🛡️ InfoSec Blue Team Briefing

Saturday, August 29, 2026

🎧 Audio Briefing

Download MP3

Security news from the BlueTeamSec community for Saturday the 29th of August 2026. Six stories to get through this morning.

CERT Austria reports a significant uptick in business email compromise attacks targeting Austrian organisations. Attackers are impersonating executives and suppliers to manipulate staff into transferring funds or handing over sensitive information — social engineering rather than technical exploits, using look-alike domains and compromised accounts. We covered a related SMTP spoofing technique just yesterday that fits the same pattern.

The White House has declared a national emergency over foreign-supplied electrical equipment in the U.S. bulk power system. The executive order prohibits transactions involving equipment from certain foreign entities, citing risks of digital backdoors and supply chain compromises in critical infrastructure — transformers, industrial control systems, grid management hardware, the lot.

The UK National Cyber Security Centre is warning about disruptive cyber operations targeting internet-exposed operational technology and edge devices — routers, VPNs, firewalls. The advisory highlights misconfigurations and unmanaged assets that let adversaries bypass perimeter defences and disrupt industrial processes, with comprehensive hardening guidance included. Worth flagging if you're responsible for OT environments or perimeter security.

Researchers at Verabit Labs disclosed two critical vulnerabilities in Signal's contact discovery service running on Intel secure enclaves — a use-after-free and a time-of-check-time-of-use race condition. The flaws allowed a malicious host operator to extract the enclave's private key, impersonate the enclave, decrypt user queries, and execute arbitrary code inside what's supposed to be a trusted environment. One for anyone deploying enclave-based architectures.

Tailscale has released Tailcat, an open-source netcat alternative that creates encrypted peer-to-peer tunnels without requiring control plane infrastructure or admin privileges. It runs entirely in userspace using WireGuard encryption and handles NAT traversal and fallback connectivity automatically. This follows fairly closely on the heels of BOFScale, which we covered earlier this month — offensive use cases for Tailscale's data plane seem to be a recurring theme.

And a researcher has benchmarked twenty-seven AI models to see whether they can autonomously conduct cyber threat intelligence investigations. Testing showed AI can't replace human analysts but does well at bounded investigative tasks, with some local models competitive with frontier models for specific workflows. Useful context given the swarm-based Hugging Face intrusion we covered yesterday.

That's all for today. As always, the articles are the work of their original authors — the analysis here was automated.

📰 Articles Covered