#0001
Cisco Talos7 days ago12 min▣LLM reportcritical Microsoft's August 2026 Patch Tuesday addresses 421 vulnerabilities including 62 rated critical. One vulnerability, CVE-2026-68820 (Windows Ancillary Function Driver for WinSock, CVSS 7.0), has been exploited in the wild as a local elevation of privilege flaw. Critical RCE vulnerabilities span Windows server components (DNS, DHCP, TFTP, AD CS, RRAS, SSTP, iSCSI), desktop applications (Office, Excel, SharePoint, Remote Desktop Client), and cloud services (Azure SQL, Azure Service Bus, Azure AD, Microsoft Teams). Talos released Snort rules providing network-level detection for exploitation attempts against a subset of these vulnerabilities.
#0002
Cisco Talos10 days ago8 min▣LLM reportmedium The article explains how Windows malware abuses the Component Object Model (COM) for execution, persistence, lateral movement, evasion, and data exfiltration. It presents reverse engineering workflows for analyzing COM-heavy binaries and provides case studies of Qakbot, Gh0stRAT, Attor, and WarmCookie demonstrating COM-based Task Scheduler persistence, BITS C2 communication, and WMI-based discovery. COM usage obscures malicious functionality behind indirect vtable calls, requiring analysts to reconstruct interface types to understand malware behavior.
#0003
Cisco Talos15 days ago15 min▣LLM reporthigh Cisco Talos analyzed AI/LLM prompt logs and artifacts recovered from endpoints to document how threat actors across skill levels are weaponizing AI for malicious software development, criminal force multiplication, and vulnerability research. Guardrails across all major AI platforms are failing — actors bypass them with simple ownership claims, CTF labeling, task decomposition, and persistent memory conditioning. The report details multiple active operations including a 2000-device Android TV DDoS botnet, a 50M-record bulk-mail validation platform (Tubely), a React2Shell credential harvesting pipeline targeting 9,180+ hosts, a Deluge/qBittorrent cryptojacking fleet, Telegram Mini App wallet-draining operations, and the autonomous Hephaestus red team framework. Actor skill level is the primary determinant of operational impact, with advanced actors achieving sophisticated capabilities while novice actors produce functional but limited tooling.
#0004
Cisco Talos22 days ago10 min▣LLM reporthigh Talos IR's Q2 2026 report highlights a sharp rise in phishing-driven initial access (over 50% of engagements) and authentication abuse (65% of engagements), with attackers increasingly using QR-code PDFs, OAuth device-code phishing, and AitM proxies to bypass MFA. Ransomware actors including Sinobi and Warlock (Storm-2603) weaponized legitimate RMM tools—a trojanized MeshAgent binary and Zoho Assist—for stealthy, durable C2 and remote access, blending malicious activity into normal administrative traffic. The report also details a new PhaaS platform, ARToken, and a QR-phishing campaign attributed to UAT-11764 that abuses M365 and SharePoint infrastructure for credential harvesting and self-propagation.
#0005
Cisco Talos26 days ago9 min▣LLM reporthigh This Talos newsletter highlights the discovery of msaRAT, a Rust/Tokio-based remote access trojan used by the Chaos ransomware group that establishes covert command-and-control by hijacking Chrome/Edge browsers via the Chrome DevTools Protocol, delivered through an MSI disguised as a Windows update and loaded directly into memory. The issue also reviews Q2 2026 vulnerability landscape statistics, showing 49% YoY growth in total CVEs versus only 13% growth in CISA KEVs, and advocates using EPSS scoring alongside CVSS to prioritize patching against a backlog where nearly half of actively exploited CVEs date to 2025 or earlier.
#0006
Cisco Talos27 days ago11 min▣LLM reporthigh Cisco Talos has identified msaRAT, a new Rust-based remote access trojan attributed to the Chaos ransomware group, which establishes a covert C2 channel by hijacking the victim's browser via Chrome DevTools Protocol (CDP). The RAT launches Chrome or Edge in headless mode, injects JavaScript to create a WebRTC DataChannel using Cloudflare Workers for signaling and Twilio TURN as a relay, ensuring all network traffic originates from the browser process and blends with legitimate web traffic. The malware employs double-layer encryption (DTLS plus ChaCha-Poly1305 with ECDH key exchange) and routes all C2 through legitimate cloud infrastructure, making detection and tracing exceptionally difficult.
#0007
Cisco Talosabout 1 month ago13 min▣LLM reportcritical Microsoft's July 2026 Patch Tuesday discloses 622 vulnerabilities, including 57 critical-severity issues spanning RCE, elevation of privilege, spoofing, and security feature bypass across Windows components, Office, SharePoint, SQL Server, Dynamics, and cloud services. Two vulnerabilities — an AD FS elevation of privilege flaw (CVE-2026-56155) and a SharePoint spoofing flaw (CVE-2026-56164) — are confirmed exploited in the wild, and 11 critical RCE issues plus several important EoP flaws are rated 'more likely' to be exploited by Microsoft. Cisco Talos has released Snort 2 and Snort 3 rule updates to detect exploitation attempts for a subset of the disclosed vulnerabilities.
#0008
Cisco Talosabout 1 month ago12 min▣LLM reporthigh This article provides a comprehensive analysis of how malicious Python packages can execute arbitrary code during installation and runtime, categorizing techniques into build hook abuses (setup.py command classes, .pth files, site hooks, PYTHONPATH manipulation) and package content abuses (init.py, main.py, entry point hijacking, package overriding). Each technique is assessed for persistence, OS support, and distribution compatibility. The article highlights that developers are high-value targets due to administrative access to sensitive assets, and that payload execution can occur within minutes of package installation with exfiltration within an hour.
