.83.43 - 12

    Top ASNs:
    AS135905 - 1334
    AS14061 - 26
    AS396982 - 18

    Top Accounts:
    hello - 1364
    Administr - 18
    Test - 6

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 1334
    DigitalOcean, LLC - 26
    Google LLC - 18

    Top Clients:
    Unknown - 1426

    Top Software:
    Unknown - 1426

    Top Keyboards:
    Unknown - 1426

    Top IP Classification:
    Unknown - 1344
    hosting - 80
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  13. 2026-09-10 RDP #Honeypot IOCs - 713 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 667
    165.22.57.45 - 6
    80.66.83.43 - 6

    Top ASNs:
    AS135905 - 667
    AS14061 - 13
    AS396982 - 9

    Top Accounts:
    hello - 682
    Administr - 9
    Test - 3

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 667
    DigitalOcean, LLC - 13
    Google LLC - 9

    Top Clients:
    Unknown - 713

    Top Software:
    Unknown - 713

    Top Keyboards:
    Unknown - 713

    Top IP Classification:
    Unknown - 672
    hosting - 40
    hosting & proxy - 1

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  14. 2026-09-10 RDP #Honeypot IOCs - 713 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 667
    165.22.57.45 - 6
    80.66.83.43 - 6

    Top ASNs:
    AS135905 - 667
    AS14061 - 13
    AS396982 - 9

    Top Accounts:
    hello - 682
    Administr - 9
    Test - 3

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 667
    DigitalOcean, LLC - 13
    Google LLC - 9

    Top Clients:
    Unknown - 713

    Top Software:
    Unknown - 713

    Top Keyboards:
    Unknown - 713

    Top IP Classification:
    Unknown - 672
    hosting - 40
    hosting & proxy - 1

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  15. 2026-09-10 RDP #Honeypot IOCs - 713 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 667
    165.22.57.45 - 6
    80.66.83.43 - 6

    Top ASNs:
    AS135905 - 667
    AS14061 - 13
    AS396982 - 9

    Top Accounts:
    hello - 682
    Administr - 9
    Test - 3

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 667
    DigitalOcean, LLC - 13
    Google LLC - 9

    Top Clients:
    Unknown - 713

    Top Software:
    Unknown - 713

    Top Keyboards:
    Unknown - 713

    Top IP Classification:
    Unknown - 672
    hosting - 40
    hosting & proxy - 1

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  16. 2026-09-10 RDP #Honeypot IOCs - 713 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 667
    165.22.57.45 - 6
    80.66.83.43 - 6

    Top ASNs:
    AS135905 - 667
    AS14061 - 13
    AS396982 - 9

    Top Accounts:
    hello - 682
    Administr - 9
    Test - 3

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 667
    DigitalOcean, LLC - 13
    Google LLC - 9

    Top Clients:
    Unknown - 713

    Top Software:
    Unknown - 713

    Top Keyboards:
    Unknown - 713

    Top IP Classification:
    Unknown - 672
    hosting - 40
    hosting & proxy - 1

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  17. 2026-09-09 RDP #Honeypot IOCs - 5919 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    152.42.198.23 - 3300
    168.144.34.49 - 2499
    80.66.83.43 - 18

    Top ASNs:
    AS14061 - 5817
    AS396982 - 42
    AS216473 - 18

    Top Accounts:
    hello - 5850
    Administr - 18
    Test - 6

    Top ISPs:
    DigitalOcean, LLC - 5817
    Google LLC - 42
    Bashinskii Vadim Ruslanovich - 18

    Top Clients:
    Unknown - 5919

    Top Software:
    Unknown - 5919

    Top Keyboards:
    Unknown - 5919

    Top IP Classification:
    hosting - 5910
    Unknown - 6
    hosting & proxy - 3

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  18. 2026-09-09 RDP #Honeypot IOCs - 5919 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    152.42.198.23 - 3300
    168.144.34.49 - 2499
    80.66.83.43 - 18

