🛡️ InfoSec Blue Team Briefing

Saturday, October 10, 2026

🎧 Audio Briefing

Download MP3

This is the infosec briefing for Saturday the 10th of October 2026, drawn from the BlueTeamSec community on infosec.pub. A busy one today, with twelve stories to get through.

The U.S. Department of Justice and FBI have seized infrastructure belonging to China-based Integrity Technology Group — specifically two platforms called Microscan and FishHub. The first used a Mirai botnet for vulnerability scanning, the second was a full spear-phishing platform, and both were aimed at critical infrastructure in the U.S. and Taiwan, as well as airports and NGOs. This is the second time the same company's state-sponsored operations have been disrupted.

The UK's National Cyber Security Centre, along with international partners, has formally attributed long-running malicious cyber activity to actors linked to that same company, Integrity Tech. The advisory flags their use of AI-enabled scanning tools, large-scale botnets, and hands-on exploitation to exfiltrate sensitive data across multiple industries worldwide.

And Dutch intelligence — the AIVD and MIVD — have published a warning that Chinese state-sponsored actors are systematically exploiting vulnerabilities in edge devices like firewalls, VPNs, and routers to gain initial network access. The agencies expect this targeting to increase significantly in the coming years.

Palo Alto Networks has written up the Blinder Tunnel campaign, which targeted critical infrastructure in Iraq, Israel, and the UAE — particularly aviation and telecoms sectors. The Iranian state-aligned actor behind it used spear-phishing emails masquerading as Dubai Airports IT staff, delivering trojanised coding challenges to software engineers. Reconnaissance dates back to November last year, with the main operation kicking off in March.

Zscaler have dissected a supply chain attack from North Korean group TraderTraitor — also tracked as Jade Sleet and UNC4899. In July, they distributed a trojanised Terraform provider targeting cryptocurrency developers and cloud engineers. The malware delivered cross-platform backdoors that exfiltrated browser credentials and wallet data via Telegram, GitHub API, and Nostr-based command and control.

CrowdStrike have reported on an unknown, likely Chinese-speaking financially motivated actor who hit multiple South Korean financial institutions in September and October, successfully exfiltrating data from loan inquiry and employee work systems. The notable bit here is their use of ARTEX — an open-source Chinese penetration testing tool that integrates with multiple large language models to automate offensive operations.

OX Security flagged a supply chain compromise in the npm package 'tensorlake' — version zero point five point one four four was hit with malware called Shai-Hulud. The package gets twelve thousand downloads a week, and the malware name has appeared in previous supply chain incidents, possibly from copycat actors.

Researchers Ian Muscat and Leanne Briffa have documented a phishing technique that bypasses Chromium's typosquatting protections by exploiting edge cases in how Unicode domains are rendered. Attackers use what they call 'breaker' characters to craft malicious domains that appear legitimate in the address bar rather than displaying as Punycode. Affects Chrome, Edge, and Brave users, and enables credential harvesting that evades visual security indicators.

ESET Research published analysis on MATCHBOIL malware, detailing new techniques the threat is using while maintaining its previously observed objectives. We've covered related tooling and techniques in this area a few times over the past week or so.

Hatching have written up WinLol, a previously undocumented multi-stage malware toolkit from July that targets gamers by impersonating the Riot Games client. It's a four-stage infection chain starting with a Rust dropper, progressing through DLL side-loading of OneDrive, and ending with a WebRTC-based remote access tool that captures victims' screens in real time. Extensive anti-sandbox checks, UAC bypass, and firewall manipulation throughout.

VMRay researchers used machine learning behavioural analysis to cluster two hundred and seventy-six Formbook malware samples, revealing a coordinated global business email compromise campaign running on unified infrastructure. The methodology focused on execution behaviour rather than static indicators, which let them track campaign evolution in ways that traditional defences miss.

And finally, Meta have released bpfjailer, an open-source security tool that provides fine-grained, policy-based process isolation using eBPF Linux Security Modules. It places processes into isolated 'pods' with policies defined in TOML files, intercepting system calls and restricting resource access in real time beyond what standard containers offer.

That's everything for today from BlueTeamSec. The writing is by the original authors — the analysis was automated.

📰 Articles Covered