Skip to content
.ca

cyfar.ca

DFIR, deception, detection. Posts I wrote, intel my pipeline summarized, and redacted writeups from the fleet.

Palo Alto Networks17 days agoLLM reporthigh

Double Agents: Exposing Security Blind Spots in GCP Vertex AI

Unit 42 researchers discovered that malicious AI agents deployed in GCP Vertex AI could exploit default permission scoping to extract service agent credentials. This 'double agent' attack allows unauthorized access to consumer storage buckets, restricted Google internal infrastructure, and introduces risks of remote code execution via insecure pickle deserialization.

Sophos17 days agoLLM reportcritical

Axios npm package compromised to deploy malware

A supply chain attack compromised the widely used Axios npm package (versions 1.14.1 and 0.30.4) following a maintainer account takeover. The malicious packages deploy a cross-platform remote access trojan (RAT) during installation, which fetches second-stage payloads and actively evades forensic detection by cleaning up artifacts and altering package metadata.

Trend Micro17 days agoLLM reportcritical

Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads

The highly popular Axios npm package was compromised when an attacker hijacked a lead maintainer's account to publish malicious versions. These versions included a phantom dependency that deployed a cross-platform Remote Access Trojan (RAT) via a postinstall hook, utilizing advanced obfuscation and anti-forensic techniques to hide its presence. The attack highlights critical risks in the software supply chain, specifically regarding dependency resolution and CI/CD pipeline protections.

Akamai17 days agoLLM reportlow

Akamai Enterprise Application Access Achieves FedRAMP Moderate Authorization

Akamai announced that its Enterprise Application Access solution has achieved FedRAMP Moderate authorization. This certification enables U.S. federal agencies to adopt Akamai's Zero Trust Network Access (ZTNA) platform to meet government-wide cybersecurity mandates, such as OMB M-22-09, while protecting against lateral movement and credential stuffing.

NCSC17 days agoLLM reportcritical

Vulnerability affecting F5 BIG-IP APM

The NCSC has issued an urgent alert regarding CVE-2025-53521, an actively exploited, unauthenticated remote code execution vulnerability in F5 BIG-IP Access Policy Manager (APM). Organizations are strongly advised to investigate for compromise using vendor-provided indicators, apply updates immediately, and potentially rebuild affected systems if evidence of compromise is found.

Akamai17 days agoLLM reportcritical

The Telnyx PyPI Compromise and the 2026 TeamPCP Supply Chain Attacks

Threat actor TeamPCP orchestrated a cascading supply chain attack by exploiting a misconfigured GitHub Actions workflow in Aqua Security's Trivy, harvesting credentials to compromise subsequent repositories including Checkmarx, LiteLLM, and Telnyx. The malicious packages deploy sophisticated, OS-specific remote access trojans (RATs) that utilize steganography, process hollowing, and ETW patching to evade detection while exfiltrating sensitive data.

Cofense17 days agoLLM reportmedium

One Click Away: Inside a LinkedIn Phishing Attack

A recent phishing campaign observed by the Cofense Phishing Defense Center uses highly realistic, spoofed LinkedIn notification emails to harvest user credentials. The attack leverages newly created sender domains and typosquatted landing pages to bypass traditional defenses and trick users into entering their login details on fraudulent portals.

Sekoia.io17 days agoLLM reporthigh

New widespread EvilTokens kit: device code phishing as-a-service – Part 1

EvilTokens is a newly discovered Phishing-as-a-Service (PhaaS) platform that automates Microsoft device code phishing to facilitate Business Email Compromise (BEC). By tricking victims into authorizing a malicious device via legitimate Microsoft login portals, attackers harvest access and refresh tokens to gain persistent, unauthenticated access to Microsoft 365 environments.

Sophos17 days agoLLM reporthigh

Incident responders, s'il vous plait: Invites lead to odd malware events

A phishing campaign tracked as STAC6405 uses event invitation lures to trick users into installing pre-configured legitimate RMM tools like LogMeIn Resolve and ScreenConnect. Once initial access is established, attackers deploy secondary payloads including HeartCrypt-packed infostealers and additional remote access tools, utilizing utilities to hide their activity from the user.

Akamai17 days agoLLM reportinfo

Extend Application Security Visibility from Code to Runtime

Akamai and Apiiro have announced an integration combining Akamai's App & API Protector with Apiiro's Application Security Posture Management (ASPM) platform. This collaboration aims to provide organizations with comprehensive visibility and correlated security insights across the entire software lifecycle, from code development to runtime execution.

Canadian Centre for Cyber Security17 days agoLLM reportcritical

Cyber Centre Daily Advisory Digest — 2026-03-30 (10 advisories)

The Canadian Centre for Cyber Security released a daily digest of 10 security advisories highlighting critical vulnerabilities across multiple vendors. Notably, vulnerabilities in Fortinet FortiClientEMS (CVE-2026-21643) and Citrix NetScaler (CVE-2026-3055) are currently being exploited in the wild, requiring immediate patching and potential incident response actions if compromise is suspected.

Watchtowr17 days agoLLM reportcritical

Please, We Beg, Just One Weekend Free Of Appliances (Citrix NetScaler CVE-2026-3055 Memory Overread Part 2)

A second memory overread vulnerability has been identified in Citrix NetScaler appliances under CVE-2026-3055, affecting the '/wsfed/passive?wctx' endpoint. By sending a specially crafted GET request with an empty 'wctx' parameter, attackers can force the appliance to leak sensitive memory, including administrative session IDs, via the 'NSC_TASS' cookie. Active in-the-wild exploitation has been observed since late March.

Socket17 days agoLLM reportcritical

TeamPCP Partners With Ransomware Group Vect to Target Open Source Supply Chains

Threat actor TeamPCP has formed an alliance with the Vect Ransomware-as-a-Service (RaaS) group to weaponize recent open-source supply chain compromises. By leveraging approximately 300 GB of stolen credentials and tokens harvested from CI/CD pipelines and security tools like Trivy and LiteLLM, the groups intend to facilitate large-scale ransomware deployments across affected enterprise environments.