REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
48 reports · page 1 of 2

talos · tlp:amber · 7/16/2026, 6:00:50 PM
Begun, the Patch Wars have Long foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story. Welcome to this week’s edition of the Threat Source newsletter.  We all knew, to some degree or another, that this summer was going to a hot mess. I don’t mean FIFA drama or record setting heat waves. I mean the slow but steady momentum that AI frontier models were accruing for vulnerability research. If you were like me, …
Read original ↗https://blog.talosintelligence.com/begun-the-patch-wars-have
talos · tlp:amber · 7/16/2026, 10:00:07 AM
The Hunter's Paradox: Is it time to embrace automated threat hunting? Humans can no longer keep up with the volume and velocity of security data on their own, but AI can't be fully trusted. David discusses the merits of both and muses on what the future might look like. Should we let AI run our threat hunts? The debate usually splits into two camps. One says, "Yes, obviously! The sheer scale of our security telemetry is impossible for humans to deal with." The oth…

talos · tlp:amber · 7/16/2026, 10:00:01 AM
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025. Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting user…
Read original ↗https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign
talos · tlp:amber · 7/14/2026, 8:27:33 PM
Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical." Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical." Microsoft notes that t…
Read original ↗https://blog.talosintelligence.com/microsoft-patch-tuesday-july-2026
talos · tlp:amber · 7/14/2026, 10:47:18 AM
[Video] Where protection starts: Cisco Talos Intelligence Integrations Every day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations help reduce uncertainty by turning the latest threat intelligence into proactive protections across Cisco technologies. Cybersecurity has always involved elements of uncertainty. Every day, security teams are asked to make decisions with incomplete information, while attackers…
Read original ↗https://blog.talosintelligence.com/video-where-protection-starts-cisco-talos-intelligence-integrations
talos · tlp:amber · 7/14/2026, 10:00:06 AM
The serpent’s tongue: Luring the Python out of its den This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Python environments. Python's popularity, readable syntax, and extensive third-party library ecosystem make it an attractive target for threat actors seeking to compromise developer devices and…
Read original ↗https://blog.talosintelligence.com/the-serpents-tongue-luring-the-python-out-of-its-den
talos · tlp:amber · 7/9/2026, 6:52:29 PM
WolfSSL, GeoVision, VTK vulnerabilities Cisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in GeoVision, and one vulnerability in VTK-DICOM. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy .  For Cisco Talos’ Vulnerability Discovery & Research team recently disclos…
Read original ↗https://blog.talosintelligence.com/wolfssl-vulnerabilities
talos · tlp:amber · 7/9/2026, 6:00:06 PM
Winning 54% of the time With Wimbledon's help, Hazel argues against the popular myth that "Attackers only need to be right once, but defenders need to be right 100% of the time." Welcome to this week’s Threat Source newsletter.  There’s a fairly cliché phrase in cybersecurity that I’m sure our audience is familiar with: Attackers only need to be right once, whereas defenders need to be right 100% of the time.   I guess it captures th…
Read original ↗https://blog.talosintelligence.com/winning-54-of-the-timetalos · tlp:amber · 7/7/2026, 10:00:05 AM
UAT-7810 continues building ORB networks using new malware Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware. Cisco Talos is actively tracking infrastructure and malware associated with UAT-7810, an advanced persistent threat (APT) actor responsible for maintaining and proliferating the LapDogs Operational Relay Box (ORB) network, first disclosed by SecurityScorecard in 2025. UAT-7810 is most likely tasked with …
Read original ↗https://blog.talosintelligence.com/uat-7810talos · tlp:amber · 7/2/2026, 6:00:34 PM
