# Profero > Profero provides breach readiness and rapid incident response services through a predictable subscription model. Our Incident Response Team (IRT) delivers proactive compromise assessments, tailored threat intelligence, and 24/7 emergency IR for organisations worldwide. Profero's IRT publishes in-depth technical research covering malware analysis, threat intelligence, forensics, and incident response methodology — all based on real-world engagements. ## Key Pages - [Homepage](https://profero.io/): Breach readiness and rapid IR services overview - [Get Started](https://profero.io/get-started/): Contact us to begin your breach readiness programme - [Emergency Response](https://profero.io/emergency/): 24/7 emergency IR — immediate response for active incidents - [Company](https://profero.io/company/): About Profero, our founders and advisory board - [Careers](https://profero.io/careers/): Open positions at Profero ## Blog - [Google Hid Its Quantum Result Behind a Proof. It Did Not Stay Hidden.](https://profero.io/blog/quantum-cryptography-zkp-followup/): This continues We Said Wait. The Wait Is Over.. The original post ended with a short note about a zero-knowledge proof. That note turned out to be the... - [Profero Congratulates Jet Bank on the Launch of Albania's First 100% Digital Bank](https://profero.io/blog/jet-bank-launch/): This Thursday, 18 June 2026, marks a defining moment for Albanian finance: the official launch of Jet Bank, the country’s first fully digital bank. Profero is... - [We Said Wait. The Wait Is Over.](https://profero.io/blog/quantum-cryptography-harvest-now-decrypt-later/): Update (June 2026): Two corrections since this went out. First, AES-128. We told you to move off it and filed that under the quantum threat. That was wrong.... - [We Added a Detection Rule. We Were Not Expecting This.](https://profero.io/blog/hiddenperms/): Most users never see the command line Claude Desktop runs under the hood. It’s not hidden; it’s just buried in a process list. But if you look, you’ll find... - [The AI Incident Response Framework: When Your Agent Is the Threat](https://profero.io/blog/ai-incident-response-framework/): On April 25, 2026, a developer at PocketOS gave a Cursor agent a routine task: fix a credential mismatch in a staging environment. Nine seconds later, the... - [The War Between Wars: How an IRGC Cyber Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire](https://profero.io/blog/war-between-wars/): A ceasefire on the front line is not a ceasefire on the network. Through 2025 and 2026, an Iranian state-directed persona has spent the quiet stretches breaking... - [The AI produced malware kill switch](https://profero.io/blog/windowsaudit-c2-takeover/): In part one we walked through WindowsAudit.exe, the .NET apphost backdoor we found running as LocalSystem on our client’s network. We covered how it got onto... - [WindowsAudit Backdoor: Inside a .NET RAT That Hides in Discord](https://profero.io/blog/windowsaudit-backdoor/): Advisory: Profero has observed this campaign active across multiple environments, and based on observed patterns and tradecraft, it may be positioning for... - [Everyone's Talking About Mythos. Here's What's Actually Going On.](https://profero.io/blog/everyone-talking-about-mythos/): If you’ve been anywhere near a security Slack in the last week, you’ve seen the headlines. Anthropic dropped Claude Mythos on April 7th and the internet did... - [The Theater of Cyber War: How Russian "Hacktivists" Are Performing for Iran Without Actually Hacking Anything](https://profero.io/blog/the-theater-of-cyber-war-cardinal-russian-legion/): Executive Summary Since the Iran-Israel conflict escalated in early March 2026, Russian-aligned hacktivist groups have flooded Telegram with claims of breaching... - [The Claude Code Leak: What One Missing File Cost Anthropic, and How to Check If You're Exposed](https://profero.io/blog/the-claude-code-leak-what-one-missing-file-cost-anthropic/): On March 31, 2026, Anthropic shipped the complete source code of Claude Code to every npm mirror on the planet. Not through a breach. Not through a compromised... - [Why We Reforged Rapid-IR From the Ground Up](https://profero.io/blog/why-we-reforged-rapid-ir/): When an incident hits at 2 AM, most organizations start from zero. Hunting through PDFs, guessing which findings matter, assembling scattered tools while the... - [The Key Was on the Floor: How the FBI Director's Personal Accounts Were Already Exposed](https://profero.io/blog/the-key-was-on-the-floor-fbi-directors-personal-accounts-exposed/): We don’t know exactly how Handala got into Kash Patel’s accounts. I’m not going to claim we do. But from years of responding to MOIS-linked intrusions, the... - [Hijacked at the Source: AppsFlyer's Trusted Marketing SDK Distributes a Crypto Stealer](https://profero.io/blog/hijacked-at-the-source-a-trusted-marketing-appsflyers-sdk-distributes-a-crypto-stealer/): Executive Summary On March 9, 2026, Profero began investigating a suspected compromise of the AppsFlyer SDK following customer requests. AppsFlyer is a mobile... - [P4Tr!0T3CH Channel Doxxing & Disinfo Assessment](https://profero.io/blog/p4tr-0t3ch-channel-doxxing-disinfo-assessment/): Executive Summary On March 3, 2026, the Hebrew-language Telegram channel P4Tr!0T3CH