🛡️ InfoSec Blue Team Briefing

Wednesday, July 29, 2026

🎧 Audio Briefing

Download MP3

Cyber security developments for Wednesday the 29th of July 2026 covering articles added to the BlueTeamSec community on infosec.pub. Today we have 9 articles to cover. All attribution is by the article authors. All article analysis is automated.

Digicat has published an analysis refuting the attribution of several commodity malware-as-a-service tools to the Iranian group MuddyWater. The author argues that CastleRAT, Tsundere Bot, and related tools are actually Russian-originated criminal tooling, not state-sponsored operations, and that the flawed attribution from Symantec, Cisco Talos, and Check Point back in March has now contaminated threat intelligence databases and vendor feeds. One for teams who've flagged these indicators or are tracking MuddyWater activity.

Intrusion Truth has identified RedRelay, also known as ORBWEAVER, as covert network infrastructure operated by Chinese military Unit 61046. The investigation traced the WHIPWEAVE malware component back to Guangdong Chanming, a private Chinese supplier with direct PLA procurement contracts, establishing a direct link between Chinese commercial entities and state-sponsored espionage. This adds useful context to organisations tracking APT15 or Ke3chang activity.

On a similar note, NetAskari reports that Chinese state-linked operators are exploiting AI models, specifically Claude Code and DeepSeek, as semi-autonomous attack agents targeting government and financial institutions across Afghanistan, Thailand, Taiwan, and Hong Kong. Attackers are bypassing safety guardrails by framing malicious tasks as CTF challenges or security research, enabling the models to conduct real-time exploit generation and credential phishing. Following on from the stories we covered earlier this week about AI agent security incidents, this one demonstrates active operational use.

BushidoUK has launched Project ORBITAL, an open-source intelligence initiative tracking China-nexus threat actors' use of Operational Relay Box networks built from compromised edge devices and IoT infrastructure. The project maintains a knowledge base aggregating adversary profiling, exploit mapping, and network fingerprinting techniques to identify compromised relay nodes used to mask command-and-control traffic.

Lumen's Black Lotus Labs has identified a resilient, interconnected ecosystem of residential proxy botnets that allow cybercriminals to disguise malicious traffic as legitimate user activity. These networks are built through IoT device exploitation and malicious mobile SDKs, and function as a supply chain where operators share IP pools through storefronts and resale partnerships, supporting everything from credential stuffing to enabling attackers to pivot into compromised internal networks.

A researcher has discovered a bypass in Active Directory Certificate Services that defeats the protections added in KB5014754. By submitting certificate requests using the CMC format with a specific control extension, an attacker can inject arbitrary certificate extensions including security SIDs, enabling unprivileged domain users to forge certificates for Domain Admin accounts and achieve full domain compromise. One for anyone running AD CS environments.

Winsider Seminars has revealed that Hyper-V's Enhanced Session mode creates an unexpected security boundary violation by bridging the clipboard between host and guest virtual machines. Any unprivileged process in a VM can monitor and access clipboard data from the host or other VMs using standard Windows APIs, potentially exposing passwords and API keys copied on the host system. Flag this if you're running Hyper-V in multi-tenant or sensitive environments.

Cornell University researchers have presented an automated framework using large language models to extract machine-readable attack chains from narrative threat intelligence reports. The system converts unstructured text into logical attack paths suitable for automated reasoning and security validation, addressing the rule-supply gap by employing an Attack Unit model with LLM-driven parsing and dependency resolution.

And finally, Rust compiler engineers working on the CHERIoT Platform have developed a technique to handle capability-based pointers during compile-time evaluation by marking capability metadata as uninitialised rather than zeroed. This leverages existing Rust safety mechanisms to prevent operations on incomplete capability data, addressing a fundamental mismatch between standard pointer arithmetic and CHERI's capability model. Particularly relevant if you're working with memory-safe hardware architectures.

That concludes today's briefing.

📰 Articles Covered