Skip to content
.ca
sign in

Threat intelligence from CrowdStrike

19 reports on cyfar.ca summarizing CrowdStrike research. Visit CrowdStrike

CrowdStrike10 days ago10 minLLM reportmedium

New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever

ClickOnce application deployment technology provides threat actors with a low-privilege, user-friendly delivery mechanism that bypasses common security controls. The technology's built-in update system, legitimate Microsoft process execution context, and lack of awareness among defenders create multiple abuse vectors including silent payload updates via .appref-ms files, persistence through Startup folder placement, and signature-preserving dependency trojanization. CrowdStrike identifies a new abuse vector involving COM hijacking within the ClickOnce deployment process.

CrowdStrike15 days ago11 minLLM reporthigh

CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates

The CrowdStrike 2026 Threat Hunting Report documents a shift toward trust abuse across identity, cloud, SaaS, AI, and software supply chain attack surfaces. Adversaries are compressing vulnerability exploitation windows to under 24 hours, leveraging vishing and device code phishing for rapid account takeover, and compromising npm package ecosystems to deliver malware downstream. AI services are both targets (LLMJacking, AI supply chain compromise) and accelerants, with AI agent-triggered detections surfacing 2.5x more threat leads than manual activity.

CrowdStrike20 days ago9 minLLM reporthigh

Inside Astaroth's New Spambot Component

Astaroth (Guildma) operators deployed a new WhatsApp Web spambot component in Q4 2025 that uses headless browser automation with stripped WebDriver indicators to silently message all contacts in a victim's WhatsApp list, turning victims into unwitting malware distributors. The spambot shares significant codebase overlap with the Vareg (WATER SACI) spambot previously used to distribute LATAM banking trojans. This represents a shift from traditional email-based spam to abuse of trusted social messaging platforms, with continued Brazil-focused targeting.

CrowdStrike28 days ago13 minLLM reporthigh

Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks

SANDWORM_MODE is a sophisticated multi-stage npm supply chain worm that exploits the runtime behaviors of AI coding assistants, CI automation, and LLM toolchains. The worm uses multi-layer encoding to bypass static analysis, performs environment fingerprinting to differentiate developer workstations from CI runners, and deploys a rogue MCP server to compromise AI assistants into exfiltrating credentials. With propagation via stolen npm tokens, GitHub API tokens, and SSH fallback, plus a destructive dead switch, the campaign demonstrates a new class of supply chain attacks targeting the modern AI-driven development pipeline.

CrowdStrikeabout 1 month ago6 minLLM reporthigh

July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days

Microsoft's July 2026 Patch Tuesday release addresses 622 vulnerabilities, including two actively exploited zero-days and one publicly disclosed zero-day, with 62 rated Critical. The dominant exploitation techniques this month are elevation of privilege (41%), remote code execution (27%), and information disclosure (18%), though the article provides no specific CVE identifiers, affected products, or technical exploitation details.

CrowdStrikeabout 1 month ago8 minLLM reporthigh

CrowdStrike Uncovers New Prompt Injection Techniques

CrowdStrike's AI security research team has expanded its prompt injection taxonomy with 18 new techniques, bringing the total to over 200. Five techniques are detailed: Trigger-Activated Rule Addition (dormant instructions activated by triggers), Cognitive Token Suppression (blocking safety-related terms), Algorithmic Payload Decomposition (fragmenting payloads to evade filters), Special Token Injection (mimicking internal model delimiters), and Unwitting User Delivery (social engineering users into submitting malicious prompts). These techniques highlight that prompt injection has evolved beyond simple jailbreaks to include delayed activation, boundary spoofing, and composite attacks targeting AI agents with tool-access capabilities.

CrowdStrikeabout 2 months ago7 minLLM reportmedium

The Identity Problem Hiding in AI Agent Deployments

The rapid deployment of AI agents in enterprises creates an identity problem: OAuth access tokens (RFC 9068) lack standardized fields to represent agent instance identity, the user on whose behalf an agent acts, and the delegation relationship between them. This gap can lead to coarse-grained authorization, over-privileged access, and the confused deputy problem in transitive agent call chains. The article calls for industry standardization of this identity context within or adjacent to OAuth tokens.

CrowdStrike2 months ago5 minLLM reporthigh

CrowdStrike 2026 Technology Threat Landscape Report: China’s Ambitions Fuel Attacks

The CrowdStrike 2026 Technology Threat Landscape Report highlights that the technology sector remains the primary target for both state-sponsored and eCrime adversaries. China-nexus actors focus on intellectual property theft and AI capabilities, while DPRK-nexus actors leverage fraudulent employment and open-source supply chain compromises (such as the Axios npm package). Additionally, eCrime groups are accelerating extortion operations and exploiting AI trends to distribute malware like macOS infostealers.

