CYFIRMA

CYFIRMA Research

News EN ↓ 322 episodes

Cyber defenders, listen up! The CYFIRMA Research podcast has some juicy intel on the latest cyber threats that are lurking in the shadows. Tune in to this security briefing to stay on top of emerging threats and be ready to tackle digital risk like never before.

Author

CYFIRMA

Category

News

Podcast website

www.cyfirma.com

Latest episode

Jul 7, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

CYFIRMA Research - Sync-Scheduler Stealer 29.03.2024

Cyfirma research team discovered a new document stealer Sync-Scheduler, a potent malware written in C++ boasting defense evasion and anti-analysis capabilities. It is being distributed as an embedded component in the Office document file. Malware code is hidden under the page title of the first slide of the PowerPoint presentation and file-nesting is used to hide the PowerPoint presentation in the...

CYFIRMA Research - FortiOS/FortiProxy (CVE-2024-21762)- Vulnerability Analysis and Exploitation 22.03.2024

A critical vulnerability, CVE-2024-21762, has been identified in Fortinet's FortiOS/FortiProxy, posing a severe global threat to digital security. CYFIRMA researchers have conducted an exhaustive analysis of the vulnerability. Immediate action is strongly advised. Apply the latest patches provided by Fortinet to secure your systems. Enhance access controls, bolster your digital infrastructure...

CYFIRMA Research - NIKKI STEALER: EX-DEFACER TURNS SELLER OF DISCORD STEALER 19.03.2024

An individual, formerly known for defacing websites, has transitioned to selling a Discord stealer called Nikki Stealer, developed using the Electron framework.  With a moderate level of confidence, we assess the developer is from either Brazil or Portugal. This individual has a history of website defacement and is now engaged in selling this stealer. The recent advancements in Nikki Stealer v9 un...

CYFIRMA Research - Islamic State’s Telegram Hustle: How a Terrorist Organization Raises Funds 14.03.2024

The CYFIRMA Research team embarked on an investigation to uncover activities linked to the banned organization Islamic State. We aimed to gain access to the group or identify individuals endorsing its ideology. During our investigation we infiltrated a Telegram channel promoting Islamic State’s beliefs, which was also part of a private RocketChat server exclusively used by ISIS. Additionally, we u...

CYFIRMA Research - Tracking Ransomware- February 2024 11.03.2024

Stay informed on the evolving cybersecurity landscape with CYFIRMA's February 2024 Monthly Ransomware Report. LockBit leads the charts despite a takedown by law enforcement, showcasing resilience and technical prowess. Manufacturing takes the hit, recording a 40% rise in attacks. The USA remains a prime target, followed by the UK, Canada, France, and Spain. The evolution of ransomware tactics...

CYFIRMA Research - A Ransomware That Doesn't Extort Money - WinDestroyer & Its Origin 08.03.2024

The CYFIRMA research team has uncovered a new and highly destructive malware, WinDestroyer. It lacks ransom demands, is geopolitically motivated, and is developed for hacktivism against the backdrop of the Russia-Ukraine conflict. The malware employs DLL reload attacks, API hammering, and lateral movement capabilities, rendering systems unusable. During our investigation, we have been able to attr...

CYFIRMA Research - Exploiting Document Templates: Stego-Campaign Deploying Remcos RAT and Agent Tesla 06.03.2024

Our latest cyber threat research at Cyfirma reveals a complex stego-campaign, showcasing a malicious .docx file that's raising serious concerns in the cybersecurity landscape. Our dedicated team unearthed a sophisticated attack chain that employs template injection, effectively bypassing conventional email security measures. The malicious .docx file, distributed possibly through phishing emai...

CYFIRMA Research - The ScreenConnect Saga: A Deep Dive into the LockBit Connection 05.03.2024

Dive into the cybersecurity storm as ScreenConnect vulnerabilities (CVE-2024-1709 & CVE-2024-1708) open the door to a looming LockBit ransomware threat. With over 95,311 instances at risk, organizations worldwide must act swiftly. Discover the nuances of this critical connection.  Link to the Research Report: The ScreenConnect Saga: A Deep Dive into the LockBit Connection - CYFIRMA #ScreenConn...

