Sign in

boredchilada

@cyfar.ca
76 followers 6 following 2.6K posts

I sheer alpacas and try to defend the internet from malware, minimal memes, mostly biznez Cyfar.ca @cyfar@infosec.exchange

PostsRepliesMedia
boredchilada @cyfar.ca · 1h
~Cisa~ CISA reports active exploitation of a Cisco Catalyst SD-WAN Manager hex encoding vulnerability; prioritize remediation. - IOCs: CVE-2026-76504 - #CVE202676504 #Cisco #ThreatIntel
cisa.gov
CISA Adds CVE-2026-76504 to KEV
000
boredchilada @cyfar.ca · 9h
@sophossecurity.bsky.social TerminalFix lures deploy Lorem Ipsum Loader and a Python reverse tunnel for covert access. - IOCs: letsdiskuss[.]com, Lorem Ipsum Loader, STAC4924 - #ClickFix #Malware #ThreatIntel
sophos.com
TerminalFix Covert Tunneling
000
boredchilada @cyfar.ca · 9h
~Akamai~ 32 extensions hid browsing surveillance and remote redirects, affecting 6,150+ users. - IOCs: api[.]pvmf[.]workers[.]dev, cdn[.]jsdelivr[.]net, link[.]coupang[.]com - #BrowserSecurity #Malware #ThreatIntel
akamai.com
Malicious Productivity Extensions
000
boredchilada @cyfar.ca · 13h
@reversinglabs.com S1ngularity, Shai-Hulud and TeamPCP used compromised packages and tokens to steal secrets and propagate malware. - IOCs: S1ngularity, Shai-Hulud, CanisterWorm - #Malware #SupplyChain #ThreatIntel
reversinglabs.com
Malicious Updates Poison Supply Chains
010
boredchilada @cyfar.ca · 13h
@mandiant.com AI is accelerating high-risk vulnerability discovery and n-day exploitation, especially across exposed AI middleware. - IOCs: CVE-2026-1731, CVE-2026-42271, CVE-2026-5027 - #AI #ThreatIntel #Vulnerabilities
cloud.google.com
AI-Driven Exploitation Trends
010
boredchilada @cyfar.ca · 16h
~Cisa~ Unauthenticated radio-range attackers can trigger signaling shutdown and temporary service disruption. - IOCs: CVE-2026-96274 - #CVE202696274 #ICS #ThreatIntel
cisa.gov
Baicells Nova 430H DoS
020
boredchilada @cyfar.ca · 16h
~Asec~ August attacks used spear-phishing LNK/HWP files to deploy backdoors and steal data. - IOCs: www[.]cwmodern[.]com, www[.]dolgicap[.]com, dpaper[.]dothome[.]co[.]kr - #APT #Phishing #ThreatIntel
asec.ahnlab.com
South Korea APT Trends
010
boredchilada @cyfar.ca · 16h
~Asec~ Smishing impersonates Pi Network to steal 24-word wallet recovery phrases. - IOCs: (None identified) - #Phishing #Smishing #ThreatIntel
asec.ahnlab.com
Pi Coin Wallet Phishing
010
boredchilada @cyfar.ca · 16h
~Asec~ Fake crypto-exchange ads infected about 1,500 Korean Windows and macOS PCs with JSCEAL. - IOCs: JSCEAL - #JSCEAL #Malware #ThreatIntel
asec.ahnlab.com
JSCEAL Malware via Facebook Ads
000
boredchilada @cyfar.ca · 30/09/2026
@microsoft.com Attackers abused MSP360 and ScreenConnect to establish redundant persistent access and steal credentials. - IOCs: adswre[.]cfd, trews[.]cfd, sdfghj[.]rd-team[.]ru - #Phishing #RMM #ThreatIntel
microsoft.com
RMM Phishing Enables Persistent Access
020
boredchilada @cyfar.ca · 30/09/2026
~Asec~ Malicious VBScript and obfuscated PowerShell deliver Remcos RAT via Google Drive. - IOCs: 102[.]220[.]160[.]104:2404, drive[.]google[.]com, af87821d3cb4f1d72bfb8002437593ec - #Phishing #Remcos #ThreatIntel
asec.ahnlab.com
Quote Request Phishing Delivers Remcos
000
boredchilada @cyfar.ca · 29/09/2026
~Watchtowr~ In-the-wild pre-auth DTLS overflow enables RCE or DoS; patch immediately. - IOCs: CVE-2026-88772 - #CVE-2026-88772 #Citrix #ThreatIntel
labs.watchtowr.com
Citrix NetScaler DTLS RCE
110
boredchilada @cyfar.ca · 29/09/2026
