Archives: Out of Band

Crystal Ball Series
2026-04-14
Crystal Ball Series

Crystal Ball Series In this Instalment we Explore Attackers will Overwhelmingly Avoid Persistence

Silent Crypto Wallet Takeover Unlimited USDT Approval Exploitation via Trust Wallet QR Code Phishing
2026-04-14
Silent Crypto Wallet Takeover Unlimited USDT Approval Exploitation via Trust Wallet QR Code Phishing

EXECUTIVE SUMMARY This report details an active QR code–based crypto drainer campaign targeting

CVE-2026-1492 WordPress User Registration & Membership Authentication Bypass Flaw
2026-04-11
CVE-2026-1492 WordPress User Registration & Membership Authentication Bypass Flaw

EXECUTIVE SUMMARY CVE-2026-1492 is a critical authentication bypass and privilege escalation vulnerability

TRACKING RANSOMWARE : March 2026
2026-04-08
TRACKING RANSOMWARE : March 2026

EXECUTIVE SUMMARY Ransomware activity in March 2026 reflects a maturing, highly adaptive, and increasingly

Crystal Ball Series
2026-04-08
Crystal Ball Series

Crystal Ball Series In this Instalment we Explore Exploit timing will dominate over sophistication

CONSUMER GOODS SERVICES Q1 I 2026 : INDUSTRY REPORT
2026-04-06
CONSUMER GOODS SERVICES Q1 I 2026 : INDUSTRY REPORT

CONSUMER GOODS SERVICES Q1 I 2026 : INDUSTRY REPORT EXECUTIVE SUMMARY The CYFIRMA Industry Report

Malaysia Threat Landscape Report
2026-04-03
Malaysia Threat Landscape Report

Malaysia Threat Landscape Overview Malaysia faces a persistent and increasingly complex cyber threat

Fortnightly Vulnerability Summary
2026-04-02
Fortnightly Vulnerability Summary

Fortnightly Vulnerability Summary CHECK OUT THESE FAST FACTS ON FORTNIGHTLY OBSERVED VULNERABILITIES.

HONG KONG CYBERSECURITY THREAT INTELLIGENCE REPORT
2026-04-02
HONG KONG CYBERSECURITY THREAT INTELLIGENCE REPORT

Executive Summary This report provides a threat intelligence assessment of the cyber risk landscape

PROFESSIONAL GOODS SERVICES Q1 I 2026 : INDUSTRY REPORT
2026-03-31
PROFESSIONAL GOODS SERVICES Q1 I 2026 : INDUSTRY REPORT

PROFESSIONAL GOODS SERVICES Q1 I 2026 : INDUSTRY REPORT EXECUTIVE SUMMARY The CYFIRMA Industry Report

CYBER THREAT LANDSCAPE REPORT – TAIWAN
2026-03-28
CYBER THREAT LANDSCAPE REPORT – TAIWAN

EXECUTIVE SUMMARY Taiwan’s threat landscape in 2026 remains one of the most dynamic and geopolitically

CrySome RAT : An Advanced Persistent .NET Remote Access Trojan
2026-03-27
CrySome RAT : An Advanced Persistent .NET Remote Access Trojan

EXECUTIVE SUMMARY CrySome is a feature-rich remote access trojan (RAT) developed in C# for the .NET

DEAD INFRASTRUCTURE HIJACKING – A COMPLETE AND PRECISELY BOUND THREAT ASSESSMENT
2026-03-24
DEAD INFRASTRUCTURE HIJACKING – A COMPLETE AND PRECISELY BOUND THREAT ASSESSMENT

EXECUTIVE SUMMARY Dead Infrastructure Hijacking (DIH) is the exploitation of residual trust relationships

SINGAPORE THREAT LANDSCAPE
2026-03-23
SINGAPORE THREAT LANDSCAPE

EXECUTIVE SUMMARY Singapore’s cyber threat landscape is increasingly shaped by the intersection

Invoice – Themed Phishing Campaign Targeting Financial Workflows Amid Fiscal Year-End Activity
2026-03-20
Invoice – Themed Phishing Campaign Targeting Financial Workflows Amid Fiscal Year-End Activity

INTRODUCTION CYFIRMA has identified and analyzed a phishing campaign actively targeting organizations

TRACKING RANSOMWARE : FEBRUARY 2026
2026-03-18
TRACKING RANSOMWARE : FEBRUARY 2026

EXECUTIVE SUMMARY The February 2026 ransomware landscape reflects a mature and highly adaptive threat

INFORMATION TECHNOLOGY Q1 I 2026 : INDUSTRY REPORT
2026-03-17
INFORMATION TECHNOLOGY Q1 I 2026 : INDUSTRY REPORT

EXECUTIVE SUMMARY The CYFIRMA Industry Report delivers original cybersecurity insights and telemetry-driven

Fortnightly Vulnerability Summary
2026-03-17
Fortnightly Vulnerability Summary

Fortnightly Vulnerability Summary CHECK OUT THESE FAST FACTS ON FORTNIGHTLY OBSERVED VULNERABILITIES.

CVE-2026-24423 – SmarterTools SmarterMail Remote Code Execution Vulnerability
2026-03-12
CVE-2026-24423 – SmarterTools SmarterMail Remote Code Execution Vulnerability

EXECUTIVE SUMMARY CVE-2026-24423 is a critical unauthenticated remote code execution (RCE) vulnerability

APT Profile – Earth Lusca
2026-03-11
APT Profile – Earth Lusca

Earth Lusca (aka FishMonger) is a China-linked threat actor active since 2019, that focuses primarily