Skip to content
.ca
sign in

Threat intelligence from Cisco Talos

44 reports on cyfar.ca summarizing Cisco Talos research. Visit Cisco Talos

Cisco Talos7 days ago12 minLLM reportcritical

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft's August 2026 Patch Tuesday addresses 421 vulnerabilities including 62 rated critical. One vulnerability, CVE-2026-68820 (Windows Ancillary Function Driver for WinSock, CVSS 7.0), has been exploited in the wild as a local elevation of privilege flaw. Critical RCE vulnerabilities span Windows server components (DNS, DHCP, TFTP, AD CS, RRAS, SSTP, iSCSI), desktop applications (Office, Excel, SharePoint, Remote Desktop Client), and cloud services (Azure SQL, Azure Service Bus, Azure AD, Microsoft Teams). Talos released Snort rules providing network-level detection for exploitation attempts against a subset of these vulnerabilities.

Cisco Talos10 days ago8 minLLM reportmedium

Introduction to COM usage by Windows threats

The article explains how Windows malware abuses the Component Object Model (COM) for execution, persistence, lateral movement, evasion, and data exfiltration. It presents reverse engineering workflows for analyzing COM-heavy binaries and provides case studies of Qakbot, Gh0stRAT, Attor, and WarmCookie demonstrating COM-based Task Scheduler persistence, BITS C2 communication, and WMI-based discovery. COM usage obscures malicious functionality behind indirect vtable calls, requiring analysts to reconstruct interface types to understand malware behavior.

Cisco Talos15 days ago15 minLLM reporthigh

“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI

Cisco Talos analyzed AI/LLM prompt logs and artifacts recovered from endpoints to document how threat actors across skill levels are weaponizing AI for malicious software development, criminal force multiplication, and vulnerability research. Guardrails across all major AI platforms are failing — actors bypass them with simple ownership claims, CTF labeling, task decomposition, and persistent memory conditioning. The report details multiple active operations including a 2000-device Android TV DDoS botnet, a 50M-record bulk-mail validation platform (Tubely), a React2Shell credential harvesting pipeline targeting 9,180+ hosts, a Deluge/qBittorrent cryptojacking fleet, Telegram Mini App wallet-draining operations, and the autonomous Hephaestus red team framework. Actor skill level is the primary determinant of operational impact, with advanced actors achieving sophisticated capabilities while novice actors produce functional but limited tooling.

Cisco Talos22 days ago10 minLLM reporthigh

IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains

Talos IR's Q2 2026 report highlights a sharp rise in phishing-driven initial access (over 50% of engagements) and authentication abuse (65% of engagements), with attackers increasingly using QR-code PDFs, OAuth device-code phishing, and AitM proxies to bypass MFA. Ransomware actors including Sinobi and Warlock (Storm-2603) weaponized legitimate RMM tools—a trojanized MeshAgent binary and Zoho Assist—for stealthy, durable C2 and remote access, blending malicious activity into normal administrative traffic. The report also details a new PhaaS platform, ARToken, and a QR-phishing campaign attributed to UAT-11764 that abuses M365 and SharePoint infrastructure for credential harvesting and self-propagation.

Cisco Talos26 days ago9 minLLM reporthigh

Don’t swing at everything

This Talos newsletter highlights the discovery of msaRAT, a Rust/Tokio-based remote access trojan used by the Chaos ransomware group that establishes covert command-and-control by hijacking Chrome/Edge browsers via the Chrome DevTools Protocol, delivered through an MSI disguised as a Windows update and loaded directly into memory. The issue also reviews Q2 2026 vulnerability landscape statistics, showing 49% YoY growth in total CVEs versus only 13% growth in CISA KEVs, and advocates using EPSS scoring alongside CVSS to prioritize patching against a backlog where nearly half of actively exploited CVEs date to 2025 or earlier.

Cisco Talos27 days ago11 minLLM reporthigh

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

Cisco Talos has identified msaRAT, a new Rust-based remote access trojan attributed to the Chaos ransomware group, which establishes a covert C2 channel by hijacking the victim's browser via Chrome DevTools Protocol (CDP). The RAT launches Chrome or Edge in headless mode, injects JavaScript to create a WebRTC DataChannel using Cloudflare Workers for signaling and Twilio TURN as a relay, ensuring all network traffic originates from the browser process and blends with legitimate web traffic. The malware employs double-layer encryption (DTLS plus ChaCha-Poly1305 with ECDH key exchange) and routes all C2 through legitimate cloud infrastructure, making detection and tracing exceptionally difficult.

Cisco Talosabout 1 month ago13 minLLM reportcritical

Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities

Microsoft's July 2026 Patch Tuesday discloses 622 vulnerabilities, including 57 critical-severity issues spanning RCE, elevation of privilege, spoofing, and security feature bypass across Windows components, Office, SharePoint, SQL Server, Dynamics, and cloud services. Two vulnerabilities — an AD FS elevation of privilege flaw (CVE-2026-56155) and a SharePoint spoofing flaw (CVE-2026-56164) — are confirmed exploited in the wild, and 11 critical RCE issues plus several important EoP flaws are rated 'more likely' to be exploited by Microsoft. Cisco Talos has released Snort 2 and Snort 3 rule updates to detect exploitation attempts for a subset of the disclosed vulnerabilities.