    Top ASNs:
    AS14061 - 5817
    AS396982 - 42
    AS216473 - 18

    Top Accounts:
    hello - 5850
    Administr - 18
    Test - 6

    Top ISPs:
    DigitalOcean, LLC - 5817
    Google LLC - 42
    Bashinskii Vadim Ruslanovich - 18

    Top Clients:
    Unknown - 5919

    Top Software:
    Unknown - 5919

    Top Keyboards:
    Unknown - 5919

    Top IP Classification:
    hosting - 5910
    Unknown - 6
    hosting & proxy - 3

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  19. 2026-09-09 RDP #Honeypot IOCs - 5919 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    152.42.198.23 - 3300
    168.144.34.49 - 2499
    80.66.83.43 - 18

    Top ASNs:
    AS14061 - 5817
    AS396982 - 42
    AS216473 - 18

    Top Accounts:
    hello - 5850
    Administr - 18
    Test - 6

    Top ISPs:
    DigitalOcean, LLC - 5817
    Google LLC - 42
    Bashinskii Vadim Ruslanovich - 18

    Top Clients:
    Unknown - 5919

    Top Software:
    Unknown - 5919

    Top Keyboards:
    Unknown - 5919

    Top IP Classification:
    hosting - 5910
    Unknown - 6
    hosting & proxy - 3

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  20. 2026-09-09 RDP #Honeypot IOCs - 5919 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    152.42.198.23 - 3300
    168.144.34.49 - 2499
    80.66.83.43 - 18

    Top ASNs:
    AS14061 - 5817
    AS396982 - 42
    AS216473 - 18

    Top Accounts:
    hello - 5850
    Administr - 18
    Test - 6

    Top ISPs:
    DigitalOcean, LLC - 5817
    Google LLC - 42
    Bashinskii Vadim Ruslanovich - 18

    Top Clients:
    Unknown - 5919

    Top Software:
    Unknown - 5919

    Top Keyboards:
    Unknown - 5919

    Top IP Classification:
    hosting - 5910
    Unknown - 6
    hosting & proxy - 3

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  21. 2026-09-09 RDP #Honeypot IOCs - 3946 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    152.42.198.23 - 2200
    168.144.34.49 - 1666
    80.66.83.43 - 12

    Top ASNs:
    AS14061 - 3878
    AS396982 - 28
    AS216473 - 12

    Top Accounts:
    hello - 3900
    Administr - 12
    Test - 4

    Top ISPs:
    DigitalOcean, LLC - 3878
    Google LLC - 28
    Bashinskii Vadim Ruslanovich - 12

    Top Clients:
    Unknown - 3946

    Top Software:
    Unknown - 3946

    Top Keyboards:
    Unknown - 3946

    Top IP Classification:
    hosting - 3940
    Unknown - 4
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  22. 2026-09-09 RDP #Honeypot IOCs - 3946 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    152.42.198.23 - 2200
    168.144.34.49 - 1666
    80.66.83.43 - 12

    Top ASNs:
    AS14061 - 3878
    AS396982 - 28
    AS216473 - 12

    Top Accounts:
    hello - 3900
    Administr - 12
    Test - 4

    Top ISPs:
    DigitalOcean, LLC - 3878
    Google LLC - 28
    Bashinskii Vadim Ruslanovich - 12

    Top Clients:
    Unknown - 3946

    Top Software:
    Unknown - 3946

    Top Keyboards:
    Unknown - 3946

    Top IP Classification:
    hosting - 3940
    Unknown - 4
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  23. 2026-09-09 RDP #Honeypot IOCs - 3946 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    152.42.198.23 - 2200
    168.144.34.49 - 1666
    80.66.83.43 - 12

    Top ASNs:
    AS14061 - 3878
    AS396982 - 28
    AS216473 - 12

    Top Accounts:
    hello - 3900
    Administr - 12
    Test - 4

    Top ISPs:
    DigitalOcean, LLC - 3878
    Google LLC - 28
    Bashinskii Vadim Ruslanovich - 12

