Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best…
Tag: Cisco Talos Blog
The safety penalty: Reclaiming operational sovereignty in the age of AI
As frontier AI models become increasingly restrictive, security teams are facing a “safety penalty” that hampers real-time incident response. Discover how…
Is Cyber missing the Marque?
In this week’s newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House…
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection,…
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview…
Describing attacks with crime script analysis
Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and…
Dissecting the JWR phishing framework
Cisco Talos recently identified an undocumented phishing framework, internally branded “JWR” by its developer, built to convincingly impersonate checkout…
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that…
Curiouser and Curiouser
In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a…
Dissecting the JWR phishing framework
Cisco Talos recently identified an undocumented phishing framework, internally branded “JWR” by its developer, built to convincingly impersonate checkout…
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that…
Why metaphor may dictate your security strategy
In this week’s newsletter, Martin looks at how the metaphors we use to describe AI “escaping” its sandbox can completely change how we react to the threat.
“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI
Talos has collected prompt logs from threat actor endpoints running various applications, such as Claude Code, CodeX, Cursor, or Gemini. This blog is an…
[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents
Register for an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents Talos IR faced in Q2.
Black Hat special: Rewind and revisit
Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence.
You were onto something with “It’s the Climb,” Miley
Amy hikes Virginia’s most difficult trail and muses on the persistent challenges of cybersecurity. The two aren’t dissimilar.
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
Talos IR’s Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn…
Black Hat special: Rewind and revisit
Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence.
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
Talos IR's Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses. This article has been indexed from Cisco Talos Blog Read the original article: IR…
Don’t swing at everything
Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever. This article has been indexed from Cisco Talos Blog Read the original article: Don’t swing at everything
