#blueteam — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #blueteam, aggregated by home.social.
-
PaperCut NG/MF hit by CRITICAL zero-days (CVE-2026-82078, CVE-2026-81578) exploited in AI-driven attacks. Remote code exec, credential theft, & domain admin escalation seen on 440+ deployments. Patch ASAP. Details: https://radar.offseq.com/threat/papercut-flaws-exploited-in-ai-powered-attacks-2193db246901da9f #OffSeq #PaperCut #ZeroDay #BlueTeam
-
PaperCut NG/MF hit by CRITICAL zero-days (CVE-2026-82078, CVE-2026-81578) exploited in AI-driven attacks. Remote code exec, credential theft, & domain admin escalation seen on 440+ deployments. Patch ASAP. Details: https://radar.offseq.com/threat/papercut-flaws-exploited-in-ai-powered-attacks-2193db246901da9f #OffSeq #PaperCut #ZeroDay #BlueTeam
-
PaperCut NG/MF hit by CRITICAL zero-days (CVE-2026-82078, CVE-2026-81578) exploited in AI-driven attacks. Remote code exec, credential theft, & domain admin escalation seen on 440+ deployments. Patch ASAP. Details: https://radar.offseq.com/threat/papercut-flaws-exploited-in-ai-powered-attacks-2193db246901da9f #OffSeq #PaperCut #ZeroDay #BlueTeam
-
PaperCut NG/MF hit by CRITICAL zero-days (CVE-2026-82078, CVE-2026-81578) exploited in AI-driven attacks. Remote code exec, credential theft, & domain admin escalation seen on 440+ deployments. Patch ASAP. Details: https://radar.offseq.com/threat/papercut-flaws-exploited-in-ai-powered-attacks-2193db246901da9f #OffSeq #PaperCut #ZeroDay #BlueTeam
-
2026-09-10 RDP #Honeypot IOCs - 2139 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 2001
165.22.57.45 - 18
80.66.83.43 - 18Top ASNs:
AS135905 - 2001
AS14061 - 39
AS396982 - 27Top Accounts:
hello - 2046
Administr - 27
Test - 9Top ISPs:
Vietnam Posts and Telecommunications Group - 2001
DigitalOcean, LLC - 39
Google LLC - 27Top Clients:
Unknown - 2139Top Software:
Unknown - 2139Top Keyboards:
Unknown - 2139Top IP Classification:
Unknown - 2016
hosting - 120
hosting & proxy - 3Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-10 RDP #Honeypot IOCs - 2139 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 2001
165.22.57.45 - 18
80.66.83.43 - 18Top ASNs:
AS135905 - 2001
AS14061 - 39
AS396982 - 27Top Accounts:
hello - 2046
Administr - 27
Test - 9Top ISPs:
Vietnam Posts and Telecommunications Group - 2001
DigitalOcean, LLC - 39
Google LLC - 27Top Clients:
Unknown - 2139Top Software:
Unknown - 2139Top Keyboards:
Unknown - 2139Top IP Classification:
Unknown - 2016
hosting - 120
hosting & proxy - 3Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-10 RDP #Honeypot IOCs - 2139 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 2001
165.22.57.45 - 18
80.66.83.43 - 18Top ASNs:
AS135905 - 2001
AS14061 - 39
AS396982 - 27Top Accounts:
hello - 2046
Administr - 27
Test - 9Top ISPs:
Vietnam Posts and Telecommunications Group - 2001
DigitalOcean, LLC - 39
Google LLC - 27Top Clients:
Unknown - 2139Top Software:
Unknown - 2139Top Keyboards:
Unknown - 2139Top IP Classification:
Unknown - 2016
hosting - 120
hosting & proxy - 3Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-10 RDP #Honeypot IOCs - 2139 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 2001
165.22.57.45 - 18
80.66.83.43 - 18Top ASNs:
AS135905 - 2001
AS14061 - 39
AS396982 - 27Top Accounts:
hello - 2046
Administr - 27
Test - 9Top ISPs:
Vietnam Posts and Telecommunications Group - 2001
DigitalOcean, LLC - 39
Google LLC - 27Top Clients:
Unknown - 2139Top Software:
Unknown - 2139Top Keyboards:
Unknown - 2139Top IP Classification:
Unknown - 2016
hosting - 120
hosting & proxy - 3Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-10 RDP #Honeypot IOCs - 1426 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 1334
165.22.57.45 - 12
80.66.83.43 - 12Top ASNs:
AS135905 - 1334
AS14061 - 26
AS396982 - 18Top Accounts:
hello - 1364
Administr - 18
Test - 6Top ISPs:
Vietnam Posts and Telecommunications Group - 1334
DigitalOcean, LLC - 26
Google LLC - 18Top Clients:
Unknown - 1426Top Software:
Unknown - 1426Top Keyboards:
Unknown - 1426Top IP Classification:
Unknown - 1344
hosting - 80
hosting & proxy - 2Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-10 RDP #Honeypot IOCs - 1426 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 1334
165.22.57.45 - 12
80.66.83.43 - 12Top ASNs:
AS135905 - 1334
AS14061 - 26
AS396982 - 18Top Accounts:
hello - 1364
Administr - 18
Test - 6Top ISPs:
Vietnam Posts and Telecommunications Group - 1334
DigitalOcean, LLC - 26
Google LLC - 18Top Clients:
Unknown - 1426Top Software:
Unknown - 1426Top Keyboards:
Unknown - 1426Top IP Classification:
Unknown - 1344
hosting - 80
hosting & proxy - 2Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-10 RDP #Honeypot IOCs - 1426 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 1334
165.22.57.45 - 12
80.66.83.43 - 12Top ASNs:
AS135905 - 1334
AS14061 - 26
AS396982 - 18Top Accounts:
hello - 1364
Administr - 18
Test - 6Top ISPs:
Vietnam Posts and Telecommunications Group - 1334
DigitalOcean, LLC - 26
Google LLC - 18Top Clients:
Unknown - 1426Top Software:
Unknown - 1426Top Keyboards:
Unknown - 1426Top IP Classification:
Unknown - 1344
hosting - 80
hosting & proxy - 2Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-10 RDP #Honeypot IOCs - 1426 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 1334
165.22.57.45 - 12
80.66.83.43 - 12Top ASNs:
AS135905 - 1334
AS14061 - 26
AS396982 - 18Top Accounts:
hello - 1364
Administr - 18
Test - 6Top ISPs:
Vietnam Posts and Telecommunications Group - 1334
DigitalOcean, LLC - 26
Google LLC - 18Top Clients:
Unknown - 1426Top Software:
Unknown - 1426Top Keyboards:
Unknown - 1426Top IP Classification:
Unknown - 1344
hosting - 80
hosting & proxy - 2Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-10 RDP #Honeypot IOCs - 713 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 667
165.22.57.45 - 6
80.66.83.43 - 6Top ASNs:
AS135905 - 667
AS14061 - 13
AS396982 - 9Top Accounts:
hello - 682
Administr - 9
Test - 3Top ISPs:
Vietnam Posts and Telecommunications Group - 667
DigitalOcean, LLC - 13
Google LLC - 9Top Clients:
Unknown - 713Top Software:
Unknown - 713Top Keyboards:
Unknown - 713Top IP Classification:
Unknown - 672
hosting - 40
hosting & proxy - 1Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-10 RDP #Honeypot IOCs - 713 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 667
165.22.57.45 - 6
80.66.83.43 - 6Top ASNs:
AS135905 - 667
AS14061 - 13
AS396982 - 9Top Accounts:
hello - 682
Administr - 9
Test - 3Top ISPs:
Vietnam Posts and Telecommunications Group - 667
DigitalOcean, LLC - 13
Google LLC - 9Top Clients:
Unknown - 713Top Software:
Unknown - 713Top Keyboards:
Unknown - 713Top IP Classification:
Unknown - 672
hosting - 40
hosting & proxy - 1Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-10 RDP #Honeypot IOCs - 713 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 667
165.22.57.45 - 6
80.66.83.43 - 6Top ASNs:
AS135905 - 667
AS14061 - 13
AS396982 - 9Top Accounts:
hello - 682
Administr - 9
Test - 3Top ISPs:
Vietnam Posts and Telecommunications Group - 667
DigitalOcean, LLC - 13
Google LLC - 9Top Clients:
Unknown - 713Top Software:
Unknown - 713Top Keyboards:
Unknown - 713Top IP Classification:
Unknown - 672
hosting - 40
hosting & proxy - 1Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-10 RDP #Honeypot IOCs - 713 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 667
