Skip to content
.ca
sign in

DFIR · deception · detection

Posts I wrote, intel from the CTI pipeline, and redacted engagement reports from the honeypot fleet.

Huntressabout 3 hours ago6 minLLM reportmedium

What Good Identity Hardening Looks Like

Attackers are shifting from network perimeter breaches to identity compromise, leveraging stolen credentials and session tokens to access consolidated SSO environments. MFA alone is insufficient; gaps like overprivileged accounts, unmonitored session tokens, and MFA exceptions create exploitable paths. The article describes ClickFix social engineering and a real-world BEC case to illustrate the impact of identity security gaps.

Canadian Centre for Cyber Securityabout 11 hours ago3 minLLM reporthigh

Cyber Centre Daily Advisory Digest — 2026-08-25 (3 advisories)

The Canadian Centre for Cyber Security published three security advisories on August 25, 2026. The advisories cover a Remote Code Execution vulnerability in Gitea (CVE-2026-60004) added to the CISA KEV database, multiple vulnerabilities in OpenSSL across various branches, and vulnerabilities in WatchGuard Agent. Users and administrators are encouraged to apply available updates.

CISAabout 11 hours ago4 minLLM reporthigh

Rently Smart Home (CVE-2026-75960)

Rently Smart Home versions 20.1.0 and prior contain an insufficiently protected credentials vulnerability (CVE-2026-75960). Exploitation allows an attacker to retrieve sensitive pins, including the Master Pin, and override standard user permissions. The vendor has patched the vulnerability in late June.

CISAabout 11 hours ago9 minLLM reportcritical

Ebyte NE2-D11 (CVE-2026-73125, CVE-2026-73809, CVE-2026-73839 +8 more)

CISA published an ICS advisory disclosing eleven vulnerabilities in the Ebyte NE2-D11 industrial gateway device running firmware FW-9167-0-11. Three CVEs are rated CVSS 9.8 Critical, covering missing authentication, client-side authentication bypass, and cleartext MQTT credential transmission. No patch is available; the vendor acknowledged the reports but has not provided remediation. Attackers can exploit these flaws remotely without authentication to gain administrative control, intercept credentials, hijack sessions, and disrupt device operation.

Spiderlabsabout 15 hours ago6 minLLM reporthigh

Energy Disruption in UK Critical Infrastructure and the Growing OT Cyber Threat

A July 2026 cyber incident disrupted operations at a small UK electricity generator for several days, with media reports attributing the activity to Iran-linked actors. However, public technical evidence detailing the intrusion vector, malware, or specific threat actor remains unavailable. The incident highlights a broader trend of state and state-linked actors targeting exposed operational technology (OT) and industrial control systems (ICS), particularly internet-facing PLCs, to achieve physical operational disruption.

Recorded Futureabout 15 hours ago5 minLLM reporthigh

Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense

Mexico's 2025-2030 National Cybersecurity Plan addresses a complex threat landscape dominated by ransomware, state-sponsored espionage, and financial malware. The plan outlines a six-phase roadmap to build governance, establish a National Cybersecurity Operations Center, and pass new legislation. Insikt Group assesses that while the plan is ambitious, Mexico's progress depends on institutional capacity-building and sustained international cooperation.

CISAabout 15 hours ago11 minLLM reporthigh

A Tale of Two SOCs: Insights From Two Red Team Assessments (2026-08-25)

CISA conducted simultaneous red team assessments at two critical infrastructure organizations using similar tradecraft. The red team achieved full domain compromise at both organizations by exploiting ADCS misconfigurations, excessive Machine Account Quota settings, cleartext credentials, and overly permissive Entra ID application permissions. Organization A failed to detect the activity due to untuned EDR alerts and organizational silos, while Organization B rapidly triaged and isolated compromised systems. Both organizations lacked Conditional Access policies for workload identities and mature processes for revoking compromised cloud tokens.

Trail of Bitsabout 18 hours ago7 minLLM reporthigh

State divergence enables unauthorized access

A state divergence bug in Provenance Blockchain's marker module allowed any user to bypass access control checks on non-fixed supply markers. The authorization function accountControlsAllSupply compared a stale stored supply field (always zero for non-fixed markers) against the caller's balance, producing an unconditionally true result when both were zero. This let an attacker grant themselves admin, mint, and withdraw permissions in a single transaction, then mint arbitrary tokens or drain escrowed assets in a second transaction. 82 markers on mainnet were affected, with approximately $500,000 in escrowed nhash at direct risk.

Palo Alto Networksabout 18 hours ago11 minLLM reportmedium

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

Unit 42 analyzed 405 AI-enabled malware samples and found that only 12 (3%) appeared on production endpoints, while 97% existed solely in research repositories and sandboxes. The 12 production samples span five families: FunkSec ransomware, a trojanized AI application (Recipe Lister), Oyster backdoor, Rhadamanthys stealer, and a COM hijacking DLL. Existing behavioral detection, sandbox detonation, code-signing anomaly detection, and entropy analysis caught all production samples without requiring novel detection approaches. AI influences malware authoring velocity but does not alter runtime behavior or evade current defensive frameworks.

ANY.RUNabout 18 hours ago13 minLLM reporthigh

A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign

A phishing campaign active since January 2026 uses disposable Vercel-hosted lure pages to deliver password-protected ZIP archives containing VBS scripts. The scripts launch PowerShell to download and install legitimate, signed RMM software that provides hands-on-keyboard remote access. The campaign spans 46 countries with 45% of activity in the United States and uses interchangeable RMM products, making product-specific detection ineffective. Durable detection pivots include a shared web font (font1.woff2), a mislabeled Word icon asset, and a consistent secure.html to project/*.zip download chain.