    Top Clients:
    Unknown - 3946

    Top Software:
    Unknown - 3946

    Top Keyboards:
    Unknown - 3946

    Top IP Classification:
    hosting - 3940
    Unknown - 4
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  24. 2026-09-09 RDP #Honeypot IOCs - 3946 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    152.42.198.23 - 2200
    168.144.34.49 - 1666
    80.66.83.43 - 12

    Top ASNs:
    AS14061 - 3878
    AS396982 - 28
    AS216473 - 12

    Top Accounts:
    hello - 3900
    Administr - 12
    Test - 4

    Top ISPs:
    DigitalOcean, LLC - 3878
    Google LLC - 28
    Bashinskii Vadim Ruslanovich - 12

    Top Clients:
    Unknown - 3946

    Top Software:
    Unknown - 3946

    Top Keyboards:
    Unknown - 3946

    Top IP Classification:
    hosting - 3940
    Unknown - 4
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  25. 2026-09-09 RDP #Honeypot IOCs - 1973 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    152.42.198.23 - 1100
    168.144.34.49 - 833
    80.66.83.43 - 6

    Top ASNs:
    AS14061 - 1939
    AS396982 - 14
    AS216473 - 6

    Top Accounts:
    hello - 1950
    Administr - 6
    Test - 2

    Top ISPs:
    DigitalOcean, LLC - 1939
    Google LLC - 14
    Bashinskii Vadim Ruslanovich - 6

    Top Clients:
    Unknown - 1973

    Top Software:
    Unknown - 1973

    Top Keyboards:
    Unknown - 1973

    Top IP Classification:
    hosting - 1970
    Unknown - 2
    hosting & proxy - 1

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  26. 2026-09-09 RDP #Honeypot IOCs - 1973 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    152.42.198.23 - 1100
    168.144.34.49 - 833
    80.66.83.43 - 6

    Top ASNs:
    AS14061 - 1939
    AS396982 - 14
    AS216473 - 6

    Top Accounts:
    hello - 1950
    Administr - 6
    Test - 2

    Top ISPs:
    DigitalOcean, LLC - 1939
    Google LLC - 14
    Bashinskii Vadim Ruslanovich - 6

    Top Clients:
    Unknown - 1973

    Top Software:
    Unknown - 1973

    Top Keyboards:
    Unknown - 1973

    Top IP Classification:
    hosting - 1970
    Unknown - 2
    hosting & proxy - 1

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  27. 2026-09-09 RDP #Honeypot IOCs - 1973 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    152.42.198.23 - 1100
    168.144.34.49 - 833
    80.66.83.43 - 6

    Top ASNs:
    AS14061 - 1939
    AS396982 - 14
    AS216473 - 6

    Top Accounts:
    hello - 1950
    Administr - 6
    Test - 2

    Top ISPs:
    DigitalOcean, LLC - 1939
    Google LLC - 14
    Bashinskii Vadim Ruslanovich - 6

    Top Clients:
    Unknown - 1973

    Top Software:
    Unknown - 1973

    Top Keyboards:
    Unknown - 1973

    Top IP Classification:
    hosting - 1970
    Unknown - 2
    hosting & proxy - 1

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  28. 2026-09-09 RDP #Honeypot IOCs - 1973 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    152.42.198.23 - 1100
    168.144.34.49 - 833
    80.66.83.43 - 6

    Top ASNs:
    AS14061 - 1939
    AS396982 - 14
    AS216473 - 6

    Top Accounts:
    hello - 1950
    Administr - 6
    Test - 2

    Top ISPs:
    DigitalOcean, LLC - 1939
    Google LLC - 14
    Bashinskii Vadim Ruslanovich - 6

    Top Clients:
    Unknown - 1973

    Top Software:
    Unknown - 1973

    Top Keyboards:
    Unknown - 1973

    Top IP Classification:
    hosting - 1970
    Unknown - 2
    hosting & proxy - 1

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  29. Empty scoreboard.
    80 teams.
    14 days.

    Someone's name goes first.

    WATCHLIST is a free 24-hour CTF built around one investigation.

    24 challenges - memory forensics,
    disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.

    All connected to the same case.

    First blood on each challenge gets logged permanently
    by The Machine.

