Research Labs
Interactive security operations dashboard
A live view of the intelligence, detections, and disclosures produced by CipherTest Research. Feeds shown are illustrative and update continuously.
LIVE — stream activetick 0
24h
0
Tracked CVEs
24h
0
Active Threat Actors
24h
0
Detection Rules
24h
0
Public Disclosures
CVE Feed
CVE-2025-9182New
Apache · Tomcat9.8
CVSS
CVE-2025-9170Patched
Atlassian · Confluence8.6
CVSS
CVE-2025-9144Analyzing
VMware · vCenter9.1
CVSS
CVE-2025-9121Patched
Cisco · ISE7.5
CVSS
CVE-2025-9088New
Fortinet · FortiOS8.8
CVSS
Threat Intelligence
UNC5321Finance · T1078 Valid Accounts
▲ activityScattered SpiderSaaS · T1566 Phishing
▲ activityAkiraManufacturing · T1486 Data Encrypted
– activityBlack BastaHealthcare · T1190 Exploit Public App
▼ activityDetection Rules
Suspicious Kerberoast Ticket RequestT1558.003
94%
AWS AssumeRole by Untrusted PrincipalT1078.004
88%
Persistence via WMI Event SubscriptionT1546.003
91%
LSASS Memory Access by Non-system PIDT1003.001
86%
Security Tools
CipherReconAttack-surface mapping utility
Gojwt-fuzzJWT parser and token fuzzer
Pythonshadow-proxyTransparent interception proxy
Rustsigma-genSigma rule scaffolding from ATT&CK
PythonTechnical Articles
01Breaking Trust: Abuse in Modern SaaS SSO
4.2k02Container Escape via Kernel Keyring
3.1k03Detecting C2 Over Legitimate CDNs
5.7kPublic Disclosures
A popular BPM vendorCT-2025-014
PatchedA cloud identity providerCT-2025-009
PatchedA managed Kubernetes distroCT-2025-002
PatchedFeeds are illustrative and shown for demonstration. For production threat intelligence, contact our research team.