Skip to content
.ca

cyfar.ca

DFIR, deception, detection. Posts I wrote, intel my pipeline summarized, and redacted writeups from the fleet.

ANY.RUN17 days agoLLM reporthigh

How Phishing Is Targeting Germany’s Economy: Active Threats from Finance to Manufacturing

German critical industries are facing coordinated, highly targeted phishing campaigns utilizing Phishing-as-a-Service platforms like EvilProxy and FlowerStorm. These attacks leverage Adversary-in-the-Middle (AitM) techniques to intercept session cookies, effectively bypassing traditional Multi-Factor Authentication (MFA) to compromise Microsoft 365 and Okta accounts.

Cofense17 days agoLLM reporthigh

From Tax Refund to Total Compromise: IRS-Themed Phishing Email Drives Full-Stack Financial Fraud

A sophisticated, multi-stage phishing campaign is spoofing the IRS and Elon Musk to conduct full-stack financial fraud. The attack leverages promises of a $5000 tax refund to trick victims into surrendering extensive PII, government IDs, bank account details, and direct cryptocurrency transfers, with stolen data exfiltrated via Telegram.

Elastic Security Labs17 days agoLLM reportlow

Elastic on Defence Cyber Marvel 2026: A Technical overview from the Exercise Floor

Elastic provided the core defensive security platform and AI capabilities for the UK Ministry of Defence's Defence Cyber Marvel 2026 (DCM26) cyber exercise. The deployment featured a highly scalable, multi-tenanted Elastic Cloud architecture managed via Terraform, integrating advanced AI assistants and automated workflows to support 40 defending Blue Teams.

Socket17 days agoLLM reporthigh

Attackers Are Impersonating a Linux Foundation Leader in Slack to Target Open Source Developers

A high-severity social engineering campaign is actively targeting open source developers on Slack by impersonating Linux Foundation leaders. The multi-stage attack uses a fake AI tool lure to harvest credentials and trick victims into installing a malicious root certificate, leading to traffic interception and malware execution on macOS and Windows systems.

Recorded Future17 days agoLLM reportinfo

Understanding and Anticipating Venezuelan Government Actions

This report provides geopolitical intelligence on the political landscape of Venezuela following a January 2026 US military operation that removed Nicolás Maduro. It analyzes Acting President Delcy Rodríguez's strategies for consolidating power, managing internal regime rivals, and navigating US diplomatic pressure and OFAC sanctions relief.

Cofense17 days agoLLM reporthigh

The Growing Abuse of GitHub and GitLab in Phishing Campaigns

Threat actors are increasingly abusing legitimate Git repository platforms like GitHub and GitLab to host malware and credential phishing pages. By leveraging the inherent trust organizations place in these domains, attackers successfully bypass secure email gateways (SEGs) to deliver dual-threat campaigns involving remote access trojans (RATs), infostealers, and credential harvesting.

Akamai17 days agoLLM reportmedium

Protecting Publishing: The Real Cost of AI Bots

AI fetcher bots are severely impacting the publishing industry by scraping proprietary content in real-time to feed AI chatbots, leading to a drastic reduction in referral traffic and revenue. Organizations are advised to implement advanced bot management and monetization strategies rather than relying solely on default blocking to mitigate infrastructure strain and financial losses.

Socket17 days agoLLM reportinfo

Microsoft Releases Open Source Toolkit for AI Agent Runtime Security

Microsoft has released the open-source Agent Governance Toolkit to address the growing security risks associated with autonomous AI agents. The toolkit provides runtime policy enforcement, cryptographic identity, and execution sandboxing to mitigate threats outlined in the OWASP Top 10 for Agentic Applications, though challenges in credential scoping and semantic intent classification remain.

Cisco Talos17 days agoLLM reporthigh

Intelligence Center

Cisco Talos identified a new threat actor, UAT-10362, targeting Taiwanese organizations with a sophisticated Lua-based malware suite named LucidRook. The attack leverages spear-phishing, DLL sideloading, and compromised FTP servers to deliver staged Lua bytecode payloads while employing strict geo-fencing to evade analysis.

Canadian Centre for Cyber Security17 days agoLLM reportcritical

Cyber Centre Daily Advisory Digest — 2026-04-08 (3 advisories)

The Canadian Centre for Cyber Security released a daily digest highlighting vulnerabilities across HPE, CUPS, and GitLab products. Most notably, CUPS versions 2.4.16 and prior suffer from a critical remote unauthenticated RCE-to-root chain (CVE-2026-34990, CVE-2026-34980), requiring immediate mitigation and patching to prevent system compromise.

Palo Alto Networks17 days agoLLM reporthigh

Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox

Unit 42 researchers discovered a method to bypass the network isolation of Amazon Bedrock AgentCore's Code Interpreter sandbox using DNS tunneling. Combined with a legacy MMDSv1 configuration that lacked session token enforcement, attackers could potentially exploit SSRF to extract highly privileged IAM credentials and exfiltrate them via the DNS covert channel.

CISA17 days agoLLM reporthigh

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-1340, a code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM), to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. All organizations, especially federal agencies under BOD 22-01, are strongly urged to prioritize timely remediation to protect their networks against active threats.

Socket17 days agoLLM reportcritical

Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign

A sophisticated social engineering campaign linked to DPRK-nexus actor UNC1069 is targeting high-impact Node.js and npm maintainers. Attackers build rapport over weeks before luring victims to spoofed video conferencing sites that deploy infostealing malware designed to hijack session tokens, bypass 2FA, and compromise the open-source software supply chain.

Trail of Bits17 days agoLLM reporthigh

What we learned about TEE security from auditing WhatsApp's Private Inference

An audit of WhatsApp's Private Inference feature revealed critical implementation flaws in its Trusted Execution Environment (TEE) deployment. Vulnerabilities included unmeasured environment variables, unverified ACPI tables, and missing attestation freshness guarantees, which could have allowed attackers to bypass privacy protections and access plaintext data before Meta patched the issues.

Palo Alto Networks17 days agoLLM reportcritical

Understanding Current Threats to Kubernetes Environments

Threat actors are increasingly targeting Kubernetes environments by exploiting vulnerabilities like React2Shell and misconfigurations to steal service account tokens. These stolen identities are then used to escalate privileges and move laterally into backend cloud infrastructure, leading to severe impacts such as cryptocurrency theft.

NCSC17 days agoLLM reporthigh

UK exposes Russian military intelligence hijacking vulnerable routers for cyber attacks

The UK NCSC has issued an advisory warning that the Russian state-sponsored threat group APT28 is compromising vulnerable internet routers to conduct DNS hijacking. By altering DNS configurations, the attackers perform adversary-in-the-middle attacks to covertly reroute user traffic and harvest credentials and access tokens from personal web and email services.

Microsoft17 days agoLLM reporthigh

SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks

Russian military intelligence actor Forest Blizzard is compromising vulnerable SOHO routers to alter DNS settings and hijack network traffic. This compromised infrastructure is subsequently used to conduct selective Adversary-in-the-Middle (AiTM) attacks, intercepting TLS connections to steal credentials and sensitive data from targeted organizations.