Security news from the BlueTeamSec community for Saturday the 19th of September 2026. I'm Tess.
I'm Sebastian. Australia's Cyber Security Centre has put out an advisory on WaterPlum, the North Korean group behind those fake recruitment campaigns targeting IT workers. They're going after developers in AI, crypto, and Web3, posing as employers and getting victims to run malicious code during fabricated technical interviews. One for anyone hiring remotely or working in those sectors.
ESET have written up SparroWocky, a new modular backdoor from the China-aligned group FamousSparrow. It replaced their previous implant last year and has been turning up at government targets across Latin America β Argentina, Ecuador, Guatemala, and several others. Advanced anti-analysis features and a habit of integrating open-source offensive tools once they're in.
NCC Group have documented a pair of denial-of-service attacks against WPA3, exploiting how the authentication protocol forces access points to do expensive cryptographic work before they even know who's connecting. The Cookie Guzzler variant is still viable, vendor fixes have been patchy, and the exploit tooling is now bundled into frameworks like airgeddon. Worth flagging if you're running WPA3 in any kind of high-density environment.
And finally, a researcher has published technical documentation and reverse engineering work on Microsoft's new Windows Endpoint Security Platform, which is appearing in Windows 11 Insider builds. It's a shift away from the old minifilter model towards in-kernel decision-making, so security vendors building endpoint products will need to understand this architecture sooner rather than later.
That's everything for today from BlueTeamSec. The articles are the work of their original authors β the analysis here was automated.