published a post (Message ID 639) claiming to release doxxing data and... - [địt mẹ mày morphisec: When Malware Authors Taunt Security Researchers](https://profero.io/blog/dit-me-may-morphisec-when-malware-authors-taunt-security-researchers/): Executive Summary The complete analysis of Vietnamese Stealer - a Python-based info stealer using Telegram as a C2. What started as a CrowdStrike alert with a... - [AtomicStealer Spreading via Fake Apple Support Websites](https://profero.io/blog/atomicstealer-spreading-via-fake-apple-support-websites/): Executive Summary Recently Profero uncovered an AtomicStealer campaign using a fake Apple Support website designed to trick users into running a malicious bash... - [The $5 Million Letter: When Physical Mail Becomes Digital Extortion](https://profero.io/blog/the-5-million-letter-when-physical-mail-becomes-digital-extortion/): The Letter That Started a Crisis It was 7:43 AM on a Monday when the CEO’s secretary walked into his office with an unusual envelope marked “TIME SENSITIVE -... - [New Attack Vector - AI - Induced Destruction](https://profero.io/blog/new-attack-vector--ai-induced-destruction/): From Friend to Foe: A New Era of Cybersecurity Incidents How “helpful” AI assistants are accidentally destroying production systems - and what we’re doing about... - [From Drone Strike to File Recovery: Outsmarting a Nation State](https://profero.io/blog/from-drone-strike-to-file-recovery-outsmarting-a-nation-state/): Setting the stage On January 28, 2023, an ammunition factory belonging to the Iranian Defence Ministry in Isfahan was attacked by three drones. Iran later... - [The Blurring Lines Between Financially Motivated Attacks and Nation-State Cyber Operations](https://profero.io/blog/the-blurring-lines-between-financially-motivated-attacks-and-nation-state-cyber-operations/): Since the outset of the Russia-Ukraine war in early 2022, our Incident Response Team at Profero has been engaged in multiple investigations involving Russian... - [Live Forensic Collection from Ivanti EPMM Appliances (CVE-2025-4427 & CVE-2025-4428)](https://profero.io/blog/ivanti-epmm-attacks/): Why This Matters In May 2025, Profero responded to multiple security incidents stemming from the active exploitation of two zero-day vulnerabilities in Ivanti... - [Unmasking a Sophisticated Phishing Campaign: Profero IRT’s Deep Dive into a Global Microsoft Identity Attack](https://profero.io/blog/unmasking-a-sophisticated-phishing-campaign-profero-irts-deep-dive-into-a-global-microsoft-identity-attack/): Over the past month, the Profero Incident Response Team (IRT) conducted an exhaustive forensic investigation into a global phishing campaign targeting Microsoft... - [Understanding Quantum Cryptography: Separating Fact from Fiction](https://profero.io/blog/understanding-quantum-cryptography-separating-fact-from-fiction/): Hello, tech enthusiasts! Today, we’re going to explore the intriguing world of quantum cryptography. With all the buzz about quantum computers potentially... - [A Breach Is Inevitable: Why Organizations Are Failing in Proactive Threat Detection](https://profero.io/blog/a-breach-is-inevitable-why-organizations-are-failing-in-proactive-threat-detection/): In today’s cyber security reality, security teams are drowning in acronyms. CTEM, CSPM, IDM and more: all are parts of a common defense lineup aiming to create... - [Behind the Scenes: How Pager Apps Power 24/7 Incident Response Operations](https://profero.io/blog/behind-the-scenes-how-pager-apps-power-24-7-incident-response-operations/): Behind the Scenes: How Pager Apps Power 24/7 Incident Response Operations In a surprising 90s-throwback, pagers have been making headlines lately. In this blog... - [MITRE ATT&CK: A Guidebook for the Cyber Jungle](https://profero.io/blog/mitre-att-ck-a-guidebook-for-the-cyber-jungle/): Some people go out into nature with a plant guide or a bird handbook to better understand what they see in front of them. Such a guide includes a catalogue... - [Secrets leakage – A rising threat. Development Practices to Safeguard Your Secrets](https://profero.io/blog/secrets-leakage-rising-threat-development-practices-to-safeguard-your-secrets/): Introduction During 2024 Profero’s research and incident response teams tracked a trend of cyber-attacks that are based on security misconfigurations and... - [Why Cyberattacks Spike During Holidays and How to be IR Ready](https://profero.io/blog/why-cyberattacks-spike-during-holidays-and-how-to-be-ir-ready/): Introduction Every year, as we deck the halls and prepare to celebrate major holidays like July 4th, cybercriminals are also planning their own “celebrations.”