New research How Rover caught a PAN-OS authentication bypass attempt (CVE-2025-0108) Baku · Dubai

External threat intelligence for security teams

Most attacks start somewhere you weren't looking.

Cypho watches the open, deep and dark web for anything tied to your company: a leaked password, a server nobody remembers, a copy of your login page on a new domain. An analyst checks each finding before it reaches you, so your team spends its time fixing things instead of sorting alerts.

Overviewexample.com  /  last 30 days
Open issues
414 critical, 11 high
In review
6Waiting for an analyst
Time to acknowledge
2h 30mMean, last 30 days
Time to resolve
1d 4hMean, last 30 days

Open issues by category

  • Employee credentials in stealer logs12
  • Lookalike domains9
  • Company documents on file-sharing services7
  • Mentions in messaging channels5
  • Open ports and misconfigurations5
  • Certificates close to expiry3

Most affected assets

  • vpn.example.com7 findingsCritical
  • mail.example.com5 findingsHigh
  • dev-old.example.com4 findingsCritical
  • 203.0.113.243 findingsHigh
  • app.example.com2 findingsModerate
Fig. 1 The overview. Open issues by category, the assets with the most findings, and how long issues take to acknowledge and resolve. Sample data.

Where we look

Dark web forums / Telegram channels / stealer logs / paste sites / public code repositories / mobile app stores / social networks / DNS and certificate records / news and search results / file‑sharing services

01Why it matters

Your security stack only covers what you know about.

Firewalls, EDR and your SIEM watch the systems on your asset list. Attackers don't use your asset list. They look for the test server nobody shut down, the employee password sitting in a stealer log, the domain that's one letter off from yours.

Forgotten assets

Subdomains, cloud instances and open ports pile up as teams ship. The ones nobody remembers are usually the ones nobody patched.

HIGHdev-old.example.com 3389/tcp open

Stolen credentials

Infostealer malware grabs saved passwords and session cookies from infected laptops. They often go up for sale well before anyone tries them against you.

CRITstealer_log @example.com ×3

Impersonation

Lookalike domains, fake support accounts and repackaged apps borrow your name to phish your customers. They're cheap to set up and hard to tell apart from the real thing.

CRITexamp1e-secure.com 94% similar
02Platform

Three modules. One set of data underneath.

Threat intelligence, attack surface management and brand protection run off one map of what you own, with the same analysts reviewing findings. You don't buy three tools and reconcile their alerts by hand.

A / Threat Intelligence

See which threats actually involve you.

Cypho links raw intelligence to your own assets. Instead of a feed of every new CVE, you get the ones that affect products you run, ranked by how likely they are to be exploited. We combine CVSS with SVRS scores for that.

  • Threat actor and campaign tracking by industry and region
  • Vulnerability prioritization with CVSS and SVRS
  • IoC correlation and enrichment
  • Threat hunting across leak logs and code repositories
More on Threat Intelligence
Threat huntingacross every collected source
searchexample-corp OR example.com58 results
All 58Leak logs 21Code repositories 9Paste sites 6Forums and channels 22
  1. Leak log
    Stealer log with three example.com loginsvpn.example.com  j.doe@example.com  ••••••••
  2. Code
    Access key committed to a public repositorydeploy/config.yml  AWS_ACCESS_KEY_ID=AKIA••••••••  # example-corp prod
  3. Forum
    Post offering remote access to a logistics company"...VPN access, EU logistics, domain example-corp, 2 admin accounts..."
  4. Paste
    Export of an internal wiki page1,204 lines  /  mentions example.com 37 times
  5. Channel
    Combo list shared in a Telegram channelcombo_eu_0912.txt  /  14 lines match @example.com
Fig. 2 Threat hunting. One search across leak logs, code repositories, paste sites, forums and messaging channels. Sample data.

B / Attack Surface Management

Find what's exposed before someone else does.

Start with one domain. Cypho finds the subdomains, IPs, certificates and apps connected to it, then keeps checking them for open ports, misconfigurations, expired certificates and exposed admin panels. Each finding comes with the steps to fix it.

