In this week’s newsletter, Martin looks at how the metaphors we use to describe AI “escaping” its sandbox can completely change how we react to the threat.
Tag: Cisco Talos Blog
“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI
Talos has collected prompt logs from threat actor endpoints running various applications, such as Claude Code, CodeX, Cursor, or Gemini. This blog is an…
[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents
Register for an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents Talos IR faced in Q2.
Black Hat special: Rewind and revisit
Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence.
You were onto something with “It’s the Climb,” Miley
Amy hikes Virginia’s most difficult trail and muses on the persistent challenges of cybersecurity. The two aren’t dissimilar.
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
Talos IR’s Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn…
Black Hat special: Rewind and revisit
Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence.
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
Talos IR's Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses. This article has been indexed from Cisco Talos Blog Read the original article: IR…
Don’t swing at everything
Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever. This article has been indexed from Cisco Talos Blog Read the original article: Don’t swing at everything
Preview: Cisco Talos at Black Hat USA 2026
Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk. This article has been indexed from Cisco Talos Blog Read the original article: Preview: Cisco Talos at Black Hat USA 2026
Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel
The Chaos ransomware group uses new malware “msaRAT” that hijacks browsers. The malware doesn’t communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker’s IP from victims via WebRTC over TURN. This…
Begun, the Patch Wars have
Long foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story. This article has been indexed from Cisco Talos Blog Read the original article: Begun, the Patch Wars have
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025. This article has been indexed from Cisco Talos Blog Read the original…
The Hunter’s Paradox: Is it time to embrace automated threat hunting?
Humans can no longer keep up with the volume and velocity of security data on their own, but AI can’t be fully trusted. David discusses the merits of both and muses on what the future might look like. This article…
Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical". Microsoft notes that two of the vulnerabilities disclosed this month have been exploited in…
[Video] Where protection starts: Cisco Talos Intelligence Integrations
Every day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations help reduce uncertainty by turning the latest threat intelligence into proactive protections across Cisco technologies. This article has been indexed from Cisco Talos Blog Read…
The serpent’s tongue: Luring the Python out of its den
This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Python environments. This article has…
WolfSSL, GeoVision, VTK vulnerabilities
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in GeoVision, and one vulnerability in VTK-DICOM. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party…
Winning 54% of the time
With Wimbledon’s help, Hazel argues against the popular myth that “Attackers only need to be right once, but defenders need to be right 100% of the time.” This article has been indexed from Cisco Talos Blog Read the original article:…
UAT-7810 continues building ORB networks using new malware
Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware. This article has been indexed from Cisco Talos Blog Read the original article: UAT-7810 continues building ORB networks using new malware