Skip to content
.ca
sign in

DFIR · deception · detection

Posts I wrote, intel from the CTI pipeline, and redacted engagement reports from the honeypot fleet.

Microsoft3 months ago7 minLLM reporthigh

When tax season becomes cyberattack season: Phishing and malware campaigns using tax-related lures

Microsoft Threat Intelligence observed a significant increase in tax-themed phishing and malware campaigns targeting individuals and accounting professionals. These campaigns utilize sophisticated social engineering, Phishing-as-a-Service (PhaaS) platforms for credential theft, and abused legitimate Remote Monitoring and Management (RMM) tools to establish persistent remote access.

Huntress3 months ago5 minLLM reportcritical

They Got In Through SonicWall. Then They Tried to Kill Every Security Tool

Threat actors breached a network via compromised SonicWall SSLVPN credentials and deployed a sophisticated EDR killer to blind endpoint security prior to a planned ransomware deployment. The malware utilizes a Bring Your Own Vulnerable Driver (BYOVD) technique, dropping a revoked EnCase forensic driver encoded with a novel wordlist substitution cipher to terminate 59 different security processes directly from kernel mode.

CERT-EU3 months ago4 minLLM reportcritical

Security Advisory 2026-002

Cisco has disclosed multiple critical and high-severity vulnerabilities affecting Catalyst SD-WAN Controller and Manager, including CVE-2026-20127, a CVSS 10 authentication bypass exploited in the wild since 2023. Successful exploitation allows unauthenticated remote attackers to gain administrative privileges, manipulate network configurations, and establish persistent access, sometimes by downgrading software to exploit older vulnerabilities.

CERT-EU3 months ago4 minLLM reportcritical

Security Advisory 2026-001

Ivanti has released a security advisory addressing two critical code injection vulnerabilities (CVE-2026-1281 and CVE-2026-1340) in Endpoint Manager Mobile (EPMM) that allow unauthenticated remote code execution. At least one of these flaws is currently being exploited in the wild, prompting urgent recommendations to secure forensic evidence and apply available hotfixes.

CERT-EU3 months ago4 minLLM reportcritical

Security Advisory 2025-042

Cisco has disclosed a critical, unpatched vulnerability (CVE-2025-20393) affecting its Secure Email Gateway and Secure Email and Web Manager appliances. The flaw allows attackers to execute arbitrary commands with root privileges if the Spam Quarantine feature is enabled and exposed to the internet. Organizations are urged to immediately restrict internet access to this feature and contact Cisco TAC to check for indicators of compromise.

CrowdStrike3 months ago3 minLLM reportlow

Secure Homegrown AI Agents with CrowdStrike Falcon AIDR and NVIDIA NeMo Guardrails

CrowdStrike has announced the integration of Falcon AI Detection and Response (AIDR) with NVIDIA NeMo Guardrails to secure enterprise AI agents against runtime attacks. The solution provides programmable guardrails to prevent prompt injection, data exposure, and unauthorized actions by applying over 75 built-in classification rules to LLM interactions.

Projectzero3 months ago2 minLLM reportlow

On the Effectiveness of Mutational Grammar Fuzzing

The article details the limitations of mutational coverage-guided grammar fuzzing, specifically its tendency to produce similar samples and struggle with complex function chaining. To mitigate this, the author introduces a methodology using the Jackalope fuzzer that periodically restarts workers to combine generative and mutational fuzzing, significantly improving the discovery rate of unique crashes in targets like libxslt.

Elastic Security Labs3 months ago3 minLLM reportinfo

Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)

Elastic has introduced Defend for Containers (D4C) in version 9.3.0, providing runtime visibility and detection capabilities for Linux container workloads in Kubernetes environments. The integration captures process and file activity enriched with orchestration metadata, enabling detection engineers to build robust, behavior-based security policies.

Cisco Talos3 months ago5 minLLM reporthigh

Intelligence Center

Threat actors increasingly abuse legitimate native utilities, third-party tools, and cloud service clients for data exfiltration, bypassing traditional static detections. The Exfiltration Framework models the behavioral and forensic characteristics of these tools to enable detection based on execution context, network patterns, and artifact persistence rather than tool presence.

