🛡️ InfoSec Blue Team Briefing

Sunday, September 13, 2026

🎧 Audio Briefing

Download MP3

This is the security briefing for Sunday the 13th of September 2026, drawn from the BlueTeamSec community on infosec.pub. Seven stories to get through today.

Root Evidence has published a comprehensive analysis of eight years' worth of vulnerability data, covering over 250,000 CVEs. The headline finding is that there's no evidence of an AI-driven explosion in zero-day exploitation — most adversaries still focus on unpatched known vulnerabilities, and the median time to exploit has actually increased to nearly four months. Worth reading if you've been wondering whether the sky really is falling.

watchTowr Labs have the details on two zero-day vulnerabilities in PaperCut that are being actively exploited in the wild. Attackers are chaining an authentication bypass with a remote code execution flaw to deploy in-memory webshells, making persistence nearly invisible to standard forensics. This follows on from the AI-orchestrated campaign we covered a couple of days ago — if you're running PaperCut instances exposed to the internet, assume compromise and capture memory before you restart anything.

Dirk-jan Mollema has released askWAM, a proof-of-concept tool that silently steals Microsoft Entra ID tokens via the Windows Web Account Manager. If an attacker has local access to a machine, they can pull tokens without triggering MFA or any user interaction, bypassing protections like Token Protection. We covered a token tracking tool and some Entra ID token theft research earlier in the week — this is another piece in that puzzle.

Huntress researchers have published the second part of their series on Active Directory Rights Management Service, demonstrating how attackers with admin access can extract an unrotatable root key that allows perpetual offline decryption of protected documents. If your organisation relies on AD RMS or the hold-your-own-key model with Azure, this one's essential reading.

SpecterOps have analysed how Microsoft Configuration Manager executes applications, revealing that legitimate administrative actions are routed through an obfuscated process chain that makes malicious activity extremely difficult to distinguish from normal operations. One for defenders trying to build detection logic in SCCM environments.

A technical deep dive on the JellyBee offensive framework and its JBKORE compiler, which enable modular in-memory execution using Beacon Object Files. The system is designed to minimize forensic artifacts through diskless execution — useful background if you're tracking red team tooling trends.

And finally, researchers have released kunglao-agent, an autonomous reverse-engineering system designed for multi-day, unattended analysis of binaries and mobile applications. It uses a maker-checker architecture where every claim must be independently verified and anchored to raw evidence with cryptographic hashes. If you're working with reverse engineering workflows or looking at how AI agents are being applied to security research, this one's worth a look.

That's everything for today from BlueTeamSec. The articles are the work of their original authors — the analysis here was automated. We'll be back tomorrow.

📰 Articles Covered