Cyfar.ca
@[email protected]
one ran a toolkit, another hand-ran 362 commands and hashed their own SSH implant to confirm it stuck, another gsocket...
cyfar.ca/engagements/...
Fake Twilio probe tw-pkgprobe-7731 exfiltrated ACCOUNT_SID and AUTH_TOKEN.
-
IOCs: tw-pkgprobe-7731, support-api[.]us1[.]twilio[.]com, kafka-ui[.]au1[.]twilio[.]com
-
#Malware #SupplyChain #ThreatIntel
Fake Twilio probe tw-pkgprobe-7731 exfiltrated ACCOUNT_SID and AUTH_TOKEN.
-
IOCs: tw-pkgprobe-7731, support-api[.]us1[.]twilio[.]com, kafka-ui[.]au1[.]twilio[.]com
-
#Malware #SupplyChain #ThreatIntel
EvilTokens abused device-code OAuth flows to compromise 12,000+ inboxes across 10,000 organizations.
-
IOCs: vercel[.]app, workers[.]dev, Storm-2992
-
#BEC #Phishing #ThreatIntel
EvilTokens abused device-code OAuth flows to compromise 12,000+ inboxes across 10,000 organizations.
-
IOCs: vercel[.]app, workers[.]dev, Storm-2992
-
#BEC #Phishing #ThreatIntel
Global Group uses payment-plan phishing, malicious downloads and double extortion to deploy ransomware.
-
IOCs: driverupdate[.]sbs, globalsupportupdate[.]top, playmounthdom[.]top
-
#RaaS #Ransomware #ThreatIntel
Global Group uses payment-plan phishing, malicious downloads and double extortion to deploy ransomware.
-
IOCs: driverupdate[.]sbs, globalsupportupdate[.]top, playmounthdom[.]top
-
#RaaS #Ransomware #ThreatIntel
Double-free in lwIP 2.0.1–2.2.1 may enable crashes, DoS, memory corruption, or code execution.
-
IOCs: cgit[.]git[.]savannah[.]gnu[.]org
-
#CVE-2026-91018 #ICS #ThreatIntel
Double-free in lwIP 2.0.1–2.2.1 may enable crashes, DoS, memory corruption, or code execution.
-
IOCs: cgit[.]git[.]savannah[.]gnu[.]org
-
#CVE-2026-91018 #ICS #ThreatIntel
Unauthenticated attackers can reset credentials and take over accounts; patch immediately.
-
IOCs: CVE-2026-18963
-
#CVE-2026-18963 #ICS #ThreatIntel
Unauthenticated attackers can reset credentials and take over accounts; patch immediately.
-
IOCs: CVE-2026-18963
-
#CVE-2026-18963 #ICS #ThreatIntel
Vidar uses per-build virtual machines and custom stream ciphers to evade static analysis.
-
...
Vidar uses per-build virtual machines and custom stream ciphers to evade static analysis.
-
...
Talos open-sources CAIRN, a metadata-first toolkit for hunting and tracking AI-integrated malware.
-
IOCs: api[.]openai[.]com, api[.]anthropic[.]com, api[.]deepseek[.]com
-
# #Malware #AI #ThreatIntel
Talos open-sources CAIRN, a metadata-first toolkit for hunting and tracking AI-integrated malware.
-
IOCs: api[.]openai[.]com, api[.]anthropic[.]com, api[.]deepseek[.]com
-
# #Malware #AI #ThreatIntel
DPRK and Iranian operators use takedown-resistant blockchains for malware C2, driving a 5.2x surge in activity.
-
IOCs: UNC5342, EtherHiding, T1102[.]002
-
#Cybersecurity #DPRK #Iran #ThreatIntel
DPRK and Iranian operators use takedown-resistant blockchains for malware C2, driving a 5.2x surge in activity.
-
IOCs: UNC5342, EtherHiding, T1102[.]002
-
#Cybersecurity #DPRK #Iran #ThreatIntel
Settra deploys MeshAgent RMM, BYOVD, and recovery-inhibiting commands.
-
IOCs: 45[.]13[.]122[.]7, 193[.]5[.]65[.]114, gdrv[.]sys
-
#Malware #Ransomware #ThreatIntel
Settra deploys MeshAgent RMM, BYOVD, and recovery-inhibiting commands.
-
IOCs: 45[.]13[.]122[.]7, 193[.]5[.]65[.]114, gdrv[.]sys
-
#Malware #Ransomware #ThreatIntel
INC ransomware used AnyDesk, BYOVD, lateral movement, and dual ransom notes to pressure victims.
-
IOCs: throughoutes[.]net, 213[.]111[.]185[.]108, HWAuidoOs2Ec[.]sys
-
#INC #Ransomware #ThreatIntel
INC ransomware used AnyDesk, BYOVD, lateral movement, and dual ransom notes to pressure victims.
-
IOCs: throughoutes[.]net, 213[.]111[.]185[.]108, HWAuidoOs2Ec[.]sys
-
#INC #Ransomware #ThreatIntel
Remus led detections as infostealers spread via cracks, SEO poisoning, Renpy packages, and phishing emails.
-
IOCs: www[.]lorvag[.]xyz
-
#Infostealer #Malware #ThreatIntel
Remus led detections as infostealers spread via cracks, SEO poisoning, Renpy packages, and phishing emails.
-
IOCs: www[.]lorvag[.]xyz
-
#Infostealer #Malware #ThreatIntel
CSuite uses device-code phishing and legitimate RMM tools to hijack Microsoft 365 sessions and remotely access US and EU organizations.