165.22.57.45 - 6
80.66.83.43 - 6Top ASNs:
AS135905 - 667
AS14061 - 13
AS396982 - 9Top Accounts:
hello - 682
Administr - 9
Test - 3Top ISPs:
Vietnam Posts and Telecommunications Group - 667
DigitalOcean, LLC - 13
Google LLC - 9Top Clients:
Unknown - 713Top Software:
Unknown - 713Top Keyboards:
Unknown - 713Top IP Classification:
Unknown - 672
hosting - 40
hosting & proxy - 1Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
SafeLine : un WAF prêt à protéger vos applis web des bots malveillants https://www.it-connect.fr/safeline-waf-prise-en-main/ #Cybersécurité #BlueTeam
-
2026-09-09 RDP #Honeypot IOCs - 5919 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
152.42.198.23 - 3300
168.144.34.49 - 2499
80.66.83.43 - 18Top ASNs:
AS14061 - 5817
AS396982 - 42
AS216473 - 18Top Accounts:
hello - 5850
Administr - 18
Test - 6Top ISPs:
DigitalOcean, LLC - 5817
Google LLC - 42
Bashinskii Vadim Ruslanovich - 18Top Clients:
Unknown - 5919Top Software:
Unknown - 5919Top Keyboards:
Unknown - 5919Top IP Classification:
hosting - 5910
Unknown - 6
hosting & proxy - 3Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-09 RDP #Honeypot IOCs - 5919 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
152.42.198.23 - 3300
168.144.34.49 - 2499
80.66.83.43 - 18Top ASNs:
AS14061 - 5817
AS396982 - 42
AS216473 - 18Top Accounts:
hello - 5850
Administr - 18
Test - 6Top ISPs:
DigitalOcean, LLC - 5817
Google LLC - 42
Bashinskii Vadim Ruslanovich - 18Top Clients:
Unknown - 5919Top Software:
Unknown - 5919Top Keyboards:
Unknown - 5919Top IP Classification:
hosting - 5910
Unknown - 6
hosting & proxy - 3Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-09 RDP #Honeypot IOCs - 5919 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
152.42.198.23 - 3300
168.144.34.49 - 2499
80.66.83.43 - 18Top ASNs:
AS14061 - 5817
AS396982 - 42
AS216473 - 18Top Accounts:
hello - 5850
Administr - 18
Test - 6Top ISPs:
DigitalOcean, LLC - 5817
Google LLC - 42
Bashinskii Vadim Ruslanovich - 18Top Clients:
Unknown - 5919Top Software:
Unknown - 5919Top Keyboards:
Unknown - 5919Top IP Classification:
hosting - 5910
Unknown - 6
hosting & proxy - 3Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-09 RDP #Honeypot IOCs - 5919 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
152.42.198.23 - 3300
168.144.34.49 - 2499
80.66.83.43 - 18Top ASNs:
AS14061 - 5817
AS396982 - 42
AS216473 - 18Top Accounts:
hello - 5850
Administr - 18
Test - 6Top ISPs:
DigitalOcean, LLC - 5817
Google LLC - 42
Bashinskii Vadim Ruslanovich - 18Top Clients:
Unknown - 5919Top Software:
Unknown - 5919Top Keyboards:
Unknown - 5919Top IP Classification:
hosting - 5910
Unknown - 6
hosting & proxy - 3Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-09 RDP #Honeypot IOCs - 3946 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
152.42.198.23 - 2200
168.144.34.49 - 1666
80.66.83.43 - 12Top ASNs:
AS14061 - 3878
AS396982 - 28
AS216473 - 12Top Accounts:
hello - 3900
Administr - 12
Test - 4Top ISPs:
DigitalOcean, LLC - 3878
Google LLC - 28
Bashinskii Vadim Ruslanovich - 12Top Clients:
Unknown - 3946Top Software:
Unknown - 3946Top Keyboards:
Unknown - 3946Top IP Classification:
hosting - 3940
Unknown - 4
hosting & proxy - 2Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-09 RDP #Honeypot IOCs - 3946 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
152.42.198.23 - 2200
168.144.34.49 - 1666
80.66.83.43 - 12Top ASNs:
AS14061 - 3878
AS396982 - 28
AS216473 - 12Top Accounts:
hello - 3900
Administr - 12
Test - 4Top ISPs:
DigitalOcean, LLC - 3878
Google LLC - 28
Bashinskii Vadim Ruslanovich - 12Top Clients:
Unknown - 3946Top Software:
Unknown - 3946Top Keyboards:
