Skip to content
.ca

cyfar.ca

DFIR, deception, detection. Posts I wrote, intel my pipeline summarized, and redacted writeups from the fleet.

Elastic Security Labs17 days agoLLM reporthigh

CI/CD pipeline abuse: the problem no one is watching

Attackers are increasingly targeting CI/CD pipelines to harvest secrets and pivot to production environments using techniques like workflow modification and privileged trigger exploitation. Elastic has released an open-source tool, cicd-abuse-detector, which leverages regex-based signal extraction and LLM analysis to detect suspicious pipeline changes during the pull request phase.

Check Point17 days agoLLM reportcritical

VECT: Ransomware by design, Wiper by accident

VECT 2.0 is a cross-platform (Windows, Linux, ESXi) Ransomware-as-a-Service that effectively functions as a wiper due to a critical cryptographic implementation flaw. Files larger than 128 KB are encrypted in chunks using raw ChaCha20-IETF, but the malware fails to save the required nonces for the first three chunks, rendering full data recovery impossible even if the ransom is paid.

Recorded Future17 days agoLLM reporthigh

The Money Mule Solution: What Every Scam Has in Common

The article highlights the critical role of money mule accounts in Authorized Push Payment (APP) fraud and scams, which bypass traditional breach-based detection by manipulating victims into authorizing payments. It advocates for an intelligence-led approach, utilizing agentic personas to proactively identify and verify mule accounts before fraudulent transactions occur, thereby mitigating financial losses and addressing growing regulatory pressures.

Akamai17 days agoLLM reporthigh

The API Weak Spot: Study Shows AI Is Compounding Security Pressures

A recent Akamai study reveals that API security incidents are escalating, exacerbated by the rapid adoption of AI technologies like LLMs. Organizations are struggling with API visibility and governance, leading to increased susceptibility to BOLA attacks, business logic abuse, and prompt injection, which bypass traditional WAFs and result in significant financial losses.

ANY.RUN17 days agoLLM reporthigh

Phishing-to-RMM Attacks: The Remote Access Blind Spot CISOs Can’t Ignore

Threat actors are increasingly leveraging phishing campaigns to deliver legitimate Remote Monitoring and Management (RMM) tools like ScreenConnect and LogMeIn Rescue, bypassing traditional malware defenses. These attacks often utilize compromised domains, SEO injection, and VBS scripts to weaken endpoint controls (e.g., SmartScreen, Defender) before silently installing the RMM payload, creating significant visibility gaps for SOC teams.

Recorded Future17 days agoLLM reporthigh

Lazarus Doesn't Need AGI

North Korean state-sponsored actors, including Lazarus and TraderTraitor, are highly motivated to access advanced AI models to accelerate their labor-intensive cryptocurrency heists. The primary attack vectors are not direct breaches of AI cryptographic perimeters, but rather supply chain compromises, fraudulent hiring of DPRK IT workers, and third-party contractor misuse.

Cisco Talos17 days agoLLM reportinfo

Intelligence Center

The Cisco Talos Year in Review highlights a shifting threat landscape where attackers leverage AI and rapid exploit development to target identity infrastructure and exposed vulnerabilities. Defenders are urged to prioritize identity protection, remediate internet-facing vulnerabilities, address legacy system risks, secure trust-brokering platforms, and focus on behavioral anomaly detection to identify post-compromise activity.

Canadian Centre for Cyber Security17 days agoLLM reporthigh

Cyber Centre Daily Advisory Digest — 2026-04-28 (4 advisories)

The Canadian Centre for Cyber Security released a daily digest highlighting recent security advisories from SmarterTools, Zyxel, Citrix, and Mozilla. Notably, Zyxel addressed command injection vulnerabilities across various networking devices, while the other vendors released standard security updates for their respective software products.

CrowdStrike17 days agoLLM reportlow

CrowdStrike Expands ChatGPT Enterprise Integration with Enhanced Audit Logging and Activity Monitoring

CrowdStrike has expanded its Falcon Shield integration with ChatGPT Enterprise to deliver enhanced audit logging and continuous activity monitoring. This update shifts the focus from basic configuration awareness to operational visibility, enabling security teams to track authentication, administrative changes, Codex events, and AI tool usage to enforce governance and detect threats in SaaS environments.

