CYFIRMA
CYFIRMA Research
Cyber defenders, listen up! The CYFIRMA Research podcast has some juicy intel on the latest cyber threats that are lurking in the shadows. Tune in to this security briefing to stay on top of emerging threats and be ready to tackle digital risk like never before.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
CYFIRMA Research: CVE-2026-1492 WordPress User Registration & Membership Authentication Bypass Flaw 13.04.2026 6:18
The CYFIRMA Research team has identified critical security insights related to CVE-2026-1492, a high-severity authentication bypass and privilege escalation vulnerability affecting the WordPress User Registration & Membership plugin. The vulnerability allows unauthenticated attackers to gain administrative access by exploiting improper server-side validation and weak authorization controls wit...
CYFIRMA Research: Tracking Ransomware- March 2026 11.04.2026 4:10
March reflected a further escalation in ransomware activity, with incident volumes rising and multiple threat actors expanding operations simultaneously. Qilin emerged as the most dominant group with a sharp increase in activity, while several others, including Akira, Incransom, Nightspire, Dragonforce, and LockBit5, showed significant growth, indicating a highly competitive and rapidly scaling ec...
CYFIRMA Research: CrySome RAT 10.04.2026 3:59
CrySome RAT – Advanced Threat Insight CrySome RAT is a sophisticated .NET-based remote access trojan engineered for long-term persistence and stealth on Windows systems. It extends beyond typical malware by maintaining execution even after system resets, leveraging recovery partition abuse and offline registry manipulation to ensure continued presence. Beyond persistence, it delivers a full post-e...
CYFIRMA Research: Invoice-Themed Phishing Campaign Targeting Financial Workflows Amid Fiscal Year-End Activity 09.04.2026 3:45
New Threat Intelligence Report: Invoice-Themed Phishing Campaign A sophisticated phishing campaign is actively targeting finance and procurement teams using invoice, payment, and operational lures—timed strategically around financial year-end activities. With increased transaction volumes and audit processes, employees are more likely to engage with seemingly routine emails—making this campaign pa...
CYFIRMA Research: Tracking Ransomware- February 2026 07.04.2026 4:18
Stay informed with CYFIRMA’s February 2026 Ransomware Threat Report. February continued to reflect a high-activity ransomware environment, with noticeable shifts in group dynamics and operational patterns. While Qilin sustained consistent activity levels, other actors showed mixed trends, with some groups scaling rapidly and others reducing operations, highlighting the constantly evolving nature o...
CYFIRMA Research: CVE-2026-24423 – SmarterTools SmarterMail Remote Code Execution Vulnerability 02.04.2026 7:57
The CYFIRMA Research team has identified critical security insights related to CVE-2026-24423, a high-severity unauthenticated remote code execution vulnerability impacting SmarterTools SmarterMail. The vulnerability allows attackers to execute arbitrary commands through the ConnectToHub API, potentially leading to full system compromise. Our research highlights the exploitation mechanism, threat...
CYFIRMA Research: Operation False Siren- A Trojanized Android Spyware Campaign 31.03.2026 6:05
CYFIRMA Research uncovered a targeted Android spyware campaign, Operation False Siren, exploiting wartime urgency by weaponizing the trusted Israeli civil defense alert application. In this operation, threat actors distributed a trojanized version of the missile warning app via SMS phishing (smishing) campaigns, convincing victims to install what appeared to be a critical alert system update. Once...
CYFIRMA Research- TaxiSpy RAT: Analysis of TaxiSpy RAT – Russian Banking-Focused Android Malware with Full Remote Control 30.03.2026 5:23
New Report Released: Advanced Android Banking RAT Targeting Russian Financial Institutions CYFIRMA Research has uncovered a highly sophisticated Android Banking Trojan with integrated Remote Access Trojan (RAT) capabilities targeting Russian users and financial institutions, such as banking apps, cryptocurrency applications, government services apps, and marketplace platforms. What the report cove...
