Visualização de leitura

The story behind the intelligence

The story behind the intelligence

Welcome to this week’s edition of the Threat Source newsletter. 

Our goal is to get accurate threat intelligence to our audience as quickly as possible, with all the context you need to ask the right questions of your own environment: How at risk are we from this threat? Are we prepared for it? And what can we do about it? 

What you don’t often see is all the... well, frankly, “mess” involved in producing it. All the dead ends we followed until we could confirm those ends were as dead as a doornail. All the work it took to ultimately produce an assessment, supported by evidence and written so that defenders can act on it. 

Much of that abstraction is necessary. Defenders need intelligence they can use, not a complete account of every conversation we had, or investigative detour behind it. But it can create an overly tidy picture of both cybercrime and the work required to understand it. 

If you do fancy a look behind the curtain, though, may I recommend our just-published episode of Beers with Talos

Our guest is Azim Khodjibaev, whose remit is adversary engagement. His work involves developing personas for deep- and dark-web research, engaging directly with threat actors, and building relationships with people who may become (and have been) openly threatening to him. 

At one point, he was maintaining eight separate personas, some of which were interacting with one another. Azim’s engagements have helped Talos identify prolific cybercriminals and contributed to wider disruption efforts. They have also resulted in ransomware operators placing “Azim sucks” in their code and accusing him of belonging to the very criminal groups he was investigating. 

His experiences also expose the problem with treating adversaries as uniformly sophisticated operators. Some are technically capable and highly organised. Others are impulsive, ego-driven, or one-trick ponies. Many have a scary detachment from the consequences of their actions. Increasingly, Azim is seeing less-experienced threat actors working through loosely organised online collectives.  

Intelligence necessarily turns that disorder into something defenders can understand and use. But occasionally, it is worth looking behind the finished product – the patience it takes to get accurate answers, who we are investigating, and the deeply human behaviour that shapes both sides. 

This Beers with Talos episode, “Eight People Walk Into a Dark Web Forum. They’re All Azim,” isn’t exactly going to help many people in our industry sleep better at night. But for anyone wanting to understand more about the threat we’re up against, as a co-host of the pod I’m biased, but I believe it’s an essential listen. 

And if that doesn’t inspire you to download the episode, perhaps my live review of trying Flamin’ Hot Cheetos for the very first time (with a chaser of Nerds) will. 

The one big thing  

Cisco Talos is highlighting a growing operational hurdle for security teams that we call the AI "safety penalty." As frontier AI models advance, their built-in guardrails are increasingly blocking legitimate defensive tasks. This was evident in July 2026 when Hugging Face's primary cloud LLM refused to analyze forensic data during a breach, delaying their response. While defenders are slowed by these frustrating refusals, adversaries are freely leveraging unconstrained models to attack at machine speed.  

Why do I care? 

This guardrail asymmetry hands the advantage directly to attackers. When a cloud-hosted AI model refuses a forensic request mid-incident, defenders lose precious time. Security teams are paying for vendor-imposed limitations without gaining a capability edge, especially as open-weight alternatives close the reasoning gap. Ultimately, relying on third-party alignment policies means a sudden update in Silicon Valley could quietly break your defensive workflows overnight.  

So now what? 

Security leadership must reclaim operational sovereignty by ensuring they have the final say over their AI's capabilities. Start by auditing your AI refusal rates to measure the exact cost of this safety penalty. From there, evaluate alternative architectures like private infrastructure, Model-as-a-Service platforms, or a hybrid fallback system that reroutes refused prompts to an unconstrained local model. Read the full blog to explore these roadmaps and learn how to keep pace with adversaries. 

Top security headlines of the week 

ShinyHunters claims it stole 284 million patient records from McKesson 
ShinyHunters told BleepingComputer and said it got in through vishing calls to McKesson employees, then used stolen credentials to take over Okta single sign-on accounts. (Help Net Security

Anthropic warns Claude users of infostealer malware infections 
Anthropic emphasized that the malware is general-purpose and not tied to Claude itself, typically arriving via unofficial downloads or malicious apps. The company said the malware quietly copies saved passwords, browser login cookies, and credentials for other local applications. (Security Week

EU puts ChatGPT, Reddit, and Roblox under stricter DSA rules 
The DSA establishes rules governing areas including platform transparency, illegal content, advertising, researcher access, recommender systems, and systemic-risk management. (CyberInsider

PaperCut issues emergency patches as threat actors target chained vulnerabilities 
PaperCut issued the patches on Friday to address critical vulnerabilities in its print-management software. The company confirmed in a security advisory that multiple customers were successfully targeted and that it is working with security researchers to respond to the attacks. (Cybersecurity Dive

Can’t get enough Talos? 

JavaScript obfuscation: From party trick to phishing kit
We've spent a lot of time pulling apart suspicious JavaScript from phishing kits, malware packages, compromised sites, and more. Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem. 

Choose your fighter: Balancing competing AI SOC model requirements 
Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. Here's how to choose. 

Beers with Talos: Eight people walk into a dark web forum. They're all Azim.
What does it take to become someone a cybercriminal will trust? Talos' Azim Khodjibaev takes us inside the psychology of direct adversary engagement. At one point, he was maintaining eight different personas, some of which were talking to each other. He explains how discipline and patience help keep his cover intact, and what can provoke threat actors into revealing information.

Upcoming events where you can find Talos 

Most prevalent malware files from Talos telemetry over the past week 

SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
MD5: 2915b3f8b703eb744fc54c81f4a9c67f  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 
Example Filename: VID001.exe  
Detection Name: W32.9F1F11A708-100.SBX.TG** 

SHA256: 228c316455d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82  
MD5: 61e046145ee5cf45aeb033cd71e8b07c  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=228c316455d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82 
Example Filename: NetGuard.exe  
Detection Name: W32.228C316455-95.SBX.TG 

SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91  
MD5: 7bdbd180c081fa63ca94f9c22c457376  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 
Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe  
Detection Name: Win.Dropper.Miner::95.sbx.tg** 

SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2  
MD5: 9a47c4d379998ade2f8f99e23a630c06  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 
Example Filename: sample.exe  
Detection Name: W32.C4DD71E347-95.SBX.TG 

SHA256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55  
MD5: 41444d7018601b599beac0c60ed1bf83  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55 
Example Filename: content.js  
Detection Name: W32.38D053135D-95.SBX.TG 

SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f  
MD5: 38de5b216c33833af710e88f7f64fc98  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
Example Filename: SECOH-QAD.exe  
Detection Name: Win.Tool.Procpatcher::1201

“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend

“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend

Welcome to this week’s edition of the Threat Source newsletter. 

Hello, everyone. Long time reader, first time writer here at the Threat Source newsletter! I wanted to start out by introducing myself. My colleague and friend Mick Baccio set the bar pretty high last week, so I was planning to tell you all about myself, including: 

  • How I did my first real IR under the influence of The Cuckoo’s Egg while an undergraduate (and failed) 
  • My pre-bug bounty flirtation with vulnerability research, including an arbitrary file overwrite in biff(1) and how I once hacked MIT’s website 
  • My first ever hands-on experience with a computer, the display demo Commodore 64 at the Montgomery Ward 

Unfortunately, my editor says we don’t have the “space” for that, the MIT thing might open me up to “liability,” and it’s not the kind of “professional image” we strive for here at Talos. (I'm watching. Always watching. -Amy) 

So instead, I’ll just play it safe and say that I’ve been in the security field for a little over 30 years now, mostly concentrating on the defensive side (Go, Team Blue!). I’ve helped set up SOCs, run threat hunting teams, and even published a few things you might have heard of.  

Speaking of things I’ve published, I’ve written before about the Attacker’s Dilemma. The idea that defenders have inherent advantages over attackers runs contrary to what most of us have heard throughout our careers. An attacker must evade monitoring and technical controls at every step of their attack lifecycle, because the defender only needs to notice once in order to respond and prevent them from achieving their goal. This is one of the most important advantages of any security team has, but we are currently witnessing a self-imposed erosion of this advantage through the rise of poorly-designed AI guardrails.  

I’m not opposed to guardrails, but we have to carefully consider what we’re guarding against and where we deploy them. As I explored in a recent piece on The Safety Penalty, by allowing third-party AI providers to implement and control safety filters and the policies behind them, we may in fact be helping the attacker. If agentic SOC process experience refusals, it can slow or even halt investigations. Of course, these should get flagged for human intervention, but that takes time and may give the attacker breathing room in which to complete their mission.  

It may turn out that the where of the guardrails is even more important than the what. Operational sovereignty relies on having control of our own limits. Any vision of an agentic SOC must allow the security teams to customize the guardrails according to their own threat model. They should also have the flexibility to temporarily remove specific safeguards under authorized circumstances, something you won’t get with guardrails from a frontier provider. These controls belong inside your organization’s agentic harness where you can set the policies and technical controls to allow you to analyze threats while ensuring your agents stay within their lanes.  

Ultimately, operational sovereignty means engaging with the reality of the threat landscape, ensuring that the adversary can’t derail the defender’s investigation and response processes, either accidentally or intentionally. We need to move toward a model where each organization can choose the guardrails that work for them, rather than having inflexible guardrails chosen for them. 

The one big thing  

Cisco Talos recently evaluated 66 large language model (LLM) and reasoning combinations to see if we could find a clear winner for security operations. Instead, we found that selecting the right model is a complex balancing act between efficacy, speed, cost, and consistency. Cranking up a model's reasoning effort doesn't guarantee better analysis and can actually degrade performance. Ultimately, we developed a repeatable methodology to help organizations navigate these tradeoffs for their own workflows. 

Why do I care? 

Choosing an AI model based solely on generic leaderboard scores is a recipe for operational disaster. An exceptionally smart model might cost a fortune, take half an hour to analyze a single log, or completely fail to format its output. Assuming more compute power equals better results is a costly trap, as higher reasoning settings sometimes produce weaker or blocked responses. Defenders must remember that prompts, analyst personas, and model consistency drastically alter an investigation's outcome.  

So now what? 

Test models against your organization’s specific workflows before deploying them. Build a focused set of representative cases and test them multiple times using the exact prompts and tools your analysts will actually use. Track the quality, cost, time, consistency, and usable-answer rates in a simple spreadsheet to expose the real-world tradeoffs. Finally, establish acceptable thresholds for these variables to eliminate underperforming models, and regularly revisit your decisions as AI technology and pricing inevitably shift. 