#0009
Cisco Talosabout 1 month ago9 min▣LLM reporthigh Cisco Talos disclosed vulnerabilities across three products: WolfSSL (3 CVEs involving improper input validation and integer underflow), GeoVision (37 CVEs across 14 advisories covering memory corruption, command injection, buffer overflows, privilege escalation, XSS, weak encryption, and authentication flaws), and VTK-DICOM (1 heap-based buffer overflow). All vulnerabilities have been patched by their respective vendors. Snort coverage is available for exploitation detection.
#0010
Cisco Talosabout 1 month ago14 min▣LLM reporthigh UAT-7810, a China-nexus APT actor, continues to build Operational Relay Box (ORB) networks by exploiting n-day vulnerabilities in Ruckus and ASUS AiCloud routers. Talos identified four new malware families — LONGLEASH (an upgraded multi-protocol proxy backdoor), DOGLEASH (a passive C-based Linux backdoor), JARLEASH (a Java-based administrative backdoor), and LEASHTEST (a MIPS test binary) — deployed across MIPS, ARM, and x64 platforms. The actor uses at least four new servers to host payloads and deploy DOGLEASH via shell scripts that modify iptables rules on compromised devices.
#0011
Cisco Talosabout 2 months ago12 min▣LLM reporthigh Cisco Talos identified ARToken, a phishing-as-a-service platform linked to EvilTokens, that abuses Microsoft's OAuth 2.0 Device Authorization Grant to bypass MFA and capture victim tokens. The platform provides affiliates with a comprehensive post-compromise toolkit including PRT-based persistence surviving password resets, BEC email operations, inbox rule manipulation, and SharePoint exfiltration. ARToken deploys a sophisticated seven-layer client-side anti-analysis system and abuses legitimate sharepoint.com URLs from attacker-controlled Microsoft 365 workspaces to evade security scanners.
#0012
Cisco Talos2 months ago3 min▣LLM reportinfo The article details a novel approach to reverse engineering where the VB6 disassembler vbdec exposes its internal object model via the Windows Component Object Model (COM). This allows local AI agents to programmatically query and automate complex analysis tasks, such as decompilation and call graph generation, without requiring built-in AI features or cloud uploads.
#0013
Cisco Talos2 months ago5 min▣LLM reportcritical Microsoft's June 2026 Patch Tuesday addresses 206 vulnerabilities, including 32 critical flaws primarily involving Remote Code Execution (RCE). Four critical vulnerabilities affecting the Remote Desktop Client, HTTP Protocol Stack, and Windows Graphics component are highlighted as more likely to be exploited, prompting immediate patching and the deployment of updated network intrusion rules.
#0014
Cisco Talos3 months ago4 min▣LLM reportinfo This week's Threat Source newsletter highlights the importance of combining EPSS and CVSS for risk-based vulnerability prioritization. It also introduces EvidenceForge, a new open-source tool by Cisco Talos for generating synthetic security logs, and summarizes recent security news including the 'Megalodon' GitHub supply chain attack and 'Underminr' domain-fronting techniques.
#0015
Cisco Talos3 months ago4 min▣LLM reporthigh Security research highlights a heap overflow vulnerability within DICOM parsing, specifically targeting Orthanc servers during image uploads. By exploiting the complex DICOM file format, attackers can trigger an out-of-bounds write, posing a significant risk to hospital PACS systems that automatically ingest and decode these files.
#0016
Cisco Talos3 months ago4 min▣LLM reporthigh Cisco Talos disclosed four heap-based buffer overflow vulnerabilities in MediaArea MediaInfoLib version 26.01. These flaws (CVE-2026-25104, CVE-2026-25713, CVE-2026-28764, CVE-2026-22554) can be triggered by processing a malicious media file, potentially leading to arbitrary code execution on the host system.
#0017
Cisco Talos3 months ago3 min▣LLM reportlow Cisco Talos has introduced EvidenceForge, an open-source tool designed to generate high-fidelity, correlated synthetic security logs across multiple formats. The tool addresses the data bottleneck in detection engineering and SOC training by providing realistic datasets with causal ordering, background noise, and AI-assisted scenario authoring.
#0018
Cisco Talos3 months ago4 min▣LLM reporthigh Cisco Talos disclosed a series of vulnerabilities affecting TP-Link routers, Adobe Photoshop, OpenVPN, and Norton VPN. Notably, a privilege escalation flaw in Norton VPN (CVE-2025-58074) was exploited in the wild before a patch was available, while the TP-Link flaws allow for remote code execution via command injection and buffer overflows.
#0019
Cisco Talos3 months ago7 min▣LLM reporthigh Cisco Talos has identified a commodity BadIIS malware ecosystem operating under a Malware-as-a-Service (MaaS) model, primarily used by Chinese-speaking threat actors for SEO fraud and traffic manipulation. The developer, known as 'lwxat', provides a dedicated builder and sophisticated service-based installers that ensure persistence on compromised Windows IIS servers while evading detection through custom Base64 encoding and service impersonation.
#0020
Cisco Talos3 months ago5 min▣LLM reportmedium The Talos Threat Source newsletter highlights an impending surge in software patching driven by AI vulnerability discovery tools. It also contrasts state-sponsored espionage tactics—which leverage valid credentials and native tools to bypass traditional defenses—with commodity ransomware, while summarizing recent supply chain compromises across developer platforms like Hugging Face and Jenkins.