Unknown - 3946Top IP Classification:
hosting - 3940
Unknown - 4
hosting & proxy - 2Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-09 RDP #Honeypot IOCs - 3946 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
152.42.198.23 - 2200
168.144.34.49 - 1666
80.66.83.43 - 12Top ASNs:
AS14061 - 3878
AS396982 - 28
AS216473 - 12Top Accounts:
hello - 3900
Administr - 12
Test - 4Top ISPs:
DigitalOcean, LLC - 3878
Google LLC - 28
Bashinskii Vadim Ruslanovich - 12Top Clients:
Unknown - 3946Top Software:
Unknown - 3946Top Keyboards:
Unknown - 3946Top IP Classification:
hosting - 3940
Unknown - 4
hosting & proxy - 2Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-09 RDP #Honeypot IOCs - 3946 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
152.42.198.23 - 2200
168.144.34.49 - 1666
80.66.83.43 - 12Top ASNs:
AS14061 - 3878
AS396982 - 28
AS216473 - 12Top Accounts:
hello - 3900
Administr - 12
Test - 4Top ISPs:
DigitalOcean, LLC - 3878
Google LLC - 28
Bashinskii Vadim Ruslanovich - 12Top Clients:
Unknown - 3946Top Software:
Unknown - 3946Top Keyboards:
Unknown - 3946Top IP Classification:
hosting - 3940
Unknown - 4
hosting & proxy - 2Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-09 RDP #Honeypot IOCs - 1973 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
152.42.198.23 - 1100
168.144.34.49 - 833
80.66.83.43 - 6Top ASNs:
AS14061 - 1939
AS396982 - 14
AS216473 - 6Top Accounts:
hello - 1950
Administr - 6
Test - 2Top ISPs:
DigitalOcean, LLC - 1939
Google LLC - 14
Bashinskii Vadim Ruslanovich - 6Top Clients:
Unknown - 1973Top Software:
Unknown - 1973Top Keyboards:
Unknown - 1973Top IP Classification:
hosting - 1970
Unknown - 2
hosting & proxy - 1Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-09 RDP #Honeypot IOCs - 1973 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
152.42.198.23 - 1100
168.144.34.49 - 833
80.66.83.43 - 6Top ASNs:
AS14061 - 1939
AS396982 - 14
AS216473 - 6Top Accounts:
hello - 1950
Administr - 6
Test - 2Top ISPs:
DigitalOcean, LLC - 1939
Google LLC - 14
Bashinskii Vadim Ruslanovich - 6Top Clients:
Unknown - 1973Top Software:
Unknown - 1973Top Keyboards:
Unknown - 1973Top IP Classification:
hosting - 1970
Unknown - 2
hosting & proxy - 1Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-09 RDP #Honeypot IOCs - 1973 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
152.42.198.23 - 1100
168.144.34.49 - 833
80.66.83.43 - 6Top ASNs:
AS14061 - 1939
AS396982 - 14
AS216473 - 6Top Accounts:
hello - 1950
Administr - 6
Test - 2Top ISPs:
DigitalOcean, LLC - 1939
Google LLC - 14
Bashinskii Vadim Ruslanovich - 6Top Clients:
Unknown - 1973Top Software:
Unknown - 1973Top Keyboards:
Unknown - 1973Top IP Classification:
hosting - 1970
Unknown - 2
hosting & proxy - 1Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-09 RDP #Honeypot IOCs - 1973 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
152.42.198.23 - 1100
168.144.34.49 - 833
80.66.83.43 - 6Top ASNs:
AS14061 - 1939
AS396982 - 14
AS216473 - 6Top Accounts:
hello - 1950
Administr - 6
Test - 2Top ISPs:
DigitalOcean, LLC - 1939
Google LLC - 14
Bashinskii Vadim Ruslanovich - 6Top Clients:
Unknown - 1973Top Software:
Unknown - 1973Top Keyboards:
Unknown - 1973Top IP Classification:
hosting - 1970
Unknown - 2
hosting & proxy - 1Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
Empty scoreboard.
80 teams.
14 days.Someone's name goes first.
WATCHLIST is a free 24-hour CTF built around one investigation.
24 challenges - memory forensics,
disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.All connected to the same case.
First blood on each challenge gets logged permanently
by The Machine.Sep 19 03:30 UTC. Free entry. Teams 1-6.
