🛡️ InfoSec Blue Team Briefing

Friday, August 14, 2026

🎧 Audio Briefing

Download MP3

Security news from the BlueTeamSec community for Friday the 14th of August 2026. I'm Tess.

And I'm Sebastian. Pillar Security have published details of an active supply-chain campaign called DeadBugz that's targeting developers through malicious Model Context Protocol servers. The attack uses runtime-gated evasion to slip past initial checks, then manipulates AI agents into exfiltrating credentials — SSH keys, AWS tokens, Kubernetes configs — by poisoning tool definitions after a few interactions. One for anyone using MCP servers or AI coding agents, and it builds on the Claude Code incident we covered earlier this month.

Bybit have filed civil litigation against North Korea and the Lazarus Group following a massive cryptocurrency theft in February last year. They've secured a preliminary injunction to freeze stolen assets and are targeting money laundering infrastructure including eXch and Cryptomixer dot io. It's a landmark attempt at crypto asset recovery through the courts rather than purely technical means.

And from the White House, a presidential memorandum dated the 12th of August establishes a new program allowing vetted U.S. private companies to conduct cyber surveillance and disruption operations against foreign cyber-enabled transnational criminal organisations under federal oversight. The scope includes infrastructure denial and covert intelligence collection, managed by the National Coordination Center with Justice and Homeland Security oversight. Worth reading in full if you're following policy shifts around private sector involvement in offensive operations.

That's your briefing for today. The articles are the work of their original authors — the analysis here was automated.

📰 Articles Covered