    Sep 19 03:30 UTC. Free entry. Teams 1-6.
    Prizes: $750 / $500 / $250

    ctf.xposedornot.com
    CTFtime: ctftime.org/event/3326

    #CTF #DFIR #forensics #infosec #blueteam

  30. Subdomain Takeover Vulnerabilities and Prevention

    In this article, I cover:
    * How subdomain takeover vulnerabilities occur
    * Real-world exploitation scenarios
    Reconnaissance and detection techniques
    * Practical prevention and DNS hygiene strategies

    denizhalil.com/2026/02/16/subd

    #CyberSecurity #SubdomainTakeover #DNS #AttackSurface #BugBounty #RedTeam #BlueTeam #InfoSec #CloudSecurity #WebSecurity #EthicalHacking

  31. UNC3886 leveraged ORB infrastructure for stealthy telecom targeting.

    Per Cyber Security Agency of Singapore:
    • Zero-day firewall compromise
    • Rootkit persistence mechanisms
    • GOBRAT & TINYSHELL C2 nodes
    • ORB-tagged IP clustering in Singapore ASNs
    • NetFlow-confirmed router-to-ORB communications
    • Pre-positioned reconnaissance

    Attribution aligned with assessments from Mandiant linking activity to China-sponsored espionage.

    ORB networks blur the line between botnets and residential proxy ecosystems, increasing attribution friction and collateral risk.

    Defensive priorities:
    • Threat intel enrichment
    • Edge device patch enforcement
    • ASN anomaly detection
    • Zero-trust segmentation
    • IoT telemetry visibility

    How mature are ORB detection capabilities in your SOC?

    Engage below.

    Source: cyberpress.org/orb-networks-ma

    Follow @technadu for advanced threat analysis.

    #ThreatIntel #UNC3886 #ORBNetworks #IoTSecurity #ZeroDay #C2Infrastructure #NetFlow #TelecomSecurity #BlueTeam #ThreatHunting #APTActivity #CyberOperations #Infosec

  32. Server Security Checklist — Essential Hardening Guide

    Securing your servers isn’t optional — it’s your first line of defense against data breaches, ransomware, insider threats, and lateral movement. Use this checklist as a baseline for Linux, Windows, cloud, hybrid, or on-prem servers.

    🔧 1. System & OS Hardening
    • Keep OS & packages updated (apply security patches frequently).
    • Remove / disable unused services & software.
    • Enforce secure boot + BIOS/UEFI passwords.
    • Disable auto-login and guest accounts.
    • Use minimal OS images only (reduce attack surface).

    🔐 2. Access Control
    • Enforce strong passwords & MFA everywhere.
    • Use RBAC & least privilege access.
    • Disable root/Administrator login over SSH/RDP.
    • Rotate credentials & keys regularly.
    • Implement just-in-time access for privileged users.

    🌐 3. Network Security
    • Restrict inbound/outbound traffic via firewalls.
    • Segment critical servers from general LANs/VLANs.
    • Disable unused ports & protocols.
    • Enable DoS/DDoS protection.
    • Apply zero-trust network principles.

    🔑 4. Secure Remote Access
    • Use SSH key-based authentication (disable password login).
    • Enforce VPN for admin access.
    • Log & monitor all remote access sessions.
    • Disable legacy protocols (Telnet, FTP, SMBv1).
    • Require bastion/jump host for critical access.

    📊 5. Logging & Monitoring
    • Enable centralized logging (syslog / SIEM).
    • Track failed login attempts & anomalies.
    • Configure alerts for privilege escalation or config changes.
    • Monitor log tampering.
    • Retain logs securely for audits & forensics.

    🔒 6. Data Protection
    • Encrypt data at rest (LUKS, BitLocker, etc.).
    • Encrypt data in transit (TLS 1.2+).
    • Strict database access policies.
    • Regular, offline, immutable backups.
    • Test restore procedures (don’t assume backups work).

    🔁 7. Application & Patch Management
    • Keep middleware, frameworks, and apps patched.
    • Delete default credentials & sample files.
    • Enable code signing for software packages.
    • Use secure coding practices (OWASP Top 10).
    • Implement dependency scanning (Snyk, Trivy, etc.).

