Notes from our sensors and analysts.
Research from the Cypho team: attacks our Siren sensors catch, how they work, and what to do about them. Plus longer pieces on threat actors, stealer logs and the tools we use.
Everything we've published.
-
Threat intel
The Stealer Log Supply Chain: Who Does What
Stealer logs pass through specialist roles, from malware developers to cash-out services. See each stage and where defenders can break the chain.
-
Threat intel
What Do Buyers Want in a Stealer Log?
We read public listings on underground log markets. Buyers want bank access, email and fresh cookies. Here is what to monitor and how to respond.
-
Threat intel
What Happens to Stealer Logs After the Sale
Once sold, stealer logs are split by domain and country, searched by target and released as free dumps. Why old logs stay dangerous and what to do.
-
Threat intel
CVE‑2025‑0108: Rover Detects a PAN‑OS Authentication Bypass Attempt
Rover caught the public CVE-2025-0108 exploit path in Siren telemetry. Here is how one double-encoded traversal crosses Nginx and Apache to bypass PAN-OS management authentication.
-
Threat intel
Wearing a Crawler's Name: What Happens When Attackers Claim to Be GPTBot
A Siren sensor caught a command-injection attempt against a fake admin endpoint, sent under a spoofed GPTBot and Amazonbot User-Agent. Here's what that costs an attacker, why it works, and how to detect it without trusting the header at all.
-
Threat intel
Free vs. Premium: The Hidden Pricing Model Behind Stolen Credentials
How the stealer log economy splits into free and paid tiers, what actually makes a log valuable, what a single credential can expose inside an organization, and how the 2024 Snowflake breach shows exactly how far that chain can run.
-
Threat intel
Pequod: A Docker and Redis Botnet Delivering an XMRig Miner and Reverse‑Proxy Payload
One rented VPS, three payloads — a self-naming dropper, a Docker API scanner, and a Redis module that turns MODULE LOAD into remote code execution — all converging on the same Monero wallet.
-
Threat intel
Anatomy of a Multi‑Architecture IoT Botnet
Inside a three-tier infrastructure of adaptive droppers and fileless C2 — a brute-force stager, an adaptive dropper, and a C2 hiding behind a real web server, tracked tier by tier from honeypot capture to payload teardown.
-
Threat intel
Closing the Loop on a Redis Worm: From Cron Injection to Self‑Propagation
A captured Redis exploit led us from a 1,644-byte cron injection to a self-propagating cryptomining campaign that disables defenses, hides behind shell-script rootkits, and hunts for its next victim.
-
Threat intel
Beyond IOC Feeds: Building a Modern CTI Platform for Proactive Cyber Defense
Why simple Indicator of Compromise lists are losing their edge, how the Pyramid of Pain and MITRE ATT&CK reframe threat intelligence around attacker behavior, and what a modern CTI platform actually looks like in practice.
-
Brand protection
From Fake Domains to Deepfake Scams: One Target, Two Tools
Brand impersonation has evolved from typo-squatted domains and fake login pages to cloned executive voices and fabricated videos. A look at why the old brand-monitoring playbook is falling behind, and what a threat-intelligence-driven defense actually looks like.
-
Threat intel
API Security Meets Threat Intelligence: Why Defending Endpoints Without Outside Visibility Is Half a Job
API Security Meets Threat Intelligence refers to integrating real-time threat intelligence into API protection strategies to detect, prevent, and respond to cyber threats more effectively. It combines secure API design with actionable insights about evolving attack patterns, helping organizations stay ahead of potential vulnerabilities and malicious activities.
-
Threat intel
What Are Stealer Logs? How Your Passwords Get Stolen & How to Stay Safe
Learn what stealer logs are, how infostealer malware steals passwords, cookies, and browser data, and how you can protect yourself from cyber threats.
-
Threat intel
The Art of Threat Hunting
A practical guide to proactive threat detection - why waiting for alerts is no longer enough, and how modern security teams hunt adversaries before damage is done.
-
Threat intel
Artificial Intelligence in Cybersecurity
Cybersecurity is no longer just about firewalls and signatures. Explore how artificial intelligence enables smarter threat detection, reduces false positives, and powers the next generation of intelligent defense.
