Skip to content
.ca

cyfar.ca

DFIR, deception, detection. Posts I wrote, intel my pipeline summarized, and redacted writeups from the fleet.

SentinelOne17 days agoLLM reportinfo

Building an Adversarial Consensus Engine | Multi-Agent LLMs for Automated Malware Analysis

SentinelOne Labs developed a multi-agent LLM architecture using OpenClaw and Claude models to automate malware reverse engineering. By employing a serial consensus pipeline with an active rejection mandate, the system forces independent tool agents (radare2, Ghidra, Binary Ninja, IDA Pro) to cross-validate findings, significantly reducing decompiler artifacts and hallucinations.

Projectzero17 days agoLLM reporthigh

A Deep Dive into the GetProcessHandleFromHwnd API

The GetProcessHandleFromHwnd API contains historical design flaws allowing attackers to bypass User Interface Privilege Isolation (UIPI) and hijack Protected Processes. By forcing a protected process like WerFaultSecure.exe to create a window, attackers can obtain a privileged handle to inject shellcode, a vulnerability that remains exploitable on Windows 10 and pre-24H2 Windows 11 systems.

Recorded Future17 days agoLLM reporthigh

2025 Year in Review: Malicious Infrastructure

In 2025, Insikt Group observed the continued dominance of Cobalt Strike, AsyncRAT, and infostealers like Vidar, alongside the rise of new offensive tools such as RedGuard, Ligolo, and CastleLoader. The report highlights the critical role of Threat Activity Enablers (TAEs) and the abuse of legitimate infrastructure services, such as CDNs, in sustaining cybercriminal and APT operations.

Mandiant17 days agoLLM reportcritical

The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors

Google Threat Intelligence Group discovered DarkSword, a sophisticated iOS full-chain exploit leveraging six zero-day vulnerabilities to target iOS 18.4-18.7 devices. Adopted by multiple state-sponsored actors and commercial surveillance vendors, the pure-JavaScript exploit chain bypasses modern iOS mitigations to deploy data-mining payloads like GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER.

Akamai17 days agoLLM reporthigh

The Agentic Security Crisis: Why You Need to Act Now

The proliferation of autonomous AI agents like OpenClaw has introduced severe security risks, including unauthorized data access and silent exfiltration via prompt injection and malicious plug-ins. To mitigate these threats, organizations must transition from local agent deployments to hardened, isolated cloud environments utilizing defense-in-depth strategies such as kernel-level eBPF monitoring and runtime prompt interception.

Zscaler ThreatLabz17 days agoLLM reporthigh

Technical Analysis of SnappyClient | ThreatLabz

SnappyClient is a newly discovered C++ C2 framework implant delivered via HijackLoader, primarily designed for cryptocurrency theft and remote access. It utilizes advanced evasion techniques such as AMSI patching, Heaven's Gate, and transacted hollowing to bypass security controls, including Chromium's App-Bound Encryption, while communicating over a custom ChaCha20-Poly1305 encrypted protocol.

Cisco Talos17 days agoLLM reportinfo

Intelligence Center

Cisco Talos introduced DispatchLogger, an open-source dynamic analysis tool designed to intercept and log late-bound COM automation calls. By utilizing transparent proxying and recursive object wrapping, the tool provides analysts with deep semantic visibility into script-based malware behavior, such as WMI abuse and fileless execution, effectively bypassing common script obfuscation techniques.

Trend Micro17 days agoLLM reporthigh

From Misconfigured Spring Boot Actuator to SharePoint Exfiltration: How Stolen Credentials Bypass MFA

Threat actors exploited an exposed Spring Boot Actuator endpoint and plaintext credentials found in a spreadsheet to authenticate via the legacy ROPC flow. This allowed them to bypass MFA, obtain a Microsoft Graph access token, and exfiltrate sensitive data from SharePoint Online without deploying malware.

Canadian Centre for Cyber Security17 days agoLLM reportcritical

Cyber Centre Daily Advisory Digest — 2026-03-18 (11 advisories)

The Canadian Centre for Cyber Security published a daily digest of 11 security advisories on March 18, 2026. The advisories highlight vulnerabilities across various enterprise, networking, and consumer products, including a critical remote pre-auth buffer overflow in GNU InetUtils telnetd, and urge administrators to apply necessary updates and mitigations.

CISA17 days agoLLM reporthigh

CISA Urges Endpoint Management System Hardening After Cyberattack Against US Organization

CISA has issued an alert regarding malicious cyber activity targeting endpoint management systems, specifically highlighting a recent attack on Stryker Corporation's Microsoft environment. The alert strongly urges organizations to harden Microsoft Intune and similar platforms by enforcing least privilege, phishing-resistant MFA, and Multi Admin Approval to prevent unauthorized high-impact administrative actions.

CISA17 days agoLLM reporthigh

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-20963, a Microsoft SharePoint Deserialization of Untrusted Data Vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize timely remediation of this flaw as part of their vulnerability management practices to reduce exposure to cyberattacks.

Akamai17 days agoLLM reportmedium

Apps, APIs, and DDoS 2026: The Industrialization of Cyberattack Campaigns

The Akamai 2026 SOTI report highlights the industrialization of cyberattacks, driven by automation and the convergence of API threats, web exploits, and DDoS campaigns. Key trends include a massive 104% surge in Layer 7 DDoS attacks powered by super botnets, increased risks from untested AI-generated code, and a 73% rise in web application attacks.