    🛡️ 8. Malware & Intrusion Defense
    • Deploy EDR/AV on endpoints.
    • Enable IDS/IPS at network edge.
    • Automatic vulnerability scans (schedule weekly/monthly).
    • Monitor persistence techniques (cron, startup scripts).
    • Block known malicious IP ranges & TLDs.

    🏢 9. Physical & Cloud Security
    • Restrict physical access to server racks/rooms.
    • Enable provider security tools (AWS Security Groups, Azure NSG, IAM).
    • Harden cloud images (CIS benchmarks).
    • Review cloud logging & audit trails regularly.
    • Disable unused cloud API keys / roles.

    📜 10. Policy & Compliance
    • Use CIS / NIST / ISO-27001 benchmarks.
    • Track & document every access change.
    • Force annual access reviews & key rotation.
    • Perform regular security training for admins.
    • Maintain disaster recovery & incident plans.

    ➕ Additional 5 Critical Controls (Advanced Hardening)

    🧠 11. Privileged Access Management (PAM)
    • Use jump hosts & session recording.
    • Just-In-Time access for admins.
    • Store keys in secure vaults (HashiCorp Vault, CyberArk).

    🚨 12. Real-Time Threat Detection
    • Use behavioral analytics → UEBA/XDR.
    • AI-based anomaly detection recommended.
    • Block suspicious IPs automatically.

    🧪 13. Red Team & Pentesting
    • Run regular internal pentests.
    • Validate configuration weaknesses.
    • Simulate phishing + lateral movement scenarios.

    🧱 14. Container / VM Isolation
    • Use AppArmor, SELinux, Seccomp profiles.
    • Limit Docker socket access & root containers.
    • Scan images before deployment.

    📦 15. Automated Configuration Management
    • Use IaC (Terraform, Ansible, Puppet) for repeatable and secure builds.
    • Detect drift using compliance scanning.
    • Version control all infrastructure.

    🧠 Core Reminder

    A server is only as secure as the team who maintains it.
    Hardening isn’t one task — it’s an ongoing

    #ServerSecurity #SystemHardening #InfoSec #CyberSecurity #BlueTeam
    #DevSecOps #SysAdmin #ThreatDetection #AccessControl #NetworkSecurity
    #LinuxSecurity #SecureArchitecture #RiskMitigation #SecurityChecklist
    #CloudSecurity #InfrastructureSecurity #ZeroTrust #SecurityMonitoring

  33. #GammaGroup clients use

    🔎 UDP port 123 🔍

    as default #RedTeam data #exfiltration ports

    #gammagroup #finfsher #finspy #infosec #memes
    #BlueTeam
    #statesponsoredmalware ☣️🤳🐐☣️

    Update: Add logging before implementing BLOCKING the #exfil shim, obviously. ☣️🤳🔎🐐☣️🔍🧐

  34. Happy Tuesday everyone!

    Just your weekly reminder that Regular Registration is closing this Friday, July 19th! So you still have some time to get the regular pricing when you register for Cyborg Security's and Intel 471's Threat Hunter training at Black Hat USA in Las Vegas!

    You will you learn:
    What a threat hunt looks like from start to finish.
    What tools and resources we can leverage to research and communicate with shareholders.
    How to navigate through an investigation following process chains, finding correlating information, and how to find related events that help you better tell the story!

    If any of this sounds fun, come join me at Black Hat in Vegas this year for a fun time! I can't wait to meet everyone there, but until then, Happy Hunting!

    Registration Links:
    Aug 3rd - 4th:
    blackhat.com/us-24/training/sc

    Aug 5th - 6th:
    blackhat.com/us-24/training/sc

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel
    #ThreatHunting #ThreatDetection #HappyHunting #Intel471 #BlackHat

  35. Happy Monday everyone!

    We are going to start this week off with a nice resource in our #readoftheday! If you have yet to hear about Wazuh, now is your chance! It is a free, open-source security platform that protects data assets from threats [2]. In this article, the researchers cover what abusing Living-off-the-Land binaries (LOLBINs) looks like from the perspective of an Ubuntu and Kali Linux endpoint and focus on the #DirtyPipe exploit and the DDexec utility. After walking readers through the emulation they then discuss how Wazuh helps detect these techniques. It is a good read and a resource I want to get into my own lab to start playing with!

