Skip to content
.ca
sign in

DFIR · deception · detection

Posts I wrote, intel from the CTI pipeline, and redacted engagement reports from the honeypot fleet.

Palo Alto Networks4 months ago7 minLLM reporthigh

Boggy Serpens Threat Assessment

Boggy Serpens (MuddyWater) is conducting ongoing cyberespionage campaigns targeting critical infrastructure and diplomatic entities globally. The group leverages hijacked accounts for trusted relationship compromises, delivering advanced, AI-assisted malware toolkits including Rust-based backdoors and custom C2 protocols to maintain long-term persistence and evade detection.

Trend Micro4 months ago8 minLLM reportcritical

Web Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack

The Warlock ransomware group (Water Manaul) has enhanced its attack chain by exploiting Microsoft SharePoint servers for initial access and deploying a sophisticated post-exploitation toolkit. The group leverages BYOVD techniques via the NSecKrnl.sys driver to disable security tools, establishes redundant C&C channels using legitimate tools like Velociraptor and Cloudflare Tunnels, and automates ransomware deployment domain-wide using Group Policy Objects (GPO).

Akamai4 months ago3 minLLM reportinfo

Secure the AI Factory: Data Center Security for Accelerated Intelligence

Modern AI factories utilize massive, interconnected GPU clusters that generate high volumes of east-west traffic, rendering traditional perimeter and host-based security ineffective. To secure these environments without degrading performance, organizations must adopt infrastructure-level, identity-based microsegmentation using technologies like DPUs to enforce Zero Trust and contain lateral movement.

Mandiant4 months ago8 minLLM reportcritical

Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape

In 2025, ransomware operators increasingly relied on vulnerability exploitation for initial access and heavily targeted virtualization infrastructure like ESXi. While overall ransomware profitability appears to be declining, threat actors have adapted by increasing data theft extortion, targeting smaller organizations, and utilizing cross-platform ransomware families like REDBIKE, AGENDA, and INC.

Cofense4 months ago5 minLLM reporthigh

LiveChat Abuse: How Phishers Are Exploiting SaaS Support Tools to Steal Sensitive Data

A novel phishing campaign is abusing the legitimate LiveChat SaaS platform to impersonate brands like PayPal and Amazon. By engaging victims in real-time chat interfaces using automated bots or human operators, attackers successfully harvest sensitive information, including account credentials, multi-factor authentication (MFA) codes, personally identifiable information (PII), and credit card details.

CISA4 months ago3 minLLM reporthigh

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2025-47813, an information disclosure vulnerability in Wing FTP Server, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. All organizations are strongly urged to prioritize timely remediation of this vulnerability to reduce exposure to cyberattacks.

Socket4 months ago8 minLLM reporthigh

72 Malicious Open VSX Extensions Linked to GlassWorm Campaign Now Using Transitive Dependencies

The GlassWorm threat actor has evolved its supply chain attack methodology by abusing VS Code extension manifest fields to transitively deliver malicious payloads. This technique allows initially benign extensions to pull in malicious dependencies during later updates, executing staged JavaScript loaders that target developer workstations for credential and secret theft.

Recorded Future4 months ago4 minLLM reporthigh

2025 Identity Threat Landscape Report

The 2025 Identity Threat Landscape Report highlights a massive surge in credential theft driven by infostealer malware, with LummaC2 leading the ecosystem. A critical finding is the widespread theft of active session cookies, which allows attackers to bypass multi-factor authentication (MFA) and directly access high-value corporate systems, VPNs, and cloud platforms.

Akamai4 months ago4 minLLM reporthigh

Fortify Your Network Security from Emerging Geopolitical Cyberthreats

Following the outbreak of a geopolitical conflict in the Middle East in early 2026, Akamai observed a 245% surge in malicious cyber activity targeting global enterprises. The threat landscape is characterized by massive increases in automated reconnaissance, credential harvesting, and data-wiping attacks by state-sponsored and hacktivist groups like Handala, primarily targeting the financial, ecommerce, and healthcare sectors.

Socket4 months ago5 minLLM reporthigh

6 Malicious Packagist Themes Ship Trojanized jQuery and FUNNULL Redirect Payloads

Security researchers identified six malicious Composer packages on Packagist masquerading as OphimCMS themes. These packages contain trojanized JavaScript that executes client-side attacks, including URL exfiltration, ad injection, and redirects to gambling sites operated by the OFAC-sanctioned FUNNULL network.

Recorded Future4 months ago4 minLLM reportcritical

The Iran War: What You Need to Know

The ongoing geopolitical conflict involving Iran has triggered significant cyber and influence operations, with multiple nation-state and hacktivist groups leveraging the crisis for espionage, destructive attacks, and narrative manipulation. Organizations are advised to prepare for a surge in Iranian cyber activity as domestic internet blackouts lift, alongside heightened risks of physical threats and supply chain disruptions.

Palo Alto Networks4 months ago7 minLLM reportcritical

Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia

A suspected China-nexus threat actor tracked as CL-STA-1087 has been conducting a persistent espionage campaign against Southeast Asian military targets since 2020. The attackers utilize custom malware, including the AppleChris and MemFun backdoors, leveraging Dead Drop Resolvers (DDR) like Pastebin and Dropbox for C2 resolution alongside advanced evasion techniques like process hollowing and DLL hijacking.

Akamai4 months ago3 minLLM reportlow

RSAC 2026: Tag in a Partner for the AI Security Showdown

This promotional article highlights Akamai's upcoming presence at RSAC 2026, focusing on the escalating arms race between AI-driven cyber threats and enterprise security. It emphasizes that adversaries are using AI to automate API attacks and exploit cloud misconfigurations, necessitating a shift away from legacy security toward robust Zero Trust frameworks and strategic partner ecosystems.

Sophos4 months ago6 minLLM reportcritical

March Patch Tuesday visits 15 product families

Microsoft's March Patch Tuesday addressed 84 vulnerabilities across 15 product families, including 8 Critical and 76 Important flaws. While no zero-days were reported as actively exploited, two vulnerabilities have been publicly disclosed, and six are deemed highly likely to be exploited within 30 days. Organizations are advised to prioritize patching for critical Remote Code Execution and Elevation of Privilege vulnerabilities affecting Windows, Office, and Azure environments.

Sophos4 months ago4 minLLM reporthigh

Initial access techniques used by Iran-based threat actors

Iranian-linked threat actors consistently utilize a core set of cost-effective initial access techniques, including social engineering, rapid exploitation of known vulnerabilities, and credential abuse. These groups frequently leverage legitimate RMM tools and trusted cloud services to establish persistence and evade detection, highlighting the need for robust identity management, prompt patching, and perimeter security.

WithSecure4 months ago4 minLLM reporthigh

The Changing Economics of Cybercrime-as-a-Service: What Defenders Need to Know

The cybercrime-as-a-service ecosystem is evolving rapidly, characterized by a shift towards trading live session tokens, the integration of generative AI for dynamic payload generation, and a preference for data exfiltration over encryption. Defenders must adapt by prioritizing identity monitoring, rapid session revocation, and recognizing the blurring lines between commodity cybercrime and state-aligned operations.