CYFIRMA

CYFIRMA Research

News EN ↓ 322 episodes

Cyber defenders, listen up! The CYFIRMA Research podcast has some juicy intel on the latest cyber threats that are lurking in the shadows. Tune in to this security briefing to stay on top of emerging threats and be ready to tackle digital risk like never before.

Author

CYFIRMA

Category

News

Podcast website

www.cyfirma.com

Latest episode

Jul 7, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

CYFIRMA Research - Episode 022: Who are the Wagner PMCs of Russia : Is There a Risk of a Cyber Fallout? 18.07.2023

By the end of June 2023, Wagner, a Russian mercenary organization mutinied against its state backers. The Russian government has been using the PMC for its dirty work for years. The rebellion seriously shook the political system in Russia and weakened the position of President Putin, even though the mercenaries stood down and agreed to a deal offered by the Kremlin. The full extent of the damage i...

CYFIRMA Research - Episode 021: XORTIGATE Vulnerability: Unmasking Critical Threats in Fortinet’s FortiOS and FortiProxy SSL-VPN (CVE-2023-27997) 13.07.2023

This research by the CYFIRMA Research team investigates a critical vulnerability, tracked as CVE-2023-27997, affecting FortiOS and FortiProxy SSL-VPN, a popular operating system and VPN, used in their security products. The vulnerability, known as XORTIGATE, has the potential for remote code execution (RCE) and is being exploited in recent attacks. The XORTIGATE vulnerability arises from an insecu...

CYFIRMA Research - Episode 020: Blank Grabber Returns with High Evasiveness 07.07.2023

CYFIRMA researchers have uncovered a new infostealer builder called "Blank Grabber" that poses a significant threat to Windows operating systems. It was released in 2022, however since then, it has been frequently updated – with 85 contributions to the project in the last one month alone. It’s sophisticated and is evolving, with frequent updates and a growing list of features, aimed at s...

CYFIRMA Research - Episode 019: WISE REMOTE Stealer Unleashed: Unveiling Its Multifaceted Malicious Arsenal 06.07.2023

Information stealers remain an enduring and evolving security concern for individuals and organizations alike. CYFIRMA’s Research team has recently uncovered an advanced information stealer, known as “WISE REMOTE Stealer,” that functions as both a stealer and a Remote Access Trojan (RAT). This sophisticated malware has gained significant traction through promotion in underground forums. Continual...

CYFIRMA Research - Episode 018: CHINA IP THEFT REPORT 03.07.2023

The loss of intellectual property (IP) through cyber espionage and cyber crime constitutes the greatest transfer of wealth in history. U.S. companies alone loose around a quarter to half a trillion dollars annually through intellectual property theft, with over a hundred billion lost due to cyber crime – a number that can be tripled when the costs of downtime are taken into account. There are many...

CYFIRMA Research - Episode 017: Beyond Search Results: Deconstructing SEO Poisoning Technique & Safeguarding Measures 30.06.2023

Detecting SEO poisoning attacks can be a significant challenge due to the ever-changing nature of search engine algorithms and the sophisticated techniques used by attackers. Cybercriminals are constantly evolving their tactics, and they're even leveraging advanced technologies like AI and ChatGPT to make their SEO poisoning attacks more convincing. This report provides valuable insights into...

CYFIRMA Research - Episode 016: Zero Day Shop 26.06.2023

The CYFIRMA research team has identified a new marketplace run by unknown threat actors, known as the Zero-Day Shop. It serves as a one-stop destination for threat actors, offering a range of dangerous tools and services.  Zero Day Shop acts as a middleman between initial access brokers, offers malware and exploit software to launch devastating cyber-attacks.    The consequences of the products on...

CYFIRMA Research - Episode 015: Typosquatting Unmasked: Exposing the Threats of Misplaced Keystrokes 23.06.2023

Typosquatting, also known as URL hijacking or domain mimicry, exploits the typing errors made by internet users when entering website URLs, aiming to redirect them to malicious websites.  Attackers register domain names that closely resemble popular or legitimate websites, capitalizing on common misspellings or slight variations.  By luring unsuspecting users to typosquatted websites, threat actor...

CYFIRMA Research - Episode 014: DoNot APT Elevates its Tactics by Deploying Malicious Android Apps on Google Play Store 19.06.2023

​​​​​​​The team at CYFIRMA recently obtained suspicious Android apps hosted on the Google Play Store under the account “SecurITY Industry”. Further technical analysis revealed that the apps have malware characteristics and belong to the notorious Advanced Persistent Threat Group; “DoNot”.    A total of three Android apps were hosted with the name Device Basic Plus, nSure Chat, and iKHfaa VPN, with...

CYFIRMA Research - Episode 013: Mystic Stealer – Evolving “stealth” Malware 15.06.2023

Information stealers pose an ongoing and dynamic threat to the security of both individuals and organizations. CYFIRMA’s Research team recently discovered an information stealer called “Mystic Stealer” being promoted in an underground forum, with the threat actor utilizing a Telegram channel for their operations. This threat actor continuously enhances the malware, incorporating new features to en...