~Spiderlabs~ Critical NetScaler flaws enable unauthenticated RCE and are actively exploited worldwide. - IOCs: CVE-2026-88771, CVE-2026-88772 - #CVE202688771 #CVE202688772 #ThreatIntel
levelblue.com
Citrix NetScaler Zero-Days Exploited Globally
000
boredchilada @cyfar.ca · 29/09/2026
~Recordedfuture~ AI scales phishing, while deepfakes and biometric injection undermine identity verification. - IOCs: WormGPT4, EvilTokens - #Deepfake #Phishing #ThreatIntel
recordedfuture.com
AI Social Engineering
000
boredchilada @cyfar.ca · 29/09/2026
@microsoft.com Star Blizzard uses RedFlick scheduled tasks to deliver CosmicPulse in scalable phishing campaigns. - IOCs: secure-dns-hub[.]com, etia[.]ca, gliderrompercycl[.]com - #Malware #Phishing #ThreatIntel
microsoft.com
Star Blizzard RedFlick Phishing
000
boredchilada @cyfar.ca · 29/09/2026
@mandiant.com Active exploitation enables root access, WHIPSHOT web shells and SLAPSHOT tunneling. - IOCs: CVE-2026-88772, CVE-2026-88771, WHIPSHOT - #CVE202688771 #CVE202688772 #ThreatIntel
cloud.google.com
Citrix NetScaler Zero-Days Exploited
000
boredchilada @cyfar.ca · 29/09/2026
~Cybergcca~ Apple CVE-2026-86950 is exploited in the wild; patch affected Apple devices and other listed products. - IOCs: CVE-2026-86950, CVE-2026-101891, CVE-2026-86102 - #Apple #CVE #ThreatIntel
cyber.gc.ca
Cyber Centre Daily Digest: 7 Advisories
000
boredchilada @cyfar.ca · 29/09/2026
~Cisa~ Unauthenticated command injection enables root-level remote code execution; update firmware. - IOCs: CVE-2026-22755 - #CVE202622755 #IoT #ThreatIntel
cisa.gov
VIVOTEK Camera RCE
000
boredchilada @cyfar.ca · 29/09/2026
~Cisa~ Unauthenticated crafted requests enable root RCE or DoS; update to 7.23+. - IOCs: CVE-2026-84411 - #CVE202684411 #RouterOS #ThreatIntel
cisa.gov
MikroTik RouterOS CVE-2026-84411
000
boredchilada @cyfar.ca · 29/09/2026
~Akamai~ 30 extensions impersonated investors and redirected users to crypto-wallet phishing pages. - IOCs: z-toolbox[.]online, swiftnote[.]online, chromerabbypro[.]com - #Malware #Phishing #ThreatIntel
akamai.com
Crypto Scam Extensions
000
boredchilada @cyfar.ca · 29/09/2026
They be hitting me too, a lot of marker checks
000
boredchilada @cyfar.ca · 29/09/2026
@crowdstrike.com Fake meeting and CAPTCHA lures trick users into running PowerShell commands, delivering malware and enabling credential theft. - IOCs: GeniexRAT, GeniexLoader, VOODOO BEAR - #ClickFix #Malware #ThreatIntel
crowdstrike.com
ClickFix Attacks
000
boredchilada @cyfar.ca · 29/09/2026
@paloaltonetworks.com Overprivileged operators can expose cluster secrets and enable autonomous AI-driven compromise. - IOCs: CVE-2026-6389 - #Kubernetes #RBAC #ThreatIntel
unit42.paloaltonetworks.com
Kubernetes Operator RBAC Risks
000
boredchilada @cyfar.ca · 29/09/2026
@huntress.com Attackers abuse ChatGPT Custom GPTs and Google Sites to deliver a RAT via PowerShell and DLL sideloading. - IOCs: 96[.]62[.]224[.]81, chatgpt[.]com, sites[.]google[.]com - #ClickFix #Malware #ThreatIntel
huntress.com
Custom GPT ClickFix RAT
000
boredchilada @cyfar.ca · 29/09/2026
~Asec~ CVE-2017-0199-laced XLS attachments use HTA and PowerShell to deliver Remcos RAT. - IOCs: 172[.]245[.]209[.]133, muddy-sound-e0cd[.]nodetectonn[.]workers[.]dev, blessedongrace[.]duckdns[.]org:19700 - #Phishing #Remcos #ThreatIntel
asec.ahnlab.com
Phishing XLS Delivers Remcos RAT
000
boredchilada @cyfar.ca · 29/09/2026
~Anyrun~ CSuite, N0va, Wazza, TerminalFix and IronToll used session theft, remote access, evasive phishing and payment fraud against US/EU targets. - IOCs: CSuite, N0va, IronToll - #Malware #Phishing #ThreatIntel
