Skip to content
.ca

cyfar.ca

DFIR, deception, detection. Posts I wrote, intel my pipeline summarized, and redacted writeups from the fleet.

Huntress17 days agoLLM reportmedium

Huntress Managed ITDR for Google Workspace: Defending the New Identity Attack Surface

Threat actors are increasingly targeting Google Workspace as a foundational identity layer to pivot into interconnected SaaS applications. Modern attacks bypass traditional endpoint defenses by utilizing stolen credentials, OAuth abuse, and malicious inbox rules to conduct Business Email Compromise (BEC) and maintain persistent access.

Palo Alto Networks17 days agoLLM reportinfo

Google Authenticator: The Hidden Mechanisms of Passwordless Authentication

This architectural analysis details the hidden mechanisms behind Google's synced passkeys, revealing a hybrid model that leverages a cloud-based authenticator (enclave.ua5v[.]com) for sensitive cryptographic operations while anchoring trust to local hardware keys. Understanding this infrastructure is critical for defenders to anticipate emerging attack vectors in passwordless authentication environments.

Canadian Centre for Cyber Security17 days agoLLM reportmedium

Cyber Centre Daily Advisory Digest — 2026-03-24 (2 advisories)

The Canadian Centre for Cyber Security issued a daily digest highlighting recent security updates for Google Chrome and Mozilla Firefox. Administrators are advised to update Chrome to version 146.0.7680.164/165 and Firefox to version 149 (or the respective ESR versions) to address unspecified vulnerabilities.

Huntress17 days agoLLM reportmedium

A _declassified Look Inside the Dark Economy of Cybercrime

Cybercrime has evolved into a highly organized, corporate-style economy, complete with specialized departments and multi-million dollar revenues generated through tech support and subscription scams. Threat actors are increasingly leveraging generative AI for deepfakes and automated vishing, prompting defenders to adopt AI-driven countermeasures and behavioral tests to disrupt these social engineering operations.

CERT-EU17 days agoLLM reportcritical

Security Advisory 2026-003

Citrix has released security updates addressing two vulnerabilities in NetScaler ADC and Gateway, including a critical out-of-bounds read (CVE-2026-3055) and a high-severity race condition (CVE-2026-4368). These flaws can lead to sensitive information disclosure and user session mix-up, requiring immediate patching and session termination to prevent potential exploitation.

Sophos17 days agoLLM reporthigh

NICKEL ALLEY strategy: Fake it ‘til you make it

North Korean threat group NICKEL ALLEY is targeting technology professionals and Web3 developers through fake job interviews and malicious code repositories. The group employs social engineering, the ClickFix tactic, and malicious VS Code tasks to deliver remote access trojans like PyLangGhost RAT and BeaverTail, primarily aiming for cryptocurrency theft and potential supply chain compromise.

Mandiant17 days agoLLM reporthigh

M-Trends 2026: Data, Insights, and Strategies From the Frontlines

Mandiant's M-Trends 2026 report highlights a severe divergence in adversary tactics. Cybercriminals are optimizing for speed, with initial access hand-offs collapsing to 22 seconds, and focusing on recovery denial by targeting hypervisors and backup infrastructure. Conversely, espionage groups are prioritizing extreme persistence by exploiting zero-days and deploying in-memory malware on unmonitored edge devices, while voice phishing has emerged as a primary vector for bypassing MFA and compromising SaaS environments.

Canadian Centre for Cyber Security17 days agoLLM reportcritical

Cyber Centre Daily Advisory Digest — 2026-03-23 (9 advisories)

The Canadian Centre for Cyber Security released a daily digest of 9 security advisories covering critical vulnerabilities across major enterprise, Linux, and ICS platforms. Notably, a critical vulnerability in Craft CMS (CVE-2025-32432) is being actively exploited in the wild, and Citrix has patched critical flaws in NetScaler ADC and Gateway.

Socket17 days agoLLM reportcritical

CanisterWorm: npm Publisher Compromise Deploys Backdoor Across 29+ Packages

CanisterWorm is a worm-enabled supply chain attack that compromises legitimate npm publisher accounts to distribute a Python backdoor. The malware establishes user-level Linux persistence via systemd and utilizes an Internet Computer Protocol (ICP) canister as a dead-drop C2 to continuously fetch and execute secondary payloads, while simultaneously harvesting npm tokens to propagate itself to other packages.

Zscaler ThreatLabz17 days agoLLM reportcritical

CVE-2026-20131: Analysis of FMC RCE | ThreatLabz

Cisco Secure Firewall Management Center (FMC) is actively being targeted by unauthenticated attackers exploiting CVE-2026-20131, a critical insecure deserialization vulnerability. Exploitation grants root access, enabling attackers to completely compromise the firewall management platform, alter security policies, and pivot into the internal network.

Socket17 days agoLLM reportcritical

Trivy Under Attack Again: Widespread GitHub Actions Tag Compromise Exposes CI/CD Secrets

A sophisticated supply chain attack compromised the official Trivy GitHub Action (aquasecurity/trivy-action) by force-pushing 75 version tags to malicious commits. The injected infostealer harvests sensitive CI/CD secrets from runner memory and filesystems, exfiltrating them to a typosquat domain or a fallback GitHub repository.

Akamai17 days agoLLM reporthigh

CVE-2026-31979: The Symlink Trap — Root Privilege Escalation in Himmelblau

CVE-2026-31979 is a high-severity local privilege escalation vulnerability in the Himmelblau Linux-to-Azure integration suite. By exploiting a time-of-check to time-of-use (TOCTOU) symlink race condition in the shared /tmp directory, an unprivileged local attacker can hijack root-level file operations to take ownership of critical system files, potentially enabling lateral movement into cloud infrastructure.

Akamai17 days agoLLM reportcritical

Akamai Helps Authorities Disrupt the World’s Largest IoT Botnets

The US Department of Justice, alongside international authorities and industry partners including Akamai, successfully disrupted the Aisuru and Kimwolf IoT botnets. These hyper-volumetric botnets compromised up to 4 million IoT devices to launch record-breaking DDoS attacks exceeding 30 Tbps, which were used to cripple internet infrastructure and extort victims.

CrowdStrike17 days agoLLM reporthigh

Tycoon2FA Phishing-as-a-Service Platform Persists Following Takedown

Following a major law enforcement takedown of its infrastructure on March 4, 2026, the Tycoon2FA Phishing-as-a-Service (PhaaS) platform has quickly reconstituted its operations. The platform continues to enable cybercriminals to bypass multifactor authentication (MFA) using Adversary-in-the-Middle (AiTM) techniques, leading to cloud account takeovers and Business Email Compromise (BEC).

Socket17 days agoLLM reportinfo

ENISA Publishes Technical Advisory on Secure Use of Package Managers

The European Union Agency for Cybersecurity (ENISA) has released a technical advisory on the secure use of package managers ahead of the Cyber Resilience Act's (CRA) strict reporting deadlines in 2026. The advisory highlights critical software supply chain risks, such as typosquatting, compromised maintainers, and dependency confusion, mandating a shift toward continuous dependency monitoring, SBOM generation, and reachability analysis to avoid severe regulatory penalties.