boredchilada
cyfar.ca
boredchilada
@cyfar.ca
I sheer alpacas and try to defend the internet from malware, minimal memes, mostly biznez

Cyfar.ca
@[email protected]
Pinned
Stood up an Ivanti Sentry honeypot for 5 days post-CISA-KEV (CVE-2026-10520). They bombarded the snot out of it...

one ran a toolkit, another hand-ran 362 commands and hashed their own SSH implant to confirm it stuck, another gsocket...

cyfar.ca/engagements/...
Ten Operators, One Ivanti Sentry Command-Injection Endpoint
Within five days of exposing an Ivanti Sentry management surface to the internet, a controlled sensor recorded ten distinct operators attempting to exploit CVE-2026-10520, the CVSS 10.0...
cyfar.ca
@reversinglabs.com
Fake Twilio probe tw-pkgprobe-7731 exfiltrated ACCOUNT_SID and AUTH_TOKEN.
-
IOCs: tw-pkgprobe-7731, support-api[.]us1[.]twilio[.]com, kafka-ui[.]au1[.]twilio[.]com
-
#Malware #SupplyChain #ThreatIntel
Malicious npm Campaign Targets Twilio Developers
www.reversinglabs.com
September 22, 2026 at 4:29 PM
@microsoft.com
EvilTokens abused device-code OAuth flows to compromise 12,000+ inboxes across 10,000 organizations.
-
IOCs: vercel[.]app, workers[.]dev, Storm-2992
-
#BEC #Phishing #ThreatIntel
EvilTokens Device-Code Phishing
www.microsoft.com
September 22, 2026 at 4:24 PM
~Cofense~
Global Group uses payment-plan phishing, malicious downloads and double extortion to deploy ransomware.
-
IOCs: driverupdate[.]sbs, globalsupportupdate[.]top, playmounthdom[.]top
-
#RaaS #Ransomware #ThreatIntel
Global Group RaaS Attack
cofense.com
September 22, 2026 at 4:16 PM
~Cisa~
Double-free in lwIP 2.0.1–2.2.1 may enable crashes, DoS, memory corruption, or code execution.
-
IOCs: cgit[.]git[.]savannah[.]gnu[.]org
-
#CVE-2026-91018 #ICS #ThreatIntel
lwIP Double-Free
www.cisa.gov
September 22, 2026 at 4:09 PM
~Cisa~
Unauthenticated attackers can reset credentials and take over accounts; patch immediately.
-
IOCs: CVE-2026-18963
-
#CVE-2026-18963 #ICS #ThreatIntel
Siemens Industrial Edge Auth Bypass
www.cisa.gov
September 22, 2026 at 4:05 PM
@zscalerinc.bsky.social
Vidar uses per-build virtual machines and custom stream ciphers to evade static analysis.
-
...
Vidar VM Obfuscation
www.zscaler.com
September 22, 2026 at 1:15 PM
@talosintelligence.com
Talos open-sources CAIRN, a metadata-first toolkit for hunting and tracking AI-integrated malware.
-
IOCs: api[.]openai[.]com, api[.]anthropic[.]com, api[.]deepseek[.]com
-
# #Malware #AI #ThreatIntel
CAIRN Tracks AI Malware
blog.talosintelligence.com
September 22, 2026 at 1:04 PM
~Malpedia~
DPRK and Iranian operators use takedown-resistant blockchains for malware C2, driving a 5.2x surge in activity.
-
IOCs: UNC5342, EtherHiding, T1102[.]002
-
#Cybersecurity #DPRK #Iran #ThreatIntel
Blockchain Dead Drops Surge
malpedia.caad.fkie.fraunhofer.de
September 22, 2026 at 12:52 PM
@huntress.com
Settra deploys MeshAgent RMM, BYOVD, and recovery-inhibiting commands.
-
IOCs: 45[.]13[.]122[.]7, 193[.]5[.]65[.]114, gdrv[.]sys
-
#Malware #Ransomware #ThreatIntel
Settra Ransomware Uses MeshAgent
www.huntress.com
September 22, 2026 at 12:45 PM
@huntress.com
INC ransomware used AnyDesk, BYOVD, lateral movement, and dual ransom notes to pressure victims.
-
IOCs: throughoutes[.]net, 213[.]111[.]185[.]108, HWAuidoOs2Ec[.]sys
-
#INC #Ransomware #ThreatIntel
Two INC Ransom Notes
www.huntress.com
September 22, 2026 at 12:40 PM
~Asec~
Remus led detections as infostealers spread via cracks, SEO poisoning, Renpy packages, and phishing emails.
-
IOCs: www[.]lorvag[.]xyz
-
#Infostealer #Malware #ThreatIntel
August 2026 Infostealer Trends
asec.ahnlab.com
September 22, 2026 at 12:37 PM
~Anyrun~
CSuite uses device-code phishing and legitimate RMM tools to hijack Microsoft 365 sessions and remotely access US and EU organizations.
-
IOCs: maillive[.]sbs, 207[.]189[.]19[.]40:26688, gddfzxa[.]online
-
#Phishing #RemoteAccess #ThreatIntel
CSuite Phishing Operation
any.run
September 22, 2026 at 12:34 PM
@volexity.com
UTA0565 used fake sites to chain Chrome/Windows 0-days and deliver CLEANGULP.
-
IOCs: americanprgoress[.]top, thecovnresation[.]com, 96[.]9[.]125[.]52
-
#CLEANGULP #ThreatIntel #ZeroDay
UTA0565 Chrome/Windows 0-Day Campaign
www.volexity.com
September 22, 2026 at 4:12 AM
~Cisa~
CISA confirms active exploitation of a Zyxel GS1900 switch buffer overflow; prioritize remediation.
-
IOCs: CVE-2026-7273
-
#CVE20267273 #KEV #ThreatIntel
CISA Adds CVE-2026-7273 to KEV
www.cisa.gov
September 22, 2026 at 4:05 AM
~Arcticwolf~
Public PoC enables local users to gain SYSTEM; patch Veeam immediately.
-
IOCs: CVE-2026-32996
-
#CVE-2026-32996 #ThreatIntel #Veeam
Active Exploitation: Veeam Agent LPE
arcticwolf.com
September 21, 2026 at 8:02 PM
~Kaspersky~
Attackers used domain-root GPOs to disrupt endpoints and extort without encryption or malware binaries.
-
IOCs: 37[.]19[.]210[.]12, 146[.]70[.]117[.]239, 149[.]102[.]229[.]154
-
#ActiveDirectory #Ransomware #ThreatIntel
PAYLOAD Hijacks AD GPO
securelist.com
September 21, 2026 at 12:32 PM
~Cisa~
Local users or compromised containers can gain root on affected Edgenius gateways; update to 3.2.4.1.
-
IOCs: CVE-2026-31431
-
#CVE202631431 #ICS #ThreatIntel
ABB Edgenius Copy Fail
www.cisa.gov
September 19, 2026 at 4:03 AM
~Cisa~
CISA confirms active exploitation of a Linux kernel vulnerability and urges rapid remediation.
-
IOCs: CVE-2025-39682
-
#CVE202539682 #Linux #ThreatIntel
CISA Adds CVE-2025-39682 to KEV
www.cisa.gov
September 19, 2026 at 4:02 AM
@sentinelone.com
DPRK actors used fake job lures and weaponized Terraform files to deploy FLATROOF and ROOFDECK on developer Macs.
-
IOCs: grenight[.]com, 176[.]97[.]114[.]232, 45[.]11[.]59[.]140
-
#Malware #ThreatIntel #TraderTraitor
TraderTraitor macOS Backdoors
www.sentinelone.com
September 18, 2026 at 8:04 PM
get it while its hot