Catan and Mouse What do board games and cybersecurity have in common? Pattern recognition. Strategy. Adaptation. In this week’s Threat Source Bill explores why curiosity may be a defender’s most valuable skill. Welcome to this week’s edition of the Threat Source newsletter.   “I do not know everything; still many things I understand.” ― Madeleine L'Engle, A Wrinkle in Time  “Don't try to comprehend with y…
Read original ↗https://blog.talosintelligence.com/catan-and-mousetalos · tlp:amber · 7/1/2026, 10:00:57 AM
Martin Lee: Running through the Arctic (and the threat landscape) Ever wonder how someone goes from studying human viruses to leading cybersecurity teams? In this Humans of Talos, we’re joined by Martin Lee, EMEA Lead, to talk about his journey into the industry. Ever wonder how someone goes from studying human viruses to leading cybersecurity teams? In this Humans of Talos, we’re joined by Martin Lee, EMEA Lead, to talk about his journey into the industry. Martin ta…
Read original ↗https://blog.talosintelligence.com/martin-lee-running-through-the-arctic-and-the-threat-landscapetalos · tlp:amber · 7/1/2026, 10:00:38 AM
ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 Talos has identified "ARToken," a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoint exfiltration. Cisco Talos identified a fully-featured phishing-as-a-service (PhaaS) operator panel, branded "ARToken," that shares infrastructure, API cont…
Read original ↗https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365talos · tlp:amber · 6/25/2026, 6:00:26 PM
Beyond IOCs: AI-enabled threat intelligence In this week’s newsletter, Martin considers how AI will help threat intelligence by creating an easily queryable data source of intelligence reports. Welcome to this week’s Threat Source newsletter.  The issue of AI in cybersecurity is often portrayed as a binary choice: either a force multiplier for our adversaries, or a tool bringing professional obsolescence. The reality is more nuanced. While AI certainly brings so…
Read original ↗https://blog.talosintelligence.com/beyond-iocs-ai-enabled-threat-intelligencetalos · tlp:amber · 6/25/2026, 10:00:26 AM
Introduction to COM usage by Windows threats Component Object Model (COM) is a fundamental Windows technology used by legitimate applications for object activation, inter-process communication, automation and language-independent component reuse. Those same qualities make it useful to threat actors. Component Object Model (COM) is a fundamental Windows technology used by legitimate applications for object activation, inter-process communication, automation&#x…
Read original ↗https://blog.talosintelligence.com/introduction-to-com-usage-by-windows-threatstalos · tlp:amber · 6/18/2026, 6:00:24 PM
Close Encounters of the Human Kind In the latest Threat Source, Hazel channels her inner Spielberg to explore why humans are delightfully irrational, reminding us that while security best practices are simple in theory, they’re a lot harder to pull off when you’re busy dealing with real life. Welcome to this week’s Threat Source newsletter.  I love a Spielberg summer. His ability to imbue a sense of wonder, awe, curiosity, and connection means heȁ…
Read original ↗https://blog.talosintelligence.com/close-encounters-of-the-human-kindtalos · tlp:amber · 6/18/2026, 10:00:05 AM
Scripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object model Cisco Talos detailed a new approach to reverse engineering that pairs local AI agents with traditional analysis tools like the VB6 disassembler vbdec. Instead of awkwardly bolting AI onto the software, vbdec exposes its parsed data through a live COM interface. Analysis tools do not need AI built in to support agentic workflows; they simply need to expose their data through a…
Read original ↗https://blog.talosintelligence.com/scripting-the-disassemblertalos · tlp:amber · 6/11/2026, 6:00:49 PM
A tale of two eras In this week’s newsletter, Amy reminisces on the tech toys of their childhood, inspired by a hilarious lesson about why your digital privacy shouldn't be left on an open channel. Welcome to this week’s edition of the Threat Source newsletter.  To the surprise of absolutely no one who has seen my face, I’m one of the younger employees at Talos. As my industry veteran colleagues were buying the first iPods, n…
Read original ↗https://blog.talosintelligence.com/a-tale-of-two-erastalos · tlp:amber · 6/9/2026, 9:21:00 PM
Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities Microsoft Patch Tuesday details for June 2026. Microsoft has released its monthly security update for June 2026, which includes 206 vulnerabilities affecting a range of products, including 32 that Microsoft marked as “critical”.  Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsof…
Read original ↗https://blog.talosintelligence.com/microsoft-patch-tuesday-for-june-2026-snort-rules-and-prominent-vulnerabilitiestalos · tlp:amber · 6/4/2026, 6:00:59 PM
Reporting from Vegas: Networking, AI, and good boys Joe’s on-the-ground report from Cisco Live U.S. is here, complete with therapy dog pictures and tips on handling conference overstimulation. Welcome to this week’s edition of the Threat Source newsletter.  Howdy friends, and hello from Cisco Live U.S., here in sunny (and very hot) Las Vegas!   An interesting quirk of being sent to one of these events is you learn to understand your…
Read original ↗https://blog.talosintelligence.com/reporting-from-vegas-networking-ai-and-good-boystalos · tlp:amber · 6/4/2026, 12:05:31 PM
Winning the cyber marathon with Tony Giandomenico Tony Giandomenico, Senior Director of Product Management, joins Amy to discuss the Talos Threat Hunting launch what he's excited about for the future of cybersecurity, and, of course, his Ironman triathlons. In the high-speed world of cybersecurity, the difference between a breach and a breakthrough often comes down to endurance. Tony Giandomenico, Senior Director of Product Management with Cisco Talos, joins me to discuss h…
Read original ↗https://blog.talosintelligence.com/winning-the-cyber-marathon-with-tony-giandomenicotalos · tlp:amber · 6/4/2026, 12:05:05 PM
Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting Learn how Cisco Talos Threat Hunting uses hypothesis-driven methods and multi-domain telemetry correlation to find stealthy threats operating below automated detection thresholds. By Ron Scott-Adams Most security tools operate on a simple principle: If a known-bad pattern appears, fire an alert. This works well enough for many threats, but it fails against adversaries who closely stu…
Read original ↗https://blog.talosintelligence.com/hypotheses-telemetry-and-human-judgment-inside-cisco-talos-threat-huntingtalos · tlp:amber · 5/28/2026, 6:00:27 PM
Less panic patching, more precision In this newsletter, Thor breaks down why you should stop relying solely on CVSS and start using EPSS and GCVE to focus your patching efforts on the threats that actually matter. Welcome to this week's edition of the Threat Source newsletter.  Recently, Martin closed his introduction with a  warning : Ready or not, the time of much patching is coming. I've been chewing on that one for a while because I&ap…
Read original ↗https://blog.talosintelligence.com/less-panic-patching-more-precisiontalos · tlp:amber · 5/28/2026, 10:00:52 AM
DICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heap This white paper presents a concrete case study demonstrating the creation of a heap overflow vulnerability through the exploitation of the DICOM file format. Over the last decade, DICOM parsing has become an active research topic. The reason is simple: DICOM is both critical and complicated. Hospitals rely on DICOM-based PACS systems, and those systems often automatically ingest files re…
Read original ↗https://blog.talosintelligence.com/dicom-pydicom-gdcm-and-orthanc-a-technical-tour-of-what-really-happens-in-the-heaptalos · tlp:amber · 5/27/2026, 2:00:14 PM
MediaArea heap-based buffer overflow vulnerabilities Talos researchers find 4 heap-based buffer overflow vulnerabilities in MediaArea's MediaInfoLib. Cisco Talos’ Vulnerability Discovery & Research team recently disclosed four vulnerabilities in MediaArea MediaInfoLib library. The vulnerabilities mentioned in this blog post have been patched by their respective vendor, in adherence to Cisco’s third-party vulnerability disclosure policy . For Snort coverage…
Read original ↗https://blog.talosintelligence.com/mediaarea-heap-based-buffer-overflow-vulnerabilitiestalos · tlp:amber · 5/27/2026, 10:00:47 AM
Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake EvidenceForge generates high-quality, realistic, and consistent datasets across multiple log formats, enabling teams to effectively train personnel and validate detection models without the need for complex manual simulations. Security teams need high-quality, labeled datasets to train threat hunters and incident responders, validate detection logic, and develop robust analytic …