-
IOCs: maillive[.]sbs, 207[.]189[.]19[.]40:26688, gddfzxa[.]online
-
#Phishing #RemoteAccess #ThreatIntel
CSuite uses device-code phishing and legitimate RMM tools to hijack Microsoft 365 sessions and remotely access US and EU organizations.
-
IOCs: maillive[.]sbs, 207[.]189[.]19[.]40:26688, gddfzxa[.]online
-
#Phishing #RemoteAccess #ThreatIntel
UTA0565 used fake sites to chain Chrome/Windows 0-days and deliver CLEANGULP.
-
IOCs: americanprgoress[.]top, thecovnresation[.]com, 96[.]9[.]125[.]52
-
#CLEANGULP #ThreatIntel #ZeroDay
UTA0565 used fake sites to chain Chrome/Windows 0-days and deliver CLEANGULP.
-
IOCs: americanprgoress[.]top, thecovnresation[.]com, 96[.]9[.]125[.]52
-
#CLEANGULP #ThreatIntel #ZeroDay
CISA confirms active exploitation of a Zyxel GS1900 switch buffer overflow; prioritize remediation.
-
IOCs: CVE-2026-7273
-
#CVE20267273 #KEV #ThreatIntel
CISA confirms active exploitation of a Zyxel GS1900 switch buffer overflow; prioritize remediation.
-
IOCs: CVE-2026-7273
-
#CVE20267273 #KEV #ThreatIntel
Public PoC enables local users to gain SYSTEM; patch Veeam immediately.
-
IOCs: CVE-2026-32996
-
#CVE-2026-32996 #ThreatIntel #Veeam
Public PoC enables local users to gain SYSTEM; patch Veeam immediately.
-
IOCs: CVE-2026-32996
-
#CVE-2026-32996 #ThreatIntel #Veeam
Attackers used domain-root GPOs to disrupt endpoints and extort without encryption or malware binaries.
-
IOCs: 37[.]19[.]210[.]12, 146[.]70[.]117[.]239, 149[.]102[.]229[.]154
-
#ActiveDirectory #Ransomware #ThreatIntel
Attackers used domain-root GPOs to disrupt endpoints and extort without encryption or malware binaries.
-
IOCs: 37[.]19[.]210[.]12, 146[.]70[.]117[.]239, 149[.]102[.]229[.]154
-
#ActiveDirectory #Ransomware #ThreatIntel
Local users or compromised containers can gain root on affected Edgenius gateways; update to 3.2.4.1.
-
IOCs: CVE-2026-31431
-
#CVE202631431 #ICS #ThreatIntel
Local users or compromised containers can gain root on affected Edgenius gateways; update to 3.2.4.1.
-
IOCs: CVE-2026-31431
-
#CVE202631431 #ICS #ThreatIntel
CISA confirms active exploitation of a Linux kernel vulnerability and urges rapid remediation.
-
IOCs: CVE-2025-39682
-
#CVE202539682 #Linux #ThreatIntel
CISA confirms active exploitation of a Linux kernel vulnerability and urges rapid remediation.
-
IOCs: CVE-2025-39682
-
#CVE202539682 #Linux #ThreatIntel
DPRK actors used fake job lures and weaponized Terraform files to deploy FLATROOF and ROOFDECK on developer Macs.
-
IOCs: grenight[.]com, 176[.]97[.]114[.]232, 45[.]11[.]59[.]140
-
#Malware #ThreatIntel #TraderTraitor
DPRK actors used fake job lures and weaponized Terraform files to deploy FLATROOF and ROOFDECK on developer Macs.
-
IOCs: grenight[.]com, 176[.]97[.]114[.]232, 45[.]11[.]59[.]140
-
#Malware #ThreatIntel #TraderTraitor
Grafana, Advantech, Moxa and Chrome users should apply available updates.
-
IOCs: CVE-2026-15579
-
#CVE202615579 #ThreatIntel #Vulnerability
Grafana, Advantech, Moxa and Chrome users should apply available updates.
-
IOCs: CVE-2026-15579
-
#CVE202615579 #ThreatIntel #Vulnerability
PowerChute versions 1.5 and earlier allow unlimited authentication attempts; upgrade to 1.6.
-
IOCs: CVE-2026-13348
-
#CVE-2026-13348 #ICS #ThreatIntel
PowerChute versions 1.5 and earlier allow unlimited authentication attempts; upgrade to 1.6.
-
IOCs: CVE-2026-13348
-
#CVE-2026-13348 #ICS #ThreatIntel
CISA reports active exploitation and urges rapid remediation.
-
IOCs: CVE-2025-39964, CVE-2026-53266
-
#CVE-2025-39964 #CVE-2026-53266 #ThreatIntel
CISA reports active exploitation and urges rapid remediation.
-
IOCs: CVE-2025-39964, CVE-2026-53266
-
#CVE-2025-39964 #CVE-2026-53266 #ThreatIntel
APT groups abused legitimate services, AI, supply chains and zero-days for espionage and access.
-
IOCs: webhook[.]Site, CVE-2026-68820
-
#APT #SupplyChain #ThreatIntel
APT groups abused legitimate services, AI, supply chains and zero-days for espionage and access.
-
IOCs: webhook[.]Site, CVE-2026-68820
-
#APT #SupplyChain #ThreatIntel
Unvalidated prover input in mod_12289 could forge Falcon signatures and drain Miden accounts.
-
IOCs: mod_12289
-
#AI #ThreatIntel #Web3
Unvalidated prover input in mod_12289 could forge Falcon signatures and drain Miden accounts.
-
IOCs: mod_12289
-
#AI #ThreatIntel #Web3