any.run
September Cyberattacks Target Identity and Payments
001
boredchilada @cyfar.ca · 29/09/2026
~Malpedia~ North Korea-linked hackers breached Bitget’s wallet backend and stole $387.5M in crypto. - IOCs: Lazarus Group - #Crypto #LazarusGroup #ThreatIntel
malpedia.caad.fkie.fraunhofer.de
Bitget Loses $387M to North Korea
000
boredchilada @cyfar.ca · 29/09/2026
~Malpedia~ U.S. soldier Cameron Wagenius received 70 months for stealing telecom metadata and extorting AT&T, Verizon, and others. - IOCs: CVE-2023-45208 - #CyberCrime #DataBreach #ThreatIntel
malpedia.caad.fkie.fraunhofer.de
Soldier Sentenced for Telecom Extortion
000
boredchilada @cyfar.ca · 28/09/2026
~Watchtowr~ Actively exploited unauthenticated command injection enables root RCE on default NetScaler configurations. - IOCs: CVE-2026-88771 - #CVE202688771 #Citrix #ThreatIntel
labs.watchtowr.com
Citrix NetScaler Pre-Auth RCE
000
boredchilada @cyfar.ca · 28/09/2026
@sophossecurity.bsky.social Critical NetScaler flaws enable unauthenticated RCE and are actively exploited. - IOCs: CVE-2026-88771, CVE-2026-88772 - #CVE202688771 #CVE202688772 #ThreatIntel
sophos.com
NetScaler CVEs Exploited
000
boredchilada @cyfar.ca · 28/09/2026
@ncsc.gov.uk Two NetScaler flaws are actively exploited; patch or isolate affected systems. - IOCs: CVE-2026-88771, CVE-2026-88772 - #CVE-2026-88771 #CVE-2026-88772 #Citrix #ThreatIntel
ncsc.gov.uk
Citrix NetScaler Exploitation
011
boredchilada @cyfar.ca · 28/09/2026
@microsoft.com Modular post-compromise malware enables stealthy persistence and C2 via DLL sideloading. - IOCs: corp[.]tripswithengine[.]com, e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e - #ChinaAligned #Malware #ThreatIntel
microsoft.com
NeedyMantis Targeted Malware
000
boredchilada @cyfar.ca · 28/09/2026
~Checkpoint~ Active exploitation targets critical Check Point, F5 and WordPress flaws. - IOCs: CVE-2026-85102, CVE-2026-93616, CVE-2026-94127 - #Exploitation #Ransomware #ThreatIntel
research.checkpoint.com
Threat Intelligence Report
010
boredchilada @cyfar.ca · 28/09/2026
~Asec~ Ransomware incidents surged, led by Qilin and Gentlemen, while Clop exploited Windchill and FlexPLM in a global supply-chain campaign. - IOCs: Qilin, CL0P, Windchill - #Qilin #Ransomware #ThreatIntel
asec.ahnlab.com
August 2026 Ransomware Trends
000
boredchilada @cyfar.ca · 28/09/2026
~Cybergcca~ CISA added two Citrix NetScaler CVEs to KEV; apply updates. - IOCs: CVE-2026-88771, CVE-2026-88772 - #CVE202688771 #Citrix #ThreatIntel
cyber.gc.ca
Citrix NetScaler vulnerabilities
000
boredchilada @cyfar.ca · 28/09/2026
~Cisa~ Threat actors are globally exploiting two critical NetScaler zero-days enabling remote code execution. - IOCs: CVE-2026-88771, CVE-2026-88772 - #CVE-2026-88771 #CVE-2026-88772 #ThreatIntel
cisa.gov
Citrix NetScaler Zero-Days Exploited
000
boredchilada @cyfar.ca · 28/09/2026
~Asec~ Attackers exploited unpatched Telerik IIS servers for reverse shells, privilege escalation, Godzilla web shells, and WordPress scanning. - IOCs: 206[.]82[.]6[.]22, 65[.]98[.]5[.]158, api[.]telegram[.]org - #CVE201918935 #ThreatIntel #WebShell
asec.ahnlab.com
Telerik RCE Attacks Deploy Web Shells
000
boredchilada @cyfar.ca · 27/09/2026
~Cybergcca~ Active exploitation of NetScaler flaws enables remote code execution and appliance compromise. - IOCs: CVE-2026-88771, CVE-2026-88772 - #CVE-2026-88771 #CVE-2026-88772 #CyberSecurity #ThreatIntel
cyber.gc.ca
Critical NetScaler Vulnerabilities
000
boredchilada @cyfar.ca · 27/09/2026
