Skip to content
.ca

cyfar.ca

DFIR, deception, detection. Posts I wrote, intel my pipeline summarized, and redacted writeups from the fleet.

Cofense17 days agoLLM reporthigh

The Unintentional Enabler: How Cloudflare Services are Abused for Credential Theft and Malware Distribution

Threat actors are actively abusing legitimate Cloudflare services, specifically Workers and Tunnels, to conduct adversary-in-the-middle (AiTM) phishing and distribute malware. By leveraging Cloudflare's trusted infrastructure and free tiers, attackers successfully bypass traditional security controls to deliver remote access trojans like Xeno RAT and XWorm RAT via obfuscated WebDAV connections.

Socket17 days agoLLM reportcritical

TeamPCP Is Systematically Targeting Security Tools Across the OSS Ecosystem

The threat actor TeamPCP is conducting a highly coordinated supply chain campaign targeting widely used open-source security tools and developer infrastructure, including Trivy, Checkmarx' KICS, and LiteLLM. By compromising CI/CD pipelines and GitHub Actions, the attackers are successfully turning trusted security scanners into infostealers to harvest and exfiltrate massive amounts of enterprise credentials.

CERT-EU17 days agoLLM reportcritical

Security Advisory 2026-004

CERT-EU issued an urgent security advisory regarding CVE-2026-20963, a critical unauthenticated remote code execution vulnerability in Microsoft SharePoint caused by the deserialization of untrusted data. The flaw is actively being exploited in the wild, prompting strong recommendations to immediately patch internet-facing servers, enable AMSI, and rotate ASP.NET machine keys.

Akamai17 days agoLLM reportlow

Machine Learning Operations: Yesterday, Today, and Tomorrow

Akamai details its internal Machine Learning Operations (MLOps) platform, highlighting the transition from manual model management to a standardized, Kubeflow-based infrastructure. The platform enhances real-time security detections by streamlining model evaluation, tuning, and deployment, and is currently evolving to support LLMOps and AgentOps for generative AI applications.

ANY.RUN17 days agoLLM reporthigh

Kamasers Analysis: A Multi-Vector DDoS Botnet Targeting Organizations Worldwide

Kamasers is a sophisticated, multi-vector DDoS botnet and loader that leverages resilient Dead Drop Resolver (DDR) mechanisms via legitimate public services to maintain command-and-control communication. It poses significant enterprise risk by turning infected hosts into attack infrastructure and facilitating follow-on payload delivery, including potential ransomware deployment.

Recorded Future17 days agoLLM reporthigh

ClickFix Campaigns Targeting Windows and macOS

Insikt Group identified five distinct threat clusters utilizing the ClickFix social engineering technique to trick users into manually executing malicious commands via native system tools. This living-off-the-land approach bypasses traditional browser security to deliver payloads like NetSupport RAT and macOS infostealers across both Windows and macOS environments.

Socket17 days agoLLM reportcritical

Trivy Supply Chain Attack Expands to Compromised Docker Images

A supply chain attack on Aqua Security's Trivy project resulted in compromised Docker images containing the TeamPCP infostealer being pushed to Docker Hub. The attackers leveraged unauthorized access to the Aqua Security GitHub organization to distribute malicious versions (0.69.4, 0.69.5, 0.69.6) that exfiltrate sensitive CI/CD data to a typosquatted C2 domain.

Arctic Wolf17 days agoLLM reporthigh

The AI Malware Surge: Behavior, Attribution, and Defensive Readiness

AI-assisted malware development has rapidly matured, driven largely by the adoption of models like DeepSeek R1, which lowers the barrier to entry for threat actors. This surge has resulted in a high volume of structurally novel malware, including infostealers, RATs, and ransomware, many of which evade traditional signature-based detection while leaving distinct LLM-generated artifacts in their code.

Trail of Bits17 days agoLLM reportmedium

Spotting issues in DeFi with dimensional analysis

The article introduces dimensional analysis as a methodology for identifying arithmetic and logic vulnerabilities in DeFi smart contracts. By ensuring that variables representing different tokens, prices, or liquidity shares are not erroneously combined, developers can prevent severe financial logic flaws. The post highlights real-world examples of dimensional bugs and advocates for explicit unit documentation in Solidity codebases.

Sekoia.io17 days agoLLM reporthigh

Silver Fox: The Only Tax Audit Where the Fine Print Installs Malware

Silver Fox (also known as Void Arachne) is a China-based threat actor conducting dual-purpose campaigns in South Asia that blend financial cybercrime with APT-style espionage. Recent operations leverage tax-themed phishing to deliver evolving payloads, transitioning from the ValleyRAT backdoor to abused legitimate RMM tools, and most recently, a custom Python-based stealer disguised as a WhatsApp application.

Elastic Security Labs17 days agoLLM reportlow

Security Automation with Elastic Workflows: From Alert to Response

Elastic has introduced Elastic Workflows, a native automation capability within its SIEM that allows security teams to build YAML-based playbooks for alert triage, enrichment, and response. The feature integrates directly with Elasticsearch data, external threat intelligence platforms, and AI-driven analysis tools to streamline security operations.

Huntress17 days agoLLM reportcritical

Riding the Rails: Threat Actors Abuse Railway.com PaaS as Microsoft 365 Token Attack Infrastructure

Threat actors are leveraging the EvilTokens Phishing-as-a-Service platform hosted on Railway.com to conduct large-scale device code phishing campaigns against Microsoft 365 users. By abusing legitimate cloud infrastructure and multi-hop redirect chains, attackers successfully bypass email filtering and MFA to harvest persistent OAuth tokens.