Infoblox3 months ago7 minLLM reporthigh

Inside Keitaro Abuse: A Persistent Stream of AI-Driven Investment Scams

Threat actors are extensively abusing the legitimate Keitaro Tracker platform to conduct domain cloaking, facilitating large-scale, AI-driven investment and tech support scams. By combining traffic distribution systems with AI-generated deepfakes and localized lures, attackers effectively evade automated security scanners while maximizing victim engagement and conversion rates.

Socket3 months ago5 minLLM reporthigh

GlassWorm Sleeper Extensions Activate on Open VSX, Shift to GitHub-Hosted VSIX Malware

The GlassWorm malware campaign has evolved to deploy 'sleeper' extensions on Open VSX that are subsequently weaponized to download malicious VSIX payloads hosted on GitHub. The malware employs sophisticated evasion techniques, including Russian geofencing, source-to-compiled code mismatches, and utilizing the Solana blockchain as a dead-drop resolver for command and control, ultimately leading to arbitrary Node.js code execution across multiple developer IDEs.

Huntress3 months ago3 minLLM reportinfo

From Seconds to Story: How Huntress Managed ITDR's New Incident Report Timeline Changes Response

Huntress has introduced a new Incident Report Timeline feature for its Managed ITDR platform to combat rapid, identity-driven data exfiltration in cloud environments. This feature provides a chronological narrative of attacker actions and response efforts, enabling faster decision-making and better communication for security teams and MSPs.

Elastic Security Labs3 months ago5 minLLM reporthigh

From Invitation to Infection: How SILENTCONNECT Delivers ScreenConnect

Elastic Security Labs identified a new .NET loader dubbed SILENTCONNECT, which is distributed via phishing emails and Cloudflare Turnstile CAPTCHA pages. The loader utilizes living-off-the-land binaries, PEB masquerading, and UAC bypass techniques to silently install remote monitoring and management (RMM) tools like ScreenConnect for persistent access.

Huntress3 months ago5 minLLM reporthigh

From Code to Coverage (Part 4): Hunting SOAPHound - The (!FALSE) Pattern

Attackers are utilizing the SOAPHound enumeration tool to map Active Directory environments by querying non-existent LDAP attributes. Due to Active Directory's query optimization logic, these queries are transformed into a generic '(! (FALSE))' pattern in Event ID 1644 logs, effectively hiding the tool's signature and bypassing traditional string-based detection mechanisms.

ESET3 months ago7 minLLM reportcritical

EDR killers explained: Beyond the drivers

Ransomware affiliates increasingly rely on EDR killers—ranging from BYOVD exploits and abused anti-rootkits to driverless tools—to disrupt security solutions prior to deploying encryptors. This approach allows encryptors to remain simple while the EDR killers handle complex defense evasion, complicating attribution and defense strategies.

Canadian Centre for Cyber Security3 months ago2 minLLM reportcritical

Cyber Centre Daily Advisory Digest — 2026-03-19 (1 advisories)

The Canadian Centre for Cyber Security issued an advisory regarding a critical vulnerability in multiple versions of the Ubiquiti UniFi Network application. Administrators are strongly encouraged to apply the latest vendor updates to mitigate potential risks.

CrowdStrike3 months ago2 minLLM reportlow

CrowdStrike Innovates to Modernize National Security and Protect Critical Systems

CrowdStrike announced new product capabilities at Fal.Con Gov 2026 aimed at modernizing national security and protecting critical government systems. The updates include Falcon Flex for flexible procurement and new Charlotte AI features for automated, natural language-driven security investigations within FedRAMP-authorized environments.

Trend Micro3 months ago7 minLLM reporthigh

Copyright Lures Mask a Multi‑Stage PureLog Stealer Attack on Key Industries

A targeted campaign is delivering the PureLog Stealer via localized copyright violation lures. The attack employs a sophisticated multi-stage infection chain, utilizing a Python-based loader to bypass AMSI, establish registry persistence, and execute the final .NET stealer entirely in memory to evade detection.

CISA3 months ago3 minLLM reporthigh

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-20131, a deserialization of untrusted data vulnerability affecting Cisco Secure Firewall Management Center (FMC) and Cisco Security Cloud Control (SCC), to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation.