REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
48 reports · page 2 of 2
talos · tlp:amber · 4/23/2026, 6:00:22 PM
It pays to be a forever student In this newsletter, Joe discusses why understanding other disciplines can often flow back into the macro and micro of cybersecurity, especially in a world of AI. Welcome to this week’s edition of the Threat Source newsletter.  If I haven’t said it in a newsletter before, I'll say it now: If you want to be good at cybersecurity, be a forever student. Cultivating and feeding your desire to know how th…
Read original ↗https://blog.talosintelligence.com/it-pays-to-be-a-forever-studenttalos · tlp:amber · 4/23/2026, 3:10:57 PM
UAT-4356's Targeting of Cisco Firepower Devices Cisco Talos is aware of UAT-4356's continued active targeting of Cisco Firepower devices’ Firepower eXtensible Operating System (FXOS). UAT-4356 exploited n-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) to gain unauthorized access to vulnerable devices. Cisco Talos is aware of UAT-4356 's continued active targeting of Cisco Firepower devices’ Firepower eXtensible Operating System (FXOS). UAT-4356 exploite…
talos · tlp:amber · 4/22/2026, 10:00:34 AM
IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist Phishing reemerged as the most observed means of gaining initial access, accounting for over a third of the engagements where initial access could be determined. Phishing has not been the top vertical for initial access since Q2 2025. Phishing reemerged as the most observed means of gaining initial access, accounting for over a third of the engagements wher…
Read original ↗https://blog.talosintelligence.com/ir-trends-q1-2026talos · tlp:amber · 4/21/2026, 12:29:49 PM
[Podcast] It's not you, it's your printer: State-sponsored and phishing threats in 2025 In this episode of Talos Takes, Amy and Martin Lee unpack state-sponsored and phishing trends from the 2025 Talos Year in Review. In this episode, we unpack state-sponsored and phishing trends from the 2025 Talos Year in Review. Amy and Martin Lee explore the alarming rise of internal phishing campaigns that bypass traditional perimeter defenses, including the widespread weaponization of…
Read original ↗https://blog.talosintelligence.com/podcast-its-not-you-its-your-printer-state-sponsored-and-phishing-threats-in-2025talos · tlp:amber · 4/21/2026, 12:00:08 PM
Phishing and MFA exploitation: Targeting the keys to the kingdom In 2025, attackers increasingly targeted weaknesses in multi-factor authentication (MFA) workflows, and phishing attacks leveraged valid, compromised credentials to launch lures from trusted accounts. The trends focused entirely on trust, or the lack thereof, in everyday business operations. In 2025, attackers increasingly targeted weaknesses in multi-factor authentication (MFA) workflows, and phishing attacks…
Read original ↗https://blog.talosintelligence.com/phishing-and-mfa-exploitation-targeting-the-keys-to-the-kingdomtalos · tlp:amber · 4/21/2026, 10:00:29 AM
Bad Apples: Weaponizing native macOS primitives for movement and execution Cisco Talos documents several macOS living-off-the-land (LOTL) techniques, demonstrating that native pathways for movement and execution remain accessible to those who understand the underlying architecture. As macOS adoption grows among developers and DevOps, it has become a high value target; however, native "living-off-the-land" (LOTL) techniques for the platform remain significantl…
Read original ↗https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-executiontalos · tlp:amber · 4/16/2026, 7:00:24 PM
Foxit, LibRaw vulnerabilities Cisco Talos’ Vulnerability Discovery & Research team recently disclosed one Foxit Reader vulnerability, and six LibRaw file reader vulnerabilities. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to Cisco’s third-party vulnerability disclosure policy .     For Cisco Talos’ Vulnerability Discovery & Research team recently disclosed on…
Read original ↗https://blog.talosintelligence.com/foxit-libraw-vulnerabilitiestalos · tlp:amber · 4/16/2026, 6:00:31 PM
The Q1 vulnerability pulse Thor provides an overview of the Q1 2026 vulnerability statistics, highlighting key trends in legacy CVEs and the evolving impact of AI on the threat landscape. Welcome to this week’s edition of the Threat Source newsletter.  The first quarter of 2026 passed faster than a misconfigured firewall rule gets exploited — and the last few weeks have been firmly stamped with the "software supply chain compromise" la…
Read original ↗https://blog.talosintelligence.com/the-q1-vulnerability-pulse