
Understand threats. Know what to do.
Serify connects current threat intelligence to your infrastructure and questions. Your team gets reasoned recommendations, investigates relationships and creates its own analyses and reports.
Cyber threat intelligence for IT operations, SOC, CTI and CSIRT teams · Demonstrator in development
Does CISA ICSA-25-023-02 on RTU500 (CVE-2024-2617) affect us?
- Affected sites
- North (13.5.2) and South (13.4.3), both high criticality. West: inventory unclear.
- Source and evidence
- CISA ICSA-25-023-02: 13.4.1–13.4.4 and 13.5.1–13.5.3 affected if secure update is not enabled on all CMUs.
- Next step
- Verify secure update at North and South, assess updates to 13.5.4 or 13.7.7, collect West’s inventory.
Why now
The work is growing faster than the teams.
Analysts absorb more sources, more alerts, and now the output of AI systems they still have to check. European regulation adds fixed clocks on top.
- 81%
- say their security workload grew over the past year.
- 44%
- of team time still goes on manual, repetitive work.
- 76%
- report emotional exhaustion, reduced motivation or mental fatigue.
From a survey of more than 1,800 security leaders and practitioners. 99% of them already run AI somewhere in the stack, and the manual share did not fall. Tines Voice of Security 2026
And the clocks are already running
- NIS2
An early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours. The Commission estimates over 160,000 entities now fall in scope.
NIS2 Article 23 - DORA
More than 22,000 financial entities. Initial notification within four hours of classifying an incident as major, and no later than 24 hours after detection.
DORA Article 19 - CRA
Manufacturers must report actively exploited vulnerabilities to ENISA and their national CSIRT within 24 hours of becoming aware, with a technical notification at 72 hours.
CRA reporting obligations
What you can do with it
From a report to a reasoned next decision.
Serify is being developed for IT operations, SOC, CTI and CSIRT teams that want to turn threat information into practical actions and their own analyses.
See what affects you
Automatically compare supplied SBOM and infrastructure data with new reporting.
Understand relationships
Trace evidenced links between vulnerabilities, indicators, actors and campaigns.
Put findings to work
Review, investigate and report results shaped for each role and question.
Interactive examples
One question. The context your team needs.
Choose a perspective and explore the response, from practical actions to campaign analysis.
Follow-up on CISA ICSA-25-023-02 (CVE-2024-2617): which of our RTU500 sites need further investigation, and what is missing for a decision?
Advisory, version ranges and SBOM inventory of four sites matched· Reconstructed · real advisory, fictional sites
North and South are in the affected range. West is a data gap.
The CMU firmware at North (13.5.2) and South (13.4.3) falls within the affected version ranges; both sites are recorded as high criticality. The vulnerability is only exploitable if secure update is not enabled on all CMUs. No evidence of that configuration has been supplied yet.
- Nord · high · 2× 13.5.2Verify secure update on both CMUs; assess an update to 13.5.4 or later.
- South · high · 2× 13.4.3Verify secure update on both CMUs; assess an update to 13.7.7 or later.
- West · high · unclearThe export from 20 Aug lists one CMU on 13.5.4 but is neither confirmed as current nor complete. Collect a current inventory.
- OT lab · low · 13.5.4Outside the range. Usable as a reference device for a compatibility test.
View source, remediations and limits
CISA ICSA-25-023-02, Update B of 3 Mar 2026 · CVE-2024-2617 · CVSS 7.2. Authenticated, authorised users can bypass secure update and install unsigned firmware if secure update is not enabled on all CMUs of an RTU500. Affected: CMU firmware 13.2.1–13.2.7, 13.4.1–13.4.4 and 13.5.1–13.5.3.
Vendor remediation: 13.4.x to 13.7.7 or later, 13.5.x to 13.5.4 or later; in both cases enable secure update on all CMUs.
Limits: the version match does not establish exploitability. An update target is not an operational approval; compatibility testing and a maintenance window are pending. 13.5.4 is not a general all-clear; other advisories need separate review.
Data as of: SBOM inventory from 15 Sep 2026, West from 20 Aug 2026. Sites, criticality and operator details are fictional; the advisory is real.
lastauthserverused.js was modified on our Ivanti Connect Secure. The external Integrity Checker Tool reports no mismatches. What do we know, and how do we proceed?
File matched against CISA AA24-060B; malware, infrastructure and vulnerabilities retrieved· Reconstructed · real advisory, fictional alert
The change matches known credential theft. A clean ICT scan is no all-clear.
CISA AA24-060B describes this exact file as modified to send entered credentials to an attacker-controlled domain and lists variants of it as the WARPWIRE credential harvester. The same advisory reports web shells on devices where the ICT showed no mismatches. This does not prove a compromise, but the credentials should be treated as at risk.
- lastauthserverused.js → WARPWIRE
Credential harvester variant · AA24-060B, p. 21 - WARPWIRE → symantke[.]com
C2 server · AA24-060B, p. 23 - Your gateway → symantke[.]com
Inferred, to be checked in proxy and DNS logs
Solid: described in the advisory. Dashed: inferred. The advisory attributes the activity to no actor; UTA0178 appears only in its IOC tables.
View next check, sources and case reports
Next check: search proxy and DNS logs for symantke[.]com and the advisory’s other indicators. Run the current external ICT, but do not treat a clean result as an all-clear. Treat VPN user and service account credentials as compromised.
CISA AA24-060B of 29 Feb 2024: CVE-2023-46805 and CVE-2024-21887 can be chained into unauthenticated code execution; all supported versions 9.x and 22.x are affected. In CISA lab tests, root-level persistence survived factory resets and upgrades. According to CISA, some IP addresses in the advisory may also be used legitimately.