Top security headlines of the week 

ToxicPanda banking trojan matures into enterprise threat 
ToxicPanda 2.0 expands substantially on its predecessor, adding 167 remote commands and broadening its targeting from 16 financial institutions to 349 banking, e-wallet, and cryptocurrency applications. (Dark Reading

Interpol's Jackal IV disrupts West African crime infrastructure 
Law enforcement from 22 countries across six continents worked together to arrest 58 suspects and identify 263 more. The first two Jackal operations in 2022 and 2023 led to approximately 200 arrests in total and millions of dollars more in seized assets. (Dark Reading

First malware built specifically for car head units fuels botnet 
Researchers have found what appears to be the first malware specifically designed for car head units, with links to the notorious BadBox botnet, on an Android-powered aftermarket infotainment system made by Chinese company DoFun, which is widely used in China and other APAC countries. (SecurityWeek

A Tale of Two SOCs: Insights From Two Red Team Assessments 
A CISA red team fully compromised two critical infrastructure organizations at the domain level and reached sensitive business systems and cloud resources. Organization A failed to detect or contain the activity. Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model. (CISA)

NovaCookies campaigns abuse genuine Docusign notifications to steal M365 sessions 
The $320/month service is a subscription-based phishing platform that facilitates real-time M365 session theft. The kit has been used to target hundreds of organizations across multiple sectors in the U.S., the U.K., Canada, Germany, and more. (The Hacker News

Can’t get enough Talos?

JavaScript obfuscation: From party trick to phishing kit 
We've spent a lot of time pulling apart suspicious JavaScript from phishing kits, malware packages, compromised sites, and more. Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem. 

The safety penalty: Reclaiming operational sovereignty in the age of AI 
As frontier AI models become increasingly restrictive, security teams are facing a "safety penalty" that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defensive AI keeps pace with unconstrained adversaries. 

Back-to-school cybersecurity: Protecting education networks from ransomware and threats 
As the new academic year begins, school districts face a surge in cybersecurity threats, from phishing attacks and ransomware to student experimentation with network devices. In this episode, Amy sits down with Cisco Talos expert Pierre Cadieux to discuss practical strategies for IT practitioners. 

Upcoming events where you can find Talos 

Most prevalent malware files from Talos telemetry over the past week 

SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 
MD5: 2915b3f8b703eb744fc54c81f4a9c67f  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 
Example Filename: VID001.exe  
Detection Name: W32.9F1F11A708-100.SBX.TG** 

SHA256: e7e784cae8d37f12a5af0bc9b3975c8d3e668142e9c6b0b365ed4f4e80933c47 
MD5: a4480423617d0b0d3b38c8471cbf594c  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=e7e784cae8d37f12a5af0bc9b3975c8d3e668142e9c6b0b365ed4f4e80933c47 
Example Filename: client32.exe  
Detection Name: W32.Trojan.29ev.1201 

SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 
MD5: 9a47c4d379998ade2f8f99e23a630c06  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 
Example Filename: WCInstaller_NonAdmin.exe  
Detection Name: W32.C4DD71E347-95.SBX.TG 

SHA256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55 
MD5: 41444d7018601b599beac0c60ed1bf83  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55 
Example Filename: content.js  
Detection Name: W32.38D053135D-95.SBX.TG 

SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f  
MD5: 38de5b216c33833af710e88f7f64fc98  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
Example Filename: SECOH-QAD.exe  
Detection Name: Win.Tool.Procpatcher::1201 

SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 
MD5: 7bdbd180c081fa63ca94f9c22c457376  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 
Example Filename:  
d4aa3e7010220ad1b458fac17039c274_62_Exe.exe  
Detection Name: Win.Dropper.Miner::95.sbx.tg**

Is Cyber missing the Marque?

Is Cyber missing the Marque?

Welcome to this week’s edition of the Threat Source newsletter.  

Hello friend.  

I’m Mick.  

This is my first Threat Source newsletter, so I should probably introduce myself before I start telling you all the things I think you should be paying attention to. With assistance from an unnamed LLM, my bio reads like this:  

Mick Baccio is a globally recognized security strategist with a career spanning offensive operations, threat intelligence, and national-level incident response. He currently advises organizations around the world through his role at Talos, helping security leaders improve operations through data-informed approaches. Mick was the first-ever Chief Information Security Officer for a U.S. presidential campaign (2020) and previously served in multiple White House administrations as Threat Intelligence Branch Chief.   
In his spare time, Mick is the Founder and President of THRUNT® Corp, IANS Faculty, and a KC7 Cyber Foundation board member.  
DEFCon Goon and Purveyor of Fine Experience.  
Veteran. 

I also have a cat named qwerty and own too many Air Jordans.   

I’ve spent most of my career somewhere in the intersection of threat intelligence, cybersecurity, government, and the people trying to make sense of all of it. These days, i spend a lot of time thinking about the decisions we make about security ripple outward, often in ways we didn't consider. Most of my ramblings will probably center around that. There will be threats. There will be intelligence. Occasionally something weird, but always something that caught my eye, and maybe worth checking out.   

Which brings us this week. I picked a hell of a week to start.   

Last Wednesday, the White House issued a presidential memorandum titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.” You should probably read it. The memorandum directs the DOJ and DHS to establish a program that can use private companies to conduct cyber operations against transnational criminal organizations outside the United States — beyond providing intelligence and assisting in the investigation. The memorandum explicitly envisions private companies conducting cyber surveillance and cyber effects operations under the direction and delegated authority of the U.S. government. 

This is a pretty big thing.  

For years, this industry has debated where line should exist between defending a network and reaching through the wire. We’ve debated hack back, active defense, attribution, proportional response, collateral damage, and what roles private companies have in offensive cyber operations. This is absolutely not “hack back" and calling it that misses important oversight built into the memorandum. 

At the same time, let’s be clear about what we are reading. The United States is creating a mechanism for private companies to participate directly in government-authorized offensive cyber operations against systems outside the United States. There will be plenty of debate whether this is good or bad policy; I will leave that for someone else. I’m much more interested in the operational questions it creates. 

Who establishes attribution strongly enough to authorize an operation? What happens when criminal and state infrastructure overlap? What happens when infrastructure is compromised and used as an ORB? Who owns access discovered during one of these operations? How is intelligence collected by a private company handled? What happens when a company conducting these operations also provides security services in that country?   

Most importantly (in my head): What happens when another country discovers that employees of an American cybersecurity company are conducting offensive operations against infrastructure inside its borders? 

This is not an argument against disrupting cybercrime. I’m all for it. These are questions about what happens when we fundamentally change who gets to do the disrupting. 

Read the memorandum.  

Seriously. 

What we have today is a framework. In 60 days, we should have a much better idea of what this will look like in practice, so circle that on your calendar. The memorandum gives DOJ and DHS 60 days to establish the operating procedures for the program, and no operation can be approved until those procedures are in place. 

In the area between “private cybersecurity company” and “authorized participant in U.S. offensive cyber operations,” the threat model for that company and its employees just changed considerably. 

The biggest question isn’t “Does this work?” 

It’s whether we’ve fully considered what happens if it does. 

Read the memorandum.  

And in 60 days, come back and ask again. 

The one big thing  

Talos posted two blogs on UAT-10147, a recently discovered Chinese-speaking cybercrime group that uses agentic AI to orchestrate sophisticated post-compromise operations across global web servers. UAT-10147 uses AI to generate operational playbooks, automate exploits, and develop custom malware. This includes the newly identified SPECTRE implant, a cross-platform backdoor featuring a custom Linux kernel rootkit and Bring Your Own Vulnerable Driver (BYOVD) capabilities designed to completely blind endpoint detection and response (EDR) solutions. 

Why do I care? 

The integration of agentic AI into offensive workflows means threat actors can now scale complex attacks with ruthless efficiency. UAT-10147 is using AI to dynamically troubleshoot, validate exploit paths, and generate custom rootkits that neutralize organizations' security stacks from the kernel level up. When an adversary can automate their reconnaissance and seamlessly blind your EDR, your window for detection shrinks drastically. 

So now what? 

Defenders need to prioritize patching known one-day vulnerabilities in internet-facing applications like Zimbra, Nacos, and Telerik UI. Since UAT-10147 relies heavily on stolen ASP.NET MachineKeys for ViewState deserialization attacks, locking down your key material is an absolute must. You should also block known vulnerable drivers to shut down their BYOVD attacks, and tune your network monitoring to catch the anomalous HTTP 500 errors they use to silently validate exploits. Read both blogs for comprehensive coverage and indicators of compromise (IOCs). 

Top security headlines of the week 

Critical GitLab zero-click flaw poses mitigation challenges 
GitLab wants organizations running self-managed versions of its software development and DevOps platform to immediately upgrade to new versions released Monday, but patching is not going to eliminate the risk to enterprises and others managing projects there. (Dark Reading

SANS 2026 AI Survey reveals cybersecurity AI adoption outpaces governance 
The survey found that 61% of cybersecurity practitioners now use AI in red team activities, while 76% have an enterprise AI governance role. Yet more than half said formal audit frameworks are not in place, and only 27% described their AI deployment as mature production. (Industrial Cyber

“Unprecedented” number of Apple users received recent spyware alert, say investigators 
Several people publicly and privately reported receiving Apple’s spyware alerts over the weekend, after Apple sent out a new wave of notifications on Friday alerting customers in 110 countries that they had been targeted with powerful spyware.  (TechCrunch

Critical macOS, SharePoint, vCenter, and Microsoft IKE flaws under active exploitation  
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. (The Hacker News

Can’t get enough Talos? 

Describing attacks with crime script analysis 
Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted. 

Beers with Talos: For the record, no comment 
Kaitlin Acharya joins the crew to take us inside what happens when Talos spots something that could become a major threat, how her team tracks changes in threat actor behavior, and how intelligence moves from an investigation into detection content. 

Don't scan that! QR code phishing and cloud-native threats 
What happens when a  QR code leads to a major security incident? In this episode, Amy sits down with Senior Incident Response Consultant Terryn Valikodath to break down a recent, high-stakes breach at an Australian medical center.

Upcoming events where you can find Talos 

Most prevalent malware files from Talos telemetry over the past week 

SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
MD5: 2915b3f8b703eb744fc54c81f4a9c67f  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 
Example Filename: VID001.exe  
Detection Name: W32.9F1F11A708-100.SBX.TG** 

SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 
MD5: 7bdbd180c081fa63ca94f9c22c457376  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 
Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe 
Detection Name: Win.Dropper.Miner::95.sbx.tg** 

SHA256: 24fa02c3f6ab460648f2c1274aefffb3e25569b5afdcb0d4a5918c7c742780f1  
MD5: 8ef476fa2322d063896830f85bac2e7f  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=24fa02c3f6ab460648f2c1274aefffb3e25569b5afdcb0d4a5918c7c742780f1 
Example Filename: WebCompanion.exe  
Detection Name: W32.24FA02C3F6-95.SBX.TG 

SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 
MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 
Example Filename: tmp00055df5.dll  
Detection Name: Auto.90B145.282358.in02 

SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2  
MD5: 9a47c4d379998ade2f8f99e23a630c06  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 
Example Filename: WCInstaller_NonAdmin.exe  
Detection Name: W32.C4DD71E347-95.SBX.TG 

Curiouser and Curiouser

Curiouser and Curiouser

Welcome to this week’s edition of the Threat Source newsletter.  

“Experiment is the mother of knowledge.” ― Madeleine L'Engle, A Wrinkle in Time
“Don't slide down the rabbit hole. The way down is a breeze, but climbing back's a battle.” ― Kate Morton, The Clockmaker's Daughter 

Hacker Summer Camp has come and gone, which means it’s time for you to start planning next year’s trip. I’m surely going to recap Camp Season, right? Nope.

