Skip to content
.ca

cyfar.ca

DFIR, deception, detection. Posts I wrote, intel my pipeline summarized, and redacted writeups from the fleet.

Arctic Wolf17 days agoLLM reporthigh

Token Bingo: Don’t Let Your Code be the Winner

A widespread phishing campaign is leveraging the Kali365 Live Phishing-as-a-Service (PhaaS) platform to execute device code phishing and AiTM attacks. By tricking users into authorizing legitimate Microsoft device login requests, threat actors steal OAuth access and refresh tokens, bypassing traditional credential-based defenses and MFA to gain persistent access to Microsoft 365 environments.

Sophos17 days agoLLM reportcritical

Supply chain attacks hit Checkmarx and Bitwarden developer tools

A coordinated supply chain attack compromised official distribution channels for Checkmarx KICS and the Bitwarden CLI, pushing malicious updates designed to harvest developer credentials, cloud keys, and AI assistant configurations. The payloads exfiltrated data to a shared C2 domain and exhibited advanced techniques, including weaponizing stolen GitHub tokens to inject malicious workflows and using victim repositories as dead drops.

Socket17 days agoLLM reportlow

Introducing Data Exports

Socket has introduced a new Data Exports feature for its Enterprise customers, enabling the automated daily export of security alert data to customer-owned AWS S3, Google Cloud Storage, or Azure Blob Storage buckets. This integration supports multiple formats (JSON, CSV, Parquet) and modes (Full Snapshot, Incremental) to streamline ingestion into existing SIEM platforms and internal analytics workflows.

ANY.RUN17 days agoLLM reportcritical

Inside agenteV2: How Brazilian Attackers Use Fake Court Summons to Steal Banking Credentials in Real Time

A new phishing campaign targets Brazilian users with fake judicial summons to deliver agenteV2, a Nuitka-compiled interactive banking trojan. The malware establishes a persistent WebSocket backdoor for live screen streaming and remote shell access, enabling attackers to conduct real-time, operator-assisted financial fraud.

Socket17 days agoLLM reportcritical

Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign

The Bitwarden CLI npm package was compromised in a supply chain attack linked to the ongoing Checkmarx campaign. The malicious payload, injected via GitHub Actions, harvests extensive cloud and developer credentials, exfiltrating them through unauthorized GitHub repositories and a dedicated C2 server while employing a Russian locale kill switch and shell profile persistence.

Akamai17 days agoLLM reporthigh

A Shortcut to Coercion: Incomplete Patch of APT28's Zero-Day Leads to CVE-2026-32202

Akamai researchers discovered that Microsoft's patch for an APT28 zero-day (CVE-2026-21510) was incomplete, resulting in a new zero-click authentication coercion vulnerability (CVE-2026-32202). While the patch successfully mitigated remote code execution by adding SmartScreen verification, it failed to prevent Windows Explorer from initiating an SMB connection to resolve UNC paths during icon extraction, allowing attackers to steal Net-NTLMv2 hashes without user interaction.

SentinelOne17 days agoLLM reportcritical

fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet

SentinelLABS discovered fast16, a sophisticated 2005 cyber sabotage framework that uses a Lua-based carrier and a kernel driver to selectively patch high-precision calculation software in memory. The malware subtly corrupts floating-point arithmetic in engineering and simulation tools, representing an early, state-level capability for physical-world sabotage.

Recorded Future17 days agoLLM reportlow

Today, trust is the superpower that makes innovation possible

This thought leadership article emphasizes the critical role of digital trust and proactive threat intelligence in fostering economic growth. It highlights the partnership between Recorded Future and Mastercard and underscores the need for enhanced public-private collaboration to address rising cyber threats, particularly noting the surge of ransomware incidents in Latin America.

Mandiant17 days agoLLM reportcritical

Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

Google Threat Intelligence Group identified UNC6692, a threat actor utilizing Microsoft Teams phishing and email bombing to deploy a custom modular malware suite. The attack chain leverages a malicious Chromium extension (SNOWBELT), a Python tunneler (SNOWGLAZE), and a Python bindshell (SNOWBASIN) to establish persistence, move laterally, and exfiltrate sensitive Active Directory data via legitimate cloud services.

NCSC17 days agoLLM reportlow

NCSC: Leave passwords in the past - passkeys are the future

The UK's National Cyber Security Centre (NCSC) has updated its official guidance to recommend passkeys as the default authentication method for consumers and businesses, replacing traditional passwords. Passkeys provide superior resilience against modern cyber threats, particularly phishing and credential theft, while offering a faster, more user-friendly login experience.

Socket17 days agoLLM reportcritical

Malicious Checkmarx Artifacts Found in Official KICS Docker Repository and Code Extensions

A sophisticated supply chain attack compromised official Checkmarx KICS Docker images and VS Code extensions, injecting malware designed to harvest and exfiltrate cloud, developer, and CI/CD credentials. The threat actor, believed to be TeamPCP, utilized the Bun runtime to execute the payload, subsequently abusing stolen GitHub and NPM tokens to propagate the infection through malicious GitHub Actions workflows and poisoned NPM packages.

Socket17 days agoLLM reportlow

Introducing Organization Notifications in Socket

Socket has introduced Organization Notifications, a new feature allowing security teams to subscribe to, filter, and receive batched email updates for organization-level security alerts. This capability aims to streamline vulnerability management and reduce alert fatigue by grouping updates and sending them at most every 20 minutes, with Slack and Microsoft Teams integrations planned for the future.

NCSC17 days agoLLM reporthigh

International cyber agencies share fresh advice to defend against China-linked covert networks

An international coalition of cyber agencies has issued a joint advisory warning that China-linked threat actors are leveraging covert networks of compromised edge devices to disguise their attacks. The advisory highlights the growing problem of 'IOC extinction' and urges organizations to shift towards dynamic threat filtering and behavioral baselining of edge device traffic to maintain effective defense.

Cisco Talos17 days agoLLM reporthigh

Intelligence Center

Cisco Talos' Q1 2026 incident response trends highlight a resurgence in phishing as the primary initial access vector, augmented by AI tools like Softr for rapid credential harvesting. Threat actors are increasingly abusing legitimate tools such as TruffleHog to discover exposed secrets, while specific campaigns like UAT-4356 have been observed exploiting n-day vulnerabilities to deploy custom backdoors on network devices.