🛡️ InfoSec Blue Team Briefing

Saturday, August 22, 2026

🎧 Audio Briefing

Download MP3

This is your security briefing for Saturday the 22nd of August 2026, drawn from the BlueTeamSec community on infosec.pub. We've got nine stories to get through, so let's get started.

IBM observed Mustang Panda running live espionage operations in simulated government and energy sector environments mid-year. The China-attributed group deployed custom backdoors including a newly identified tool called Havencode, and helpfully kept their activity confined to China Standard Time business hours. One for anyone tracking infrastructure-focused espionage campaigns in the region.

Bloomberg reported that T-Mobile physically disconnected a network cable back in 2024 to evict Chinese hackers from the Salt Typhoon group who'd compromised their infrastructure. The breach was part of a broader campaign that also affected AT&T and Verizon, targeting telecom networks to access cellphone communications of intelligence targets.

Google Threat Intelligence identified three Russian-linked clusters running targeted espionage against high-value individuals across the U.S., Europe, Ukraine, and Armenia. The operations used sophisticated social engineering including OAuth phishing and device-code attacks, with some clusters deploying malware like VIDAR and custom tools. Worth flagging if you're securing environments with academics, government staff, or think tank personnel.

Wiz disclosed a supply chain compromise of the Rust arrayref crate, affecting roughly three-quarters of Rust environments. North Korean actors used typosquatted dependencies and malicious build scripts to deploy a full-featured backdoor during compilation, exfiltrating browser credentials and maintaining persistence across Windows, macOS, and Linux. This follows North Korean activity we've covered recently, including crypto-to-fiat operations and IT worker infiltration campaigns.

Cloudflare researchers demonstrated an updated Spectre attack against Cloudflare Workers that bypasses previous mitigations. The side-channel exploit achieves cross-tenant memory leakage at 12 bits per second with 99 percent accuracy in production multi-tenant serverless environments. No evidence of active exploitation in the wild, but notable given how widely these architectures are deployed.

Check Point reverse-engineered the Windows Defender remediation driver and showed how it can be weaponised as a living-off-the-land driver. Attackers can craft malicious instructions in an alternate data stream to perform arbitrary file and registry operations at kernel level during boot time, disabling security solutions and establishing persistence across Windows 7 through 11. This builds on earlier work around Defender bypass techniques and kernel driver exploitation that we've covered this month.

Researchers demonstrated that standard user-mode processes without elevated privileges can disrupt antivirus and EDR update mechanisms using Windows file-handle semantics and byte-range locks. The technique targets the staging phase when updates are written to disk, causing products to become stale while appearing healthy to administrators. Multiple major vendors relying on standard staging directories are affected, and we've seen related signature bypass research surface in the past week.

Bitbison disclosed an unauthenticated remote code execution vulnerability in Langflow, an open-source AI agent framework. The flaw is actively exploited in the wild through authentication bypass and code validation endpoints, with attackers achieving full system compromise, deploying cryptominers, and stealing credentials in roughly 34 minutes. Langflow versions 1.0.0 through 1.10.0 are affected.

The National Cyber Security Centre published guidance on managing the security risks of agentic AI systems operating with high autonomy. AI agents may perform unintended actions through flawed instructions, environmental misinterpretations, or exploitation of accessible tools, with risk scaling according to the degree of autonomy granted. Useful background if you're evaluating or deploying these systems.

That's your briefing for today. The articles are the work of their original authors — the analysis here was automated. We'll be back with the next one soon.

📰 Articles Covered