Prizes: $750 / $500 / $250ctf.xposedornot.com
CTFtime: ctftime.org/event/3326 -
We have updated https://www.valtersit.com/methodology/ with the actual information #CVE #Dokploy #infosec #SysAdmin #cybersecurity #Linux #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta
-
Linux Security Auditing with Lynis
In this article, I cover how to use Lynis for Linux security auditing, system hardening, and practical vulnerability assessment.
🔗 https://denizhalil.com/2025/03/17/linux-security-auditing-with-lynis/
#CyberSecurity #LinuxSecurity #Lynis #SecurityAuditing #SystemHardening #BlueTeam #DevSecOps #InfoSec #Linux #ITSecurity #SecurityEngineering #DenizHalil
-
Linux Security Auditing with Lynis
In this article, I cover how to use Lynis for Linux security auditing, system hardening, and practical vulnerability assessment.
https://denizhalil.com/2025/03/17/linux-security-auditing-with-lynis/
#CyberSecurity #LinuxSecurity #Lynis #SecurityAuditing #SystemHardening #BlueTeam #DevSecOps #InfoSec #Linux #ITSecurity #SecurityEngineering #DenizHalil
-
Subdomain Takeover Vulnerabilities and Prevention
In this article, I cover:
* How subdomain takeover vulnerabilities occur
* Real-world exploitation scenarios
Reconnaissance and detection techniques
* Practical prevention and DNS hygiene strategieshttps://denizhalil.com/2026/02/16/subdomain-takeover-vulnerabilities-prevention/
#CyberSecurity #SubdomainTakeover #DNS #AttackSurface #BugBounty #RedTeam #BlueTeam #InfoSec #CloudSecurity #WebSecurity #EthicalHacking
-
UNC3886 leveraged ORB infrastructure for stealthy telecom targeting.
Per Cyber Security Agency of Singapore:
• Zero-day firewall compromise
• Rootkit persistence mechanisms
• GOBRAT & TINYSHELL C2 nodes
• ORB-tagged IP clustering in Singapore ASNs
• NetFlow-confirmed router-to-ORB communications
• Pre-positioned reconnaissanceAttribution aligned with assessments from Mandiant linking activity to China-sponsored espionage.
ORB networks blur the line between botnets and residential proxy ecosystems, increasing attribution friction and collateral risk.
Defensive priorities:
• Threat intel enrichment
• Edge device patch enforcement
• ASN anomaly detection
• Zero-trust segmentation
• IoT telemetry visibilityHow mature are ORB detection capabilities in your SOC?
Engage below.
Source: https://cyberpress.org/orb-networks-masks-attacks/
Follow @technadu for advanced threat analysis.
#ThreatIntel #UNC3886 #ORBNetworks #IoTSecurity #ZeroDay #C2Infrastructure #NetFlow #TelecomSecurity #BlueTeam #ThreatHunting #APTActivity #CyberOperations #Infosec
-
Server Security Checklist — Essential Hardening Guide
Securing your servers isn’t optional — it’s your first line of defense against data breaches, ransomware, insider threats, and lateral movement. Use this checklist as a baseline for Linux, Windows, cloud, hybrid, or on-prem servers.
⸻
🔧 1. System & OS Hardening
• Keep OS & packages updated (apply security patches frequently).
• Remove / disable unused services & software.
• Enforce secure boot + BIOS/UEFI passwords.
• Disable auto-login and guest accounts.
• Use minimal OS images only (reduce attack surface).⸻
🔐 2. Access Control
• Enforce strong passwords & MFA everywhere.
• Use RBAC & least privilege access.
• Disable root/Administrator login over SSH/RDP.
• Rotate credentials & keys regularly.
• Implement just-in-time access for privileged users.⸻
🌐 3. Network Security
• Restrict inbound/outbound traffic via firewalls.
• Segment critical servers from general LANs/VLANs.
• Disable unused ports & protocols.
• Enable DoS/DDoS protection.
• Apply zero-trust network principles.⸻
🔑 4. Secure Remote Access
• Use SSH key-based authentication (disable password login).
• Enforce VPN for admin access.
• Log & monitor all remote access sessions.
• Disable legacy protocols (Telnet, FTP, SMBv1).
• Require bastion/jump host for critical access.⸻
📊 5. Logging & Monitoring
• Enable centralized logging (syslog / SIEM).
• Track failed login attempts & anomalies.
• Configure alerts for privilege escalation or config changes.
• Monitor log tampering.