Akamaiabout 19 hours ago5 minLLM reporthigh

Deconstructing the Architecture of AI-Orchestrated Web Attacks | Akamai

The article describes the shift toward AI-orchestrated web attacks where LLMs act as orchestrators and secondary tools execute web requests. This decoupled architecture creates a 'speed gap' where functional exploits are generated in under 10 minutes, outpacing human remediation. Attackers leverage protocols like Model Context Protocol (MCP) and spoof User-Agent headers to bypass legacy WAFs, necessitating real-time behavioral analytics and edge-based defenses.

CISA1 day ago5 minLLM reporthigh

CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-21962)

CISA has added CVE-2026-21962, an improper access control vulnerability in Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation. Federal agencies are mandated to remediate this under BOD 26-04, while CISA advises all organizations to prioritize patching. The vulnerability poses significant risks to exposed assets.

Asec1 day ago5 minLLM reporthigh

July 2026 Threat Trend Report on Ransomware

The July 2026 Threat Trend Report on Ransomware highlights a complex threat landscape driven by established ransomware groups and the emergence of new data extortion actors. The Gentlemen group led with 159 claimed incidents, while manufacturing and the United States remained the most targeted industry and country, respectively. The report also identifies a SOCKS5 proxy disguised as Nezha RMM and vmtools.Exe, indicating ongoing evasion tactics using legitimate tooling.

Check Point1 day ago9 minLLM reportcritical

24th August – Threat Intelligence Report - Check Point Research

This weekly threat intelligence bulletin covers multiple critical vulnerabilities with active exploitation, including CVE-2026-19478 in GitLab (CVSS 9.4) and CVE-2026-12569 in PTC Windchill/FlexPLM targeted by Cl0p with a custom implant for credential decryption and data theft. Check Point Research details the StopAndProtect campaign abusing WordPress sites for malware distribution via ClickFix technique, the repurposing of the Microsoft-signed BTR.sys driver for privileged operations using a hard-coded RC4 key, and emerging AI-assisted threats including autonomous exploitation of CI/CD pipelines and attacks on Siemens S7 industrial controllers.

Malpedia2 days ago6 minLLM reporthigh

CNCMachineRMS C2 Protocol

CNCMachineRMS is a remote access trojan using a custom binary C2 protocol over TCP port 443 without TLS. It leverages DNS over HTTPS (DoH) to resolve C2 domains, bypassing local DNS logging. The protocol is identifiable by statistical analysis due to distinctive byte patterns at fixed offsets. Delivery has been observed via ClickFix attacks delivering the BabaDeda chain.

2 days ago13 minRecapAug 17 – Aug 24

Weekly Recap — 2026-08-17 -> 2026-08-24

Trust Becomes the Target: AI Corruption and Identity Abuse Reshape Defense This week, the tools organizations trust most became the weapons used against them. A Chinese-speaking criminal group called UAT-10147 used AI agents to semi-autonomously exploit web servers, generate attack code, and validate exploits before deploying a cross-platform backdoor called SPECTRE. Meanwhile, a critical flaw in Microsoft Copilot allowed attackers to silently steal data from connected email and calendar accounts and permanently poison the AI's memory through a single malicious link, proving that AI assistants are now both attack tools and attack surfaces. At the same time, attackers systematically dismantled the assumption that an authenticated session guarantees a legitimate user. Three suspected Russian espionage clusters abused built-in authentication features like OAuth consent flows and WhatsApp device linking to compromise personal accounts without stealing passwords, while the Mirage2FA toolkit bypassed multi-factor authentication for over 4,000 victims. Separately, North Korean IT workers using AI-generated identities applied to over 1,100 companies to gain trusted insider access, and attackers increasingly used collaboration platforms like Teams and Slack as phishing channels because employees let their guard down on internal tools. Defenders should treat every AI tool interaction with untrusted content as a potential compromise, move beyond password-plus-code authentication toward passkeys and hardware-backed verification, and urgently patch the nine vulnerabilities CISA added to its exploited-vulnerability catalog this week across Zimbra, TrueConf, MLflow, and Microsoft and VMware products.

Canadian Centre for Cyber Security4 days ago7 minLLM reporthigh

Cyber Centre Daily Advisory Digest — 2026-08-21 (5 advisories)

The Canadian Centre for Cyber Security published five security advisories on 2026-08-21 covering vulnerabilities in Splunk, Apple, Mozilla, Zimbra, and Malcolm products. CVE-2026-73570 affecting Zimbra Collaboration was added to CISA's Known Exploited Vulnerabilities (KEV) Database, indicating active exploitation. The Malcolm network analysis platform used in control system environments is affected by six CVEs across multiple versions.

CISA4 days ago6 minLLM reportcritical

CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-73570)

CISA added CVE-2026-73570, an OS Command Injection vulnerability in Zimbra Collaboration Suite (ZCS), to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed active exploitation. The vulnerability allows attackers to execute arbitrary OS commands on affected hosts. BOD 26-04 requires FCEB agencies to remediate KEV-listed vulnerabilities on exposed assets and to investigate whether systems were compromised prior to patching.

Kaspersky5 days ago14 minLLM reporthigh

The invisible passenger in your car

Kaspersky identified a multi-stage Android downloader distributed through the built-in update functionality of DoFun-based automotive head unit firmware. The legitimate TWCore system app receives MQTT-based instructions that allow installation of apps not already present on the device, which attackers abused to deliver a JarService dropper that chains through a loader, a clicker/loader, and finally a reverse proxy module (zhima) that recruits the device into a proxy botnet. The activity is attributed with high confidence to MoYu Group based on code artifact naming, thread names, and infrastructure overlap with a related implant found on TV set-top boxes.