Technical case report · example
Finding: modified lastauthserverused.js on Ivanti Connect Secure, ICT without mismatch. External context: AA24-060B lists the file as a WARPWIRE credential harvester with C2 symantke[.]com. Gaps: time of modification, outbound connections, affected accounts. Next step: check logs for the indicators, isolate or reimage the device, reset all credentials used through the gateway.
Customer report · example
A file on your VPN gateway was modified that, according to a warning from the US agency CISA, is used to steal login credentials. Whether any data was actually taken is still open. As a precaution we are resetting credentials and examining the device; the VPN may be briefly unavailable.
Do the ANSSI report on APT28 in France and the joint advisory on GRU targeting of logistics companies describe the same activity? Show the evidence and its limits.
Two reports: actors, tools, vulnerabilities and periods compared· Reconstructed · real reports
Same actor, different campaigns. The reports are not independent.
Both attribute the activity to APT28 and name HeadLace, CVE-2023-23397 and services such as Mocky and InfinityFree. The targets differ: French government, defence industry and research for ANSSI; logistics, transport and IT in 13 countries in the joint advisory. ANSSI co-sealed that advisory, and it cites the ANSSI report. The overlap is therefore not independent confirmation.
Same actor per both sources · common campaign not established
Sources not independent · no shared indicators
Overlap, differences and limits
Shared: Attribution to APT28 (Fancy Bear); HeadLace, OceanMap, MASEPIE and SteelHook are named in both; CVE-2023-23397 and attacks on Roundcube servers; phishing, brute force and compromised routers; services such as Mocky and InfinityFree.
Differences: Only the joint advisory names GRU unit 26165, the Roundcube CVEs, CVE-2023-38831 (WinRAR) and concrete indicators. According to it, OceanMap and SteelHook were not observed against logistics or IT. Period: ANSSI from 2021, joint advisory from 2022.
Limits: The ANSSI report contains no indicators, so an IOC comparison is not possible. There, “targeting” also covers unsuccessful attempts. The joint advisory notes that its indicators may be shared or compromised infrastructure.
Sources and collection gaps
ANSSI CERTFR-2025-CTI-007 of 29 Apr 2025: APT28 activity against French entities since 2021.
CISA AA25-141A of May 2025: joint advisory by NSA, CISA, FBI and partners including BSI, BND, BfV and ANSSI on GRU unit 26165 and Western logistics and IT. Cites the ANSSI report as a source on CVE-2023-23397.
Collection gap: own telemetry or reporting from outside the co-sealing agencies to connect or separate the campaigns.
Knowledge base in development
Each analysis builds on existing knowledge.
Example with real reports: new sources add to existing evidence instead of replacing it. Continuous updates and notifications are planned.
- 01
New report: CISA AA25-141A
The joint advisory of May 2025 describes GRU unit 26165 (APT28) targeting Western logistics and IT companies.
- 02
Link to existing knowledge
The ANSSI report of April 2025 already attributes HeadLace and CVE-2023-23397 to APT28. The new advisory cites it; ANSSI co-sealed it.
- 03
Extend the assessment
Previously: government, defence and research in France. Now: also logistics, transport and IT in 13 countries, with checkable indicators. Not independent confirmation, as the sources are linked.
In development
Keep your data and decisions under your control.
European sovereignty starts with clear boundaries: public threat information as a shared knowledge base, separate from protected organisational context.
- Knowledge base
- Public sources and their evidence.
- Organisation context
- Your supplied inventories remain a separate context.
- Models
- Model choice is part of the intended flexible design.
- Integration
- Interfaces and local processing will be scoped with pilot teams.
Local processing and private knowledge bases are a target, not an available feature. Demonstrator in development.
Our team
The people behind Serify
We build Serify together with security teams. Philipp translates their requirements into the product. Markus develops the AI methods that extract information and prepare it for analysis.


Selected research
Automate the intelligence cycle
Proactive Cyber Threat Intelligence · 2025
The research basis for turning sources into usable findings.
View publicationAI for security text with little data
Deep Learning in Textual Low-Data Regimes for Cybersecurity · 2025
Research on deep learning that understands security text from few training examples.
View publicationOur Journey
What we are working on
2026In Progress
Platform Development
2026 Q4In Progress
Pilot Program
Before you ask
The questions we get first.
Serify is a demonstrator in development, so these answers say what holds today and what is still a target. If something here does not survive contact with your environment, that is worth a conversation.
Where does our data live?
On European infrastructure. Public threat information sits in a shared knowledge base. Anything you supply, such as an inventory, stays in a separate context and is not mixed into it.
Which model do you use, and does our data train it?
Model choice is part of the intended design rather than a fixed dependency, and we are evaluating open-weight and commercial options during the pilot phase. Nothing you supply is used to train a model.
Can we run this on-premise?
Not today. Local processing is a target for the platform, not a feature you can buy. Tell us what your environment requires and we will be specific about what the demonstrator can and cannot do inside it.
We already run MISP and OpenCTI. Why add this?
Those store and share what you already hold. Serify is aimed at the step before: reading new public reporting, extracting what is in it, and connecting it to what you have. Open formats such as STIX and MISP are part of the intended design, so the goal is to feed those tools rather than replace them.
What does a pilot cost us?
Your time, mainly. A pilot means bringing a real recurring task and enough context to judge whether the answers hold up. We are not selling licences yet.
Pilot project
Which part of your workflow needs less manual work?
Tell us about your team, your sources and a specific task. Together we can define what to explore with the demonstrator and how to measure its value.
Or write to us directly:
contact@serify.eu