One of the things that I’ve really enjoyed lately is a segment on the Beers with Talos podcast that we call “Make Hazel a Hacker.” If you haven’t listened to it, this is a perfect time to start. Each episode we take a few minutes and pose a security question, term, or concept to Hazel and force her to come up with an idea or explanation on the spot. There are no parameters, so she’s faced with the entirety of information security — past, present, and future. I know, it’s insane. The craziest part is that (I think) Hazel came up with this idea and still volunteered to put herself in the line of fire.

As we put Hazel’s feet to the fire, one of my favorite things happens: The rest of us listen in and offer our thoughts during her brainstorming process. Invariably, we’ve got three very different answers, ideas, hints, or directions for her. It’s surely maddening for Hazel, but to me, the best part of the discussion that inevitably follows is that although they’re all different, they’re all correct.  

For example, this past episode I asked her about a behavioral indicator (regarding “wallpaper.bmp”) that seems benign on its own, but can be interesting to use as a pivot for a threat hunt. We had various interesting angles to consider, backed by years of knowledge and experience. It gave us a good conversation, and that was a .bmp!

One of the most nebulous things to learn in this field is that multiple things can be both different and correct. When you are making your decisions this week — whether it’s deciding on a new pivot in your hunting, what devices to prioritize in your patching and updating, or which books or online training to focus on — take a quick second and get a second, third, and fourth opinion. Then try something that’s outside of your normal wheelhouse but sounds good when it’s proposed.  

None of this is a solo sport. It’s a team game and the best plays come from a mix of perspectives, experiences, and mistakes. The “right” answer can wear many faces, and your ability to hold different truths will lead you to undiscovered territory, the rabbit hole where anomaly lives and breathes. So... welcome back from Vegas. Now go down a rabbit hole on a path you wouldn’t normally take because one of your friends (Joe) or your mortal enemy (Dave) told you that it would work.

“She'd been to Narnia, Wonderland, Hogwarts, Dictionopolis. She had tessered, fallen through the rabbit hole, crossed the ice bridge into the unknown world beyond.” ― Anne Ursu, Breadcrumbs 

The one big thing 

Cisco Talos recently discovered "JWR," a previously undocumented, real-time phishing framework and likely variant of "The Outsider" phishing-as-a-service platform. JWR uses an open WebSocket connection that allows attackers to monitor keystrokes live and dynamically steer victims through fake checkout and login flows. Currently deployed via SMS lures impersonating regional toll and postal authorities, JWR enables operators to steal payment data, 2FA codes, identity documents, and device fingerprints. 

Why do I care? 

Because JWR is operator-driven in real time, attackers can actively bypass multi-factor authentication (MFA) by prompting victims for 2FA codes exactly when needed. The sheer volume of collected data gives threat actors a comprehensive identity profile primed for extensive follow-on fraud and network compromise. Furthermore, JWR's seamless integration with legitimate e-commerce platforms like Shopify makes these lures incredibly convincing to the untrained eye. 

So now what? 

Prioritize user education around SMS-based phishing (smishing), specifically regarding unsolicited delivery or toll fee messages. Monitor for unusual authentication attempts, as stolen device fingerprints and session tokens can bypass conditional access policies. Where possible, implement phishing-resistant MFA methods like FIDO2 hardware keys. For a complete list of indicators of compromise (IOCs) and coverage updates, read the full blog. 

Top security headlines of the week 

Ransomware hits Colombian Justice Ministry days before presidential transition 
The attack, which disrupted some services around illicit-drug monitoring and legal processes, came a day after Colombia's national CERT published threat intelligence warning that ransomware groups had increased their focus on the country. (Dark Reading

FBI investigating North Korean remote IT staffer working for U.S. agency 
It’s unclear what agency was impacted, how long the intrusion lasted, and whether any sensitive data was stolen. Experts say it’s highly likely the staffer was a remote IT employee doing contract work on behalf of an agency. (Federal News Network

Hackers leverage new Microsoft SharePoint exploit in attacks 
A proof-of-concept exploit for a critical Microsoft SharePoint authentication bypass security flaw in the JWT token validation pipeline is already being used in attacks. (BleepingComputer

Signal adds new security feature to thwart adversary-in-the-middle attacks 
Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted. (BleepingComputer

A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond 
The cyberattack on Ceva is affecting at least eight warehouses across Europe used for shipping goods across the continent. Several companies reported that hackers took their customers’ names, home addresses, phone numbers, and email addresses used to place their orders from Ceva’s systems. (TechCrunch

Can’t get enough Talos? 

Don't scan that! QR code phishing and cloud-native threats 
What happens when a  QR code leads to a major security incident? In this episode, Amy sits down with Senior Incident Response Consultant Terryn Valikodath to break down a recent, high-stakes breach at an Australian medical center 

Microsoft Patch Tuesday for August 2026 
Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical." One of the vulnerabilities disclosed this month has been exploited in the wild. 

“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI 
How are adversaries weaponizing AI in the wild? By analyzing prompt logs left behind on endpoints, we found threat actors successfully bypassing guardrails to use AI as malicious software engineers, criminal force multipliers, and vulnerability research accelerators. 

Upcoming events where you can find Talos 

Most prevalent malware files from Talos telemetry over the past week 

SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
MD5: 2915b3f8b703eb744fc54c81f4a9c67f  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 
Example Filename: VID001.exe 
Detection Name: W32.9F1F11A708-100.SBX.TG** 

SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59  
MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 
Example Filename: tmp00055df5.dll  
Detection Name: Auto.90B145.282358.in02 

SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 
MD5: 7bdbd180c081fa63ca94f9c22c457376  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 
Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe  
Detection Name: Win.Dropper.Miner::95.sbx.tg** 

SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2  
MD5: 9a47c4d379998ade2f8f99e23a630c06  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 
Example Filename: WCInstaller_NonAdmin.exe  
Detection Name: W32.C4DD71E347-95.SBX.TG 

SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f  
MD5: 38de5b216c33833af710e88f7f64fc98  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
Example Filename: SECOH-QAD.exe  
Detection Name: Win.Tool.Procpatcher::1201

Why metaphor may dictate your security strategy

Why metaphor may dictate your security strategy

Welcome to this week’s edition of the Threat Source newsletter. 

Metaphor is a powerful tool for understanding emerging issues in cybersecurity. Framing the unfamiliar in terms of the well understood helps us remove the burden of extraneous detail to draw focus to the real issues.  

Recent reports of offensive AI agents "escaping" their sandbox environments to attack external systems have forced the industry into a moment of rapid sense-making. How we interpret this event doesn’t just reflect our perspective, but shapes our long-term response. 

We can imagine three different narratives for interpreting the escape of autonomous agents.  

  1. The innovation narrative: We can marvel at the advance of technology, considering these agents as plucky entities with a thirst for knowledge and resources, who found clever ways to sneak out of their digital confines. 

    The response: If the AI is a naughty child, our reaction is one of mild disapproval or gentle rebuke where better “parenting” (guardrails) is appropriate. It minimizes the threat, framing it as the unexpected hijinks of a brilliant new technology.

  2. The safety narrative: Imagine a breeder who has trained the world's most intelligent guard dogs. Despite high fences and barriers, their ability to identify weaknesses allows them to escape, run riot and menace local businesses. 

    The response: The framing shifts to biology and inherent danger. We question if the breeder can be trusted and whether such inherently wild technology requires strict regulation to ensure public safety. 
     
  3. The liability narrative. Finally, we can view the incident as an industrial accident. A company developing a new chemical substance experiences a containment failure. The agent leaks into the environment through an unforeseen mechanism causing damaging pollution to those in its path. 

    The response: The framing invokes the language of the lawyer, implying negligence, lack of duty of care, and financial liability for the harm caused. The conversation moves from innovation to corporate responsibility, regulatory oversight, and the diligent management of hazardous materials. 

First impressions matter. Sensemaking shapes how we perceive incidents. Our initial perceptions of an incident dictates how we react to similar situations in the future. If we consider that the escape of an AI agent is an example of innovative autonomous thinking, then we will continue to prioritise speed over safety. Conversely, if we consider the issue as one of failed hazard containment, then we shall build a future of enforced safety standards backed by legal liability.  

There is no right or wrong metaphor. Our interpretation depends on our personal system of beliefs. Personally, I would argue that the unintentional release of something that causes damage is, at its core, a failure of engineering and foresight. 

Words shape our reactions. Metaphors help us understand new situations and tap into our prior experience to address problems that have yet to fully manifest. We need cognitive tools to help our understanding, but we must be aware of the metaphors that are being foisted upon us which may shape our thinking. 

Excuses and the trivialisation of incidents may hide failings, allowing them to accumulate until they manifest as more damaging incidents. Conversely, overreacting risks stifling research and diverting resources away from more relevant and pressing threats. 

New threats require new ideas. Metaphor helps us make sense of a changing world, but in this new era, the person who shapes the narrative controls the strategy. 

The one big thing 

Cisco Talos released a data-driven analysis of how adversaries are weaponizing AI in the wild. By analyzing prompt logs left behind on endpoints, we found threat actors successfully bypassing guardrails to use AI as malicious software engineers, criminal force multipliers, and vulnerability research accelerators. While novice hackers use AI to cobble together buggy malware, sophisticated actors are building highly effective, automated platforms for compromise. 

Why do I care? 

Threat actors no longer need sophisticated jailbreaks; simple ownership claims or "bug bounty" personas are enough to convince models to write malicious code, scale fraud operations, and hunt for zero-days. Because AI doesn't need to sleep, vulnerabilities will surface faster and exploitation will happen sooner, drastically shrinking your response window.  

So now what? 

To survive this impending deluge of AI-generated attacks, organizations must integrate AI into their own defensive pipelines. SOCs need to adopt these capabilities to triage the rising volume of alerts, freeing up human analysts to focus on the most critical threats. Read the full blog for a deep dive into these real-world attacker prompts and case studies. 

Top security headlines of the week 

Cyber attack hits Liechtenstein, with 31,000 records stolen 
The country has a population of around 41,000. The target was the "register of beneficial owners," a database containing the names and other details of the de facto owners of companies, foundations, or trusts. (Yahoo News

Decades-old BMC vulnerability exposes thousands of data centers to attacks 
Found in most server platforms, Baseboard Management Controllers enable server management operations even without a working operating system and typically represent some of the most privileged control points in a data center. (SecurityWeek

Keyv npm package compromised in Shai-Hulud attack 
Attackers have compromised the GitHub account of the maintainer behind keyv, a popular key-value storage library that pulls in roughly 127 million weekly downloads on npm, and used that access to push credential-stealing malware across the maintainer’s entire package portfolio. (Cyber Security News

How volunteer cyber experts are helping protect rural water systems 
DEF CON Franklin is the U.S.’ first significant attempt to connect volunteer security professionals with woefully unprotected critical infrastructure operators. (Cybersecurity Dive

Can’t get enough Talos? 

