Skip to content
.ca

cyfar.ca

DFIR, deception, detection. Posts I wrote, intel my pipeline summarized, and redacted writeups from the fleet.

Akamai17 days agoLLM reportmedium

Compliance Won’t Save Healthcare: Reducing the Blast Radius Will

The U.S. Department of Health and Human Services (HHS) Notice of Proposed Rulemaking (NPRM) emphasizes that healthcare organizations must move beyond basic HIPAA compliance to achieve true cybersecurity resilience. To combat the rising threat of ransomware, organizations are urged to implement continuous asset monitoring and microsegmentation to contain lateral movement, reduce the blast radius of attacks, and protect electronic protected health information (ePHI).

Socket17 days agoLLM reportcritical

Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise

The lead maintainer of the widely used Axios npm package fell victim to a sophisticated social engineering attack. Attackers tricked the maintainer into installing a Remote Access Trojan (RAT) during a fake MS Teams meeting, enabling session hijacking that bypassed 2FA and allowed the unauthorized publication of malicious Axios versions to the npm registry.

Mandiant17 days agoLLM reportcritical

vSphere and BRICKSTORM Malware: A Defender's Guide

Threat actors are increasingly targeting VMware vSphere environments, specifically the vCenter Server Appliance (VCSA) and ESXi hypervisors, to establish deep persistence and bypass traditional EDR solutions. This defender's guide outlines a comprehensive strategy to secure the virtualization control plane against advanced malware like BRICKSTORM, emphasizing infrastructure hardening, Zero Trust network segmentation, and enhanced OS-level forensic visibility using auditd and AIDE.

Watchtowr17 days agoLLM reportcritical

You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701)

Security researchers discovered a pre-authenticated Remote Code Execution (RCE) chain in Progress ShareFile Storage Zone Controller. By chaining an Execution After Redirect (EAR) authentication bypass (CVE-2026-2699) with an arbitrary file upload vulnerability (CVE-2026-2701), attackers can reconfigure the storage repository to the webroot and extract an ASPX webshell, achieving full system compromise.

Cofense17 days agoLLM reportinfo

The AI Security Compliance Gap: Fighting Polymorphic Phishing While Staying Regulatory Ready

Organizations face a dual challenge of combating rapidly evolving polymorphic phishing attacks using AI-driven automation while ensuring these opaque security tools comply with strict data governance regulations like GDPR and DORA. Security teams must prioritize transparent, auditable AI solutions to bridge this compliance gap.

CrowdStrike17 days agoLLM reportcritical

STARDUST CHOLLIMA Likely Compromises Axios npm Package

A DPRK-nexus threat actor, likely STARDUST CHOLLIMA, compromised the widely used Axios npm package using stolen maintainer credentials. The supply chain attack deployed updated, cross-platform variants of the ZshBucket malware capable of arbitrary command execution, payload injection, and file system enumeration, likely targeting the cryptocurrency and fintech sectors for financial gain.

Elastic Security Labs17 days agoLLM reportinfo

Prioritizing Alerts Triage with Higher-Order Detection Rules

Elastic outlines the methodology and operational benefits of Higher-Order Rules (HOR), which correlate atomic security alerts across entities, data sources, and timeframes. By aggregating signals from endpoints, network devices, and observability metrics, HORs significantly reduce alert fatigue and surface high-confidence malicious activity for prioritized SOC triage.

Recorded Future17 days agoLLM reporthigh

Latin America and the Caribbean Cybercrime Landscape

In 2025, the Latin America and the Caribbean (LAC) region faced escalating cybercriminal activity driven by rapid digital adoption and economic instability. Threat actors heavily utilized Telegram and dark web forums to distribute ransomware, banking trojans, and infostealers, increasingly targeting the healthcare, manufacturing, and government sectors while adapting to law enforcement disruptions.

Cisco Talos17 days agoLLM reporthigh

Intelligence Center

Advancements in AI have democratized Business Email Compromise (BEC) attacks, allowing threat actors to efficiently target smaller organizations with tailored social engineering. Concurrently, attackers are exploiting the React2Shell vulnerability (CVE-2025-55182) in Next.js applications to harvest cloud and database credentials, while Qilin ransomware has been observed deploying a sophisticated EDR-killing payload.

Elastic Security Labs17 days agoLLM reportcritical

How we caught the Axios supply chain attack

Suspected DPRK state actors compromised the highly popular Axios npm package by taking over a maintainer's account and publishing malicious versions that deployed a cross-platform RAT via a phantom dependency. Concurrently, a threat group named TeamPCP conducted a cascading supply chain attack affecting Trivy, LiteLLM, and Telnyx to harvest CI/CD credentials. These incidents underscore the critical need for automated package monitoring, rapid credential rotation, and delayed dependency updates.

Elastic Security Labs17 days agoLLM reporthigh

Hooked on Linux: Rootkit Detection Engineering

This article details behavioral detection engineering strategies for Linux rootkits, emphasizing the failure of static signatures against trivial binary modifications. It provides actionable detection logic for userland and kernel-space rootkits, including emerging threats leveraging eBPF and io_uring, alongside common persistence and defense evasion techniques.

Canadian Centre for Cyber Security17 days agoLLM reporthigh

Cyber Centre Daily Advisory Digest — 2026-04-02 (2 advisories)

The Canadian Centre for Cyber Security issued two security advisories. Apple released extensive updates across its operating systems to mitigate vulnerabilities, specifically targeting web attacks from the DarkSword iOS exploit kit. WatchGuard patched an Arbitrary File Write via Path Traversal vulnerability affecting the Fireware Web UI in multiple versions of Fireware OS.

Recorded Future17 days agoLLM reportinfo

The Shift: An Era of Quantum Geopolitics

The article introduces the concept of 'Quantum Geopolitics' to describe the current fluid and interconnected state of international relations. It emphasizes that cybersecurity is now a core enterprise risk, requiring organizations to adopt continuous scenario planning, invest in operational resilience, and improve cross-functional communication to navigate geopolitical uncertainties.