Cypho research

Intelligence for the teams behind the defense.

Research, analysis, and practical guidance on the threats, vulnerabilities, and adversaries shaping today's security landscape.

Explore the latest research
Research coverageContinuously updated
01Threat actors
02Dark web
03Attack surface
04Vulnerability research
Latest intelligence

Research you can put to work.

Go beyond headlines with analyst-led context, defensive guidance, and clear takeaways for security teams.

23articles
APT29 – Cozy Bear: Russia's Ghost in Every Network
Threat Intel
Feb 27, 2026Cypho Research Team

APT29 – Cozy Bear: Russia's Ghost in Every Network

A deep-dive threat intelligence report on APT29 — the SVR-backed group behind SolarWinds, the DNC breach, and attacks on Microsoft and HPE — covering their TTPs, malware arsenal, detection guidance, and mitigations.

Read analysis
OSINT and Internet Scanning Platforms Matter: A Practical Look at Popular Tools
Osint
Jun 15, 2025Cypho Research Team

OSINT and Internet Scanning Platforms Matter: A Practical Look at Popular Tools

Anyone working in cybersecurity knows that understanding your infrastructure requires more than checking what happens internally. Many risks come from externally exposed services, outdated technologies, or poorly configured systems. To see these problems clearly, OSINT tools have become essential.

Read analysis
Data Leaks in the Modern World: Understanding the Threat and Learning from Recent Global Incidents
Data Breach
Jun 10, 2025Cypho Research Team

Data Leaks in the Modern World: Understanding the Threat and Learning from Recent Global Incidents

In today's interconnected digital landscape, information flows constantly between individuals, organisations, cloud infrastructures, mobile devices and third-party services. This continuous exchange creates a dynamic ecosystem where data becomes one of most valuable assets and one of most vulnerable.

Read analysis
Silent Threats in Your Browser: How Chrome Extensions Can Compromise You
Browser Security
Jun 5, 2025Cypho Research Team

Silent Threats in Your Browser: How Chrome Extensions Can Compromise You

Originally, Chrome extensions were designed to enhance productivity and personalize the browsing experience, but over time, they evolved into a powerful attack surface. Threat actors quickly realized that extensions have privileged access to browser data, including cookies, sessions, browsing history, and sometimes even credentials. This makes them an ideal vector for silent data theft.

Read analysis
CVE-2025-12480: Critical Improper Access Control in Triofox
Cve
May 28, 2025Cypho Research Team

CVE-2025-12480: Critical Improper Access Control in Triofox

A newly disclosed critical vulnerability in Triofox (CVE-2025-12480) exposes organizations to unauthenticated access, full administrative takeover, and rapid escalation to remote code execution. Actively exploited by threat actors, this flaw turns publicly reachable deployments into high-risk entry points for deeper network compromise, making swift patching, isolation, and thorough hunting essential for defenders.

Read analysis
Codefinger Ransomware: The Operation Targeting Critical Infrastructure Worldwide
Ransomware
May 20, 2025Cypho Research Team

Codefinger Ransomware: The Operation Targeting Critical Infrastructure Worldwide

Appearing during the initial months of 2025, Codefinger has rapidly attracted the attention of cybersecurity specialists because of its highly advanced tactics and rapid growth across various industries. Suspected to be conducted by a well-planned group of attackers, Codefinger combines traditional ransomware functionality with highly advanced evasion and data extraction strategies.

Read analysis
Move from reading to response

Bring real-time threat intelligence into your workflow.

See how Cypho turns external signals into prioritized action.

Request a demo