Cisco Talosabout 1 month ago12 minLLM reporthigh

The serpent’s tongue: Luring the Python out of its den

This article provides a comprehensive analysis of how malicious Python packages can execute arbitrary code during installation and runtime, categorizing techniques into build hook abuses (setup.py command classes, .pth files, site hooks, PYTHONPATH manipulation) and package content abuses (init.py, main.py, entry point hijacking, package overriding). Each technique is assessed for persistence, OS support, and distribution compatibility. The article highlights that developers are high-value targets due to administrative access to sensitive assets, and that payload execution can occur within minutes of package installation with exfiltration within an hour.

Cisco Talosabout 1 month ago9 minLLM reporthigh

WolfSSL, GeoVision, VTK vulnerabilities

Cisco Talos disclosed vulnerabilities across three products: WolfSSL (3 CVEs involving improper input validation and integer underflow), GeoVision (37 CVEs across 14 advisories covering memory corruption, command injection, buffer overflows, privilege escalation, XSS, weak encryption, and authentication flaws), and VTK-DICOM (1 heap-based buffer overflow). All vulnerabilities have been patched by their respective vendors. Snort coverage is available for exploitation detection.

Cisco Talosabout 1 month ago14 minLLM reporthigh

UAT-7810 continues building ORB networks using new malware

UAT-7810, a China-nexus APT actor, continues to build Operational Relay Box (ORB) networks by exploiting n-day vulnerabilities in Ruckus and ASUS AiCloud routers. Talos identified four new malware families — LONGLEASH (an upgraded multi-protocol proxy backdoor), DOGLEASH (a passive C-based Linux backdoor), JARLEASH (a Java-based administrative backdoor), and LEASHTEST (a MIPS test binary) — deployed across MIPS, ARM, and x64 platforms. The actor uses at least four new servers to host payloads and deploy DOGLEASH via shell scripts that modify iptables rules on compromised devices.

Cisco Talosabout 2 months ago12 minLLM reporthigh

ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365

Cisco Talos identified ARToken, a phishing-as-a-service platform linked to EvilTokens, that abuses Microsoft's OAuth 2.0 Device Authorization Grant to bypass MFA and capture victim tokens. The platform provides affiliates with a comprehensive post-compromise toolkit including PRT-based persistence surviving password resets, BEC email operations, inbox rule manipulation, and SharePoint exfiltration. ARToken deploys a sophisticated seven-layer client-side anti-analysis system and abuses legitimate sharepoint.com URLs from attacker-controlled Microsoft 365 workspaces to evade security scanners.

Cisco Talos2 months ago3 minLLM reportinfo

Scripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object model

The article details a novel approach to reverse engineering where the VB6 disassembler vbdec exposes its internal object model via the Windows Component Object Model (COM). This allows local AI agents to programmatically query and automate complex analysis tasks, such as decompilation and call graph generation, without requiring built-in AI features or cloud uploads.

Cisco Talos2 months ago5 minLLM reportcritical

Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities

Microsoft's June 2026 Patch Tuesday addresses 206 vulnerabilities, including 32 critical flaws primarily involving Remote Code Execution (RCE). Four critical vulnerabilities affecting the Remote Desktop Client, HTTP Protocol Stack, and Windows Graphics component are highlighted as more likely to be exploited, prompting immediate patching and the deployment of updated network intrusion rules.

Cisco Talos3 months ago4 minLLM reportinfo

Less panic patching, more precision

This week's Threat Source newsletter highlights the importance of combining EPSS and CVSS for risk-based vulnerability prioritization. It also introduces EvidenceForge, a new open-source tool by Cisco Talos for generating synthetic security logs, and summarizes recent security news including the 'Megalodon' GitHub supply chain attack and 'Underminr' domain-fronting techniques.

Cisco Talos3 months ago4 minLLM reporthigh

DICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heap

Security research highlights a heap overflow vulnerability within DICOM parsing, specifically targeting Orthanc servers during image uploads. By exploiting the complex DICOM file format, attackers can trigger an out-of-bounds write, posing a significant risk to hospital PACS systems that automatically ingest and decode these files.

Cisco Talos3 months ago3 minLLM reportlow

Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake

Cisco Talos has introduced EvidenceForge, an open-source tool designed to generate high-fidelity, correlated synthetic security logs across multiple formats. The tool addresses the data bottleneck in detection engineering and SOC training by providing realistic datasets with causal ordering, background noise, and AI-assisted scenario authoring.

Cisco Talos3 months ago4 minLLM reporthigh

TP-Link, Photoshop, OpenVPN, Norton VPN vulnerabilities

Cisco Talos disclosed a series of vulnerabilities affecting TP-Link routers, Adobe Photoshop, OpenVPN, and Norton VPN. Notably, a privilege escalation flaw in Norton VPN (CVE-2025-58074) was exploited in the wild before a patch was available, while the TP-Link flaws allow for remote code execution via command injection and buffer overflows.

Cisco Talos3 months ago7 minLLM reporthigh

From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat

Cisco Talos has identified a commodity BadIIS malware ecosystem operating under a Malware-as-a-Service (MaaS) model, primarily used by Chinese-speaking threat actors for SEO fraud and traffic manipulation. The developer, known as 'lwxat', provides a dedicated builder and sophisticated service-based installers that ensure persistence on compromised Windows IIS servers while evading detection through custom Base64 encoding and service impersonation.

Cisco Talos3 months ago5 minLLM reportmedium

The time of much patching is coming

The Talos Threat Source newsletter highlights an impending surge in software patching driven by AI vulnerability discovery tools. It also contrasts state-sponsored espionage tactics—which leverage valid credentials and native tools to bypass traditional defenses—with commodity ransomware, while summarizing recent supply chain compromises across developer platforms like Hugging Face and Jenkins.