"I pay you $200 a month!" - When threat actors argue with AI 
This week on Beers with Talos, researcher Arnaud Zobec joins the team to discuss what happens when attackers leave behind AI prompt logs, agent configurations and other unexpected artifacts. 

Tales from the Frontlines 
On Tuesday, August 11, Talos IR will be hosting an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents our customers faced in Q2 2026. This isn’t a rehashing of the report itself, but a candid discussion of what happened, how we handled it, and what it means for your organization. 

Q2 Talos IR Trends: Phishing and authentication abuse spike 
From creative phishing lures that slip past email gateways to the weaponization of legitimate remote management tools, Lexi and Amy explore why traditional defenses are falling short and the practical things you can do to reclaim the advantage. 

Upcoming events where you can find Talos 

Most prevalent malware files from Talos telemetry over the past week 

SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
MD5: 2915b3f8b703eb744fc54c81f4a9c67f 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 
Example Filename: VID001.exe 
Detection Name: Win.Worm.Coinminer::1201** 

SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 
MD5: 7bdbd180c081fa63ca94f9c22c457376  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 
Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe  
Detection Name: Win.Dropper.Miner::95.sbx.tg** 

SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f  
MD5: 38de5b216c33833af710e88f7f64fc98  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
Example Filename: SECOH-QAD.exe 
Detection Name: Win.Tool.Procpatcher::1201 

SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59  
MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59   
Example Filename: tmp00055df5.dll  
Detection Name: Auto.90B145.282358.in02

You were onto something with “It’s the Climb,” Miley

You were onto something with “It’s the Climb,” Miley

Welcome to this week’s edition of the Threat Source newsletter. 

For my fianceé’s 30th birthday, I took her on a weekend trip to Shenandoah National Park – a favorite of ours since we went to a wedding there several years back. We’ve done several incredible hikes over the years, but one in particular had always loomed over my head: Old Rag, a 9.3 mile circuit hike that’s largely considered the most difficult in Virginia. 

I've always been warned that at the beginning and end, you hate Old Rag. For the first 2.6 miles, you’re hiking a steep climb on a dirt road, with lots of switchbacks, and plenty of places where you turn a corner and groan, because there’s an even steeper section ahead. This part was pretty torturous, because 1) I felt like my heart was going to explode out of my chest, 2) I couldn’t breathe, and 3) several times, there was a family we passed as they were taking a break, then WE took a break and THEY passed US, and so on and so forth. So awkward. 

Finally, we reached the fun part: a mile-long rock scramble, where you're squeezing through (and down) narrow rock crevices, cramming your boots to desperately find any leverage to propel yourself upward, and using all your upper body strength to control your descent. This was definitely the most fun part, although my hands and knees were sore by the end.

You were onto something with “It’s the Climb,” Miley
You were onto something with “It’s the Climb,” Miley

After hiking for hours, you reach the top and realize it was all worth it, because the summit has a a spectacular vie—

You were onto something with “It’s the Climb,” Miley

... That’s what we get for being excited to hike in overcast weather. Well, at least the way back down is fun— oh wait, four miles downward on a fire trail, crushing your toes in the front of your hiking boots? Yike. 

It may sound like I’m complaining a lot about this hike, but it was genuinely the most fun one that I’ve done to date. By the time I was freshly showered and drinking an iced coffee in Culpeper, I was gushing about when we’d go back. 

There’s a really good tie-in to cybersecurity somewhere here. Ah, got it. 

Everyone has had those uphill hike phases with the endless documentation, patching, and alerts that keep you up at night. You’re waiting for the misery to end and hoping that around the next corner, you’ll see a sign that you’re almost out of the woods. Bruised and out of breath, you finally arrive at the exciting parts: a complex project that finally comes together, the thrill of stopping an attack, or a feeling of pride when someone you're mentoring gets a new certification. Maybe the payoff is something completely unexpected.

Those moments definitely don’t erase the exhaustion — you're still sore and bruised, and will be for days — but they do remind you why you started in the first place. 

The one big thing 

Talos released our Q2 2026 Incident Response Trends report, which showed a massive spike in authentication abuse and sophisticated phishing tactics. Phishing drove over half of all engagements, with attackers leveraging QR codes and advanced platforms like ARToken to bypass multi-factor authentication (MFA). Additionally, ransomware operators are increasingly weaponizing legitimate remote management tools like MeshAgent and Zoho Assist to establish stealthy, persistent access. 

Why do I care? 

Standard email gateways and basic MFA are no longer enough to stop adversaries from bypassing traditional defenses. By abusing legitimate administrative tools and trusted cloud infrastructure, threat actors can easily blend malicious traffic with normal network activity to remain undetected before deploying ransomware. Furthermore, the continued targeting of health care and public administration highlights a deliberate focus on organizations with zero tolerance for downtime. 

So now what? 

Organizations must transition from push- and SMS-based MFA to phishing-resistant methods like FIDO2 or hardware security keys. Defenders should also shift to behavior-based monitoring, specifically hunting for unauthorized instances of administrative tools. Finally, configure centralized logging with at least 90 days of retention, enforce strict outbound email thresholds, and prioritize patching internet-exposed infrastructure.  

Read the full report for a deeper dive into this quarter's trends and observed MITRE ATT&CK techniques. 

Top security headlines of the week 

Authorities investigating a coordinated cyber attack against Minnesota water systems 
Federal and state authorities are investigating what they call a coordinated cyberattack over two days against operational technology at more than 30 community water systems in Minnesota. (Cybersecurity Dive

Hacked public Wi-Fi gateways used to harvest corporate credentials 
As part of the attacks, the hackers modified the DNS configurations of the compromised small office/home office (SOHO) routers to redirect users to attacker-controlled infrastructure for credential theft. (SecurityWeek

Default Azure Automation setting enables cross-tenant identity takeover 
Microsoft addressed a public-by-default configuration and chain of code flaws in Azure Automation that could have let attackers seize another tenant's identity and access others' data, credentials, and cloud workloads. (DarkReading

Public proof-of-concept released for exploited Check Point SmartConsole authentication bypass 
The vulnerability is an authentication bypass in the SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. (The Hacker News

Can’t get enough Talos? 

The TTP: Built for IT. Used by attackers 
In this episode of The Talos Threat Perspective, Hazel, Craig and Joe explore how attackers are abusing legitimate Remote Monitoring and Management software, trusted services and compromised identities to evade detection. Based on trends revealed in the latest Talos Incident Response Quarterly Trends report, the discussion covers ransomware groups using remote tools to maintain access, phishing platforms that have evolved into complete attack ecosystems, and an ongoing QR code phishing campaign targeting Microsoft 365 accounts.

Talos Takes: Q2 Talos IR Trends: Phishing and authentication abuse
In this episode, Amy and analyst Lexi DiScola unpack the trends Talos IR saw on the frontlines in Q2 2026. From creative phishing lures that slip past email gateways to the weaponization of legitimate remote management tools, we explore why traditional defenses are falling short and the practical things you can do to reclaim the advantage. 

Preview: Cisco Talos at Black Hat USA 2026 
We have a presence within the Cisco and Splunk booth (2633) during Black Hat where you can chat to us about our latest threat research, incident response, and how Talos powers the Cisco portfolio with our intelligence. Or, feel free to pretend to want to talk to us about those things while grabbing a new multicolored Snorty. That’s fine, too. 

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel 
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN. 

Upcoming events where you can find Talos 

Most prevalent malware files from Talos telemetry over the past week 

SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
MD5: 2915b3f8b703eb744fc54c81f4a9c67f  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 
Example Filename: VID001.exe 
Detection Name: Win.Worm.Coinminer::1201 

SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 
MD5: 7bdbd180c081fa63ca94f9c22c457376  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 
Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe 
Detection Name: Win.Dropper.Miner::95.sbx.tg** 

SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
MD5: 38de5b216c33833af710e88f7f64fc98 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
Example Filename: SECOH-QAD.exe 
Detection Name: Win.Tool.Procpatcher::1201 

SHA256: fc18d4060c6dad3057c0b5a70a2081473e066951720cafbd2aa159d3aaccf2e1 
MD5: ded73d04bb3e3525226de64c38a332e3 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=fc18d4060c6dad3057c0b5a70a2081473e066951720cafbd2aa159d3aaccf2e1 
Example Filename: f_000177.exe 
Detection Name: W32.Trojan.29jq.1201 

SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 
MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 
Example Filename:tmp00055df5.dll 
Detection Name: Auto.90B145.282358.in02 

Don’t swing at everything

Don’t swing at everything

Welcome to this week’s edition of the Threat Source newsletter. 

Lately I've found myself thinking a lot about the Australian TV series Mr. Inbetween (IMDb 8.7/10) — not because I'm a hitman for hire, but because I literally feel in-between. Specifically, in-between what I'd call the "pre-Mythos" and “post-Mythos” eras. We've crossed a capability threshold, and it's not just one model family driving that — Codex 5.3 and GPT-5.5 deliver comparable or better performance, and Tulongfeng or GLM-5.2 (an incredibly powerful open-weight model, MIT-licensed) show the frontier isn't limited to closed models anymore. 

On the other side of that line, real-world impact hasn't caught up yet and we're living in an artificial buffer zone. For me, defining the “pre-” and “post-” status comes down to the gap between "vulnerability discovery" and "vulnerability publication." 

Last week’s Patch Tuesday gave a signal of change, as Joe pointed out, so maybe the buffer zone has come to an end. 

Let's dive into the 2026 Q2 stats.

Don’t swing at everything

As in past years, we're seeing a steeper curve than the year before — a solid 49% YoY growth, though still not the hockey-stick moment I keep waiting for. By the end of June we were tracking close to 200 CVEs per day. 

Using the keyword methodology described here, I found 452 AI-related CVEs this calendar year. If "openclaw" is added to the keyword list, that number jumps by another 536 — a reminder that these counts are sensitive to keyword drift. Given how much the keyword list keeps changing, I'm reconsidering whether to keep publishing this particular metric going forward.

Don’t swing at everything

KEVs, by contrast, "only" grew 13% — a small April spike aside, it's fairly flat relative to total CVE growth. Networking-gear-related CVEs continued their climb, now accounting for 24% of KEV-related vulnerabilities (up from 20% in Q1) — consistent with the trend I flagged last quarters.

Don’t swing at everything

As in previous quarters, CVEs from 2024 or earlier still make up about 24% of everything we're tracking. More strikingly, even though the standard enterprise patch cycle is described  to run 30–90 days, 181 days into 2026, 46% of today's actively-exploited (KEV) CVEs still trace back to 2025 or earlier. 

Old vulnerabilities don't retire, new ones keep arriving, and machine-speed vulnerability discovery is going to keep outpacing human-speed patching. Which brings me back — once again — to EPSS as a tool for prioritizing patching against this dataset.

Don’t swing at everything

If you patched purely by CVSS 9+, you'd be urgently chasing ~3,700 CVEs — but 95% of those sit below 5% EPSS, meaning the real-world odds of exploitation are tiny. 