Read original ↗https://blog.talosintelligence.com/introducing-evidenceforge-synthetic-security-logs-that-dont-look-as-faketalos · tlp:amber · 5/21/2026, 6:00:14 PM
The art of being ungovernable In this edition of the Threat Source newsletter, William explores the value of being "ungovernable" in a professional setting, sharing how challenging the status quo and seeking out the smartest people in the room can lead to a more fulfilling and successful career. Welcome to this week’s edition of the Threat Source newsletter.   “It takes very little to govern good people. Very little. And bad people
…
Read original ↗https://blog.talosintelligence.com/the-art-of-being-ungovernabletalos · tlp:amber · 5/19/2026, 3:39:37 PM
TP-Link, Photoshop, OpenVPN, Norton VPN vulnerabilities Cisco Talos’ Vulnerability Discovery & Research team recently disclosed eight vulnerabilities in TP-Link, and one each in Adobe Photoshop, OpenVPN, and Gen Digital's Norton VPN. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability Cisco Talos’ Vulnerability Discovery & Research team recently dis…
Read original ↗https://blog.talosintelligence.com/tp-link-photoshop-openvpn-norton-vpn-vulnerabilitiestalos · tlp:amber · 5/19/2026, 10:00:20 AM
From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat Cisco Talos has uncovered a BadIIS variant — identifiable by its embedded "demo.pdb" strings — that functions as commodity malware, likely sold or shared among multiple Chinese-speaking cyber crime groups operating under a malware-as-a-service (MaaS) model for continuous monetization. Cisco Talos has uncovered a BadIIS variant — identifiable by its embedded "demo.pdb&…
Read original ↗https://blog.talosintelligence.com/from-pdb-strings-to-maas-tracking-a-commodity-badiis-ecosystemtalos · tlp:amber · 5/14/2026, 6:00:24 PM
The time of much patching is coming In this week’s newsletter, Martin reflects on what the next iteration of AI tools means for vulnerability discovery and our ability to manage large-scale patch releases. Welcome to this week’s edition of the Threat Source newsletter.  Many solutions have been proposed to reduce software bugs: zero-defect mandates, pair programming, formal methods, and mathematical software proofs. The reality is that software engineering …
Read original ↗https://blog.talosintelligence.com/the-time-of-much-patching-is-comingtalos · tlp:amber · 5/14/2026, 4:02:36 PM
Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities Cisco Talos is tracking the active exploitation of CVE-2026-20182, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage. Cisco Talos is tracking the active exploitation of CVE-2026-20182 , an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD…
Read original ↗https://blog.talosintelligence.com/sd-wan-ongoing-exploitationtalos · tlp:amber · 5/13/2026, 10:00:54 AM
Breaking things to keep them safe with Philippe Laulheret Philippe shares his unique journey from French engineering school to the front lines of cybersecurity, explaining how his lifelong love for solving puzzles helps him uncover critical security flaws before they can be exploited. In the latest Humans of Talos, Amy sits down with Senior Vulnerability Researcher Philippe Laulheret to demystify the world of ethical hacking. Philippe shares his unique journey from French e…
Read original ↗https://blog.talosintelligence.com/breaking-things-to-keep-them-safe-with-philippe-laulherettalos · tlp:amber · 5/12/2026, 7:57:04 PM
Microsoft Patch Tuesday for May 2026 — Snort rules and prominent vulnerabilities Microsoft has released its monthly security update for May 2026, which includes 112 vulnerabilities affecting a range of products, including 16 that Microsoft marked as “critical”. By   Jaeson Schultz   Microsoft has released its monthly security update for May 2026, which includes 137 vulnerabilities affecting a range of products, including 31 that Microsoft …
Read original ↗https://blog.talosintelligence.com/microsoft-patch-tuesday-may-2026talos · tlp:amber · 5/12/2026, 10:00:54 AM
State-sponsored actors, better known as the friends you don’t want Responding to a state-sponsored threat is nothing like responding to ransomware, and the differences can make or break the outcome. Learn why your IR plan might need revisiting, and the factors you should consider. State-sponsored actors don't break in. They log in, and they use your own tools to stay invisible for months. Responding to a state-sponsored threat is nothing like respon…
Read original ↗https://blog.talosintelligence.com/state-sponsored-actors-better-known-as-the-friends-you-dont-wanttalos · tlp:amber · 5/7/2026, 6:00:40 PM
Unplug your way to better code Cybersecurity concepts — logs, packets, DNS exfiltration, and more — are usually intangible, and its practitioners are prone to mental fatigue, Amy takes a second to yell at you to go touch grass. Welcome to this week’s edition of the Threat Source newsletter. Hey, you. Yeah, you! The person endlessly scrolling or typing away at their computer. Did you touch grass today? It's just an expression, but if nature’s your thing, t…
Read original ↗https://blog.talosintelligence.com/unplug-your-way-to-better-codetalos · tlp:amber · 5/6/2026, 10:00:12 AM
Insights into the clustering and reuse of phone numbers in scam emails Talos has recently started to collect and gather intelligence around phone numbers within emails as an additional indicator of compromise (IOC). In this blog, we discuss new insights into in-the-wild phone number reuse in scam emails. Cisco Talos has recently started to collect and gather intelligence around phone numbers within emails as an additional indicator of compromis…
Read original ↗https://blog.talosintelligence.com/insights-into-the-clustering-and-reuse-of-phone-numbers-in-scam-emailstalos · tlp:amber · 5/5/2026, 10:00:30 AM
UAT-8302 and its box full of malware Cisco Talos is disclosing UAT-8302, a sophisticated, China-nexus advanced persistent threat (APT) group targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025. Cisco Talos is disclosing UAT-8302, a sophisticated, China-nexus advanced persistent threat (APT) group targeting government entities in South America since at least late 2024 and government agencies in southe…
Read original ↗https://blog.talosintelligence.com/uat-8302talos · tlp:amber · 5/5/2026, 10:00:18 AM
CloudZ RAT potentially steals OTP messages using Pheno plugin Cisco Talos discovered an intrusion, active since at least January 2026, where an unknown attacker implanted a CloudZ remote access tool (RAT) and a previously undocumented plugin called “Pheno.” Cisco Talos discovered an intrusion, active since at least January 2026, where an unknown attacker implanted a CloudZ remote access tool (RAT) and a previously undocumented pl…
Read original ↗https://blog.talosintelligence.com/cloudz-pheno-infostealertalos · tlp:amber · 4/30/2026, 6:00:07 PM
Great responsibility, without great power In this week’s newsletter, Hazel uses International Superhero Day as a springboard to explore why empathy — rather than just technical prowess — is the most essential, underrated superpower for navigating the human side of cybersecurity. Welcome to this week’s edition of the Threat Source newsletter.  As I’m writing this, today (April 28) is International Superhero Day. If you don’t know…
Read original ↗https://blog.talosintelligence.com/great-responsibility-without-great-powertalos · tlp:amber · 4/29/2026, 10:00:42 AM
AI-powered honeypots: Turning the tables on malicious AI agents Just as AI brings time-saving advantages to our lives, it brings similar advantages to threat actors. We can take the advantage back. This blog shows how generative AI can be used to rapidly deploy adaptive honeypot systems. Generative AI allows defenders to instantly create diverse honeypots, like Linux shells or Internet of Things (IoT) devices, using simple text prompts. This makes deploying c…
Read original ↗https://blog.talosintelligence.com/ai-powered-honeypots-turning-the-tables-on-malicious-ai-agentstalos · tlp:amber · 4/28/2026, 1:23:20 PM
Five defender priorities from the Talos Year in Review With attackers moving faster than ever, it’s easy to feel overwhelmed. This blog breaks down five practical priorities from the Cisco Talos 2025 Year in Review to help defenders focus and prioritize, amidst all the noise. A familiar theme in security right now is that the barrier to entry for attackers is at an all-time low. AI tools can spin up websites within minutes that can easily direct data to disposable exte…
Read original ↗https://blog.talosintelligence.com/five-defender-priorities-from-the-talos-year-in-review