CYFIRMA Research- Dead Infrastructure Hijacking 26.03.2026 7:44
New Research: Dead Infrastructure Hijacking — The Attack That Doesn't Need a Vulnerability Most breaches start with an exploit. This one starts with a domain registration. We've published a full threat intelligence report on Dead Infrastructure Hijacking (DIH) — a threat class that exploits residual trust relationships left behind when digital infrastructure is decommissioned, migrated,...
CYFIRMA Research- APT36: Multi-Vector Execution Malware Campaign Targeting Indian Government Entities 25.03.2026 5:39
APT36 Multi-Vector Execution Malware Campaign Targeting Indian Government Entities Researchers at CYFIRMA have identified and analyzed a sophisticated malware campaign attributed to APT36 targeting Indian government entities. The campaign demonstrates a structured, multi-stage infection chain designed for stealth, persistence, and long-term remote access. This campaign reflects a targeted espionag...
CYFIRMA Research- Telegram as the New Operational Layer of Cyber Threat Activity 24.03.2026 9:40
The Telegram ecosystem. Ransomware groups, Initial Access Brokers, malware operators, and leak channels are converging on a single platform for coordination, recruitment, validation, and amplification. This isn’t a migration from darknet forums — it’s an operational upgrade. Link to the Research Report: Telegram as the New Operational Layer of Cyber Threat Activity - CYFIRMA #CyberSecurity #Thr...
CYFIRMA Research- CharlieKirk Grabber: A Python Based infostealer 23.03.2026 8:59
Emerging Threat Model: Python-Based Credential Stealer (CharlieKirk Grabber): Recent analysis of a Python-based information stealer highlights the continued growth of modular, builder-driven malware targeting Windows environments. The sample demonstrates how commodity stealers are evolving to combine credential harvesting, system profiling, and cloud-based exfiltration using legitimate services an...
CYFIRMA Research- Tracking Ransomware – January 2026 20.03.2026 3:20
Stay ahead with CYFIRMA’s January 2026 Ransomware Threat Report. January 2026 opened with sustained high ransomware activity and sharp operational volatility across major groups. Qilin remained one of the most active actors despite a post-surge decline, while Cl0p executed a dramatic rebound after a December pause, highlighting how quickly campaigns can reactivate at scale. Thegentlemen and Sinobi...
CYFIRMA Research- LTX Stealer: Analysis of a Node.js–Based Credential Stealer 12.03.2026 8:57
Malware Spotlight: LTX Stealer CYFIRMA researchers uncovered a sophisticated Windows info-stealer hidden in a legit Inno Setup installer. Key takeaways: 🔹 Node.js stealer with Bytenode bytecode obfuscation 🔹 Targets Chromium browsers & crypto wallets 🔹 Persists in hidden/system folders under Program Files(x86) 🔹 Uses Supabase for operator auth + Cloudflare to mask backend 🔹 Commerc...
CYFIRMA Research- Re-Emerging Telegram Phishing Campaign Targeting User Authorization Prompts 09.03.2026 3:14
CYFIRMA has identified an active Telegram phishing campaign that abuses Telegram’s legitimate login and in-app authorization workflows to fully compromise user accounts without malware or exploits. By leveraging QR codes and manual login flows tied to attacker-controlled Telegram API credentials, victims are tricked into approving genuine authorization prompts inside the Telegram app under false s...
CYFIRMA Research: CVE-2026-23760 – SmarterTools SmarterMail Authentication Bypass Vulnerability 05.03.2026 7:56
Critical Alert: CVE-2026-23760 – SmarterMail Pre-Auth Bypass Leading to Full System Compromise Organizations running SmarterTools SmarterMail email servers—widely deployed across SMBs, MSPs, educational institutions, and healthcare environments—must take immediate action. This actively exploited authentication bypass vulnerability allows unauthenticated attackers to reset system administrator pass...
CYFIRMA Research- PlayCloak: A Play Store–Distributed Travel Utility Covertly Operating as a Financial Fraud and Cybercrime Platform 03.03.2026 4:31
Threat Research Alert | Android Loan Scam Our analysis uncovered an Android application, Hicas, distributed via the Google Play Store and marketed as a Smart Travel Packing Companion, which covertly operates as a region-targeted fraudulent loan platform. Key Findings: • Play Store app masquerading as a travel utility • Region-based cloaking activates loan flow on IN devices • Remote WebView delive...
