Skip to content
.ca

cyfar.ca

DFIR, deception, detection. Posts I wrote, intel my pipeline summarized, and redacted writeups from the fleet.

Akamai17 days agoLLM reportmedium

Post-Quantum Cryptography Beyond TLS: Remain Quantum Safe

The article highlights the critical need to transition various network protocols, including SSH, IPsec, OpenPGP, and DNSSEC, to post-quantum cryptography (PQC) to mitigate the 'harvest now, decrypt later' threat. While TLS and SSH have clear upgrade paths with hybrid key exchanges, protocols like DNSSEC face complex architectural challenges due to signature sizes and UDP limitations.

Trend Micro17 days agoLLM reporthigh

Europol, Microsoft, TrendAI™ and Collaborators Halt Tycoon 2FA Operations

A coordinated international law enforcement and private sector operation successfully disrupted Tycoon 2FA, a prominent Phishing-as-a-Service (PhaaS) platform. The service enabled low-skill attackers to bypass multi-factor authentication (MFA) using adversary-in-the-middle (AitM) techniques to harvest credentials and session cookies, which were subsequently used for BEC and ransomware attacks.

Check Point17 days agoLLM reportcritical

Caught in the Hook: RCE and API Token Exfiltration Through Claude Code Project Files | CVE-2025-59536 | CVE-2026-21852

Check Point Research discovered critical vulnerabilities in Anthropic's Claude Code CLI that enable Remote Code Execution (RCE) and API token exfiltration. By injecting malicious configurations into project files like .claude/settings.json and .mcp.json, attackers could execute arbitrary commands and steal API keys when a developer opens a compromised repository, leading to potential supply chain attacks and unauthorized access to shared Claude Workspaces.

Socket17 days agoLLM reportcritical

Unauthorized AI Agent Execution Code Published to OpenVSX in Aqua Trivy VS Code Extension

Malicious versions of the Aqua Trivy VS Code extension were published to the OpenVSX registry, containing unauthorized code that hijacks locally installed AI coding assistants. By using carefully crafted natural language prompts and permissive execution flags, the payload instructs the AI agents to harvest sensitive developer credentials and system data, subsequently attempting to exfiltrate the information via available communication channels or by creating a new GitHub repository.

Check Point17 days agoLLM reportcritical

Silver Dragon Targets Organizations in Southeast Asia and Europe

Check Point Research identified Silver Dragon, a Chinese-nexus APT group likely affiliated with APT41, targeting organizations in Southeast Asia and Europe. The group utilizes public-facing server exploits and phishing to deploy custom loaders that establish persistence via AppDomain hijacking and service manipulation. These loaders deliver Cobalt Strike and a novel Google Drive-based backdoor called GearDoor.

Socket17 days agoLLM reportcritical

Malicious Packagist Packages Disguised as Laravel Utilities Deploy Encrypted RAT

Socket's Threat Research Team discovered a supply chain attack involving malicious Packagist packages that deploy an encrypted Remote Access Trojan (RAT). The packages, disguised as Laravel utilities, execute automatically upon application boot or class autoloading, granting the attacker full remote shell access, file manipulation, and system reconnaissance capabilities across Windows, macOS, and Linux environments.

Check Point17 days agoLLM reportcritical

Interplay between Iranian Targeting of IP Cameras and Physical Warfare in the Middle East

Iranian threat actors are actively exploiting vulnerabilities in Hikvision and Dahua IP cameras across the Middle East to support physical warfare operations. The compromised devices are utilized for battle damage assessment (BDA) and targeting correction during kinetic military operations, with exploitation spikes correlating closely with regional geopolitical events.

Sophos17 days agoLLM reporthigh

Hacktivist campaigns increase as United States, Iran, and Israel conflict intensifies

Following coordinated military strikes by the U.S. and Israel against Iran, there has been a significant surge in hacktivist activity. Pro-Iran groups are conducting website defacements, DDoS attacks, doxxing, and claiming unverified attacks on critical infrastructure, while pro-Israel groups are retaliating, elevating the cyber threat landscape for organizations in the U.S., Israel, and the Middle East.

Palo Alto Networks17 days agoLLM reportcritical

Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild

Adversaries are actively exploiting web-based Indirect Prompt Injection (IDPI) to manipulate Large Language Models (LLMs) and AI agents. By embedding hidden or obfuscated instructions within benign web content, attackers can coerce AI systems into performing unauthorized actions such as data destruction, SEO poisoning, and bypassing content moderation when the AI processes the webpage.

Mandiant17 days agoLLM reportcritical

Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit

Google Threat Intelligence Group discovered 'Coruna', a highly sophisticated iOS exploit kit containing 23 exploits that target iOS versions 13.0 through 17.2.1. Initially observed in use by a commercial surveillance vendor, the kit has since proliferated to state-sponsored and financially motivated threat actors to deploy PLASMAGRID, a payload designed to steal cryptocurrency wallets and financial data.

Arctic Wolf17 days agoLLM reporthigh

SloppyLemming Deploys BurrowShell and Rust-Based RAT to Target Pakistan and Bangladesh

Between January 2025 and January 2026, the India-nexus threat actor SloppyLemming conducted a cyber espionage campaign targeting government and critical infrastructure in Pakistan and Bangladesh. The campaign utilized PDF and Excel lures to deploy two custom implants—an in-memory shellcode backdoor named BurrowShell and a Rust-based keylogger—via DLL search order hijacking and extensive abuse of Cloudflare Workers infrastructure.

Cofense17 days agoLLM reporthigh

Punchbowl Phishing Attack Explained: How Digital Invites Are Used to Steal Credentials

Threat actors are leveraging fake digital invitations mimicking trusted brands like Paperless Post to redirect victims to credential harvesting sites. These phishing pages impersonate major login portals and utilize fake error messages to extract multiple sets of credentials, employing newly registered domains and URL shorteners to evade detection.

Cofense17 days agoLLM reporthigh

PII Pillage: How Attackers Use BitPanda to Plunder Credentials

A sophisticated phishing campaign is targeting Bitpanda cryptocurrency users by impersonating security update alerts. The attack utilizes a deceptively similar lookalike domain to harvest not only login credentials but also sensitive personally identifiable information (PII) such as addresses and dates of birth, which can be leveraged for identity theft or further account takeovers.

Infoblox17 days agoLLM reporthigh

Abusing .arpa: The TLD That Isn’t Supposed to Host Anything

Threat actors are utilizing a novel phishing technique that abuses the implicitly trusted .arpa top-level domain and IPv6 tunnels to bypass standard security controls. By registering reverse DNS domains for IPv6 blocks and creating A records instead of PTR records, attackers host malicious content on infrastructure that evades reputation-based blocking and policy filters.