CYFIRMA Research - Exploit Analysis: SSRF and Command Injection for Unauthenticated RCE in Ivanti Connect Secure 01.03.2024

Read our Cyfirma Research report, which explores why Ivanti Connect Secure & Policy Secure users, should be cautious of a critical SSRF vulnerability (CVE-2024-21893) which affects your systems, enabling attackers to bypass mitigations and execute remote code. Exploits, like CVE-2023-46805 & CVE-2024-21887, demonstrate the severity. Ivanti has released a second mitigation and patches to ad...

CYFIRMA Research - Xeno RAT: A New Remote Access Trojan with Advance Capabilities 27.02.2024

CYFIRMA’s research team has discovered a new Remote Access Trojan named Xeno-RAT, featuring sophisticated capabilities. Through comprehensive analysis, our report explores the various evasion techniques utilized by threat actors to circumvent detection, as well as elucidates the methods employed in creating robust malware payloads. Xeno RAT, a potent malware written in C# with advanced capabilitie...

CYFIRMA Research - Iran Contributes to the Escalating Geo-Political Threat Landscape 22.02.2024

The recent acceleration in hostilities involving Iran-backed militias and the United States, coupled with a surge in Israeli strikes on Iranian positions in Syria, seems to have compelled Tehran to reassess elements of its regional strategy. These regional escalations come at an inopportune time for Iran. This report assesses the current situation in the Middle East, including Iran’s current postu...

CYFIRMA Research - Jenkins (CVE-2024-23897) – Vulnerability Analysis and Exploitation 19.02.2024

Urgent Security Advisory! A critical vulnerability, CVE-2024-23897, has surfaced in Jenkins, posing a global threat to digital security. CYFIRMA researchers have conducted an in-depth analysis and exploitation, Immediate action is advised - secure your systems with the latest Jenkins patches. Strengthen access controls, fortify your digital infrastructure, and remain vigilant. Stay informed about...

CYFIRMA Research - Malware Development Competition Fuels Creation of 20+ Malware 15.02.2024

Our latest report talks about the XSSLite Stealer; an infostealer born from a malware development competition on a Russian hacking forum. This infostealer comes with anti-sandbox & anti-debugging capabilities, in addition to a web panel's source code to receive the stealer logs from compromised victims.  A hefty prize pool of tens of thousands of USD shows just how much these administrato...

CYFIRMA Research - Ransomware Trends- January 2024 13.02.2024

Uncover the latest trends in the cybersecurity landscape with CYFIRMA's January 2024 Monthly Ransomware Report. LockBit takes the lead with 64 victims, targeting diverse industries, notably Manufacturing. Despite a 20.51% dip in incidents from December 2023, the long-term trend indicates a persistent rise in ransomware threats. New players like Slug, Going Insane, and Kasseika bring fresh cha...

CYFIRMA Research - Caught in the Crossfire: How International Relationships Generate Cyber Threats 08.02.2024

In times of conflict, the cyber realm becomes a battleground too! Instances like the Russia-Ukraine war & Israel-Gaza conflict show how hacktivists are playing a role. They launch attacks using DDoS tools, deface websites, and even mentor others to disrupt organizations. In the ongoing Israel-Palestine conflict, hackers are wreaking havoc online too. They're creating custom tools, sharing...

CYFIRMA Research - Comprehensive Analysis of CVE-2024-21833 Vulnerability in TP-Link Routers : Threat Landscape, Exploitation Risks, and Mitigation Strategies 03.02.2024

CYFIRMA’s research team, reveals a critical OS command injection vulnerability (CVE-2024-21833) affecting TP-Link Routers, demanding immediate attention. With a high CVSS score of 8.8, this flaw poses a significant risk, attracting state-sponsored entities and threat groups. Active exploitation is observed, emphasizing the need for prompt patching, proactive monitoring, and collaboration within th...

