🛡️ InfoSec Blue Team Briefing

Wednesday, August 19, 2026

🎧 Audio Briefing

Download MP3

This is the BlueTeamSec briefing for Wednesday the 19th of August 2026, drawn from the community on infosec.pub.

CrowdStrike have documented twenty-one shell command obfuscation techniques that ransomware operators are using to evade detection on VMware ESX hypervisors. The techniques exploit BusyBox shell features to hide malicious commands before they reach the logs, which makes traditional keyword-based detection rather useless — attackers including SCATTERED SPIDER, BlackBasta, and Akira are using them to disable security controls and encrypt multiple virtual machines simultaneously. Worth reading if you're responsible for hypervisor security or threat hunting in virtualised environments.

That's all for today. The original articles are the work of their authors — the analysis here was automated.

📰 Articles Covered