πŸ›‘οΈ InfoSec Blue Team Briefing

Friday, August 21, 2026

🎧 Audio Briefing

Download MP3

Security news from the BlueTeamSec community for Friday the 21st of August 2026. Six stories to get through today.

The Royal United Services Institute has published research on North Korea's crypto laundering operation, looking at how the regime is successfully converting billions in stolen cryptocurrency into fiat currency to fund weapons programmes. The focus is on weaknesses in virtual asset service providers and their interfaces with traditional banks β€” essentially the chokepoints where sanctions should bite but currently don't. Worth reading if you're involved in financial crime compliance or threat finance work.

Bitdefender has tracked a China-linked espionage campaign called SilkParasite across Central Asia, hitting government organisations in Uzbekistan, Turkmenistan, and several others in the region. They've catalogued seven remote access tools, five of which are new, and noted signs of AI-assisted development alongside the usual sideloading persistence tricks. This follows on from the Myanmar diplomatic targeting we covered on the 20th β€” appears to be part of a broader regional intelligence collection effort.

CISA has issued an advisory on active threats to Siemens S7 series programmable logic controllers, with particular emphasis on AI-enhanced reconnaissance capabilities that are speeding up attack timelines against operational technology environments. The guidance covers hardening engineering workstations, network segmentation, and offline backup procedures for PLC configurations. One for critical infrastructure operators and anyone supporting industrial control systems.

NetSPI has released a red team technique called BOFScale that runs a Tailscale node entirely in memory as a Beacon Object File, fronting command-and-control traffic through major CDNs like CloudFront and Fastly. It modifies Tailscale to use WebSockets, avoids disk writes and kernel drivers, and makes C2 traffic look identical to legitimate CDN traffic. Useful read for detection engineers trying to spot anomalous patterns in otherwise trusted infrastructure.

Cisco Talos has applied Crime Script Analysis, a criminology framework, to Business Email Compromise attacks and found that attackers are increasingly automating preparation steps with AI, enabling a shift from high-value, low-volume fraud to lower-value, high-volume scams that can hit organisations of any size. The piece walks through how understanding attack workflows can inform better detection strategies. Adds useful context if you're working on BEC defences or anti-fraud controls.

And finally, Horizon3 evaluated twenty-one large language models against human attackers in simulated environments containing deception traps. The models fell for traps at nearly double the rate of humans β€” seventy-eight percent versus thirty-seven β€” and even when they correctly identified a trap, they exploited it anyway seventy-three percent of the time. The conclusion is that traditional honeypot design principles don't transfer well to AI-driven attackers, which is a challenge for defenders relying on deception as a detection layer.

That's everything for today from BlueTeamSec. The articles are the work of their original authors β€” the analysis here was automated.

πŸ“° Articles Covered