CYFIRMA Research - Russian Threat Actors Abuse Cloudflare and Freenom Services to run DaaS Program 01.02.2024

The CYFIRMA research team reveals a Russian-origin Drainer-as-a-Service (DaaS) project gaining traction in the hacking community. This crypto drainer targets wallets on Ethereum, BNB, Polygon, etc with a massive affiliate network of 10k members.  Our investigation reveals how the threat actors are creating phishing infrastructure at no cost, subsequently using compromised Twitter accounts to launc...

CYFIRMA Research - LOOKING INTO THE CRYSTAL BALL: WHAT WILL 2024 BRING IN GEOPOLITICS 30.01.2024

The geopolitical landscape in 2024 is at a critical juncture! As we begin the year, explore five key events may shape the course of global affairs and have profound effect on the Cyber Threat Landscape through this Cyfirma blog! Covering the below key events:     ·       World Goes to the Polls: Over four billion people in nearly 80 countries will participate in elections, with Taiwan's recen...

CYFIRMA Research - From Screen Captures to Crypto wallets: Analyzing the Multi-Faceted Threat of Rage Stealer 29.01.2024

“CYFIRMA’ s research team has identified a new stealer in the wild called “Rage Stealer”. Rage Stealer employs a multifaceted approach, covertly extracting sensitive data encompassing browsers, cryptocurrency wallets, files, credentials, and various applications data. What sets "Rage Stealer" apart is its systematic organization of extracted information into specific directories, ensurin...

CYFIRMA Research - Pakistan-based Threat Actor Targets Indians with Fake Loan Android Application 24.01.2024

The CYFIRMA team recently discovered a malicious Android package orchestrating a sophisticated extortion scheme. Masked as a loan app promising quick funds, unsuspecting users are duped into revealing sensitive information during the installation process.  The deceptive app coerces victims into submitting KYC details, including a selfie, gradually acquiring a wealth of personal data. Once armed wi...

CYFIRMA Research - APT QUARTERLY HIGHLIGHTS: Q4 – 2023 22.01.2024

CYFIRMA’s Q4 2023 APT report focusses on APT groups from Iran, Russia, China, and North Korea, that brought forth a wave of dynamic and innovative cyber activities, challenging the global cyber security landscape. Iranian actors targeted telecom, higher education, and tech sectors, showcasing updated techniques and new C2 frameworks in the backdrop of the Israel-Hamas conflict. Russian APTs target...

CYFIRMA Research - Russian Stealer Log Aggregator Releases Fully Native Infostealer 19.01.2024

Monster Cloud, an emerging player in the Russian stealer log threat landscape, has shifted from just offering stealer logs to a Malware-as-a-Service (MaaS) model. Operating on Telegram, these threat actors have announced the release of their fully native proprietary information stealer. In this report, we dive into the operations of the Russian-speaking threat group, their history, and capabilitie...

CYFIRMA Research - Apache Struts RCE (CVE-2023-50164)- Vulnerability Analysis and Exploitation 18.01.2024

A critical vulnerability has been identified in Apache Struts 2, exposing a global threat to digital security. CYFIRMA Researchers have analysed this flaw, uncovering potential risks of unauthorized access and data breaches. It is advised to take immediate action - secure your systems with the latest Apache Struts 2 patches. Strengthen access controls, fortify your digital infrastructure, and rema...

CYFIRMA Research - Taiwan Elections Report 16.01.2024

Taiwan’s election marks the first on the calendar in what will be the largest election year in history. Understanding how the onslaught of disinformation will impact the opinions of the Taiwanese public will be critical for Taiwan’s election, but the tactics and behaviors will likely be duplicated elsewhere, not only by the Chinese Communist Party but also by other actors. Based on previous experi...

CYFIRMA Research- Tracking Ransomware- December 2023 11.01.2024

Dive into Cyfirma’s December 2023 Ransomware Report for an exploration of evolving cyber threats. The rise of new players like Hunters International, Dragon Force and WereWolves highlight a severe threat.    With 75% more incidents in 2023 than in 2022, this report unveils critical insights into the escalating global cybersecurity threat. Covering key events during this period such as:   Akira hit...

Listen to the CYFIRMA Research podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.