Cypho research

Intelligence for the teams behind the defense.

Research, analysis, and practical guidance on the threats, vulnerabilities, and adversaries shaping today's security landscape.

Explore the latest research
Research coverageContinuously updated
01Threat actors
02Dark web
03Attack surface
04Vulnerability research
Latest intelligence

Research you can put to work.

Go beyond headlines with analyst-led context, defensive guidance, and clear takeaways for security teams.

23articles
Scattered Spider: The Group Currently Scattering UK Retail Organizations
Threat Actor
May 15, 2025Cypho Research Team

Scattered Spider: The Group Currently Scattering UK Retail Organizations

This report expands on our previous research into the DragonForce ransomware cartel, which publicly claimed responsibility for the string of disruptive attacks on UK retail organizations between April and May 2025. While DragonForce handled the ransomware deployment and data-leak extortion phases, forensic and behavioral evidence indicates that another entity — Scattered Spider — played a critical enabling role behind the scenes.

Read analysis
Stealer Logs in 2025: Anatomy of a Silent Data Heist
Info Stealer
May 10, 2025Cypho Research Team

Stealer Logs in 2025: Anatomy of a Silent Data Heist

A stealer log is not just a file – it's the full memory of a stolen identity. It's a structured package created by infostealer malware that collects everything a user's device "knows": browser-saved passwords, session cookies, autofill data, cryptocurrency wallet keys, FTP/VPN credentials, even system fingerprints and chat tokens.

Read analysis
CVE-2025-24091: iOS and iPadOS Vulnerability Allows App to Impersonate System Notifications
Cve
May 5, 2025Cypho Research Team

CVE-2025-24091: iOS and iPadOS Vulnerability Allows App to Impersonate System Notifications

Apple has recently patched a critical security flaw in iOS and iPadOS that posed a significant risk to user security. The vulnerability, identified as CVE-2025-24091, allowed malicious applications to impersonate system notifications, which could potentially cause user confusion, security lapses, or denial-of-service (DoS) conditions. Discovered by security researcher Guilherme Rambo, this flaw highlights the need for rapid response in the mobile security landscape.

Read analysis
CVE-2025-55315: Critical HTTP Request Smuggling in ASP.NET Core
Cve
Apr 28, 2025Cypho Research Team

CVE-2025-55315: Critical HTTP Request Smuggling in ASP.NET Core

This blog explains the CVE-2025-55315 vulnerability in ASP.NET Core (Kestrel) — a critical HTTP Request Smuggling flaw that can allow attackers to bypass authentication, manipulate traffic, and compromise web servers.

Read analysis
Neptune Loader: Exposing the Hidden Realms of Malware Command And Control / Vulnerability that exposes affected machines
Malware
Apr 20, 2025Cypho Research Team

Neptune Loader: Exposing the Hidden Realms of Malware Command And Control / Vulnerability that exposes affected machines

This post talks about a vulnerability that we discovered in Neptune loader. Neptune loader is used for remotely controlling your device, it has some features that help attackers to easily use it. This vulnerability allows us to get information about the affected machines that are called bots. Neptune has a web interface that is used for control. We found a serious vulnerability. The post shares details that can help cybersecurity experts find and fix this weakness.

Read analysis
Move from reading to response

Bring real-time threat intelligence into your workflow.

See how Cypho turns external signals into prioritized action.

Request a demo