🛡️ InfoSec Blue Team Briefing

Tuesday, August 18, 2026

🎧 Audio Briefing

Download MP3

Security news from the BlueTeamSec community for Tuesday the 18th of August 2026. It's a busy one, with nineteen stories to get through — I'm Tess.

And I'm Sebastian. Starting with threat intelligence, USENIX Association have published a technical analysis of leaked source code from Geedge Networks, which reveals the internal architecture of the Tiangou Secure Gateway — a national-scale censorship infrastructure. The leak exposes modular design components, fingerprinting methodologies, and the iterative development process behind state-level content filtering systems.

Picus Security have a detailed write-up on Dragon Breath, also tracked as APT-Q-27 — a Chinese-speaking threat actor targeting online gambling and financial services across Asia-Pacific. Notably, the group compromised DigiCert support workstations back in April to steal code-signing certificates, which they've since used to sign trojanised versions of Telegram and Microsoft Teams. We covered the DigiCert incident when it surfaced in July.

Elsewhere, a researcher posting as Axel Z has traced OctLurk infrastructure impersonating Leroy Merlin, Tajikistan's Civil Aviation Agency, and Afghanistan's Ministry of Interior — all part of an espionage campaign targeting Central Asia. The investigation used passive DNS to map interconnected malicious domain clusters sharing common infrastructure.

BushidoToken have published a review of Qilin ransomware activity in the UK during the first half of this year. The group maintained steady operations, averaging seven to nine victims monthly with a six-week extortion lifecycle, exploiting VPN gateways from Fortinet, Check Point, and WatchGuard. They're also using vulnerable driver techniques to evade endpoint detection — we covered similar tactics from Akira just yesterday.

Push Security's mid-year report on browser-based attacks notes that Scattered Spider, Lapsus, and ShinyHunters have accounted for seventy percent of browser and identity-related breaches since 2024. The report highlights the industrialisation of device code phishing and Phishing-as-a-Service platforms — more than twenty-five kits are now enabling attackers to bypass multi-factor authentication through adversary-in-the-middle and device authorisation exploits.

On tooling and techniques, Kevin Gosse has released windbg-bridge, an open-source tool that connects AI coding agents like Claude or Codex to live WinDbg debugging sessions via named pipes. The agents can execute debugger commands, read command history, and analyse system state in real time — which has obvious security implications around command injection and exposure of sensitive debugging data.

Trellix have identified an active DarkCrystal RAT campaign this year using legal-themed phishing lures targeting Colombian users. The attack chain involves HTML smuggling via SVG files, DLL sideloading with fake Brotli components, and process hollowing injection techniques to achieve remote control while evading detection.

VMRay Labs report on a commodity malware campaign leveraging vulnerable driver techniques to disable Windows security software. The malware weaponises a signed IObit Unlocker driver within WinRAR self-extracting archives to terminate antivirus, backup tools, and Windows Update services — preparing systems for secondary payloads like ransomware or cryptominers. It's widely used within Russian-speaking cybercrime communities.

Gen Digital have documented a sophisticated phishing campaign using the Mailer-Go platform with single-use burnable links that abuse Microsoft's OAuth Device Code flow to steal session tokens rather than credentials. The campaign leverages Cloudflare Workers running the EvilTokens kit and targets business-to-business entities by impersonating Microsoft OneDrive, using text obfuscation and domain spoofing to bypass security controls.

Moving to exploitation, Fortra have a report on ExfilSquad, a new data extortion group that's exfiltrated three hundred and eighty-two gigabytes from fifteen organisations by exploiting misconfigured Microsoft Power Pages portals. The group uses automated tools like Power Pwn to enumerate and extract data directly from Dynamics 365 environments via exposed API endpoints, targeting education, finance, government, and retail sectors.

On offensive techniques, Varonis researchers have found that a legacy WS-Trust authentication endpoint in Entra ID can be exploited for password spraying attacks that bypass Smart Lockout protections and don't appear in standard sign-in logs. The endpoint, designed for older clients like Office 2013, returns error codes that confirm valid passwords even when multi-factor or Conditional Access would block the login — enabling attackers to validate credentials invisibly.

Ridgeline Cyber Defence have written up a case where a macOS user was compromised through social engineering — a fake technical support caller convinced them to grant Full Disk Access permissions to legitimate, signed remote support software. The attacker exploited the macOS Transparency, Consent, and Control framework to exfiltrate browser history, mail stores, and messages without triggering traditional security controls. One for those running awareness training programmes.

On discovery, a security researcher has developed a high-fidelity Sigma detection rule to identify macOS Gatekeeper bypass attempts via the xattr utility. The technique involves removing the quarantine extended attribute from downloaded files to execute malicious code without triggering security warnings. The rule achieved one hundred percent true positive and zero percent false positive rates in testing.

Microsoft Defender XDR has added a new DeviceRoles column to the DeviceInfo table in Advanced Hunting, enabling automated device classification. Blu Raven Academy note this allows SOC analysts and threat hunters to instantly identify device functions and administrative importance, improving detection engineering through role-based query tuning and better identification of high-value targets like domain controllers and admin workstations.

Kevin Pagano has written about Android's new intrusion logging feature, integrated into Advanced Protection mode. It generates JSON-formatted logs capturing security events, DNS queries, and network connections. Forensic investigators can extract these logs using tools like MVT and ALEX, and parse them with ALEAPP to identify indicators of compromise during incident response.

And another forensics tool — researchers have released IRFlow Timeline version one point one zero, which adds forensic analysis capabilities for macOS ChatGPT Computer History artifacts. The tool enables investigators to recover deleted user activity including keystrokes, clicks, and window interactions, and reconciles metadata to detect cleared history from the ChatGPT desktop application's local storage.

CKE Limited have introduced the NIST Digital Forensics Artifact Catalog, or ArtCat — a standardised, community-driven framework for digital forensics using the CASE ontology and atomic artifacts. The platform aims to increase reliability of forensic findings and ensure legal scrutiny compliance by moving away from ad-hoc investigation practices toward rigorous scientific structure.

On defence, ETSI has launched the approval process for seventeen European Standards supporting the EU's Cyber Resilience Act. These standards provide manufacturers of connected products and software with technical requirements to achieve presumption of conformity with security mandates, covering all products with digital elements including IoT devices, smart home products, and security software.

And finally, Filippo Valsorda has written a clarification on quantum computing threats to symmetric encryption. He notes that quantum computers pose minimal threat to one-hundred-and-twenty-eight-bit symmetric keys due to Grover's algorithm limitations, which only provide quadratic speedup and face practical parallelisation constraints. The piece emphasises that symmetric key systems remain secure at current key lengths while asymmetric systems require immediate attention.

That's all for today. The articles are the work of their original authors — the analysis here was automated. We'll be back tomorrow.

📰 Articles Covered