  • Subdomain and asset discovery
  • Port, vulnerability and uptime monitoring
  • SPF, DKIM and DMARC checks
  • Hard-coded secrets in mobile apps
More on Attack Surface Management
Asset inventory2,418 assets  /  sorted by risk
AssetTypeFindingRisk
dev-old.example.comSubdomainAdmin panel reachableCritical
203.0.113.24IPRDP open on 3389High
api.example.comAPISchema publicly readableHigh
mail.example.comDNSDMARC set to p=noneModerate
vpn.example.comCertificateExpires in 6 daysLow
Fig. 3 Asset inventory, sorted by risk. Sample data.

C / Brand Protection

Catch the fakes early.

We search for your name, domains, logo and keywords across the web, social platforms and app stores. Every lookalike domain gets a similarity score, so the likeliest phishing sites sit at the top of the list.

  • Lookalike domains with similarity scoring
  • Fake company and executive accounts
  • Rogue and repackaged mobile apps
  • Leaked documents, payment data and dark web mentions
More on Brand Protection
Brand protectiondomains, social accounts and apps
Lookalike domainRegisteredSimilarityRisk
examp1e-secure.comCopy of your login page2 days ago94%Critical
example-support.netMail server set up6 days ago88%High
exarnple.comParked3 weeks ago86%Moderate
example-login.appNo content yet1 month ago81%Low
Account or appWhereRisk
@example_helpSupport account using your logoXHigh
Example Corp, CFOProfile copying your CFOLinkedInModerate
Example MobileRepackaged copy of your appThird-party app storeCritical
Fig. 4 Brand protection. Lookalike domains ranked by similarity to yours, plus fake accounts and copied apps. Sample data.
03How it works

It runs every day, not once a quarter.

  1. 1

    Discover

    We map the internet-facing assets behind your domains, including subdomains you may have forgotten, plus your brand names and key people.

  2. 2

    Monitor

    Collection runs around the clock across forums, Telegram, paste sites, code repositories, app stores and the open web.

  3. 3

    Prioritize

    Findings are scored on how exploitable they are and what they would affect. An analyst reviews them before you see them.

  4. 4

    Fix

    Each issue comes with an impact summary and remediation steps. If something is unclear, comment on the issue and an analyst replies.

04Why Cypho

A person checks every finding.

Scraping the dark web is the easy part. Deciding what's real is harder.

Every candidate finding in Cypho goes into an in-review queue, and one of our analysts confirms it before it becomes an issue in your account. You get fewer alerts, and the ones you get are worth opening.

Analyst reviewtoday
6 candidates3 verified2 dismissed1 in review
  1. Credentials for 3 employees in a stealer logLeak log  /  Issue #2233
    VerifiedCritical
  2. Company contract on a file-sharing serviceFile sharing  /  Issue #2231
    VerifiedHigh
  3. Brand named in a carding channelTelegram  /  Issue #2232
    VerifiedModerate
  4. Lookalike domain example-corp.devDomain watch  /  Not confirmed
    Dismissed
  5. Paste mentioning "Example"Paste site  /  Not confirmed
    Dismissed
  6. Admin panel on 203.0.113.24Port scan  /  Analyst checking now
    In review
Fig. 5 Analyst review. Candidates are checked by a Cypho analyst before they become issues. Sample data.
AI detection
Models trained on cybercrime data surface candidates and rank them.
Real-time alerts
Critical issues reach you as soon as they're confirmed.
Wide collection
Clear and dark web sources, collected continuously.
Self-serve platform
Search, filter and export reports without waiting on us.
Support at any hour
Our team answers 24/7, weekends included.
Pricing that fits
You pay for the coverage you need, based on your footprint.
75%faster investigations
60%less manual analysis
90%more visibility across surface, deep and dark web

Figures reported through the Cypho partner program.

05AI Assistant

Ask your security data a question.

The AI Assistant in Cypho answers from your own issues, assets and sensor activity, plus shared threat intelligence. It shows which data it checked and links its answers to the sources it used. It is built to separate what it found from what it infers, and to say when evidence is missing.

AI Assistant Read-onlyPage: Dashboard
You

What should we focus on today?

