Skip to content
.ca

cyfar.ca

DFIR, deception, detection. Posts I wrote, intel my pipeline summarized, and redacted writeups from the fleet.

Akamai17 days agoLLM reportlow

RSAC 2026: Tag in a Partner for the AI Security Showdown

This promotional article highlights Akamai's upcoming presence at RSAC 2026, focusing on the escalating arms race between AI-driven cyber threats and enterprise security. It emphasizes that adversaries are using AI to automate API attacks and exploit cloud misconfigurations, necessitating a shift away from legacy security toward robust Zero Trust frameworks and strategic partner ecosystems.

Sophos17 days agoLLM reportcritical

March Patch Tuesday visits 15 product families

Microsoft's March Patch Tuesday addressed 84 vulnerabilities across 15 product families, including 8 Critical and 76 Important flaws. While no zero-days were reported as actively exploited, two vulnerabilities have been publicly disclosed, and six are deemed highly likely to be exploited within 30 days. Organizations are advised to prioritize patching for critical Remote Code Execution and Elevation of Privilege vulnerabilities affecting Windows, Office, and Azure environments.

Sophos17 days agoLLM reporthigh

Initial access techniques used by Iran-based threat actors

Iranian-linked threat actors consistently utilize a core set of cost-effective initial access techniques, including social engineering, rapid exploitation of known vulnerabilities, and credential abuse. These groups frequently leverage legitimate RMM tools and trusted cloud services to establish persistence and evade detection, highlighting the need for robust identity management, prompt patching, and perimeter security.

WithSecure17 days agoLLM reporthigh

The Changing Economics of Cybercrime-as-a-Service: What Defenders Need to Know

The cybercrime-as-a-service ecosystem is evolving rapidly, characterized by a shift towards trading live session tokens, the integration of generative AI for dynamic payload generation, and a preference for data exfiltration over encryption. Defenders must adapt by prioritizing identity monitoring, rapid session revocation, and recognizing the blurring lines between commodity cybercrime and state-aligned operations.

Microsoft17 days agoLLM reporthigh

Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft

Storm-2561 is conducting a credential theft campaign leveraging SEO poisoning to distribute fake enterprise VPN clients. The attack utilizes digitally signed payloads and DLL side-loading to deploy the Hyrax infostealer, which harvests VPN credentials and configuration data before redirecting victims to legitimate software to evade detection.

ANY.RUN17 days agoLLM reporthigh

MicroStealer Analysis: A Fast-Spreading Infostealer with Limited Detection

MicroStealer is a newly identified, fast-spreading infostealer that targets sensitive corporate and personal data, including browser credentials, session cookies, and cryptocurrency wallets. It employs a sophisticated NSIS to Electron to Java execution chain, combined with obfuscation and anti-analysis checks, to maintain a low detection rate across security vendors.

Check Point17 days agoLLM reportcritical

“Handala Hack” – Unveiling Group’s Modus Operandi

Handala Hack, an Iranian MOIS-affiliated threat actor also known as Void Manticore, conducts destructive wiping and hack-and-leak operations against US, Israeli, and Albanian targets. The group leverages compromised VPN credentials for initial access, uses NetBird for internal tunneling, and deploys multiple parallel wiping techniques—including custom MBR wipers, PowerShell scripts, and VeraCrypt—distributed via Active Directory Group Policy.

Socket17 days agoLLM reportlow

GCVE Launches Decentralized Publishing Ecosystem for Vulnerability Disclosure

GCVE, operated by CIRCL, has launched a decentralized vulnerability publishing ecosystem utilizing Vulnerability-Lookup 4.1.0 to address the limitations of the centralized CVE system. The federated model allows organizations to act as autonomous publishers (GNAs) while synchronizing vulnerability intelligence, sightings, and KEV data globally.

Zscaler ThreatLabz17 days agoLLM reporthigh

China-nexus Group Targets Persian Gulf Region | ThreatLabz

A China-nexus threat actor, assessed with medium confidence as Mustang Panda, targeted the Persian Gulf region using a multi-stage attack chain themed around the Middle East conflict. The campaign leverages LNK and CHM files to execute a heavily obfuscated shellcode loader via DLL sideloading, ultimately deploying a PlugX backdoor capable of HTTPS and DNS-over-HTTPS (DoH) C2 communications.

Cofense17 days agoLLM reporthigh

Weaponizing Telegram Bots: How Threat Actors Exfiltrate Credentials

Threat actors are increasingly weaponizing the legitimate Telegram Bot API to establish Command and Control (C2) channels and exfiltrate stolen data. This technique is widely adopted across credential phishing campaigns and malware families like Agent Tesla and Pure Logs Stealer, allowing attackers to bypass traditional network defenses by blending malicious traffic with legitimate Telegram communications.

Socket17 days agoLLM reporthigh

OpenClaw Advisory Surge Highlights Gaps Between GHSA and CVE Tracking

The rapid proliferation of GitHub Security Advisories (GHSAs) for the OpenClaw AI agent has highlighted a significant gap in vulnerability tracking, as many GHSAs lack corresponding CVE identifiers. This discrepancy creates critical blind spots for enterprise security tools that rely exclusively on CVEs, prompting debate over the future of decentralized vulnerability disclosure and the need for multi-source advisory tracking.

Sophos17 days agoLLM reporthigh

Evil evolution: ClickFix and macOS infostealers

Threat actors are evolving 'ClickFix' social engineering campaigns to target macOS users with the MacSync infostealer. Recent iterations bypass traditional security controls by tricking users into executing obfuscated terminal commands that deploy fileless, API-gated AppleScript payloads designed to harvest credentials, browser data, and cryptocurrency wallet seed phrases.