... - [Cloud Security Alliance Conference: Attacker Perspective Panel Overview](https://profero.io/blog/cloud-security-alliance-conference-attacker-perspective-panel-overview/): At the recent Cloud Security Alliance Conference, a compelling panel on cloud security from an attacker’s perspective brought together industry experts to... - [Microsoft Windows Endpoint Forensics Readiness Booster](https://profero.io/blog/microsoft-windows-endpoint-forensics-readiness-booster/): This short blog post will run through a few ways the IT/Security teams can configure their existing Windows environment in order to improve forensics readiness... - [Profero is now Certified for SOC 2 (type 2) and ISO 27001](https://profero.io/blog/profero-is-now-certified-for-soc-2-and-iso-27001/): At Profero, trust is the cornerstone of our relationships with clients. As a leading incident response company, we are entrusted with sensitive data and conduct... - [The 10.0 Rated CVE in xz-utils Jeopardizing SSH Security](https://profero.io/blog/the-10-0-rated-cve-in-xz-utils-jeopardizing-ssh-security/): On March 29th, 2024, our security team was alerted to a newly identified CVE, assigned a critical severity rating of 10.0. This vulnerability was found in... - [SysAid On-Prem Vulnerability Disclosure](https://profero.io/blog/sysaid-on-prem-vulnerability-disclosure/): CVE-2023-47246 On Nov 2nd, our security team received reports regarding a potential vulnerability in our on-premise software which was being actively exploited.... - [CyberWeek RedAlert 2023 Focus Shift: Parallels between Europe and Israel's Cyber Incident Response Preparedness](https://profero.io/blog/redalert2023/): Focus Shift: Parallels between Europe and Israel’s Cyber Incident Response Preparedness TL;DR During CyberWeek 2023 I’ve had the opportunity to share our... - [Malicious Extensions - What They Are And How To Fight Them](https://profero.io/blog/malicious-extensions-what-they-are-and-how-to-fight-them/): Introduction According to DebugBear, there were about 1.7 billion users with installed Chrome extensions in 2020, out of more than 2.5 billion users of Chrome.... - [LastPass Breach - and your SSO](https://profero.io/blog/lastpass-breach-and-your-sso/): see our previous blog post On Feb 28th, 2023, new information disclosed by LastPass revealed that users of their organizational product relying on SSO are also... - [LastPass Breach - What went wrong?](https://profero.io/blog/lastpass-breach-what-went-wrong/): disclaimer: this is based on our experience, expertise, and public sources What is a password manager? A password manager is a place to store your passwords... - [Online Programming Learning Sites Can Be Manipulated By Hackers To Launch Cyberattacks](https://profero.io/blog/online-programming-learning-sites-can-be-manipulated-by-hackers-to-launch-cyberattacks/): Introduction Hackers commonly launch their attacks using compromised machines rather than directly from owned devices, which allows them to conceal their... - [Multi-factor Authentication In-The-Wild bypass methods](https://profero.io/blog/multi-factor-authentication-in-the-wild-bypass-methods/): Introduction Two-factor authentication (2FA) or multi-factor authentication ( MFA ) is a method to authenticate through a service that requires at least two... - [Static unpacker and decoder for Hello Kitty Packer](https://profero.io/blog/static-unpacker-and-decoder-for-hello-kitty-packer/): During a recent incident response engagement, the Profero IR team observed a sample of Hello Kitty ransomware. This version of ransomware is intriguing as this... - [OSS Getting Hammered for BigCorp Failures](https://profero.io/blog/oss-getting-hammered-for-bigcorp-failures/): Everyone heard of log4j by now You might not know what the log4j vulnerability is, or what it means — but the memes are everywhere! The log4j vulnerability has... - [log4jScanner](https://profero.io/blog/log4jscanner/): Background Our customers faced a serious issue, they did not know which servers on their internal network were vulnerable to log4j, and were reluctant to send... - [Log4Shell & massive Kinsing deployment](https://profero.io/blog/log4shell-massive-kinsing-deployment/): On December 9th, 2021 news broke about a newly discovered vulnerability affecting the java logging library, Log4j. Since this news broke out, threat actors... - [From the Trenches: Common-Sense Measures to Prevent Cloud Incidents](https://profero.io/blog/from-the-trenches-common-sense-measures-to-prevent-cloud-incidents/): Introduction As an incident response team, we see a lot of cloud breaches that could have been prevented. Adequate protection requires in-depth knowledge of the... - [RansomEXX, Fixing Corrupted Ransom](https://profero.io/blog/ransomexx-fixing-corrupted-ransom/): Since the sudden disappearance of the REvil ransomware operation, there has been a rise in other “ransomware as a service” (RaaS) operators attempting to claim... - [Secrets Behind Ever101 Ransomware](https://profero.io/blog/secrets-behind-ever101-ransomware/): A victim called the incident response teams of Global Threat Center, reporting a seemingly new stream of ransomware attack. Upon investigation, we determined... - [Cuba Ransomware Group on a Roll](https://profero.io/blog/cuba-ransomware-group-on-a-roll/): At the end of 2020, our team made up of SecurityJoes and Profero incident responders, led an investigation into a complex attack in which hundreds of machines... - [APT27 Turns to Ransomware](https://profero.io/blog/apt27-turns-to-ransomware/): At the peak of the COVID-19 pandemic and economic crisis, our Global Incident Response and Cyber Crisis Management teams were engaged on several fronts around... ## Optional - [Trust Portal](https://trust.profero.io): SOC 2 Type 2 and ISO 27001 certification documents - [GitHub](https://github.com/proferosec): Open source IR tools from Profero's team - [Sitemap](https://profero.io/sitemap.xml): Full site index