🛡️ InfoSec Blue Team Briefing

Saturday, September 05, 2026

🎧 Audio Briefing

Download MP3

Security news from the BlueTeamSec community for Saturday the 5th of September 2026 — a busy one, with eleven stories. I'm Tess.

And I'm Sebastian. The Australian Signals Directorate's Cyber Security Centre has published guidance on managing communications during cyber incidents — particularly aimed at managed service providers. It's a framework for establishing response teams, keeping messaging factual, and shielding technical staff from constant stakeholder queries while still getting actionable information out the door. One for anyone who's had to brief executives while remediation is still underway.

A new sandboxing tool called Ephemora Cell has been released for executing untrusted AI-generated code. It's WebAssembly-based, blocks filesystem access, networking, and shell operations by default, and enforces explicit CPU, memory, and time limits. This follows Anthropic's recent note that all cyber evaluations should run in hardened sandboxes — so the timing's rather apt.

The U.S. State Department's Rewards for Justice programme is now offering up to ten million dollars for information on Amir Yaryab, head of Iran's Revolutionary Guard cyber operations command. He's tied to multiple groups including CyberAv3ngers and others targeting critical infrastructure worldwide — defence, energy, finance, telecoms, transport. We've covered several of those groups in recent weeks, including BlueDelta and Tortoiseshell operations.

Whisper Security mapped the infrastructure of Iranian group Prince of Persia, also known as Infy. They've found dormant reserve command-and-control domains pre-staged for future operations — registered via Spaceship and delegated to actor-controlled nameservers, allowing rapid activation without triggering the usual security alerts. Worth a look if you track Iranian infrastructure patterns.

The Citizen Lab confirmed that NSO Group's Pegasus spyware infected a Serbian pro-democracy student activist via zero-click iMessage exploit between December 2025 and January this year. At least fourteen individuals, including student activists and an opposition MP, received Apple threat notifications ahead of the 2026 elections. The zero-click exploit has since been patched in iOS eighteen point four point one. We last covered Pegasus in July, when Amnesty International published details on the system's evolution.

The U.S. Department of Justice indicted and extradited Russian national Searzhudin Aktulaev for exploiting a freelance employment platform to distribute malware between 2016 and 2017. He used malicious Excel attachments to deliver remote access tools to roughly eighty thousand users worldwide, exfiltrating credentials and personal information via command-and-control infrastructure funded with virtual currency. The technique's familiar, but the scale and the platform abuse are notable.

Coder disclosed that an attacker compromised their Cloudflare infrastructure on the thirty-first of August and injected unauthorised IP addresses to serve malicious registry packages for about fourteen hours. The malicious code was designed to exfiltrate database passwords, authentication tokens, and SSH keys to a command-and-control domain registered days before the attack. Anyone who downloaded modules or created workspaces during that window should assume compromise.

Huntress identified rogue ScreenConnect installations spreading across unrelated organisations through social engineering. Compromised endpoints automatically infected other systems connecting via ScreenConnect sessions, deploying crypto miners, tunnelling tools, and privilege escalation payloads. The propagation method suggests worm-like behaviour, which is uncommon for remote management tools exploited in the wild.

A multinational law enforcement operation led by the FBI disrupted the Sality botnet, which has been active since 2003. The peer-to-peer botnet was used for cryptocurrency theft and launching cyberattacks — the operation involved seizing domains and executing a sinkhole technique with support from agencies in Bulgaria, Hungary, Romania, and partners including CrowdStrike and the Shadowserver Foundation. Twenty-three years is quite a run.

And finally, Broadcom have written up a trend where threat actors are deploying legitimate, signed Node.js binaries to execute malicious scripts while evading signature-based detection. The campaign's been running since February, impacting government, technology, fintech, education, and hospitality sectors. It's been linked to multiple ransomware groups including Qilin, Interlock, Rhysida, and several others, as well as tools like ModeloRAT and AsukaStealer. The technique uses blockchain-based command-and-control and registry persistence — not new, but increasingly common. We covered a similar Node.js-based campaign from Mirage Kitten earlier this week.

That's everything for today from BlueTeamSec. The articles are the work of their original authors — the analysis here was automated. We'll be back next time.

📰 Articles Covered