  1. Checked security overview
  2. Checked issues
  3. Checked issue evidence
AI Assistant

Four critical issues are open. I'd start with these three:

  1. Employee credentials in a stealer log. Logins for 3 employees on vpn.example.com turned up on Sep 19. Reset those passwords and end their active sessions.1
  2. Admin panel reachable on dev-old.example.com. Restrict access to it or take the host offline.2
  3. Lookalike domain examp1e-secure.com. It hosts a copy of your login page and was registered 2 days ago.3

The fourth, a repackaged copy of your app, I haven't checked yet. Ask me about it and I'll pull its evidence.

Sources

  1. 1Issue #2233 Stealer log with 3 employee logins
  2. 2Issue #2236 Admin panel on dev-old.example.com
  3. 3Issue #2240 Lookalike domain examp1e-secure.com
Suggested
Fig. 6 AI Assistant. Questions about your own security data, answered with the evidence it checked and a source for each claim. Sample data.
Read-only
It uses read-only tools. It can look things up but can't change anything in your account.
Linked sources
Answers link to the issues, assets and records it retrieved.
Starts where you are
Open it on an issue, an asset or your sensor activity and it picks up that context.
Your permissions
Access follows your company, your role and your licensed modules.
Clear about gaps
It is instructed not to treat partial or missing evidence as a clean result.
Screened input
Questions and evidence are screened for known injection patterns, and recognized credential formats are redacted.
08From the lab

Notes from our sensors.

Our research team watches traffic from Siren sensors, with Rover flagging anything unusual. When something interesting turns up, we take it apart and publish what we find.

Aug 25, 2026  /  CVE-2025-0108  /  CVSS 8.8

Rover detects a PAN-OS authentication bypass attempt

GET /unauth/%252e%252e/php/ztp_gate.php/PAN_help/x.css HTTP/1.1
Host: [sensor]
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:136.0) Gecko/20100101 Firefox/136.0

1 Nginx decodes the path once, still sees a route under /unauth/, and switches the authentication check off.

2 Apache decodes it again. The fake x.css triggers a rewrite, and on the second pass %2e%2e turns into a working ../ traversal.

3 PHP runs the request. Authentication was decided on one version of the URL and executed on another.

Read the full analysis
All research
09Partners

Partner with us.

MSSPs can deliver Cypho to their clients under their own brand, and resellers can add it to what they already sell. We provide REST APIs and pre-built connectors, plus a partner team that helps with sales calls and technical setup.

MSSP partners
Add external threat intelligence to your SOC, white-labelled.
Technology partners
Build Cypho data into your own detection and response product.
Resellers
Competitive margins, with our sales engineers on the harder deals.
Strategic alliances
Joint offers with consulting and managed service firms.

Become a partner How the program works

10Questions

Things people ask us.

What does "continuous threat exposure management" mean in practice?

It means the checks never stop. We keep finding what you expose, watching it for threats, ranking what we see by real risk and following each issue to a fix. A yearly pentest tells you where you stood on one day. This tells you where you stand today.

How is this different from buying a threat feed?

A feed gives you indicators. Cypho ties those indicators to your own assets and to known threat actors, and an analyst reviews them first. What reaches you is a short list of issues with remediation steps, not a spreadsheet of IPs.

Which sources do you monitor?

Underground forums, Telegram and other messaging channels, paste sites, stealer logs, public code repositories, file-sharing services, mobile app stores, social networks, news and search engines. For your own infrastructure we also watch DNS and certificate records.

How do you keep false positives down?

Models trained on cybercrime data score each candidate, then an analyst reviews it before it becomes an issue. If you disagree with a finding, comment on it and we'll look again.

Do you work with MSSPs?

Yes. There's a partner program with white-label options, APIs, pre-built connectors and a dedicated partner team.

How much does it cost?

It depends on how big your footprint is and which modules you need. We'll give you a number after a short call.

Unknown threats are unstoppable. Until we expose them.

Send us your company domain. We'll walk you through what's already out there about you and how Cypho would handle it, with one of our analysts on the call.

Or write to [email protected]

We'll use your details to respond to your request. See our privacy policy.