r/blueteamsec is a subreddit with 70k members. The most common kinds of discussions are news and solution requests, and the community frequently discusses cve 2026 16723, yara x rules, packetsmith, local ai agents, and endpoint ai agents.
We focus on technical intelligence, research and engineering to help operational [blue|purple] teams defend their estates and have awareness of the world.
Our primary home is on Lemmy after the great ban debacle of 2025.
Popular Themes in r/blueteamsec
#1
News
: "Amazon identifies North Korean hacker group behind open-source supply chain attacks"
10 posts
#2
Solution Requests
: "data-diode: A Data Diode with 2 Raspberry Pi and OpenBSD"
5 posts
#3
Advice Requests
: "Sources for post-infection PCAP (C2 beaconing, exfiltration) - what am I missing?"
3 posts
#4
Pain & Anger
: "DNS Poisoning Tactics Expand to Hospitality Wi-Fi"
1 post
Popular Topics in r/blueteamsec
#1
Cve 2026 16723
2 posts
#2
Yara X Rules
2 posts
#3
Packetsmith
2 posts
#4
Local Ai Agents
: "Curated catalog of local AI agent abuse techniques and real-world cases"
2 posts
#5
Endpoint Ai Agents
: "Open-Source Visibility, Detection, and Enforcement for Endpoint Ai Agents"
2 posts
#6
Open Source
: "Open-Source Visibility, Detection, and Enforcement for Endpoint AI Agents"
2 posts
#7
Shellcode
1 post
#8
Cyber Resilience
1 post
Flair Used in r/blueteamsec
#1
intelligence (threat actor activity)
: "Finding actors that probe a CVE's exploit path before public disclosure in 30M honeypot records."
51 posts
#2
tradecraft (how we defend)
: "ADR: ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber."
22 posts
#3
highlevel summary|strategy (maybe technical)
: "Cisco's Transition to a Risk-Based Vulnerability Disclosure Model"
22 posts
#4
low level tools|techniques|knowledge (work aids)
: "Careful adoption of Agentic AI in cyber defence"
20 posts
#5
research|capability (we need to defend against)
: "Inside the Falcon How CrowdStrike Catches You"
17 posts
#6
vulnerability (attack surface)
: "Apple Screen Sharing Pre-Auth RCE (macOS ≤ 26.5)"
16 posts
#7
malware analysis (like butterfly collections)
: "HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels"
11 posts
#8
discovery (how we find bad stuff)
: "The One Chokepoint to Rule Them All: Why I Deleted 50 ClickFix Detection Rules and Replaced Them with One"
10 posts
#9
incident writeup (who and how)
: "We pushed .env files with working canary credentials to public GitHub repos - attacker timeline and the gaps in GitHub/AWS automated response"
9 posts
#10
exploitation (what's being exploited)
: "Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure"
9 posts
Member Growth in r/blueteamsec
Yearly
+15k members(26.2%)
Similar Subreddits to r/blueteamsec
r/AskNetsec
260k members
14.4% / yr
r/cybersecurity_
665 members
114.5% / yr
r/Cybersecurity101
62k members
204.2% / yr
r/Cyber_Security_News
1k members
37.7% / yr
r/Infosec
38k members
28.5% / yr
r/netsec
569k members
6.9% / yr
r/purpleteamsec
9k members
20.5% / yr
r/pwnhub
41k members
398.3% / yr
r/SecOpsDaily
13k members
598.9% / yr
r/threatintel
17k members
81.8% / yr
About
GummySearch helps people research Reddit communities by organizing activity, growth, themes, and post-level signals into one place.
This page gives a focused view of r/blueteamsec, including current member size, discussion patterns, product reviews, and related communities to explore.
This data is synced periodically so insights stay current and useful for ongoing research.
Last updated: August 6, 2026