• Retain logs securely for audits & forensics.⸻
🔒 6. Data Protection
• Encrypt data at rest (LUKS, BitLocker, etc.).
• Encrypt data in transit (TLS 1.2+).
• Strict database access policies.
• Regular, offline, immutable backups.
• Test restore procedures (don’t assume backups work).⸻
🔁 7. Application & Patch Management
• Keep middleware, frameworks, and apps patched.
• Delete default credentials & sample files.
• Enable code signing for software packages.
• Use secure coding practices (OWASP Top 10).
• Implement dependency scanning (Snyk, Trivy, etc.).⸻
🛡️ 8. Malware & Intrusion Defense
• Deploy EDR/AV on endpoints.
• Enable IDS/IPS at network edge.
• Automatic vulnerability scans (schedule weekly/monthly).
• Monitor persistence techniques (cron, startup scripts).
• Block known malicious IP ranges & TLDs.⸻
🏢 9. Physical & Cloud Security
• Restrict physical access to server racks/rooms.
• Enable provider security tools (AWS Security Groups, Azure NSG, IAM).
• Harden cloud images (CIS benchmarks).
• Review cloud logging & audit trails regularly.
• Disable unused cloud API keys / roles.⸻
📜 10. Policy & Compliance
• Use CIS / NIST / ISO-27001 benchmarks.
• Track & document every access change.
• Force annual access reviews & key rotation.
• Perform regular security training for admins.
• Maintain disaster recovery & incident plans.⸻
➕ Additional 5 Critical Controls (Advanced Hardening)
🧠 11. Privileged Access Management (PAM)
• Use jump hosts & session recording.
• Just-In-Time access for admins.
• Store keys in secure vaults (HashiCorp Vault, CyberArk).🚨 12. Real-Time Threat Detection
• Use behavioral analytics → UEBA/XDR.
• AI-based anomaly detection recommended.
• Block suspicious IPs automatically.🧪 13. Red Team & Pentesting
• Run regular internal pentests.
• Validate configuration weaknesses.
• Simulate phishing + lateral movement scenarios.🧱 14. Container / VM Isolation
• Use AppArmor, SELinux, Seccomp profiles.
• Limit Docker socket access & root containers.
• Scan images before deployment.📦 15. Automated Configuration Management
• Use IaC (Terraform, Ansible, Puppet) for repeatable and secure builds.
• Detect drift using compliance scanning.
• Version control all infrastructure.⸻
🧠 Core Reminder
A server is only as secure as the team who maintains it.
Hardening isn’t one task — it’s an ongoing#ServerSecurity #SystemHardening #InfoSec #CyberSecurity #BlueTeam
#DevSecOps #SysAdmin #ThreatDetection #AccessControl #NetworkSecurity
#LinuxSecurity #SecureArchitecture #RiskMitigation #SecurityChecklist
#CloudSecurity #InfrastructureSecurity #ZeroTrust #SecurityMonitoring -
#GammaGroup clients use
🔎 UDP port 123 🔍
as default #RedTeam data #exfiltration ports
#gammagroup #finfsher #finspy #infosec #memes
#BlueTeam
#statesponsoredmalware ☣️🤳🐐☣️Update: Add logging before implementing BLOCKING the #exfil shim, obviously. ☣️🤳🔎🐐☣️🔍🧐
-
Happy Tuesday everyone!
Just your weekly reminder that Regular Registration is closing this Friday, July 19th! So you still have some time to get the regular pricing when you register for Cyborg Security's and Intel 471's Threat Hunter training at Black Hat USA in Las Vegas!
You will you learn:
What a threat hunt looks like from start to finish.
What tools and resources we can leverage to research and communicate with shareholders.
How to navigate through an investigation following process chains, finding correlating information, and how to find related events that help you better tell the story!If any of this sounds fun, come join me at Black Hat in Vegas this year for a fun time! I can't wait to meet everyone there, but until then, Happy Hunting!
Registration Links:
Aug 3rd - 4th:
https://www.blackhat.com/us-24/training/schedule/#a-beginners-guide-to-threat-hunting-how-to-shift-focus-from-iocs-to-behaviors-and-ttps-36528#CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel
#ThreatHunting #ThreatDetection #HappyHunting #Intel471 #BlackHat -
Happy Monday everyone!