CYFIRMA Research - Episode 012: Unveiling DeltaBoys : Interview about their Past and Motivation 14.06.2023

Cyfirma recently interviewed the DeltaBoys; a threat actor group that specialises in mass defacements. Following our recent research report; 'DeltaBoys- Black Hats on the Rise’ , our insightful and unique interview explores the DeltaBoys’ ideological and geopolitical motivations, affiliations, their financial motivations, and gives them the chance to have their voices heard across the world....

CYFIRMA Research - Episode 011: Unveiling an Authenticated Stored Cross-Site Scripting Zero-Day Vulnerability in PowerPress Plugin 10.2.3 and Earlier 08.06.2023

Blubrry PowerPress, a popular plugin used by podcasters to enhance their websites, has recently come under scrutiny due to a security vulnerability. Cybersecurity researchers at CYFIRMA discovered the security vulnerability, specifically affecting versions 10.2.3 and earlier. The vulnerability identified is a zero-day authenticated stored cross-site scripting (XSS) exploit, found within the “Show...

CYFIRMA Research - Episode 010: G7 Summit Assessment Report – Strong Symbolism, Military Commitments and Relations with China 06.06.2023

The Group of Seven (G7) singled out China on issues including Taiwan; non-market policies; malign business and cyber practices (such as illegitimate technology transfer, or data disclosure / human rights abuses), which naturally underscores the wide-ranging tensions between Beijing and the group of major industrialized democracies. Beijing has responded in a fiery way, with Chinese state media ber...

CYFIRMA Research - Episode 009: DeltaBoys - Black Hats On The Rise 29.05.2023

DeltaBoys have been operating since December 2021, initially starting out as database brokers and carders. However, in August 2022, their operation evolved into mass defacement and the ‘initial access’ broking market, providing webshells to sensitive websites. To fund their geopolitically motivated operations, they built a diverse catalogue of recently compromised databases, ‘zero-days’, ‘exploits...

CYFIRMA Research - Episode 008:The Meaning of ETLM for the Upcoming Ukrainian Offensive 24.05.2023

A year and a half into the Russian war in Ukraine, the defending Ukrainians are now reconstituting their attrited forces for an imminent counter-attack, which might be the last opportunity the Ukrainian commanders will get to push the occupiers out of the country, before the external support, the country is relying on gets exhausted. The future of the country hinges on the success of the counter-o...

CYFIRMA Research - Episode 007: Evolution of KILLNET from Hacktivism to Private Hackers Company and the Role of Sub-groups 17.05.2023

Recently KILLNET creator; ‘KillMilk’, announced that they were building a global team of operators from the darknet and special services members, with financially motivated destructive capabilities. Their operation went full circle from offering services to hackers and competing businessmen, to taking orders from private and state persons, along with defending the interests of the Russian Federati...

CYFIRMA Research - Episode 006:Exploiting the PowerPress 10.0 Stored Cross-Site Scripting Vulnerability (CVE-2023-1917) 16.05.2023

The PowerPress plugin, which allows WordPress users to publish and manage podcasts, was found to contain a stored Cross-Site Scripting (XSS) vulnerability. The vulnerability allowed authenticated threat actors with contributor-level permissions or higher to inject malicious web scripts into pages, using the plugin’s shortcode, potentially leading to the theft of sensitive information, manipulation...

CYFIRMA Research - Episode 005: SarinLocker Ransomware 13.05.2023

SarinLocker is written by NecroSys, who is associated with FusionCore group. The threat actor group known as FusionCore is a relatively new and determined group, originating from Europe. The group is running Malware-as-a-service, along with hacker-for-hire services. They have a wide range of skills and rely on open-source tools to increase evasiveness in their malware toolkit. The current version...

CYFIRMA Research - Episode 004:DoNot APT Targets Individuals in South Asia using Android Malware 12.05.2023

The threat actor’s named “DoNot”, also known by the name APT-C-35, is active since 2016 and has been carrying out cyber-attacks in the South Asian region.  https://www.cyfirma.com/

CYFIRMA Research - Episode 003: The impact of unauthorized access to large AI language models and their impact on the external threat landscape 11.05.2023

In this Podcast, we'll be talking about "The impact of unauthorized access to large AI language models and their impact on the external threat landscape". Hackers have shown a growing interest in AI models such as ChatGPT, as they seek to exploit the technology for their criminal activities. The potential use of ChatGPT by cybercriminals is concerning, as it could lead to an increas...

CYFIRMA Research - Episode 002: The Rise of FusionCore - An Emerging Cybercrime Group from Europe 04.05.2023

CYFIRMA observed a new European threat actor group known as FusionCore. Running Malware-as-a-service, along with the hacker-for-hire operation, they have a wide variety of tools and services that are being offered on their website, making it a one-stop-shop for threat actors looking to purchase cost-effective yet customizable malware. The operators have started a ransomware affiliate program that...

CYFIRMA Research - Episode 001: ARES Leaks Emerging Cyber Crime Cartel 28.04.2023

ARES, is a new threat actor group identified by CYFIRMA Research. ARES is involved in selling corporate and government authority databases. CYFIRMA Research has observed cartel-like behaviour, affiliations with other threat actors, and connections with established hacking groups like RANSOMHOUSE ransomware group, KelvinSecurity, and Adrastea hacker group. ARES Leaks is potentially becoming an alte...

Listen to the CYFIRMA Research podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.