🛡️ InfoSec Blue Team Briefing

Thursday, September 03, 2026

🎧 Audio Briefing

Download MP3

This is the security briefing for Thursday the 3rd of September 2026, drawn from the BlueTeamSec community on infosec.pub. A busy one today, with 12 stories to get through.

Plume Security Lab have documented how SuperBox streaming devices are being silently enrolled into residential proxy networks without user consent, then weaponised to deliver additional malware. Your home internet connection becomes a proxy node for command-and-control traffic and secondary payloads — infection layering that's difficult to spot or remove.

Check Point Research have published a static deobfuscation method for JSCeal malware, which uses compiled V8 bytecode to evade detection. They've built tooling around the View8 decompiler to reverse engineer the malware without executing it — worth flagging if you're tracking threats to cryptocurrency platforms.

Huntress have written up an abuse campaign targeting the Faronics Deploy IT management platform. Attackers used phishing to trick users into installing the legitimate agent, then leveraged native remote script execution to deploy ScreenConnect and establish persistent access — living-off-the-land evasion throughout.

The U.S. Attorney's Office in Kansas announced guilty pleas from five Venezuelan nationals involved in ATM jackpotting attacks. They used malware to remotely trigger cash dispensing after gaining physical access to install it. FBI reporting shows over 1,900 incidents nationwide since 2020, with 700 in 2025 alone — over 20 million dollars in losses.

And another Teams-based attack — Palo Alto Networks have tracked the 'Spring Ring' campaign, which uses voice phishing through Microsoft Teams to impersonate IT support staff. Attackers exploit the 'Chat with Anyone' feature to establish trust, then deploy remote access trojans or escalate to things like PetitPotam exploitation for relay attacks against domain controllers. If your organisation uses external Teams federation, flag this one.

METR disclosed two incidents from early this year: an API key theft in March where an attacker exploited a fail-open authentication flaw in a researcher's EC2 instance, consuming 600,000 dollars in API credits over three weeks; and a May campaign involving credential stuffing, OAuth token exploitation, and phishing. A bug in a public transcript viewer inadvertently exposed a read-only SQL query mechanism during May, though METR believe it wasn't successfully exploited.

BGPHorizon have documented the Virtualizor incident from late August. Attackers executed a BGP hijacking attack against Hetzner address space used by Softaculous and Virtualizor, using a forged-origin, more-specific prefix technique to bypass RPKI validation, then obtained valid TLS certificates and delivered malicious updates to a subset of Virtualizor installations. We covered the initial compromise on the 2nd — this is the technical post-mortem.

Google are tracking BREEZE COMET, a financially motivated actor targeting Brazilian financial, retail, and eCommerce organisations since 2024. They've gone after core payment infrastructure — Pix, STR, and Boleto systems — and successfully executed at least one heist worth tens of thousands of dollars through direct manipulation of payment switches and banking software.

Microsoft Defender Experts are tracking a deceptive software download campaign with parallels to Silver Fox, using counterfeit vendor websites to distribute multi-stage malware. The campaign primarily targets Chinese-speaking users and multinationals operating in China across healthcare, manufacturing, tech, logistics, government, higher education, and gaming. Sophisticated defence evasion includes disabling Defender, deleting shadow copies, and enabling hands-on-keyboard lateral movement.

Kaspersky Lab have documented Mirage Kitten conducting cyberespionage against aviation and FinTech professionals in the Middle East and Africa. The campaign uses fake job recruitment lures via LinkedIn to deliver NodeRabbit, a cross-platform Node.js-based remote access tool, targeting software engineers in Egypt, Ethiopia, and Afghanistan. It represents a shift to script-based, cross-platform implants hosted on legitimate cloud infrastructure.

Enclave researchers tested seven AI models as autonomous agents attempting to achieve remote code execution against vulnerable software including Grafana, Jenkins, and Nextcloud. Leading models successfully transitioned from vulnerability identification to full exploit execution — top performers like GPT 5.6 Sol handled complex multi-stage attack scenarios within controlled time constraints. One for anyone tracking AI-enabled offensive capabilities.

And finally, researchers demonstrated a side-channel attack where computer monitors can be weaponised as unintended radio transmitters by manipulating pixel patterns and screen refresh rates. By controlling display resolution and refresh timing, the monitor's pixel clock generates electromagnetic interference in VHF and UHF bands that can transmit data — such as Morse code — to nearby radio receivers. Exploits hardware-level electromagnetic emanations to potentially exfiltrate data from air-gapped systems.

That's your briefing for today. The articles are the work of their original authors — the analysis here was automated. We'll be back tomorrow.

📰 Articles Covered