< ciso
brief />
Tag Banner

All news with #talos tag

68 articles

Understanding JavaScript Obfuscation in Threats

🔎 This Talos blog post explains how obfuscated JavaScript transforms readable code into string arrays, encoded values, runtime decoders, and eval calls, making static reading ineffective. The author outlines common benign and malicious motivations for obfuscation and stresses safe handling: work on copies, avoid executing hostile scripts in useful environments, and use isolated analysis. The article introduces categories of techniques—string hiding, lookup tables, dynamic property access, dead code, runtime code generation, control-flow flattening, anti-analysis measures, and extreme forms like JSFuck—and offers practical counters like beautification, renaming, replacing execution sinks with logging, and using controlled runtime harnesses or headless browsers to recover payloads. It warns about automated obfuscators (npm packages) and Node-specific risks such as access to secrets, and emphasizes a structured, repeatable workflow that leverages tooling and AI on isolated snippets.
read more →

Talos Threat Source: Phishing Frameworks and Trends

📰 Cisco Talos highlights a newly discovered real-time phishing framework named JWR, likely related to The Outsider phishing-as-a-service. JWR uses WebSockets to capture live keystrokes and steer victims through fraudulent checkout and login flows, often delivered via SMS lures impersonating toll or postal authorities. Operators can harvest payment data, 2FA codes, identity documents, and device fingerprints, enabling MFA bypass and extensive follow-on fraud. Talos recommends user education on smishing, monitoring for unusual authentications, and adopting phishing-resistant MFA like FIDO2.
read more →

Talos webinar: Q2 incident briefing for security teams

📢 Next Tuesday, August 11, Cisco Talos Incident Responders will host a 30-minute, unrecorded webinar reviewing high-impact incidents from Q2 2026. The session will candidly cover timelines, containment, and remediation efforts rather than repeating the published trends report. Designed for security professionals at all levels, it emphasizes strategic takeaways, business impact, and enough technical detail to inform discussions. Registration is required to attend this exclusive briefing.
read more →

Talos Threat Source: Q2 IR Trends and Insights

🧭 This edition of the Threat Source newsletter ties a challenging Old Rag hike to cybersecurity resilience and introduces the Talos Q2 2026 Incident Response Trends report. The report highlights spikes in authentication abuse and advanced phishing techniques, including QR-based lures and ARToken platforms, while noting ransomware groups abusing legitimate remote management tools. It recommends phishing-resistant MFA, behavior-based monitoring, centralized logging, and prioritized patching.
read more →

Humans of Talos: Black Hat special rewind

🎙️ Amy revisits past guests in a special Black Hat edition of Humans of Talos, exploring the varied career paths that led them to threat intelligence. From forensic labs and newsrooms to kitchen lines, the episode highlights personal stories and lessons that shape the field. Attendees can meet the team at Cisco and Splunk booth 2633 during Black Hat to discuss research and incident response and pick up the latest Snorty.
read more →

Phishing Now Leading Initial Access in Incidents

📈 Analysis of incidents from March to June 2026 shows phishing was the initial entry vector in just over half of cases requiring remediation, up markedly from the prior quarter. Cisco Talos researchers highlight increasingly sophisticated campaigns, including QR code-based credential harvesting and use of trusted cloud hosting to evade detection. The report also warns that advanced Phishing-as-a-Service kits and post-compromise toolsets are expanding capabilities and recommends phishing-resistant MFA, logging, patching, and stricter email controls.
read more →

Talos IR Q2 2026 Incident Response Trends

📊 Q2 2026 Talos Incident Response (IR) engagements showed phishing as the primary initial access vector, with attackers increasingly using QR code PDFs and cloud-hosted links to bypass defenses. Authentication abuse spiked to 65% of engagements, with adversaries employing AitM proxies, session-token theft, and MFA fatigue. Ransomware activity remained significant, with Sinobi, Nitrogen, and Warlock observed leveraging trojanized RMM tools like MeshAgent and Zoho Assist. Talos recommends phishing-resistant MFA, strict control of administrative binaries, robust centralized logging, and behavior-based monitoring to detect misuse of legitimate management tools.
read more →

Threat Source newsletter: Q2 2026 vulnerability trends

📈 This edition of the Threat Source newsletter reviews Q2 2026 vulnerability trends, noting a 49% YoY increase in tracked CVEs and roughly 200 CVEs per day by June. The author contrasts a shifting AI model landscape with slower real-world impact, highlights concerns about keyword-sensitive AI-CVE counts, and advocates prioritizing patches using EPSS rather than raw CVSS scores. Additional coverage includes Cisco Talos' discovery of the Rust-based msaRAT, new Antares SLMs for vulnerability localization, major incidents impacting land registries and WordPress sites, and tactical detection recommendations.
read more →

Cisco Talos preview at Black Hat USA 2026

🎤 Talos will be present at Black Hat USA 2026 across the Cisco and Splunk booths to discuss threat research, incident response, and how Talos powers the Cisco security portfolio. The team will deliver lightning talks, a Main Stage keynote on securing enterprises in the age of AI agents, and hands-on workshops demonstrating AI-driven SOC workflows and the Foundry Security Spec. Attendees can also learn how Talos is embedded across Cisco products and view the new “Where Protection Starts” video.
read more →

Cisco Talos intelligence integrations overview

🎯 Cisco Talos Intelligence Integrations apply continuous, up-to-date threat intelligence across Cisco security and enterprise products to help identify and block malicious activity. The integrations aim to reduce uncertainty for defenders facing advanced, adaptive threats such as AI-assisted attacks and polymorphic malware. A short video introduces Talos team members and demonstrates how reputation and detection feeds inform security decisions. A more detailed technical overview is available on the Cisco Security site.
read more →

