๐Ÿ›ก๏ธ InfoSec Blue Team Briefing

Friday, July 17, 2026

๐ŸŽง Audio Briefing

Download MP3

Cyber security developments for Friday the 17th of July 2026 covering articles added to the BlueTeamSec community on infosec.pub. Today we have 10 articles to cover. All attribution is by the article authors. All article analysis is automated.

The U.S. Department of State's Rewards for Justice program is offering up to ten million dollars for information on Russian malicious cyber actors, specifically those behind Media Land and ML.Cloud. Following on from the indictments we covered yesterday, these Russia-based entities allegedly provide infrastructure that helps malicious actors obfuscate their activities and evade law enforcement.

Thomson Reuters reports that Denis Obrezko, the alleged FSB-linked cyber spy we heard about earlier this week, previously worked as a senior specialist at Kaspersky Lab between 2017 and 2019, following what prosecutors claim was a five-year stint with Russia's FSB. The overlap raises uncomfortable questions about the line between Russian cybersecurity firms and state intelligence operations.

S2W have analysed BirdCall malware attributed to North Korea's ScarCruft group. The backdoor masquerades as the legitimate Zangi messenger app for Android, uses dual Zoho WorkDrive accounts for command and control, and targets individuals in China's Yabian region for espionage. Worth flagging if you're tracking mobile threats in the region.

Qianxin Threat Intelligence Center have published analysis of a campaign by the Lazarus Group focusing on upgrades to their surveillance and monitoring programs. The source wasn't accessible for full details, but one for those tracking North Korean tooling evolution.

Hunt.io report that suspected Chinese operators conducted a sophisticated intrusion campaign in June targeting government and financial systems across Afghanistan, Thailand, Taiwan, and the United States. What's notable here is the use of large language models, specifically Claude Code and DeepSeek, integrated directly into their workflow to automate reconnaissance, exploit development, and phishing infrastructure creation.

Expel have identified CylindricalCanine, a subgroup of GoldenEyeDog, as responsible for the DigiCert supply chain incident back in April. The attackers used DLL sideloading, hijacked legitimate executables, and deployed the Golden Gh0st malware family with over nineteen hundred known malicious files. Initial access was achieved through a malicious file submitted via a support ticket, which is either impressively patient tradecraft or someone exploiting a very obvious gap in input validation.

Cyderes document a spear-phishing campaign by DoNot, also known as APT-C-35, targeting Bangladesh Air Force personnel. The India-aligned threat actor used weaponised RTF files with remote template injection, geofencing, and AES-encrypted command and control to deploy modular implants for intelligence gathering.

Elastic have analysed TELEPUZ, a modular Malware-as-a-Service threat active since late April. It spreads via ClickFix social engineering campaigns that trick users into executing PowerShell commands, then uses VIDAR infostealer as a secondary stager. The malware features financial data theft via WebInjector, browser manipulation using Chrome DevTools Protocol, and a rather elaborate command and control setup with multiple fallback methods including Telegram, Steam, DNS, and a Polygon blockchain smart contract.

Tailscale have disclosed an ACL bypass vulnerability in Tailscale SSH that allowed attackers with existing SSH access to gain root on Linux systems. The flaw involved usernames with leading hyphens being interpreted as command-line flags by a system utility, which is a wonderfully simple way to achieve privilege escalation. Fixed in version 1.98.9.

And finally, researchers have released cyber-decoy, an open-source containerised honeypot architecture that emulates SSH, RDP, and SMB services. It uses a two-tier architecture with kernel-level traffic monitoring and isolated Docker containers running service decoys. Worth a look if you're setting up deception infrastructure within authorised environments.

That concludes today's briefing.

๐Ÿ“ฐ Articles Covered