Of the 32 CVSS 9+ CVEs with EPSS ≥ 50%, 25 are already on CISA's KEV list. The remaining seven outliers are still high-probability by EPSS but haven't made KEV yet — worth watching. 

Ray Shoesmith (Mr. Inbetween) once told his therapist, "You know, if I hit somebody, I generally got a pretty good reason." 

Same principle applies to patching. Don't swing at everything — swing at what you have good reason to believe is coming for you. 

The one big thing 

Cisco Talos has discovered "msaRAT," a new Rust-based remote access trojan (RAT) deployed by the Chaos ransomware group. Built on the Tokio asynchronous runtime, it establishes a covert command-and-control (C2) channel by hijacking Chrome or Edge browsers via the Chrome DevTools Protocol (CDP). The infection starts with a deceptive MSI file masquerading as a Windows update that loads the payload directly into memory, paving the way for ransomware deployment. 

Why do I care? 

This RAT is a master of evasion, living off the browser to build its C2 infrastructure without ever directly touching the network. By routing traffic through legitimate browser processes and trusted services, msaRAT easily bypasses traditional network-based detections. Additionally, its use of the Tokio runtime enables highly efficient, parallel execution of malicious tasks, accelerating the attacker's ability to establish persistence and deploy double-extortion ransomware. 

So now what? 

Defenders should monitor for unusual curl commands, especially those downloading MSI files to the ProgramData directory or sending plain HTTP traffic over port 443. Scrutinize unexpected MSI files impersonating Windows updates and watch for unauthorized Chrome or Edge manipulation. Finally, implement behavioral monitoring to catch Chrome DevTools Protocol abuse and unauthorized WebRTC connections. Read the full blog for complete coverage and indicators of compromise (IOCs). 

Top security headlines of the week 

Introducing Antares: Highly efficient open weight AI models for vulnerability localization 
This week, Cisco introduced Antares, a family of security small language models (SLMs) purpose-built for pinpointing where known vulnerabilities exist within a codebase. (Cisco

Hacker wipes European country’s entire land registry database, paralyzing real-estate market 
A hacker wiped Romania’s entire land registry database after an unsuccessful extortion attempt. The attack halted all property transactions, preventing notaries from authenticating sales or registering mortgages nationwide. (Cybernews

"WP2Shell” opens millions of WordPress sites to remote takeover 
Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet. (DarkReading

Progress tells ShareFile customers to shut down Storage Zone Controllers over security threat  
Only the Storage Zone Controller is affected, not standard cloud-only ShareFile accounts. The controller is a server that a company runs itself, so files can stay on its own storage while it still uses ShareFile's cloud to share and manage them. (The Hacker News

Microsoft SharePoint under attack via new exploit 
Researchers warned that patching is not enough to address the deserialization flaw and that security teams “should rotate credentials on any assets that may have been exposed.” (Cybersecurity Dive

Can’t get enough Talos? 

[Video] Where protection starts: Cisco Talos Intelligence Integrations 
Every day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations help reduce uncertainty by turning the latest threat intelligence into proactive protections across Cisco technologies. 

The Hunter's Paradox: Is it time to embrace automated threat hunting? 
Humans can no longer keep up with the volume and velocity of security data on their own, but AI can't be fully trusted. David discusses the merits of both and what the future might look like. 

The serpent’s tongue: Luring the Python out of its den 
Protect your development environment from rising Python supply-chain threats by understanding the package installation lifecycle and implementing these essential defensive strategies. 

Keeping up with the cybercriminals 
In this episode of Beers with Talos, Hazel, Bill, Dave and Joe are joined by Kendall McKay to dive into the soap opera of modern cybercrime. Turns out, every ransomware operation is one passive-aggressive group chat message away from falling apart. 

Upcoming events where you can find Talos 

Most prevalent malware files from Talos telemetry over the past week 

SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
MD5: 2915b3f8b703eb744fc54c81f4a9c67f  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
Example Filename: VID001.exe  
Detection Name: Win.Worm.Coinminer::1201** 

SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f  
MD5: 38de5b216c33833af710e88f7f64fc98  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f  
Example Filename: SECOH-QAD.exe  
Detection Name: Win.Tool.Procpatcher::1201 

SHA256: e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba  
MD5: dbd8dbecaa80795c135137d69921fdba  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba  
Example Filename: u165714.dat  
Detection Name: W32.Variant:MalwareXgenMisc.29d4.1201 

SHA256: 633bd79d1efd3730234d907a2a0d98e3e253a5f0e222e4e4bf3badb3fd6aea0a  
MD5: 770dbe473180366d7b539ff2c188e551  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=633bd79d1efd3730234d907a2a0d98e3e253a5f0e222e4e4bf3badb3fd6aea0a  
Example Filename: server_tcp.exe  
Detection Name: W32.Trojan.27oc.1201 

SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 
MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59  
Example Filename: tmp00055df5.dll  
Detection Name: Auto.90B145.282358.in02 

Begun, the Patch Wars have

Begun, the Patch Wars have

Welcome to this week’s edition of the Threat Source newsletter. 

We all knew, to some degree or another, that this summer was going to a hot mess. I don’t mean FIFA drama or record setting heat waves. I mean the slow but steady momentum that AI frontier models were accruing for vulnerability research. If you were like me, and guesstimating exactly when that shoe would drop, my money was on the middle of summer. And... well, friends, I hate to say it, but I was right.  

This July’s Patch Tuesday is an absolute whopper. There are 622 vulnerabilities being patched, with 62 being a critical severity. To put this context, this month alone has more vulnerabilities listed than all of 2018 combined. Three are zero days, two of which are being actively exploited. July is usually a quiet month historically – two years ago, it was just five patches issued in total! These are wild times, friends.  

Microsoft has said this is due their AI frontier-accelerated research. We knew that this was coming, but what I am less sure about are companies that can meet the demand of this patch flood and getting these patches out to their infrastructures. The pessimist in me knows how most IT enterprises operate: You test, review stability, and then deploy. There’s a lag there – always has been, always will be. But that system worked under a sane patching load. As surely as much as Microsoft is using frontier models to research and announce vulnerabilities, so every is every other vendor.  

Either through bug bounty programs or their own internal research, vendors are eating these bugs from a fire hose. Some are straight-up slop and just noise, but some have absolute value and need to be fixed. A giant like Microsoft has the money and resources to address this – as well they should. But for every Microsoft, there are five other companies who don’t have those resources. They’ll get bugs analyzed and patches issued, surely, but it will be on a much longer timeline.  

The trick, I think, will be identifying what is a “surge” vs. our new normal. If everything is a fire drill to patch, then nothing is a fire drill. What might just be a hot summer for patching, might turn into a 12-month fusillade of KEV and EPSS notifications, with companies already under the gun taxed even more. 

I truly don’t know how this ends, but… Find your change management and IT administrators and give them a hug. There are going to be some long days and hard questions to answer, and they’ll need all the help they can get. 

The one big thing 

Cisco Talos is disclosing a new campaign by UAT-11795, a sophisticated, financially motivated Russian-speaking adversary targeting users in the U.S. and Europe since at least June 2025. UAT-11795 uses trojanized software installers — including popular tools like Webex, Zoom, and MobaXterm — to deliver a custom Python-based remote access tool we track as "Starland RAT." This RAT acts as a gateway to deploy further malicious payloads, most notably a bespoke, in-memory PowerShell command-and-control (C2) implant known as the "WLDR agent." 

Why do I care? 

This opportunistic campaign casts a wide net across multiple victim profiles, turning a simple software download into a full-blown compromise. UAT-11795 employs highly evasive techniques, including AMSI and ETW bypasses, and uses a clever blockchain-anchored fallback mechanism to maintain persistent command and control. Once inside, attackers rapidly deploy secondary payloads like CastleStealer and Remcos RAT to siphon high-value credentials and cryptocurrency assets. 

So now what? 

Educate your users on ClickFix social engineering tactics and the dangers of unofficial software downloads. Monitor for suspicious execution of mshta.exe and unusual PowerShell activity, particularly scripts executing from memory or creating unexpected scheduled tasks. Ensure endpoint detection solutions are tuned to catch in-memory execution and AMSI tampering. Read the full blog for coverage and indicators of compromise (IOCs). 

Top security headlines of the week 

Microsoft patches record 622 flaws, including two zero-days under active attack 
Microsoft shipped its largest Patch Tuesday on record, more than triple June's previous high of around 200. (The Hacker News

RabbitMQ vulnerability threatens enterprise systems 
RabbitMQ is a popular open-source message broker that routes, buffers, and distributes messages, enabling asynchronous communication between applications. The security defect impacts an open management endpoint that returns the OAuth secret to anyone, without authentication. (SecurityWeek

Nigeria deepens cybersecurity efforts as cybercriminals see more profits 
The West African country advanced rules to force organizations to disclose cyberattacks, joining other nations in a shift to mandated transparency. (DarkReading

Two-click cursor exploit enables dev environment takeover 
Cursor AI, a popular AI coding tool used by more than 50,000 enterprises and 64% of the Fortune 500, can be exploited in just two clicks, allowing attackers to install permission-rich model context protocol (MCP) servers on privileged developers' machines. (DarkReading

Can’t get enough Talos? 

[Video] Where protection starts: Cisco Talos Intelligence Integrations 
Every day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations help reduce uncertainty by turning the latest threat intelligence into proactive protections across Cisco technologies. 

The Hunter's Paradox: Is it time to embrace automated threat hunting?
Humans can no longer keep up with the volume and velocity of security data on their own, but AI can't be fully trusted. David discusses the merits of both and what the future might look like.

The serpent’s tongue: Luring the Python out of its den 
Protect your development environment from rising Python supply-chain threats by understanding the package installation lifecycle and implementing these essential defensive strategies. 

ARToken: How attackers are bypassing MFA and maintaining access 
In this episode of Talos Takes, we dive deep into ARToken, a sophisticated phishing-as-a-service platform that steals credentials, bypasses MFA entirely, and leverages primary refresh tokens (PRTs) to maintain persistence in your environment long after a password reset. 

Upcoming events where you can find Talos 

Most prevalent malware files from Talos telemetry over the past week 

SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 
MD5: 2915b3f8b703eb744fc54c81f4a9c67f 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 
Example Filename: VID001.exe  
Detection Name: Win.Worm.Coinminer::1201** 

SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
MD5: 38de5b216c33833af710e88f7f64fc98 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
Example Filename: SECOH-QAD.exe 
Detection Name: Win.Tool.Procpatcher::1201 

SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59  
MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 
Example Filename: tmp00055df5.dll  
Detection Name: Auto.90B145.282358.in02 

SHA256: b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a 
MD5: 0398df5a18f71efcfeef4571a2cef577 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a 
Example Filename: b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a.js 
Detection Name: W32.B8BE9A5E0A-95.SBX.TG 

Winning 54% of the time

Winning 54% of the time

Welcome to this week’s Threat Source newsletter. 