-
Threat intel
APT29 – Cozy Bear: Russia's Ghost in Every Network
A deep-dive threat intelligence report on APT29 — the SVR-backed group behind SolarWinds, the DNC breach, and attacks on Microsoft and HPE — covering their TTPs, malware arsenal, detection guidance, and mitigations.
-
OSINT
OSINT and Internet Scanning Platforms Matter: A Practical Look at Popular Tools
Anyone working in cybersecurity knows that understanding your infrastructure requires more than checking what happens internally. Many risks come from externally exposed services, outdated technologies, or poorly configured systems. To see these problems clearly, OSINT tools have become essential.
-
Data breach
Data Leaks in the Modern World: Understanding the Threat and Learning from Recent Global Incidents
In today's interconnected digital landscape, information flows constantly between individuals, organisations, cloud infrastructures, mobile devices and third-party services. This continuous exchange creates a dynamic ecosystem where data becomes one of most valuable assets and one of most vulnerable.
-
Browser security
Silent Threats in Your Browser: How Chrome Extensions Can Compromise You
Originally, Chrome extensions were designed to enhance productivity and personalize the browsing experience, but over time, they evolved into a powerful attack surface. Threat actors quickly realized that extensions have privileged access to browser data, including cookies, sessions, browsing history, and sometimes even credentials. This makes them an ideal vector for silent data theft.
-
CVE
CVE‑2025‑12480: Critical Improper Access Control in Triofox
A newly disclosed critical vulnerability in Triofox (CVE-2025-12480) exposes organizations to unauthenticated access, full administrative takeover, and rapid escalation to remote code execution. Actively exploited by threat actors, this flaw turns publicly reachable deployments into high-risk entry points for deeper network compromise, making swift patching, isolation, and thorough hunting essential for defenders.
-
Ransomware
Codefinger Ransomware: Encrypting S3 Buckets With AWS's Own Keys
Codefinger abuses stolen AWS keys and S3's customer-provided-key encryption to lock data that AWS can't recover. How the attack works, how to detect it and how to stop it.
-
Threat actor
Scattered Spider: The Group Currently Scattering UK Retail Organizations
This report expands on our previous research into the DragonForce ransomware cartel, which publicly claimed responsibility for the string of disruptive attacks on UK retail organizations between April and May 2025. While DragonForce handled the ransomware deployment and data-leak extortion phases, forensic and behavioral evidence indicates that another entity — Scattered Spider — played a critical enabling role behind the scenes.
-
Infostealers
Stealer Logs in 2025: Anatomy of a Silent Data Heist
A stealer log is not just a file – it's the full memory of a stolen identity. It's a structured package created by infostealer malware that collects everything a user's device "knows": browser-saved passwords, session cookies, autofill data, cryptocurrency wallet keys, FTP/VPN credentials, even system fingerprints and chat tokens.
-
CVE
CVE‑2025‑24091: iOS and iPadOS Vulnerability Allows App to Impersonate System Notifications
Apple has recently patched a critical security flaw in iOS and iPadOS that posed a significant risk to user security. The vulnerability, identified as CVE-2025-24091, allowed malicious applications to impersonate system notifications, which could potentially cause user confusion, security lapses, or denial-of-service (DoS) conditions. Discovered by security researcher Guilherme Rambo, this flaw highlights the need for rapid response in the mobile security landscape.
-
CVE
CVE‑2025‑55315: Critical HTTP Request Smuggling in ASP.NET Core
This blog explains the CVE-2025-55315 vulnerability in ASP.NET Core (Kestrel) — a critical HTTP Request Smuggling flaw that can allow attackers to bypass authentication, manipulate traffic, and compromise web servers.
-
Malware
Neptune Loader: Exposing the Hidden Realms of Malware Command And Control / Vulnerability that exposes affected machines
This post talks about a vulnerability that we discovered in Neptune loader. Neptune loader is used for remotely controlling your device, it has some features that help attackers to easily use it. This vulnerability allows us to get information about the affected machines that are called bots. Neptune has a web interface that is used for control. We found a serious vulnerability. The post shares details that can help cybersecurity experts find and fix this weakness.
Unknown threats are unstoppable. Until we expose them.
Send us your company domain. We'll walk you through what's already out there about you and how Cypho would handle it, with one of our analysts on the call.
Or write to [email protected]