We are going to start this week off with a nice resource in our #readoftheday! If you have yet to hear about Wazuh, now is your chance! It is a free, open-source security platform that protects data assets from threats [2]. In this article, the researchers cover what abusing Living-off-the-Land binaries (LOLBINs) looks like from the perspective of an Ubuntu and Kali Linux endpoint and focus on the #DirtyPipe exploit and the DDexec utility. After walking readers through the emulation they then discuss how Wazuh helps detect these techniques. It is a good read and a resource I want to get into my own lab to start playing with!
As always, check out the full article and others by Wazuh researchers on their blog and stay tuned for the threat hunting tip of the day! Enjoy and Happy Hunting!
Detecting Living Off the Land attacks with Wazuh
https://wazuh.com/blog/detecting-living-off-the-land-attacks-with-wazuh/Other reference:
https://github.com/wazuh/wazuh [2]Intel 471 #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #Intel471
-
Happy Friday Everyone!
The Check Point Software researchers help us into the weekend with the #readoftheday, and ironically it covers some things that we have been researching as of late!
In this article, the researchers detail how a threat actor used an Internet Shortcut (.url) file to open up the attacker website in Internet Explorer (a more vulnerable brower) instead of Chrome or Edge. This is accomplished through the use of a specially crafted .url file that contains the values "mhtml" and also "!x-usc". These tactics were last when threat actors were exploiting CVE-2021-40444 (Microsoft MSHTML Remote Code Execution Vulnerability)[2] and are seen again.
As you wait for the Threat Hunting Tip of the day, go read the entire article yourself and see what I missed! Enjoy and Happy Hunting!
RESURRECTING INTERNET EXPLORER: THREAT ACTORS USING ZERO-DAY TRICKS IN INTERNET SHORTCUT FILE TO LURE VICTIMS (CVE-2024-38112)
https://research.checkpoint.com/2024/resurrecting-internet-explorer-threat-actors-using-zero-day-tricks-in-internet-shortcut-file-to-lure-victims-cve-2024-38112/Additional resource:
[2] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444Intel 471 #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #Intel471 #gethunting
-
Happy Wednesday, everyone!
I’m honored and proud to invite all my connections to join me at Cyborg Security & Intel 471’s Black Hat USA training for the second year in a row!
We cover everything from resources to use for research and models to use for communicating to your stakeholders to operationalizing intel to create a hypothesis to start a threat hunt. If you are a data junkie (like me) who loves diving into data, sifting through it, then this is the training for you! If any of this sounds fun, join my Black Hat USA training, titled “A Beginner’s Guide to Threat Hunting: How to Shift Focus from IOCs to Behaviors and TTPs”! You may have missed the early registration discount, but the regular registration discount is still available until July 19th!
I will be teaching two 2-day sessions. You can pick which one works with your schedule best and register here:
I can't wait to meet everyone there. Until then, happy hunting!
#CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #Intel471 #BlackHat
-
Happy Wednesday everyone!
This is the second #readoftheday this week that involves eBooks being used as the lure for victims and in this case Trellix reveals that this eBook delivers a malware known as #ViperSoftX.
Once the victim downloads the archive file, they are presented with an eBook cover page, a hidden folder, shortcut file and three JPGs. These files are not what they seem, as you all may have guessed. One is an AutoIT script, one the AutoIT executable, and the last a PowerShell script. The shortcut file leads to the execution of the PowerShell code that unhides the hidden folder, checks the disk size of all drives, moves the AutoIT files to the AppData\Microsoft\Windows directory and deletes the LNK files in the current directory.
A notable MITRE ATT&CK TTP here is the use of PowerShell encoded commands or T1027.013 - Obfuscated Files or Information: Encrypted/Encoded File. This is a common technique that adversaries use to hide the true nature of the commands or communication with their C2 server.
As always, I am leaving you hanging and will be back for the Threat Hunting Tip of the day! While you are waiting patiently, go read the rest of the article, it has tons of details I left out! Enjoy and Happy Hunting!
