Technical Threat Report: Russian GRU Cyber Campaign Targeting Western Logistics and Technology Sectors

On May 21, 2025, CISA and international cybersecurity authorities issued CSA AA25-141A, attributing a sophisticated espionage campaign to GRU Unit 26165 (APT28/Fancy Bear). These operations have targeted logistics and IT support organizations involved in foreign aid to Ukraine. Zeek Threat Intelligence Feed - Download Summary of Threat Campaign APT28 uses diverse tactics to infiltrate and persist in networks, combining spearphishing, zero-day exploitation, credential attacks, and post-exploitation frameworks to exfiltrate sensitive operational data. Common Techniques Used: Initial Access Credential stuffing and brute-force attacks via Tor and commercial VPNs Spearphishing with links to spoofed login pages Exploitation of CVEs, including: CVE-2023-23397 (Outlook NTLM hash leak) CVE-2023-38831 (WinRAR exploit) Roundcube CVEs: 2020-12641, 2020-35730, 2021-44026 Lateral Movement & Persistence Deployment of OpenSSH for command/control Use of native tools like Impacket, PsExec, Certipy, ADExplorer Lateral RDP access and NTDS.dit extraction Scheduled task creation with schtasks Data Collection & Exfiltration Abuse of mailbox permissions for persistent…

0 Comments

Critical Path Security Kicks Off NASCAR Canada Series with Ryan Vargas at CTMP

This past weekend marked a historic milestone for Critical Path Security Canada as we hit the track with Ryan Vargas in the NASCAR Canada Series at Canadian Tire Motorsport Park (CTMP). Proudly adorning the #28 Dodge Challenger, Critical Path Security made its sponsorship debut in front of a national audience, backed by the raw determination and skill of Vargas and the powerhouse DJK Racing team. In what was Vargas' first-ever time at CTMP-and his first time piloting this specific Dodge Challenger-the challenge was clear: learn fast, adapt faster. And that's exactly what he did. "It's never easy showing up to a track completely green, but it's even harder showing up in a car that you've never driven," said Vargas. "Thankfully, my DJK Racing team was quick to adjust and make the right calls all weekend on my #28 Critical Path Security Dodge Challenger, helping me gain a second and a…

0 Comments

Open-Source Repositories: The Front Line in Software Supply Chain Attacks

Modern software is built on open-source. Developers rely on public repositories like npm, PyPI, and Maven Central to move fast, avoid reinventing the wheel, and ship updates continuously. But this speed and openness come at a cost: your software supply chain is now a primary attack surface. Attackers have figured this out-and they're exploiting it. How Open-Source Dependencies Become Attack Vectors Open-source packages are easy to install and often trusted implicitly. That's exactly what makes them so appealing to threat actors. Here's how attackers are weaponizing open-source: 1. Typosquatting Malicious packages are uploaded with names that closely mimic legitimate libraries (e.g., expresss instead of express). If a developer makes a typo or auto-installs a dependency, they may unknowingly install malware. 2. Hijacked or Abandoned Projects Attackers take over dormant projects-sometimes by buying expired domains or credentials-and inject malicious code into new releases. Users update as usual, unaware of the compromise.…

0 Comments

Ryan Vargas and Critical Path Security Head to Canadian Tire Motorsport Park for 2025 Season Debut

As the 2025 NASCAR Canada Series kicks off in full force, Critical Path Security is proud to support driver Ryan Vargas in his return to the track at the iconic Canadian Tire Motorsport Park in Bowmanville, Ontario. The race will take place on Sunday, May 18 at 1 PM ET, marking the second stop of the season and the first road course challenge for drivers this year. This track, known for its high-speed corners and challenging elevation changes, will be a true test of driver skill and car performance. The #28 Critical Path Security Dodge, driven by Vargas, is prepped and ready to make a strong statement on the international stage. A Cross-Border Mission Our involvement in both U.S. and Canadian cybersecurity has never been more visible. Supporting Ryan Vargas on Canadian soil isn't just a race-day partnership-it's a symbol of Critical Path Security's expanding presence across North America. With…

0 Comments