cPanel exploiter repo github.com/Kamp4ng/cilako
GitHub - Kamp4ng/cilako
Contribute to Kamp4ng/cilako development by creating an account on GitHub.
github.com
September 18, 2026 at 6:30 PM
~Cybergcca~
Grafana, Advantech, Moxa and Chrome users should apply available updates.
-
IOCs: CVE-2026-15579
-
#CVE202615579 #ThreatIntel #Vulnerability
Cyber Centre: 4 Security Advisories
www.cyber.gc.ca
September 18, 2026 at 4:07 PM
~Cisa~
PowerChute versions 1.5 and earlier allow unlimited authentication attempts; upgrade to 1.6.
-
IOCs: CVE-2026-13348
-
#CVE-2026-13348 #ICS #ThreatIntel
PowerChute Authentication Flaw
www.cisa.gov
September 18, 2026 at 4:06 PM
~Cisa~
CISA reports active exploitation and urges rapid remediation.
-
IOCs: CVE-2025-39964, CVE-2026-53266
-
#CVE-2025-39964 #CVE-2026-53266 #ThreatIntel
CISA Adds 2 Linux Kernel CVEs to KEV
www.cisa.gov
September 18, 2026 at 4:05 PM
~Asec~
APT groups abused legitimate services, AI, supply chains and zero-days for espionage and access.
-
IOCs: webhook[.]Site, CVE-2026-68820
-
#APT #SupplyChain #ThreatIntel
August APT Threat Trends
asec.ahnlab.com
September 18, 2026 at 4:03 PM
~Trailofbits~
Unvalidated prover input in mod_12289 could forge Falcon signatures and drain Miden accounts.
-
IOCs: mod_12289
-
#AI #ThreatIntel #Web3
Miden VM Audit
blog.trailofbits.com
September 18, 2026 at 12:47 PM