The Mechanics of ViperSoftX: Exploiting AutoIt and CLR for Stealthy PowerShell Execution
https://www.trellix.com/blogs/research/the-mechanics-of-vipersofts-exploiting-autoit-and-clr-for-stealthy-powershell-execution/Intel 471 #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #Intel471
-
Introducing the newest major @tidalcyber TTP intelligence content roundup, the Initial Access & Malware Delivery Landscape matrix, now live in our free Community Edition platform: https://app.tidalcyber.com/share/43836024-a194-4ac7-9659-b51e88632e7f
The matrix covers 25 major & emerging #malware typically used to gain early footholds in victim environments, often leading to ingress of more impactful threats, especially #ransomware, #infostealers, cryptominers, & more. It includes many recognizable names (#QakBot, #IcedID, #Emotet, #Bumblebee, #Gootloader) plus several newer and less-discussed threats
The matrix includes 13 custom Technique Sets for threats not currently tracked in the #mitreattack knowledge base. All technique references derive from a large volume of recent, public #threat reporting (click the labels in the ribbon at the top of the matrix to view relevant source URLs for each threat)
An interactive link analysis visualization of connections among these threats, also derived from public reports, is also available here: https://onodo.org/visualizations/235067/
Community Edition matrices support easy identification of shared (and outlier) techniques among multiple threats, and quick & easy overlay or pivoting to defensive & offensive security capabilities relevant to your own #security stack. We’ll have a blog out soon reviewing our analysis of top & trending techniques common among these initial access threats
Tidal’s #Adversary Intelligence team remains focused on providing up-to-date #TTPintelligence, especially around traditionally under-represented yet widely relevant threats like crimeware. Other popular matrices in this theme include our Ransomware & Data Extortion Landscape matrix (https://app.tidalcyber.com/share/9a0fd4e6-1daf-4f98-a91d-b73003eb2d6a) and Major & Emerging Infostealers matrix (https://app.tidalcyber.com/share/ec62f5e0-bd40-476b-a560-7ad2779ea9e3), which each cover 20+ threats
Financially motivated adversaries often display a rapid pace of #TTP evolution, and this is especially apparent for #initialaccess threats. Register for our webinar on May 31 dedicated to TTP evolution, its drivers, and discussion around what defenders can do to address it and its implications: https://hubs.la/Q01NC23k0
#SharedWithTidal #threatinformeddefense #malware #infostealer #cryptominer #IAB #blueteam #detectionengineering #purpleteam #cyber
-
OffSec (tidigare Offensive Security) har släppt en ny Linux-distribution vid namn Kali Purple, läs mer här: https://kryptera.se/kali-purple-fran-offsec/
#offensivesecurity #linux #offsec #kali #cybersecurity #purpleteam #blueteaming #blueteam
-
#Gootloader is a highly active banking Trojan-turned-loader #malware that has recently appeared on multiple vendors’ priority threat lists, attacking organizations in a wide range of verticals & countries. If your leadership or other stakeholders asked for a list of this threat's most common TTPs, would you be able to provide it quickly?
Now you can, with the Gootloader #TTP matrix available in Tidal’s free Community Edition: https://app.tidalcyber.com/share/796cacb6-3bb1-474b-9747-abcce2c47de2
Gootloader, also referred to by its related payload, #Gootkit, first emerged in 2014 but has been especially active since 2020. Despite this, technical reporting around its TTPs has been relatively light until even more recently. In the past two years alone, verticals including finance, #healthcare, defense, pharmaceutical, energy, & automotive have faced Gootloader campaigns, with victims across North America, Western Europe, & South Korea, and the malware is regularly used to deliver high-impact payloads, including Cobalt Strike, #IcedID (a common #ransomware precursor), & more. Industry-based #threat profiling can be a powerful tool, but even if your industry (or your corner of it) hasn’t yet directly observed Gootloader activity, we believe broad-based threats like this should be on most teams’ radars
Our matrix summarizes Gootloader TTPs detailed across several great recent technical reports. Reports from SentinelLabs, Cybereason, & The DFIR Report were helpfully pre-mapped to #mitreattack, and we mapped a couple other detailed analyses. Procedural details are even available for nearly all the included technique mappings – be sure to click the Technique Set’s label in the ribbon at the top of the screen to pivot into the Details page with this information & relevant source links throughout
Red Canary & The DFIR Report helpfully provided tool-agnostic suggested #detection logic for key behaviors observed during recent Gootloader campaigns here https://redcanary.com/blog/gootloader/ and here https://thedfirreport.com/2022/05/09/seo-poisoning-a-gootloader-story/. Take a wider view by layering entire segments of your defensive stack over the #CTI back in the Community Edition, by toggling on any of the mappings available in @tidalcyber's Product Registry https://app.tidalcyber.com/vendors
#SharedWithTidal #threatinformeddefense #CobaltStrike #initialaccess #blueteam