Talos: Multiple Vulnerabilities in WolfSSL, GeoVision, VTK

🔒 Cisco Talos disclosed multiple vulnerabilities across WolfSSL, GeoVision, and VTK-DICOM, all of which have been patched by vendors in line with Cisco’s disclosure policy. The findings include three WolfSSL issues (two improper input validation and one integer underflow), 14 GeoVision advisories spanning 37 CVEs, and one heap-based buffer overflow in VTK-DICOM. Snort rules to detect exploit attempts are available from Snort.org. Discoveries were made by Ankur Tyagi, Philippe Laulheret, and Emmanuel Tacheau of Cisco Talos.
read more →

Winning 54% of the Time: SOC Decisions and Threats

🎾 This week’s Threat Source reflects on decision-making in cybersecurity through a tennis analogy, arguing defenders need context and resilience rather than perfection. Cisco Talos details the China-nexus actor UAT-7810 expanding ORB networks by exploiting Ruckus and ASUS router vulnerabilities and deploying new backdoors like LONGLEASH and DOGLEASH. Additional briefs cover an AI-assisted ransomware incident, AirDrop/Quick Share flaws, a Tenda firmware backdoor, Estonia’s AI agent IDs, and new phishing and coinminer detections.
read more →

ARToken PhaaS reveals EvilTokens Microsoft 365 toolkit

🛡️ Cisco Talos uncovered a React-based ARToken management panel exposing 80+ API endpoints and client-side code that reveals expanded phishing capabilities. The platform, tied to the EvilTokens ecosystem, automates Microsoft 365 account compromise by stealing authentication tokens, obtaining persistent Primary Refresh Tokens (PRTs), and accessing Outlook, SharePoint, and OneDrive. ARToken deploys Cloudflare Workers, supports multi-tenant affiliate operations, and includes tools for BEC automation and mailbox monitoring.
read more →

Board Games Sharpen Cybersecurity Intuition

🎲 The Threat Source newsletter draws a connection between learning board games and developing cybersecurity skills, arguing that games sharpen pattern recognition, intuition, and adaptive thinking. The piece highlights how diverse games—from Ticket to Ride to Go—teach strategy, breaking habits, and embracing failure as a learning tool. It also summarizes Talos research on the ARToken phishing-as-a-service panel and recent threat trends affecting Microsoft 365, AI agents, and RMM vulnerabilities.
read more →

Martin Lee on Threat Research and Career Transition

🧭 In this Humans of Talos feature, Martin Lee, EMEA Lead at Talos, discusses his journey from studying human viruses to leading cybersecurity efforts. He explains how early exposure to the internet prompted a career shift from academia to threat research and how his role now focuses on externalizing the evolving threat landscape to partners and customers. Martin also highlights using a sociological lens to assess organizational resilience and offers career advice about visibility, curiosity, and diverse experiences.
read more →

Human behavior shapes cybersecurity outcomes

🛰️ Cisco Talos' Threat Source newsletter reflects on how human behavior, context, and competing priorities often override rational security decisions. The piece links a Spielberg film theme to cybersecurity, noting that knowledge alone doesn't ensure action — organizations struggle with budgets, workloads, and urgency. Talos highlights practical controls like segmentation, backups, and MFA, and showcases a new reverse-engineering method that pairs local AI agents with tools like vbdec to accelerate analysis while protecting sensitive binaries.
read more →

AI-Driven Vulnerabilities and Security Fundamentals

🔍 Talos contrasts personal tech nostalgia with a sharp warning: AI-driven vulnerability discovery now outpaces human patching. The blog highlights how frontier models can autonomously find and exploit zero-days in minutes, collapsing the traditional vulnerability lifecycle. It urges organizations to move beyond patch-centric defenses and adopt a three-stage fallback model emphasizing prevention, detection, and resilience through controls like MFA, CIS benchmarks, segmentation, and behavioral EDR/XDR.
read more →

Cisco Live report: AI, networking, and wellbeing

🐶 At Cisco Live U.S. in Las Vegas, the author describes the conference pace, the value of quiet spaces and noise-canceling gear, and the welcome presence of therapy dogs sponsored by Splunk. Discussions at the event centered on AI from an infrastructure and security lens, including the daunting scale of data and associated defense challenges. Cisco Talos highlights expansion of its Threat Hunting program using AI-driven telemetry plus expert validation to find advanced intrusions like a recent KongTuke C2 discovery.
read more →

Balancing Cyber Product Leadership and Endurance

🔥 Tony Giandomenico of Cisco Talos discusses how endurance from Ironman training informs his approach to leading major cybersecurity product launches. He highlights rapid advances in frontier AI models, the evolving threat landscape, and the need to apply similar AI-driven speed to defensive tools. Tony explains Cisco Talos Threat Hunting, its focus on endpoint telemetry and expansion into firewalls and identity, and stresses communication, influence, and purpose as keys to sustaining focus across long careers.
read more →

Hypothesis-Driven Threat Hunting at Cisco Talos

🔍 Cisco Talos Threat Hunting adopts a hypothesis-first approach: rather than waiting for alert thresholds, analysts formulate theories about adversary behavior and search telemetry to validate them. Using AI for scale and human expertise for context, continuous hunts run across global telemetry to surface candidates that automated detection misses. Confirmed findings are reported with remediation guidance and feed back into detection tuning and product improvements.
read more →