CISA17 days agoLLM reporthigh

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added CVE-2024-1708 (ConnectWise ScreenConnect Path Traversal Vulnerability) and CVE-2026-32202 (Microsoft Windows Protection Mechanism Failure Vulnerability) to the Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize patching these systems to mitigate significant risks to their enterprise environments.

Socket17 days agoLLM reporthigh

73 Open VSX Sleeper Extensions Linked to GlassWorm Show New Malware Activations

The GlassWorm threat campaign has escalated its supply chain attacks on the Open VSX marketplace by publishing 73 impersonation 'sleeper' extensions. These extensions initially contain no malicious code to bypass security scans, but are later updated to act as thin loaders that retrieve and execute secondary .vsix payloads from GitHub releases using bundled native binaries or obfuscated JavaScript.

Huntress17 days agoLLM reportlow

What Is Multi-Factor Authentication? A Complete Guide to MFA Security

This article provides a comprehensive overview of Multi-Factor Authentication (MFA), detailing its core mechanisms across knowledge, possession, and inherence factors. It highlights the security advantages of hardware keys and authenticator apps over SMS-based methods due to risks like SIM swapping, and outlines strategic implementation practices for organizations to mitigate credential theft and account takeover risks.

Huntress17 days agoLLM reportlow

So Fresh, So Clean: Huntress’ Top Cyber Hygiene Tips

This article outlines foundational cybersecurity hygiene practices recommended by the Huntress SOC to reduce organizational attack surfaces. Key recommendations include enforcing MFA, securing or disabling exposed RDP, implementing strict access controls, and monitoring for behavioral indicators of compromise such as defense evasion, domain enumeration, and privilege escalation.

Huntress17 days agoLLM reporthigh

How Unified EDR and ITDR Stop Attacks Before They Spread

Huntress details the operational benefits of unifying EDR and ITDR to combat infostealers and rapid credential abuse. A highlighted incident demonstrates a ClickFix social engineering attack leveraging WebDAV and rundll32.exe to execute a remote payload, which was mitigated by automatically isolating the host and revoking associated Microsoft 365 identity sessions.

Canadian Centre for Cyber Security17 days agoLLM reportcritical

Cyber Centre Daily Advisory Digest — 2026-04-27 (9 advisories)

The Canadian Centre for Cyber Security released a daily digest of nine security advisories covering critical vulnerabilities across enterprise software, Linux kernels, and industrial control systems (ICS). Organizations are urged to apply patches for affected products from vendors including IBM, Dell, Ubuntu, Red Hat, Moxa, VMware, Notepad++, and Microsoft to prevent potential exploitation.

Arctic Wolf17 days agoLLM reportcritical

BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector

Arctic Wolf Labs identified a highly targeted campaign by the DPRK-nexus threat actor BlueNoroff against the Web3 sector. The attackers utilize sophisticated social engineering, including AI-generated deepfakes and stolen webcam footage, to lure victims into fake Zoom or Teams meetings. Once engaged, a ClickFix clipboard injection attack deploys a fileless PowerShell C2 implant, leading to the theft of cryptocurrency wallets, browser credentials, and Telegram sessions.

Elastic Security Labs17 days agoLLM reportinfo

Monitoring Claude Code/Cowork at scale with OTel in Elastic

Elastic's InfoSec team details a scalable architecture for monitoring AI coding assistants, specifically Claude Code and Cowork, using OpenTelemetry and Elasticsearch. The solution provides security teams with critical visibility into AI agent activities, including shell command execution, file access, and internal API interactions, enabling advanced threat detection, incident response, and EDR correlation.

Arctic Wolf17 days agoLLM reporthigh

Token Bingo: Don’t Let Your Code be the Winner

A widespread phishing campaign is leveraging the Kali365 Live Phishing-as-a-Service (PhaaS) platform to execute device code phishing and AiTM attacks. By tricking users into authorizing legitimate Microsoft device login requests, threat actors steal OAuth access and refresh tokens, bypassing traditional credential-based defenses and MFA to gain persistent access to Microsoft 365 environments.