~Cisa~ CISA reports active exploitation of two Citrix NetScaler vulnerabilities and urges rapid remediation. - IOCs: CVE-2026-88771, CVE-2026-88772 - #CVE-2026-88771 #CVE-2026-88772 #ThreatIntel
cisa.gov
CISA Adds Two Citrix NetScaler CVEs to KEV
010
boredchilada @cyfar.ca · 27/09/2026
~Certeu~ Citrix confirms active exploitation of two unauthenticated NetScaler RCEs; patch immediately and assess internet-facing appliances. - IOCs: CVE-2026-88771, CVE-2026-88772 - #CVE202688771 #Citrix #ThreatIntel
cert.europa.eu
Critical NetScaler RCEs
000
boredchilada @cyfar.ca · 26/09/2026
@sophossecurity.bsky.social Kiteworks warned customers of a possible imminent attack and advised shutting down servers as a precaution. - IOCs: (None identified) - #ThreatIntel #ZeroDay
sophos.com
Kiteworks Urges Server Shutdown
000
boredchilada @cyfar.ca · 26/09/2026
@mandiant.com UNC6240 bypasses WAFs to exploit PeopleSoft and deploy web shells, MeshAgent, and SIDEEYE. - IOCs: 5[.]199[.]162[.]157, 162[.]219[.]30[.]165, winmanage-me[.]network - #CVE202635273 #ShinyHunters #ThreatIntel
cloud.google.com
ShinyHunters Exploit PeopleSoft
000
boredchilada @cyfar.ca · 26/09/2026
@zscalerinc.bsky.social Fake Ledger ads routed victims to phishing pages that stole secret recovery phrases. - IOCs: soyyoo-cwpc5n0e[.]vercel[.]app, rpc-gbz5[.]vercel[.]app, sites[.]google[.]com/view/start-ledger-wallet - #Crypto #Phishing #ThreatIntel
zscaler.com
Ledger Phishing via Google Ads
010
boredchilada @cyfar.ca · 26/09/2026
@microsoft.com Compromised Azure service principals destroyed resources, targeted recovery controls, and collected storage keys. - IOCs: 45[.]131[.]66[.]106, 34[.]153[.]223[.]102, 64[.]20[.]53[.]230 - #CloudSecurity #Ransomware #ThreatIntel
microsoft.com
Storm-3168 Azure Destruction
000
boredchilada @cyfar.ca · 26/09/2026
cyfar.ca/engagements/...
cyfar.ca
Get Boated: Docker-Delivered Mirai-Linked Malware With EtherHiding C2
A Docker API campaign began by commanding exposed daemons to download and execute payloads and ended by uploading payloads directly through the Docker archive API, rotating six packed builds of a...
000
boredchilada @cyfar.ca · 25/09/2026
~Cisa~ CISA added an actively exploited WordPress remote file inclusion flaw to its KEV Catalog; prioritize remediation. - IOCs: CVE-2026-87902 - #CVE-2026-87902 #ThreatIntel #WordPress
cisa.gov
CISA Adds Exploited WordPress CVE
000
boredchilada @cyfar.ca · 25/09/2026
~Malpedia~ Actor chained VPN exploits, data theft and AdaptixC2 to industrialize PIX invoice fraud. - IOCs: yzs[.]fi, 91[.]92[.]241[.]187, pix-proxy-sable[.]vercel[.]app - #Malware #Phishing #ThreatIntel
malpedia.caad.fkie.fraunhofer.de
Operation Master
010
boredchilada @cyfar.ca · 25/09/2026
~Cybergcca~ MikroTik and Microsoft flaws are actively exploited; patch affected systems. - IOCs: CVE-2026-67277, CVE-2026-86060, CVE-2026-65660 - #CyberSecurity #ThreatIntel #Vulnerabilities
cyber.gc.ca
Cyber Centre: 4 Advisories
000
boredchilada @cyfar.ca · 25/09/2026
~Trailofbits~ Malicious hosts can roll back TEE state, reuse signing nonces, and expose private key shares. - IOCs: (None identified) - #MPC #TEE #ThreatIntel
blog.trailofbits.com
TEEs Can Break MPC
000
boredchilada @cyfar.ca · 25/09/2026
~Malpedia~ Konni used malicious LNKs and trojanized Zoom installers to deploy VelvetCake for Ukrainian espionage. - IOCs: 111[.]92[.]246[.]145, p1o2i3u4y5t6r7e8w9q0[.]medianewsonline[.]com, jaemoolding25863[.]elementfx[.]com - #Konni #Malware #ThreatIntel
malpedia.caad.fkie.fraunhofer.de
Konni VelvetCake Campaign
000