Tag: Cisco Talos Blog

Preview: Cisco Talos at Black Hat USA 2026

Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk. This article has been indexed from Cisco Talos Blog Read the original article: Preview: Cisco Talos at Black Hat USA 2026

Begun, the Patch Wars have

Long foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story. This article has been indexed from Cisco Talos Blog Read the original article: Begun, the Patch Wars have

The serpent’s tongue: Luring the Python out of its den

This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Python environments. This article has…

WolfSSL, GeoVision, VTK vulnerabilities

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in GeoVision, and one vulnerability in VTK-DICOM. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party…

Winning 54% of the time

With Wimbledon’s help, Hazel argues against the popular myth that “Attackers only need to be right once, but defenders need to be right 100% of the time.” This article has been indexed from Cisco Talos Blog Read the original article:…

Catan and Mouse

What do board games and cybersecurity have in common? Pattern recognition. Strategy. Adaptation. In this week’s Threat Source Bill explores why curiosity may be a defender’s most valuable skill. This article has been indexed from Cisco Talos Blog Read the…

ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365

Cisco Talos identified a fully-featured phishing-as-a-service (PhaaS) operator panel, branded "ARToken," that shares infrastructure, API contracts, and operational patterns with the EvilTokens platform documented by Sekoia and Microsoft in early 2026. The ARToken panel exposes 80+ API endpoints for device…

Beyond IOCs: AI-enabled threat intelligence

In this week’s newsletter, Martin considers how AI will help threat intelligence by creating an easily queryable data source of intelligence reports. This article has been indexed from Cisco Talos Blog Read the original article: Beyond IOCs: AI-enabled threat intelligence

Introduction to COM usage by Windows threats

Component Object Model (COM) is a fundamental Windows technology used by legitimate applications for object activation, inter-process communication, automation and language-independent component reuse. Those same qualities make it useful to threat actors. This article has been indexed from Cisco Talos…

Close Encounters of the Human Kind

In the latest Threat Source, Hazel channels her inner Spielberg to explore why humans are delightfully irrational, reminding us that while security best practices are simple in theory, they’re a lot harder to pull off when you’re busy dealing with…

A tale of two eras

In this week’s newsletter, Amy reminisces on the tech toys of their childhood, inspired by a hilarious lesson about why your digital privacy shouldn’t be left on an open channel. This article has been indexed from Cisco Talos Blog Read…