Home/Intelligence library
Cypho research

Intelligence for the teams behind the defense.

Research, analysis, and practical guidance on the threats, vulnerabilities, and adversaries shaping today's security landscape.

Explore the latest research
Research coverageContinuously updated
01Threat actors
02Dark web
03Attack surface
04Vulnerability research
Latest intelligence

Research you can put to work.

Go beyond headlines with analyst-led context, defensive guidance, and clear takeaways for security teams.

23articles
CVE-2025-0108: Rover Detects a PAN-OS Authentication Bypass Attempt
Threat Intel
Aug 25, 2026Cypho Research Team

CVE-2025-0108: Rover Detects a PAN-OS Authentication Bypass Attempt

Rover caught the public CVE-2025-0108 exploit path in Siren telemetry. Here is how one double-encoded traversal crosses Nginx and Apache to bypass PAN-OS management authentication.

Read analysis
Wearing a Crawler's Name: What Happens When Attackers Claim to Be GPTBot
Threat Intel
Aug 25, 2026Cypho Research Team

Wearing a Crawler's Name: What Happens When Attackers Claim to Be GPTBot

A Siren sensor caught a command-injection attempt against a fake admin endpoint, sent under a spoofed GPTBot and Amazonbot User-Agent. Here's what that costs an attacker, why it works, and how to detect it without trusting the header at all.

Read analysis
Free vs. Premium: The Hidden Pricing Model Behind Stolen Credentials
Threat Intel
Aug 19, 2026Cypho Research Team

Free vs. Premium: The Hidden Pricing Model Behind Stolen Credentials

How the stealer log economy splits into free and paid tiers, what actually makes a log valuable, what a single credential can expose inside an organization, and how the 2024 Snowflake breach shows exactly how far that chain can run.

Read analysis
Pequod: A Docker and Redis Botnet Delivering an XMRig Miner and Reverse-Proxy Payload
Threat Intel
Aug 13, 2026Cypho Research Team

Pequod: A Docker and Redis Botnet Delivering an XMRig Miner and Reverse-Proxy Payload

One rented VPS, three payloads — a self-naming dropper, a Docker API scanner, and a Redis module that turns MODULE LOAD into remote code execution — all converging on the same Monero wallet.

Read analysis
Anatomy of a Multi-Architecture IoT Botnet
Threat Intel
Aug 6, 2026Cypho Research Team

Anatomy of a Multi-Architecture IoT Botnet

Inside a three-tier infrastructure of adaptive droppers and fileless C2 — a brute-force stager, an adaptive dropper, and a C2 hiding behind a real web server, tracked tier by tier from honeypot capture to payload teardown.

Read analysis
Closing the Loop on a Redis Worm: From Cron Injection to Self-Propagation
Threat Intel
Jul 25, 2026Cypho Research Team

Closing the Loop on a Redis Worm: From Cron Injection to Self-Propagation

A captured Redis exploit led us from a 1,644-byte cron injection to a self-propagating cryptomining campaign that disables defenses, hides behind shell-script rootkits, and hunts for its next victim.

Read analysis
Move from reading to response

Bring real-time threat intelligence into your workflow.

See how Cypho turns external signals into prioritized action.

Request a demo