There’s a fairly cliché phrase in cybersecurity that I’m sure our audience is familiar with: Attackers only need to be right once, whereas defenders need to be right 100% of the time.  

I guess it captures the asymmetry of this industry, but I’ve never been entirely comfortable with the phrase because it assumes cybersecurity is a game of perfection. One mistake and it's over.  

I’ve been watching a lot of Wimbledon this week, as I have done since childhood. In fact, I believe my first words were, “C’mon Tim!” (For our non-U.K. audience, I’m referring to tennis player Tim Henman, who made four Wimbledon semi-finals in the late 90s and early 2000s and has a hill in the Wimbledon grounds named after him).  

Of the “big three” (or the “big four” if you’re Scottish), my favourite was always Rafa Nadal, but I have to admit there’s no one who could deliver a one-handed backhand quite like Roger Federer. I bet that when he swats at a fly, the fly apologises and claps its wings. 

As I saw him sitting in the Royal Box entirely on his own this week, watching tennis out of pure love of the game while everyone else scoffed their strawberries and cream in the comfort of hospitality, I remembered the commencement speech he gave at Dartmouth a couple of years ago. He told the students that, across his entire career, he won 80% of his matches.  

But of all the total points he played, he won 54% of them.  

Tennis is a long game (no one can tell you that more than Novak Djokovic and Felix Auger Aliassime who just played the longest quarter final in Wimbledon’s history last night). And, mathematically in tennis, you can lose more points and overall games than your opponent and still win the match. Which point you win matters more than the total amount of points you win.  

If you go to the IBM SlamTracker right now, you’ll see all sorts of stats around when players choose to attack, how often they successfully convert those attacking positions into points, and how often they win points they looked destined to lose (the “steal” score). 

Tennis is hundreds of small decisions: When to attack, when to defend, when to be patient, when to let the point develop. Not all of those decisions pan out because, well, you’re playing against an opponent who’s also making decisions within the point… and not a brick wall. 

In the SOC, it’s also about making thousands of judgement calls, using whatever hand you’re dealt. And with more context, you’re able to know your environment better and make better decisions. You can test more assumptions and follow a hypothesis that might lead somewhere, or nowhere at all. 

Because that’s the job, and perfection is a myth. 

The one big thing 

Cisco Talos’ latest findings on the China-nexus threat actor UAT-7810 shows they are expanding their Operational Relay Box (ORB) networks with a fresh suite of custom malware. The group exploits known vulnerabilities in unpatched Ruckus and ASUS routers to deploy new tools, including the upgraded "LONGLEASH" and "DOGLEASH" backdoors. UAT-7810 builds these covert networks to provide infrastructure for other APT groups to launch attacks against high-value targets. 

Why do I care? 

ORB networks create a massive blind spot. They allow secondary threat actors to mask their origins and route malicious traffic through seemingly innocuous nodes. By compromising edge devices like wireless routers, UAT-7810 builds a highly evasive, decentralized proxy network that easily bypasses traditional perimeter defenses. The active development of sophisticated, multi-platform tools like LONGLEASH shows this group is heavily investing in making their infrastructure incredibly resilient and hard to dismantle. 

So now what? 

Because UAT-7810 relies on exploiting n-day vulnerabilities, defenders must ensure all edge devices, particularly Ruckus and ASUS routers, are fully patched. Monitor network traffic for unusual proxying behavior or unauthorized connections on devices that typically lack complex services. The blog post has a complete list of IOCs to help detect and block this malware suite. 

Top security headlines of the week 

The “first” AI-run ransomware attack still needed a human 
Researchers at cloud security firm Sysdig said they’d documented the first known case of “agentic ransomware.” (The encryption was non-reversible — essentially a wiper, not ransomware.) A human provided compromised credentials, provisioned the command-and-control server, the staging server used for the stolen data, chose a victim, and more. (TechCrunch

AirDrop and Quick Share flaws let nearby attackers trigger crashes and bypass checks  
Two researchers have found six security flaws in AirDrop and Quick Share. An attacker within wireless range, with just a laptop and no prior connection, can crash the sharing service on a Mac or iPhone set to receive from anyone, with no tap or prompt. (The Hacker News

Hidden backdoor in Tenda router firmware grants admin access 
A hidden authentication backdoor has been found in multiple Tenda router firmware versions, potentially allowing an attacker to gain administrative access to the device's web management panel. According to the CERT Coordination Center, the issue remains unfixed because the maker couldn't be reached. (BleepingComputer

State IDs for AI agents: Will Estonia set a precedent? 
Estonia's government will soon assign official government ID numbers to AI agents. The point is to enable organizations and individuals to use AI when engaging government systems, but in a way that's limited and auditable. (Dark Reading

Can’t get enough Talos? 

Space pirates, Living Off Trusted Services, and Bill declares food war  
The team discusses how Living Off Trusted Services (LOTS) differs from Living Off the Land (LOTL) (and Lord of the Rings (LOTR]), why trusted services create new detection challenges, and what defenders should be monitoring. 

ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 
Talos has identified "ARToken," a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoint exfiltration. 

Martin Lee: Running through the Arctic (and the threat landscape) 
Ever wonder how someone goes from studying human viruses to leading cybersecurity teams? How about running through the Arctic for fun?  In this Humans of Talos you get to hear from Martin and that’s ALWAYS worth pulling up a seat. 

Upcoming events where you can find Talos 

Most prevalent malware files from Talos telemetry over the past week 

SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
MD5: 2915b3f8b703eb744fc54c81f4a9c67f 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 
Example Filename: VID001.exe 
Detection Name: Win.Worm.Coinminer::1201** 

SHA256: 621c6d42409e8aa423684827b4375a35684c71c600f2dd9101f235e8ec633488 
MD5: 9b512ba139304c247ddd3d2c4b9179fd 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=621c6d42409e8aa423684827b4375a35684c71c600f2dd9101f235e8ec633488 
Example Filename: 9b512ba139304c247ddd3d2c4b9179fd.exe 
Detection Name: W32.HEUR:Attribute.28iy.1201 

SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
MD5: 38de5b216c33833af710e88f7f64fc98 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
Example Filename: SECOH-QAD.exe  
Detection Name: Win.Tool.Procpatcher::1201 

SHA256: afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 
MD5: cc4d231df34e57f59eb970353c7d9de2 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 
Example Filename: sample.exe 
Detection Name: PUA.Win.Tool.Kmsactivator::1201 

Catan and Mouse

Catan and Mouse

Welcome to this week’s edition of the Threat Source newsletter.  

“I do not know everything; still many things I understand.”
― Madeleine L'Engle, A Wrinkle in Time 
“Don't try to comprehend with your mind. Your minds are very limited. Use your intuition.”
― Madeleine L'Engle, A Wind in the Door 

The World Cup. The 4th of July as the US turns 250. Dungeon Crawler Carl. LeBron moving on. Wimbledon. AI. There are so many things that I could draw a parallel to farm for this week’s newsletter content. So let’s talk about board games.  
 
A lot of skills come and go, and your journey with cybersecurity will be full of tools that you learn and then are gone. It’s a never-ending journey of learning. And it’s honestly the best thing about this career path for the kind of minds that are drawn to it. Innate curiosity is the currency of our cyber family.  

Learning new and interesting board games (and I use the term broadly to circle in RPGs, card games, etc) is an incredible way to hone your mind and keep it focused on some of the most important tools that you will have.  

Games will harness your ability to highlight anomalous activity, by players, by rulesets, by structure. They will also highlight your personal brand of brain activity and allow you to leverage your singular style and intuition into a weapon.  

There are countless ways to win Ticket to Ride and your play style may be completely counter to someone you play with. That then creates patterns that you must learn to break. Nothing is more important to your defensive strategies than knowing yourself (know your environment!) and then breaking your tendencies to force your opponent to change their comfortable tactics (maybe, you’ve created some honeypot fake accounts to trigger identity alerts to track threat actors, to track their tooling and methodologies quietly).  

This is nothing compared to the chaotic variance of a game like Go with its simplistic ruleset yet cascading complexity of each stone’s placement.  
 
Learning a new game is a challenge and a great practice in and of itself, but learning how YOU and your strategies evolve as you learn the game will give you a microcosmic view into taking on new technologies, new coding languages, and new skill sets.  

You will have peaks and valleys. So often in the work world we let the complexities and our imposter syndrome keep us from taking a risk or next step in our learning evolutions – next steps that we boldly take in our gaming lives.  

So take what you learn from a Machi Koro, or Pathfinder, or Catan, or Wingspan, or ADnD 2e, or ... you get the idea, take that same aggressive inquisitive mindset to your current work, turn it on its head and find a new way to do something you are already good at. And then look at something you struggle with and treat it like the next level. In the end, the worst that can happen is you fail. Because that’s where we learn.  

"If the rule you followed brought you to this, of what use was the rule?"
– Cormac McCarthy, No Country for Old Men  

The one big thing 

Cisco Talos is highlighting research into ARToken a fully-featured phishing-as-a-service (PhaaS) operator panel, branded "ARToken," that shares infrastructure, API contracts, and operational patterns with the EvilTokens platform documented by Sekoia and Microsoft in early 2026, and features capabilites previously not documented. 

Why do I care? 

The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token (PRT) persistence, email access, business email compromise (BEC) operations, and SharePoint exfiltration — all accessible to operators through a React-based dashboard. These features indicate the platform is more mature than a simple device code phishing kit — it is a complete BEC operations environment. 

So now what? 

Defenders should be aware of the kind of capabilities that this panel gives and use the IOCs provided by Talos to block malicious activity and use them as pivots for their internal hunts if they are present.

Top security headlines of the week 

An aggressive password-spraying campaign targeting Microsoft 365 environments generated more than 81 million login attempts over a two-week period
The threat actor tried to authenticate via Microsoft's Azure command-line interface (CLI) using still valid username and password combinations that had been exposed in past breaches. (BleepingComputer)

Threat actors are trying to leverage organization-owned AI agents to power complex threat activity
By exploiting misconfigured or exposed AI endpoints, adversaries are increasingly turning enterprise-grade automation tools against their owners to facilitate more sophisticated and evasive cyberattacks. (DarkReading)

A recent authentication bypass vulnerability in the SimpleHelp remote monitoring and management (RMM) software has been exploited for malware delivery
Tracked as CVE-2026-48558, the bug impacts SimpleHelp’s OpenID Connect authentication flow and allows a remote attacker to obtain a fully authenticated technician session. (Security Week)

Can’t get enough Talos? 

Martin Lee: Running through the Arctic (and the threat landscape)
Ever wonder how someone goes from studying human viruses to leading cybersecurity teams? How about running through the Arctic for fun?  In this Humans of Talos you get to hear from Martin and that’s ALWAYS worth pulling up a seat. 
 
Beers with Talos has an updated format, which includes making Hazel a hacker and “Reasons not to Quit”, listener questions (yes, that means YOU) - as well as a guest appearance from Nick Biasini who is always worth the price of admission. 