CYFIRMA Research- Weaponized WinRAR Exploitation and Stealth Deployment of Fileless .NET RAT 20.02.2026 8:03
WinRAR CVE-2025-8088 is a path validation vulnerability that allows a crafted RAR archive to write files outside the intended extraction directory during unpacking. In the observed attack chain, this behavior is abused to silently drop a malicious script into the Windows Startup folder, establishing persistence without requiring administrative privileges or explicit execution by the user. Once tri...
CYFIRMA Research- Mamba Phishing-as-a-Service Kit: How Modern adversary-in-the-middle (AiTM) Attacks Operate 09.02.2026 5:51
Mamba 2FA illustrates the evolution of phishing into highly automated adversary-in-the-middle attacks that can bypass traditional MFA by closely emulating legitimate cloud authentication experiences. As part of a broader phishing-as-a-service ecosystem, these tools enable scalable, low-effort campaigns with high impact across cloud environments. Addressing this threat requires MFA-resistant authen...
CYFIRMA Research- SOLYXIMMORTAL: PYTHON MALWARE ANALYSIS 28.01.2026 7:06
Emerging Threat Model: SOLYXIMMORTAL Malware Recent analysis highlights how modern commodity malware continues to evolve by abusing legitimate system functionality rather than relying on exploits or vulnerabilities. The malware demonstrates how attackers can achieve persistent access, credential theft, and user surveillance entirely within the user space, leveraging trusted operating system featur...
CYFIRMA Research- Tracking Ransomware – December 2025 16.01.2026 2:49
Stay ahead with CYFIRMA’s December 2025 Ransomware Report. December marked the most active month of 2025 with 801 global ransomware victims, signaling a strong year-end escalation. Qilin surged to 175 victims, reinforcing its dominance, while Safepay and Sinobi posted sharp month-over-month growth, highlighting shifting group momentum. Ransomware operations increasingly adopted cartel-style, acces...
CYFIRMA Research- Resurgence of Scattered Lapsus$ Hunters 09.01.2026 7:50
The threat landscape just got more complex. The Scattered LAPSUS$ Hunters-alliance has re-emerged, merging the tactics of notorious groups. This isn’t just a name change; it’s a shift toward professionalized, identity-centric extortion. What you need to know: High-Value Targets: Focused on enterprises with $500M+ revenue, specifically in Cloud, Telecom, and Finance. Identity is the Perimeter: They...
CYFIRMA Research- APT36: Multi-Stage LNK Malware Campaign Targeting Indian Government Entities 06.01.2026 4:31
APT36 Targets Indian Entities Using Weaponized Windows Shortcut Files CYFIRMA has identified a coordinated cyber-espionage campaign attributed to APT36 (Transparent Tribe), a Pakistan-aligned threat actor persistently targeting Indian government entities and strategic sectors. This campaign highlights APT36’s evolving tradecraft, leveraging malicious Windows shortcut (.LNK) files and multi-stage p...
CYFIRMA Research- PLAUSIBLE DENIABILITY IN CYBERSPACE: THE STRATEGIC USE OF HACKTIVIST PROXIES 31.12.2025 7:35
Hacktivist activity is often dismissed as low-sophistication noise, website defacements, DDoS attacks, or online activism. Our latest research argues that this view is increasingly outdated. The report introduces Hacktivist Proxy Operations as a repeatable model of deniable cyber pressure, where ideologically aligned non-state groups apply disruption, narrative amplification, and psychological pre...
CYFIRMA Research- APT36 LNK-Based Malware Campaign Leveraging MSI Payload Delivery 29.12.2025 5:02
Threat Alert: APT 36 CYFIRMA has identified a targeted malware campaign abusing fake NCERT WhatsApp advisory PDFs to compromise Windows systems. Link to the Research Report: APT36 LNK-BASED MALWARE CAMPAIGN LEVERAGING MSI PAYLOAD DELIVERY - CYFIRMA #APT36 #Cyberthreatintelligence #Malware analysis #Threathunting #Cybersecurity #ETLM #CYFIRMA https://www.cyfirma.com/
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.