home.social

#blueteam — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #blueteam, aggregated by home.social.

fetched live
  1. I spent the last few months building a CTF.

    WATCHLIST: 24 challenges, one investigation, 24 hours.

    DNS forensics. Memory analysis. A live honeypot. Disk images. OSINT.

    Sep 19. Teams 1-6. $750 first place.

    If you have been meaning to try CTFs but thought they were too technical, this one has entry points built for you.

    ctf.xposedornot.com

    #CTF #blueteam #DFIR #infosec

  2. We've uploaded 75+ production-ready scripts for #Security, #DevOps, and automation to save you hours of writing boilerplate code. Best part? We are dropping new tutorials and tools every single day!
    Find your next time-saver here: valtersit.com/python #CVE #infosec #SysAdmin #cybersecurity #Linux #devops #developer #git #github #gitlab #blueteam #python #hackers #ubuntu #debian #ukraine #spain #ireland #uk #canada #finland #lithuania #ireland #hungary #denmark #norway

  3. Three attacks this week didn't break the network trust signals a SOC leans on. They just hid inside them.

    A 633-server proxy network (CanOworms) so a state actor and a card fraudster leave through the same clean IP. Midnight Blizzard on hotel Wi-Fi captive portals serving a fake M365 login. And a PoC running code on Cloudflare's own edge.

    The address tells you where traffic sits, not who's driving it.

    reput.io/blog/reputation-radar

    #blueteam #threatintel #infosec #SOC

  4. RE: infosec.exchange/@BleepingComp

    Assuming you don’t need access to the Polygon blockchain from your business network, protect your systems by block the named public RPC endpoints using DNS, NGFW or web security proxy:

    polygon-bor-rpc.publicnode[.]com
    polygon.drpc[.]org
    polygon-pokt.nodies[.]app
    polygon-rpc[.]com
    1rpc[.]io
    polygon.meowrpc[.]com

    #cybersecurity #blueteam #ransomware

  5. 🛡️ HAVOC C2 — DEFENDER CHEAT SHEET

    Havoc is a powerful Command & Control framework used in authorized red-team operations. 🔴⚡ Understanding how C2 infrastructure, agents and communications behave can also help defenders recognize suspicious activity and improve detection. 🔍

    Learn the framework. Hunt the signals. Strengthen your defenses. 🔐

    💬 Comment “HAVOC” if you want more cybersecurity cheat sheets.

    #HavocC2 #CyberSecurity #RedTeam #BlueTeam #ThreatHunting

  6. Sweet little investigation to a malicious infrastructure, that was initiated with two web that turns out to be a Powershell, and digging deeper into the infrastructure.

    malwr-analysis.com/2026/08/08/

    #cybersecurity #infosec #blueteam #threatintel

  7. AI is not your biggest cyber threat.

    Your shitty patching process probably is.

    A slightly sarcastic take on AI hype, CISOs, security theatre, broken processes, legacy IT, SOC reality and why automation changes the speed of attacks more than the nature of the problem.

    0ut3r.space/2026/08/08/ai-is-n

    #cybersecurity #infosec #AI #CISO #BlueTeam #RedTeam #SOC #SecurityEngineering

  8. 🚨 CVE-2026-48282: una semplice Path Traversal può trasformarsi in una Remote Code Execution su Adobe ColdFusion.

    Nel video spiego:
    🔴 cos'è RDS
    🔴 perché il CVSS è 10.0
    🔴 come avviene la catena di attacco
    🔴 cosa controllare dopo aver applicato la patch

    🎥 Guarda il video:
    👉 youtu.be/SHYU1ag3NsQ

    #CyberSecurity #ColdFusion #CVE202648282 #InfoSec #BlueTeam
    @sicurezza

  9. In #cybersecurity there's always two problem sources; a perceived source, and an actual source. The two are seldom the same but the perceived source is always the easiest to blame.

    #blueteam

  10. 2026-08-05 RDP #Honeypot IOCs - 29778 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    27.71.229.97 - 29670
    134.199.168.195 - 30
    45.142.193.18 - 12

    Top ASNs:
    AS38731 - 29670
    AS14061 - 30
    AS396982 - 27

    Top Accounts:
    hello - 29712
    Test - 18
    Domain - 9

    Top ISPs:
    VIETTEL - 29670
    DigitalOcean, LLC - 30
    Google LLC - 27

    Top Clients:
    Unknown - 29778

    Top Software:
    Unknown - 29778

    Top Keyboards:
    Unknown - 29778

    Top IP Classification:
    Unknown - 29679
    hosting - 78
    proxy - 12

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  11. Palo: "Almost Half of Malware Samples Communicate Direct to IP"

    Also Palo: "We don't understand why you want to Block-by-ASN."

    unit42.paloaltonetworks.com/ma

    #blueteam #asn #paloaltonetworks #unit42

  12. Rewriting all structure for migration from #SQLite to different database engine I know I will lose a bit speed, but it is minimal, but easier to maintain and backup + new  #CVE sources will be added and additional information! #devsecops #devops #developer #sysadmin #cybersecurity #linux #python #redteam #blueteam valtersit.com CVE database will be more powerful

  13. RE: infosec.exchange/@badsamurai/1

    This week in BS Lists, AI Meeting Notetakers, the Shadow AI that's siphoning sensitive data from your organization.

    If not approved, block these in your web proxy, firewall, and SEG. You may be limited in what you can do in Teams/Zoom, but this will help deter and nerf their usability.

    Upgrade to a ban-sledge with additional LinkedIn URLs. I also included some of the most common attendee formats to hunt in your SIEM.

    But notetaker will get you real far.

    github.com/BadSamuraiDev/bs-li

    #bslists #aimeeting #ainotetakers #dataprotection #blueteam