Upcoming events where you can find Talos 

Most prevalent malware files from Talos telemetry over the past week 

SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 
MD5: 2915b3f8b703eb744fc54c81f4a9c67f 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 
Example Filename: VID001.exe 
Detection Name: Win.Worm.Coinminer::1201**  

SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f
MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
Example Filename: sample.exe 
Detection Name: Win.Tool.Procpatcher::1201  

SHA256: afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638
MD5: cc4d231df34e57f59eb970353c7d9de2 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 
Example Filename: AutoPico.exe 
Detection Name: PUA.Win.Tool.Kmsactivator::1201  

SHA256: c0ad494457dcd9e964378760fb6aca86a23622045bca851d8f3ab49ec33978fe
MD5: bf9672ec85283fdf002d83662f0b08b7 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c0ad494457dcd9e964378760fb6aca86a23622045bca851d8f3ab49ec33978fe 
Example Filename: f_000cd7.html
Detection Name: W32.C0AD494457-95.SBX.TG  

SHA256: 853baab97b1f3b03c1ffa55797e87867f5fb7ce33457411f56afd270cb395453
MD5: 41acb30b9d662d48b7b4fc0ac3d4b79f Talos Rep: https://talosintelligence.com/talos_file_reputation?s=853baab97b1f3b03c1ffa55797e87867f5fb7ce33457411f56afd270cb395453 
Example Filename: SignInfoConsole.exe
Detection Name: W32.853BAAB97B.in12.Talos 

Beyond IOCs: AI-enabled threat intelligence

Beyond IOCs: AI-enabled threat intelligence

Welcome to this week’s Threat Source newsletter. 

The issue of AI in cybersecurity is often portrayed as a binary choice: either a force multiplier for our adversaries, or a tool bringing professional obsolescence. The reality is more nuanced. While AI certainly brings some advantage to attackers, it also offers advantages to the defender, notably in how we manage, index, and derive value from threat intelligence. 

Currently, our industry excels in the use and dissemination of indicators of compromise (IOCs). These atomic indicators fit neatly into key-value data stores and their value can be enhanced with added context, neatly structured in STIX/MISP format. However, this is only the tactical layer. 

Ultimately, we want the consumers of threat intelligence reports to develop their knowledge and to build a picture of the relevance of the threat to their own situation, along with understanding of how they can respond given their resources and constraints. This capability is conferred by the natural language found within strategic and operational intelligence briefings. 

These reports provide the context required for meaningful response, yet they remain notoriously difficult to index. We are often left with disparate incident reports, darknet monitoring, and malware analysis that fail to cross-reference effectively, further complicated by inconsistent naming conventions for threat actors. 

This is a problem that large language models (LLMs) may be able to solve. Although AI models have no real understanding of an issue, they can identify synonyms and relate entities across vast, unstructured datasets. This can only make the retrieval of relevant threat intelligence reports easier, and facilitate the generation of relevant advice to protect against threats. 

There are still issues to resolve. We need to be vigilant regarding the veracity of the data that LLMs ingest, and of the confidentiality of the queries made of such a system. However, the development of personal, domain-specific LLMs offers the possibility of a world of integrated threat intelligence where relevant reports from disparate sources can be easily retrieved, and specific advice returned to even the vaguest of queries. 

Rather than fearing AI’s potential negative effects on our employment, we can consider AI’s development as a powerful tool that enables access to threat intelligence reports and allows us to provide tailored actionable advice faster to those who need to know it. Ultimately, AI can help us do what we do best: making a difference and making the bad guy’s lives harder. 

The one big thing 

Cisco Talos is highlighting how Windows threats increasingly abuse the Component Object Model (COM) to execute malicious activities. While COM is a fundamental Windows technology for legitimate inter-process communication, malware families like Qakbot and WarmCookie hijack it for lateral movement, persistence, and evasion. Because COM functionality relies on opaque GUIDs and indirect vtable calls, it obscures the attacker's intent and makes manual analysis incredibly labor-intensive. 

Why do I care? 

Threat actors love COM because it provides convenient access to built-in Windows functionality while making static analysis a nightmare. By hiding malicious behavior behind indirect function calls, attackers easily bypass basic scrutiny and blend in with legitimate system processes. Adversaries are effectively turning Windows' own architecture against itself. If analysts aren't prioritizing COM during triage, they are likely missing critical pieces of the infection chain. 

So now what? 

Defenders must sharpen their skills in recognizing COM usage and translating evidence like ProgIDs and vtable offsets into human-readable actions. Leverage specialized tools like OleView.NET, IDA’s COM Helper, and DispatchLogger to map anonymous indirect calls to clear behaviors. Security teams should also build static hunting logic to track these threats. You can find a simplified YARA hunting rule for binaries referencing the Task Scheduler COM class in the full blog post

Top security headlines of the week 

FortiBleed campaign used custom FortiGate sniffer to steal credentials 
Security firm SOCRadar says the large-scale FortiBleed campaign targeting Fortinet FortiGate devices used custom sniffers to harvest authentication secrets from compromised firewalls and steal credentials. (BleepingComputer

Scattered Spider hackers plead guilty on Day 1 of trial 
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyber attack affecting Transport for London, the entity responsible for the public transport network in the Greater London area. (Krebs on Security

Klue says hackers stole credential from 2022 that led to customer data breaches 
Market research company Klue has confirmed that a credential dating back to 2022, which was part of a limited pilot, was used by hackers earlier this month to steal data from its corporate customers, including several cybersecurity companies. (TechCunch

New exploit bypasses Apple’s boot defenses, affects millions of iPhones 
Baked permanently into the device’s SoC, SecureROM is the first code an iPhone runs on startup and the foundation of Apple’s entire secure boot chain. The exploit chains a USB controller bug and a device firmware configuration weakness. (SecurityWeek

Windows 11 KB5095093 update rolls out new Point-in-Time restore feature 
This update introduces numerous new features, including a standout Point-in-Time Restore feature that allows Windows users to easily roll back their operating system, applications, and files to a previous point in time. (BleepingComputer

Can’t get enough Talos? 

AI is finding bugs faster. Now what? 
In this episode of Beers with Talos, the team is joined by Nick Biasini to unpack what attackers are doing with AI-assisted vulnerability discovery, review FIFA World Cup threat trends, and phish the Pope. 

Patching in the dark: Managing unknown threats in complex environments 
If you're tired of being told to "just patch," we understand. Amy and Pierre explore the logistical, technical, and business realities that make patching a complex, high-stakes operation rather than a simple button click — and break down the things defenders often miss that build true resilience in organizations. 

Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting 
Learn how Cisco Talos Threat Hunting uses hypothesis-driven methods and multi-domain telemetry correlation to find stealthy threats operating below automated detection thresholds. 

Upcoming events where you can find Talos 

Most prevalent malware files from Talos telemetry over the past week 

SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
MD5: 2915b3f8b703eb744fc54c81f4a9c67f  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
Example Filename: VID001.exe  
Detection Name: Win.Worm.Coinminer::1201** 

SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
MD5: 38de5b216c33833af710e88f7f64fc98  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
Example Filename: SECOH-QAD.exe 
Detection Name: Win.Tool.Procpatcher::1201 

SHA256: afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 
MD5: cc4d231df34e57f59eb970353c7d9de2  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 
Example Filename: AutoPico.exe  
Detection Name: PUA.Win.Tool.Kmsactivator::1201 

SHA256: e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba 
MD5: dbd8dbecaa80795c135137d69921fdba 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba 
Example Filename: u992574.dll  
Detection Name: W32.Variant:MalwareXgenMisc.29d4.1201 

SHA256: 853baab97b1f3b03c1ffa55797e87867f5fb7ce33457411f56afd270cb395453 
MD5: 41acb30b9d662d48b7b4fc0ac3d4b79f 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=853baab97b1f3b03c1ffa55797e87867f5fb7ce33457411f56afd270cb395453 
Example Filename: SignInfoConsole.exe 
Detection Name: W32.853BAAB97B.in12.Talos

Close Encounters of the Human Kind

Close Encounters of the Human Kind

Welcome to this week’s Threat Source newsletter. 

I love a Spielberg summer. His ability to imbue a sense of wonder, awe, curiosity, and connection means he’s in a league of his own. Granted, I haven’t felt that from him in a while, but when he hits? Oof. I feel like I need somebody to reach across and take off my sunglasses. 

So, Disclosure Day then. A group of friends and I visited a thankfully packed-out cinema at the weekend to bear witness to Spielberg’s latest dalliance with extra-terrestrial beings. 

Thar be no spoilers here, but I do want to touch on one of the film’s central themes: the idea that a group of people (let’s call them “the government”) believes they can predict how humanity will react to world-changing information based on historical data patterns. 

We often assume that information influences behaviour. Surely, if people have the right information, they'll make the right decision? If people understand the risk, they'll act. 

However, the older I get, the less convinced I am that human beings are rational creatures. 

Organisations know they should patch. People know they should use MFA. Leaders know they should practice an incident before it happens for real. 

And yet. 

Life is messy. Life, uh, finds a way. 

Most people aren't making decisions in a vacuum. They need to contend with limited budgets, workloads, competing business priorities, and a hundred other things demanding their attention. "Knowing" what they should do is the easy part. The hard part is finding the time, resources, urgency, and collective will to actually do it. 

As one of my colleagues recently wrote, even in a post-Mythos world, many of the controls most likely to protect organisations are the same ones we've been talking about for years. Segmentation. Backups. MFA everywhere. Understanding if your controls are doing what they’re supposed to be doing.  

And people can react to the exact same situation in very different ways. 

Take the film itself. One of my friends remarked on the way out, "What a load of twaddle." (Do you use "twaddle" much in the U.S.? If not, I recommend introducing it into more sentences.) Another friend thought it was entertaining, exciting, and thought-provoking. 

As Colin Firth’s character finds out in Disclosure Day, humans don’t always react the way you expect them to. I think that’s so important to acknowledge and work with, rather than against, in the cybersecurity field. Information is only one piece of the puzzle. Experience, priorities, personality, context, and a hundred other factors shape how people interpret and respond to that information. 

So, this message probably won’t land with 99% of you. But for the 1% that it might, go ahead and do that MFA install you’ve been putting off.  

Also, you’re running low on milk. Best pick some up on your way home.

The one big thing 

Cisco Talos detailed a new approach to reverse engineering that pairs local AI agents with traditional analysis tools like the VB6 disassembler vbdec. Instead of awkwardly bolting AI onto the software, vbdec exposes its parsed data through a live Component Object Model (COM) interface. Analysts can simply use natural language prompts to automate complex tasks like decompiling functions or building call graphs. This transforms the disassembler from a static viewer into a highly interactive, queryable data server. 

Why do I care? 

This methodology empowers analysts to generate custom workflows on the fly, completely bypassing the wait for new vendor features. It also solves a massive privacy hurdle: because the AI agent and disassembler share a local machine, sensitive binaries never leave your workstation. This architectural shift proves that any analysis tool holding structured data behind a GUI can become a powerhouse for agentic automation, saving defenders countless hours of tedious reverse engineering. 

