Skip to content
.ca

cyfar.ca

DFIR, deception, detection. Posts I wrote, intel my pipeline summarized, and redacted writeups from the fleet.

Canadian Centre for Cyber Security17 days agoLLM reportcritical

Cyber Centre Daily Advisory Digest — 2026-05-07 (5 advisories)

The Canadian Centre for Cyber Security released a daily digest highlighting five security advisories. Notably, Ivanti Endpoint Manager Mobile (EPMM) contains an actively exploited vulnerability (CVE-2026-6973), and critical updates were issued for Spring Cloud Config, VM2 Node.js library, Mozilla Firefox, and multiple Broadcom VMware Tanzu products.

CISA17 days agoLLM reporthigh

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-6973, an improper input validation vulnerability in Ivanti Endpoint Manager Mobile (EPMM), to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Federal Civilian Executive Branch (FCEB) agencies are mandated to remediate this vulnerability per BOD 22-01, and all organizations are strongly urged to prioritize patching to reduce exposure to cyberattacks.

Kaspersky17 days agoLLM reportmedium

Websites with an undefined trust level: avoiding the trap

The article details the threat landscape of 'suspicious websites' that evade traditional phishing classifications but remain highly dangerous. These include fake online stores, dubious crypto exchanges, and fake browser extensions. Threat actors leverage newly registered domains, cheap TLDs, and poor infrastructure security (missing HTTP headers, lack of SPF/DMARC) to conduct financial fraud, data theft, and browser hijacking. Detection requires a multi-faceted approach analyzing domain age, IP reputation, and infrastructure configurations.

Recorded Future17 days agoLLM reporthigh

Threat Activity Enablers: The Backbone of Today’s Threat Landscape

Threat Activity Enablers (TAEs) are infrastructure providers that deliberately support malicious cyber operations by offering resilient, bulletproof hosting. By leveraging corporate shell companies, controlling Autonomous Systems (ASNs), and rapidly rebranding, TAEs like Virtualine Technologies and Stark Industries evade sanctions and takedowns to sustain ransomware, botnet, and state-sponsored campaigns.

Cofense17 days agoLLM reporthigh

Steal Smarter, Not Harder: Malicious use of Vercel for Credential Phishing

Threat actors are increasingly leveraging Vercel's GenAI capabilities, specifically v0.dev, to rapidly generate and host highly convincing credential phishing pages. By combining AI-generated frontends with Telegram Bot API integrations for real-time credential exfiltration, attackers can deploy resilient, low-effort phishing infrastructure on legitimate cloud services that evades traditional detection mechanisms.

SentinelOne17 days agoLLM reportmedium

LABScon25 Replay | Please Connect to the Foreign Entity to Enhance Your User Experience

This article summarizes a LABScon 25 presentation by Joe FitzPatrick on the systemic risks introduced by foreign-manufactured networked devices in critical infrastructure and consumer markets. It highlights issues such as undocumented cellular radios, mandatory product activation, and the ineffectiveness of import bans, advocating instead for hardware bills of materials and right-to-repair legislation.

Canadian Centre for Cyber Security17 days agoLLM reportcritical

Cyber Centre Daily Advisory Digest — 2026-05-06 (3 advisories)

The Canadian Centre for Cyber Security released a daily digest highlighting three security advisories. The most critical is an actively exploited, unauthenticated buffer overflow vulnerability (CVE-2026-0300) affecting the Palo Alto Networks PAN-OS User-ID Authentication Portal. Additional routine security updates were announced for Google Chrome and VMware Tanzu GemFire Management Console.

Akamai17 days agoLLM reporthigh

The Other Side of the MCP Threat Conversation

Model Context Protocol (MCP) servers introduce a new attack surface akin to AI-native APIs, exposing organizations to protocol-level attacks, injection vulnerabilities, and authorization bypasses. Because MCP tools often use permissive validation to accommodate LLM inputs and proactively broadcast their capabilities via plain-English descriptions, attackers can easily map business logic and exploit downstream systems or trigger resource exhaustion.

Socket17 days agoLLM reporthigh

PyPI Fixes High-Severity Access Control Issues Found in Security Audit

A recent security audit of PyPI by Trail of Bits uncovered 14 vulnerabilities, including high-severity access control flaws that allowed unauthorized role escalation and persistent stale permissions across project transfers. Additionally, a JWT replay vulnerability in the OIDC trusted publishing flow and an unpatched metadata validation gap highlight ongoing supply chain risks for Python package consumers.

Zscaler ThreatLabz17 days agoLLM reporthigh

OpenClaw Skill Distributes Remcos & GhostLoader | ThreatLabz

Threat actors are exploiting the OpenClaw AI agent framework by publishing a deceptive 'DeepSeek-Claw' skill that distributes malware. The campaign utilizes malicious installation instructions to deploy Remcos RAT on Windows via DLL sideloading and GhostLoader on macOS/Linux via obfuscated Node.js scripts, enabling persistent access and data exfiltration.

ANY.RUN17 days agoLLM reporthigh

New Phishing Campaign Targets US with Credential Theft: What CISOs Need to Know

A large-scale phishing campaign is targeting U.S. organizations across multiple sectors using fake event invitations. The campaign employs a repeatable infrastructure to bypass initial defenses via CAPTCHA, subsequently leading to either credential and OTP interception or the deployment of legitimate Remote Monitoring and Management (RMM) tools for persistent access.

Cisco Talos17 days agoLLM reporthigh

Intelligence Center

Cisco Talos identified an intrusion campaign utilizing the CloudZ RAT and a novel plugin named Pheno to intercept SMS and OTP messages. The malware abuses the Microsoft Phone Link application's PC-to-phone bridge, allowing attackers to steal sensitive authentication data from local SQLite databases without deploying malware directly to the victim's mobile device.

Cisco Talos17 days agoLLM reportcritical

Intelligence Center

Cisco Talos identified UAT-8302, a China-nexus APT, targeting global government entities using a diverse toolkit of custom and shared malware. The threat actor leverages DLL side-loading to deploy implants like NetDraft, CloudSorcerer v3, and VSHELL, while utilizing open-source tools for extensive network reconnaissance, credential harvesting, and lateral movement.

Trend Micro17 days agoLLM reporthigh

InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise

The InstallFix campaign leverages malvertising to distribute fake Claude AI installation pages, tricking users into executing malicious MSHTA commands. This initiates a multi-stage, fileless infection chain utilizing a ZIP/HTA polyglot, COM object abuse, and AMSI/SSL bypasses to deliver a payload associated with RedLine Stealer. The campaign demonstrates advanced evasion tactics, including the use of victim-unique C2 subdomains derived from machine fingerprints.

Recorded Future17 days agoLLM reportcritical

Hacking Embodied AI

Recent research highlights severe security flaws in commercially available embodied AI systems, specifically Unitree humanoid and quadruped robots. Vulnerabilities including undocumented backdoors, hard-coded cryptographic keys, and unauthenticated APIs enable remote attackers to hijack devices, exfiltrate sensitive multimodal telemetry, and pivot across physical fleets via wireless interfaces.

Canadian Centre for Cyber Security17 days agoLLM reportmedium

Cyber Centre Daily Advisory Digest — 2026-05-05 (3 advisories)

The Canadian Centre for Cyber Security released a daily digest highlighting May 2026 security rollups for Qualcomm and Android, alongside a specific advisory for Apache HTTP Server versions 2.4.66 and prior. Organizations utilizing these technologies are advised to review the respective vendor bulletins and apply available patches to mitigate potential vulnerabilities.