    As always, check out the full article and others by Wazuh researchers on their blog and stay tuned for the threat hunting tip of the day! Enjoy and Happy Hunting!

    Detecting Living Off the Land attacks with Wazuh
    wazuh.com/blog/detecting-livin

    Other reference:
    github.com/wazuh/wazuh [2]

    Intel 471 #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #Intel471

  36. Happy Friday Everyone!

    The Check Point Software researchers help us into the weekend with the #readoftheday, and ironically it covers some things that we have been researching as of late!

    In this article, the researchers detail how a threat actor used an Internet Shortcut (.url) file to open up the attacker website in Internet Explorer (a more vulnerable brower) instead of Chrome or Edge. This is accomplished through the use of a specially crafted .url file that contains the values "mhtml" and also "!x-usc". These tactics were last when threat actors were exploiting CVE-2021-40444 (Microsoft MSHTML Remote Code Execution Vulnerability)[2] and are seen again.

    As you wait for the Threat Hunting Tip of the day, go read the entire article yourself and see what I missed! Enjoy and Happy Hunting!

    RESURRECTING INTERNET EXPLORER: THREAT ACTORS USING ZERO-DAY TRICKS IN INTERNET SHORTCUT FILE TO LURE VICTIMS (CVE-2024-38112)
    research.checkpoint.com/2024/r

    Additional resource:
    [2] msrc.microsoft.com/update-guid

    Intel 471 #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #Intel471 #gethunting

  37. Happy Wednesday, everyone!

    I’m honored and proud to invite all my connections to join me at Cyborg Security & Intel 471’s Black Hat USA training for the second year in a row!

    We cover everything from resources to use for research and models to use for communicating to your stakeholders to operationalizing intel to create a hypothesis to start a threat hunt. If you are a data junkie (like me) who loves diving into data, sifting through it, then this is the training for you! If any of this sounds fun, join my Black Hat USA training, titled “A Beginner’s Guide to Threat Hunting: How to Shift Focus from IOCs to Behaviors and TTPs”! You may have missed the early registration discount, but the regular registration discount is still available until July 19th!

    I will be teaching two 2-day sessions. You can pick which one works with your schedule best and register here:

    Aug 3rd - 4th: blackhat.com/us-24/training/sc

    Aug 5th - 6th: blackhat.com/us-24/training/sc

    I can't wait to meet everyone there. Until then, happy hunting!

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #Intel471 #BlackHat

  38. Happy Wednesday everyone!

    This is the second #readoftheday this week that involves eBooks being used as the lure for victims and in this case Trellix reveals that this eBook delivers a malware known as #ViperSoftX.

    Once the victim downloads the archive file, they are presented with an eBook cover page, a hidden folder, shortcut file and three JPGs. These files are not what they seem, as you all may have guessed. One is an AutoIT script, one the AutoIT executable, and the last a PowerShell script. The shortcut file leads to the execution of the PowerShell code that unhides the hidden folder, checks the disk size of all drives, moves the AutoIT files to the AppData\Microsoft\Windows directory and deletes the LNK files in the current directory.

    A notable MITRE ATT&CK TTP here is the use of PowerShell encoded commands or T1027.013 - Obfuscated Files or Information: Encrypted/Encoded File. This is a common technique that adversaries use to hide the true nature of the commands or communication with their C2 server.

    As always, I am leaving you hanging and will be back for the Threat Hunting Tip of the day! While you are waiting patiently, go read the rest of the article, it has tons of details I left out! Enjoy and Happy Hunting!

    The Mechanics of ViperSoftX: Exploiting AutoIt and CLR for Stealthy PowerShell Execution
    trellix.com/blogs/research/the

    Intel 471 #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #Intel471

  39. Introducing the newest major @tidalcyber TTP intelligence content roundup, the Initial Access & Malware Delivery Landscape matrix, now live in our free Community Edition platform: app.tidalcyber.com/share/43836

    The matrix covers 25 major & emerging #malware typically used to gain early footholds in victim environments, often leading to ingress of more impactful threats, especially #ransomware, #infostealers, cryptominers, & more. It includes many recognizable names (#QakBot, #IcedID, #Emotet, #Bumblebee, #Gootloader) plus several newer and less-discussed threats

    The matrix includes 13 custom Technique Sets for threats not currently tracked in the #mitreattack knowledge base. All technique references derive from a large volume of recent, public #threat reporting (click the labels in the ribbon at the top of the matrix to view relevant source URLs for each threat)

    An interactive link analysis visualization of connections among these threats, also derived from public reports, is also available here: onodo.org/visualizations/23506

    Community Edition matrices support easy identification of shared (and outlier) techniques among multiple threats, and quick & easy overlay or pivoting to defensive & offensive security capabilities relevant to your own #security stack. We’ll have a blog out soon reviewing our analysis of top & trending techniques common among these initial access threats

    Tidal’s #Adversary Intelligence team remains focused on providing up-to-date #TTPintelligence, especially around traditionally under-represented yet widely relevant threats like crimeware. Other popular matrices in this theme include our Ransomware & Data Extortion Landscape matrix (app.tidalcyber.com/share/9a0fd) and Major & Emerging Infostealers matrix (app.tidalcyber.com/share/ec62f), which each cover 20+ threats

    Financially motivated adversaries often display a rapid pace of #TTP evolution, and this is especially apparent for #initialaccess threats. Register for our webinar on May 31 dedicated to TTP evolution, its drivers, and discussion around what defenders can do to address it and its implications: hubs.la/Q01NC23k0

    #SharedWithTidal #threatinformeddefense #malware #infostealer #cryptominer #IAB #blueteam #detectionengineering #purpleteam #cyber

  40. #Gootloader is a highly active banking Trojan-turned-loader #malware that has recently appeared on multiple vendors’ priority threat lists, attacking organizations in a wide range of verticals & countries. If your leadership or other stakeholders asked for a list of this threat's most common TTPs, would you be able to provide it quickly?

    Now you can, with the Gootloader #TTP matrix available in Tidal’s free Community Edition: app.tidalcyber.com/share/796ca

    Gootloader, also referred to by its related payload, #Gootkit, first emerged in 2014 but has been especially active since 2020. Despite this, technical reporting around its TTPs has been relatively light until even more recently. In the past two years alone, verticals including finance, #healthcare, defense, pharmaceutical, energy, & automotive have faced Gootloader campaigns, with victims across North America, Western Europe, & South Korea, and the malware is regularly used to deliver high-impact payloads, including Cobalt Strike, #IcedID (a common #ransomware precursor), & more. Industry-based #threat profiling can be a powerful tool, but even if your industry (or your corner of it) hasn’t yet directly observed Gootloader activity, we believe broad-based threats like this should be on most teams’ radars

    Our matrix summarizes Gootloader TTPs detailed across several great recent technical reports. Reports from SentinelLabs, Cybereason, & The DFIR Report were helpfully pre-mapped to #mitreattack, and we mapped a couple other detailed analyses. Procedural details are even available for nearly all the included technique mappings – be sure to click the Technique Set’s label in the ribbon at the top of the screen to pivot into the Details page with this information & relevant source links throughout

    Red Canary & The DFIR Report helpfully provided tool-agnostic suggested #detection logic for key behaviors observed during recent Gootloader campaigns here redcanary.com/blog/gootloader/ and here thedfirreport.com/2022/05/09/s. Take a wider view by layering entire segments of your defensive stack over the #CTI back in the Community Edition, by toggling on any of the mappings available in @tidalcyber's Product Registry app.tidalcyber.com/vendors

    #SharedWithTidal #threatinformeddefense #CobaltStrike #initialaccess #blueteam