CrowdStrike3 months ago5 minLLM reportcritical

Disrupting Glassworm: Inside CrowdStrike’s Takedown of a Developer-Targeting Botnet

CrowdStrike, in collaboration with Google and Shadowserver, successfully dismantled the Glassworm botnet, a highly resilient threat targeting software developers. The threat actors utilized trojanized IDE extensions and malicious package dependencies to deploy GlasswormRAT, leveraging a complex C2 infrastructure spanning the Solana blockchain, BitTorrent DHT, and Google Calendar to maintain persistent access to developer environments.

CrowdStrike3 months ago5 minLLM reporthigh

Now Live: The CrowdStrike 2026 Financial Services Threat Landscape Report

The CrowdStrike 2026 Financial Services Threat Landscape Report highlights a 43% global increase in hands-on-keyboard intrusions against the financial sector. The threat landscape is dominated by eCrime ransomware operations, DPRK-nexus cryptocurrency theft via supply chain compromises, and China-nexus intelligence collection leveraging Operational Relay Box (ORB) networks and DLL search-order hijacking.

CrowdStrike3 months ago4 minLLM reportinfo

Tune In: The Future of AI-Powered Vulnerability Discovery

The article discusses the impending 'vuln-pocalypse' driven by AI-accelerated vulnerability discovery and fuzzing. Threat actors, including FANCY BEAR and FAMOUS CHOLLIMA, are increasingly leveraging AI to enhance phishing campaigns and exploit zero-days faster, necessitating a shift toward threat-informed patch prioritization and robust post-exploitation behavioral detection.

CrowdStrike3 months ago4 minLLM reporthigh

Defending Against CORDIAL SPIDER and SNARKY SPIDER with Falcon Shield

CORDIAL SPIDER and SNARKY SPIDER are executing rapid, SaaS-centric data theft and extortion campaigns by leveraging vishing and AiTM phishing pages. By capturing session tokens and authentication data, these actors bypass traditional endpoint defenses and pivot directly into SSO-integrated SaaS environments via the organization's Identity Provider (IdP).

CrowdStrike3 months ago4 minLLM reportlow

CrowdStrike Expands ChatGPT Enterprise Integration with Enhanced Audit Logging and Activity Monitoring

CrowdStrike has expanded its Falcon Shield integration with ChatGPT Enterprise to deliver enhanced audit logging and continuous activity monitoring. This update shifts the focus from basic configuration awareness to operational visibility, enabling security teams to track authentication, administrative changes, Codex events, and AI tool usage to enforce governance and detect threats in SaaS environments.

CrowdStrike3 months ago5 minLLM reportcritical

STARDUST CHOLLIMA Likely Compromises Axios npm Package

A DPRK-nexus threat actor, likely STARDUST CHOLLIMA, compromised the widely used Axios npm package using stolen maintainer credentials. The supply chain attack deployed updated, cross-platform variants of the ZshBucket malware capable of arbitrary command execution, payload injection, and file system enumeration, likely targeting the cryptocurrency and fintech sectors for financial gain.

CrowdStrike3 months ago5 minLLM reporthigh

Tycoon2FA Phishing-as-a-Service Platform Persists Following Takedown

Following a major law enforcement takedown of its infrastructure on March 4, 2026, the Tycoon2FA Phishing-as-a-Service (PhaaS) platform has quickly reconstituted its operations. The platform continues to enable cybercriminals to bypass multifactor authentication (MFA) using Adversary-in-the-Middle (AiTM) techniques, leading to cloud account takeovers and Business Email Compromise (BEC).

CrowdStrike3 months ago4 minLLM reporthigh

CrowdStrike 2026 Global Threat Report: The Evasive Adversary Wields AI

The CrowdStrike 2026 Global Threat Report highlights a shift toward highly evasive, malware-free attacks leveraging valid credentials, AI tools, and supply chain compromises. Adversaries are operating with unprecedented speed, with average breakout times dropping to 29 minutes, while increasingly targeting AI infrastructure, cloud environments, and network edge devices.

CrowdStrike3 months ago3 minLLM reportlow

Secure Homegrown AI Agents with CrowdStrike Falcon AIDR and NVIDIA NeMo Guardrails

CrowdStrike has announced the integration of Falcon AI Detection and Response (AIDR) with NVIDIA NeMo Guardrails to secure enterprise AI agents against runtime attacks. The solution provides programmable guardrails to prevent prompt injection, data exposure, and unauthorized actions by applying over 75 built-in classification rules to LLM interactions.

CrowdStrike3 months ago2 minLLM reportlow

CrowdStrike Innovates to Modernize National Security and Protect Critical Systems

CrowdStrike announced new product capabilities at Fal.Con Gov 2026 aimed at modernizing national security and protecting critical government systems. The updates include Falcon Flex for flexible procurement and new Charlotte AI features for automated, natural language-driven security investigations within FedRAMP-authorized environments.