This is your security briefing for Friday the 18th of September 2026, drawn from the BlueTeamSec community on infosec.pub. Seven stories to get through today.
DomainTools published research on Lemmings, a Python framework built by Russian company Okenit for industrial-scale fake persona management. It automates everything from AI-generated profiles to phone verification and anti-detection measures, letting small teams run thousands of synthetic accounts across social platforms. One for anyone tracking influence operations infrastructure.
Kaspersky have a write-up on NightEagle, an APT that's shifted from targeting Asia to focusing on Russian organisations since 2023. They're using the GhostContainer backdoor to compromise Exchange servers via an old vulnerability, then tunnelling through Active Directory for persistence and exfiltration. Worth a look if you're tracking APT campaigns pivoting geographic focus.
The Natto Team published a detailed investigation linking Chinese hacking group QTFY to the Ministry of State Security and a network of private contractors including firms called ELEX and Lexbell. QTFY's been targeting U.S. federal agencies and critical infrastructure since 2018, including NASA and the Federal Reserve. This follows the Gitea exploitation campaign and multi-target operations we covered earlier this week, so it adds useful context to that thread.
Wokb.cz released their 2026 APT Blog, documenting what they describe as a blurring of lines between state-sponsored espionage and financially motivated cybercrime. The characterisation is of hybrid campaigns that don't fit neatly into traditional buckets. One for strategic context rather than tactical detail.
CISA published guidance on using cyber decoys to improve detection and response, particularly against adversaries using legitimate credentials and living-off-the-land techniques. The framework is pitched at organisations across different maturity levels, so it's accessible whether you're already running honeypots or just considering the idea.
HPE disclosed multiple vulnerabilities in their EdgeConnect SD-WAN products, including a critical remote code execution flaw, information disclosure issues, and a denial-of-service bug in the embedded Suricata engine. Severity ranges from unauthenticated data access to authenticated admin achieving arbitrary command execution. Flag this if you're running EdgeConnect in your environment.
And Cisco Talos reported active exploitation of vulnerabilities in Cisco Secure Firewall Management Center. No detailed technical breakdown in this alert, but if you're running FMC, treat this as immediate priority patching. We covered a related SQL injection flaw in Cisco Secure Email Gateway earlier this week, so Cisco's had a rough few days.
That's your briefing for today. The articles are the work of their original authors — the analysis here was automated.