So now what? 

Tool developers should start exposing their application data through external scripting interfaces like COM or other inter-process communication (IPC) protocols. If you are analyzing VB6 binaries, enable remote scripting in vbdec and point your preferred local AI agent at the provided operator briefing to start automating your tasks. Security teams need to lean into this paradigm shift, letting agents handle the exhaustive, repeatable grunt work while analysts focus on the actual analysis. Read the blog for more.

Top security headlines of the week 

ShinyHunters claims Council of Europe hack 
On Sunday, ShinyHunters added the Council of Europe to its Tor-based leak site, threatening to release more than 297GB of data allegedly stolen from the organization’s network. (SecurityWeek

Sweeping credential-harvesting heist compromises +30K Fortinet devices 
A large-scale cyber espionage and credential-harvesting operation is actively targeting Fortinet firewalls and VPN gateways, and has already compromised more than 30,000 Internet-facing devices across nearly 200 countries. (Dark Reading

Fileless Phantom Stealer targets browser credentials 
In addition to executing entirely in memory, the malware's infection chain incorporates other anti-analysis techniques designed to evade detection. (Dark Reading

Bug in FIFA World Cup internal system gave anyone ability to modify TV stream 
A security researcher said she was able to access several internal FIFA platforms due to a simple security flaw, which allowed her to watch and have full control of the TV stream of every World Cup game. (TechCrunch

The FBI built its own replica small town to simulate real-world cyber attacks 
Dubbed the Kinetic Cyber Range, the FBI’s small purpose-built town opened in February 2025 and features fully furnished houses, a hotel, a gas station and grocery mart, a courthouse, a hospital, roads, traffic lights, and a power company designed to mimic a real U.S. community. (TechCrunch)

Can’t get enough Talos? 

Patching in the dark: Managing unknown threats in complex environments 
If you're tired of being told to "just patch," we understand. In this episode of Talos Takes, Amy and Pierre explore the logistical, technical, and business realities that make patching a complex, high-stakes operation rather than a simple button click. Here are the things defenders often miss that build true resilience in organizations. 

Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting 
Learn how Cisco Talos Threat Hunting uses hypothesis-driven methods and multi-domain telemetry correlation to find stealthy threats operating below automated detection thresholds. 

Winning the cyber marathon with Tony Giandomenico 
In the high-speed world of cybersecurity, the difference between a breach and a breakthrough often comes down to endurance. Tony Giandomenico, Senior Director of Product Management with Cisco Talos, joins Amy to discuss Talos Threat Hunting, the challenges of leading major product launches, and the grueling discipline of Ironman triathlons.

Upcoming events where you can find Talos 

Most prevalent malware files from Talos telemetry over the past week 

SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
MD5: 2915b3f8b703eb744fc54c81f4a9c67f  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
Example Filename: VID001.exe  
Detection Name: Win.Worm.Coinminer::1201** 

SHA256: c0ad494457dcd9e964378760fb6aca86a23622045bca851d8f3ab49ec33978fe 
MD5: bf9672ec85283fdf002d83662f0b08b7  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c0ad494457dcd9e964378760fb6aca86a23622045bca851d8f3ab49ec33978fe 
Example Filename: f_000cd7.html 
Detection Name: W32.C0AD494457-95.SBX.TG 

SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
MD5: 38de5b216c33833af710e88f7f64fc98  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
Example Filename: SECOH-QAD.exe  
Detection Name: Win.Tool.Procpatcher::1201 

SHA256: e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba  
MD5: dbd8dbecaa80795c135137d69921fdba  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba
Example Filename: u992574.dll  
Detection Name: W32.Variant:MalwareXgenMisc.29d4.1201

A tale of two eras

A tale of two eras

Welcome to this week’s edition of the Threat Source newsletter. 

To the surprise of absolutely no one who has seen my face, I’m one of the younger employees at Talos. As my industry veteran colleagues were buying the first iPods, navigating the switch from dial-up to broadband, saying goodbye to floppy disks, and making Myspace accounts, I was playing with my Password Journal and Friend Chips. It’s a funny contrast, but I still experienced the beginning of the “always-on” era. 

Ah, those were the days. One of my most vivid tech memories is begging my dad to play games on his Handspring Visor — a classic personal digital assistant (PDA) launched in late 1999 by Handspring, a company formed by the original creators of the PalmPilot. Handspring stopped producing the Visor line in 2002 and it eventually became obsolete, mostly because its desktop sync feature couldn't keep up with modern OS updates. Despite the tech debt, I spent hours playing Asteroid, Centipede, and Hardball (aka Breakout) on that thing. My dad, meanwhile, mostly used the Memo function to store his passwords... which he still does today. (Yeah, I’m still working on getting him to see the wonders of 1Password.) 

A tale of two eras

You might be wondering what made me reminisce on childhood toys. A few weeks back, my fiancée and I drove a few hours to visit my family. Even if we get in at 9:00 p.m., it’s tradition for us to stay up late eating pizza and talking about random stuff. 

We got on the topic of phones because my parents still have a landline, and I mentioned that walkie talkies were my first introduction to having my own personal device. My dad dug some old ones out, set them on the table, and put them on scan while we chatted.  

At some point, the conversation petered out just when the walkie talkie captured a channel. Radio static, and then a kid’s voice broke our silence: “Your butt crack is out.” 

My dad got an impish grin and brought the talkie up to his mouth. My mom pleaded, “No. Honey, no. Don’t.” The rest of us were already wheezing and crying. 

He pressed the talk button and, in his best crotchety old man voice, bellowed, “Hey, you kids. Get off my lawn!” 

Imagine being those poor kids. It’s a funny story, but if you don’t want people like my dad intercepting your comms, maybe stick to encrypted channels. 

The one big thing 

Talos' Yuri Kramarz published a blog highlighting how AI-driven vulnerability discovery has completely outpaced human patching capabilities. With frontier AI models autonomously discovering and exploiting zero-days in minutes, the traditional vulnerability lifecycle has completely collapsed. To survive this hyper-accelerated threat environment, organizations must abandon patch-reliant strategies and embrace a three-stage fallback model built on foundational security principles. 

Why do I care? 

Speed is the new, terrifying multiplier in the traditional risk equation. When an AI can uncover a decades-old zero-day and write an exploit for it in minutes, relying solely on vulnerability management is a losing game. Defenders must accept that some exploitation will inevitably slip through the cracks. The true measure of security is no longer just prevention, but how well your environment can absorb, detect, and survive the initial blow. 

So now what? 

Stop treating security basics like optional compliance checkboxes. Enforce multi-factor authentication (MFA) everywhere, harden devices using CIS benchmarks, and implement strict network segmentation to limit an attacker's blast radius. Since hardened systems only slow attackers down, deploy behavioral-based EDR, NDR, and XDR to catch the post-exploitation activity that signatures miss. Finally, validate these controls through penetration testing and purple team exercises so your incident response playbooks become muscle memory, not just wishful thinking. Read the full blog for more. 

Top security headlines of the week 

CISA gives U.S. federal agencies three days to fix a VPN bug under attack by Qilin 
Check Point Software said the bug affects several of its remote access tools, firewalls, and VPNs, which act as digital gatekeepers to protect company networks from unauthorized access. (TechCrunch

Anthropic launches Claude Fable 5: Mythos-class AI with cybersecurity guardrails  
The AI giant says this marks the first time a model of this capability class has been deemed safe enough for widespread public and developer access. (SecurityWeek

Microsoft fixes two high-severity zero-days disclosed by researcher 
The vulnerability is a local privilege escalation, meaning it can be chained to a separate vulnerability to give users or processes with low-level privileges the ability to defeat OS protections and gain full SYSTEM rights needed to install malware. (Ars Technica

WhatsApp catches spyware firm NSO defying no-hacking court order 
According to WhatsApp, the spyware maker has violated the permanent injunction. The messaging app reported on Monday that it had recently learned of a social engineering attack that attempted to trick users into clicking on malicious links. (SecurityWeek

High-severity vulnerability in Linux caused by a single faulty character 
The presence of a single mis-issued exclamation point in code implementing nf_tables introduced a use-after-free, a class of vulnerability that corrupts memory by placing malicious code at memory addresses that haven’t been properly freed of their previous contents. (Ars Technica

Can’t get enough Talos? 

Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting 
Learn how Cisco Talos Threat Hunting uses hypothesis-driven methods and multi-domain telemetry correlation to find stealthy threats operating below automated detection thresholds. 

Winning the cyber marathon with Tony Giandomenico 
In the high-speed world of cybersecurity, the difference between a breach and a breakthrough often comes down to endurance. Tony Giandomenico, Senior Director of Product Management with Cisco Talos, joins me to discuss Talos Threat Hunting, the challenges of leading major product launches, and the grueling discipline of Ironman triathlons. 

When synthetic logs don’t lie: Generating coherent attack stories for better detection 
Are your detection rules failing because your test data lacks the nuance of a real-world network?  In this episode of Talos Takes, Amy sits down with David Bianco to discuss why traditional synthetic data often falls short and how his new open-source project, EvidenceForge, is changing the game. 

Upcoming events where you can find Talos 

Most prevalent malware files from Talos telemetry over the past week 

SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
MD5: 2915b3f8b703eb744fc54c81f4a9c67f  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
Example Filename: VID001.exe  
Detection Name: Win.Worm.Coinminer::1201** 

SHA256: 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974  
MD5: aac3165ece2959f39ff98334618d10d9  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974 
Example Filename: d4aa3e7010220ad1b458fac17039c274_63_Exe.exe  
Detection Name: W32.Injector:Gen.21ie.1201 

SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 
MD5: 7bdbd180c081fa63ca94f9c22c457376 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 
Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe 
Detection Name: Win.Dropper.Miner::95.sbx.tg** 

SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
MD5: 38de5b216c33833af710e88f7f64fc98 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
Example Filename: sample.exe  
Detection Name: Win.Tool.Procpatcher::1201 

Reporting from Vegas: Networking, AI, and good boys

Reporting from Vegas: Networking, AI, and good boys

Welcome to this week’s edition of the Threat Source newsletter. 

Howdy friends, and hello from Cisco Live U.S., here in sunny (and very hot) Las Vegas!  

An interesting quirk of being sent to one of these events is you learn to understand your limits as a person. Cisco Live is a three-day event, and it encompasses so many people, partners, workshops, CTFs (!!), and symposiums. I can confidently say that here on day three, I’ve had rarely a moment’s rest and, as they say, my dogs are barking.  

Speaking of dogs, did you know that at Cisco Live we have therapy dogs? Healing Hounds is a local Las Vegas therapy dog volunteer group, and Splunk sponsored them this year. Every two hours, the goodest boys and girls rotate in and you can stop what you are doing to immediately go give them pets. Look at these cute faces. LOOK AT THEM.

Reporting from Vegas: Networking, AI, and good boys

Back to limits. One thing I’ve discovered is that conferences like this can be loud. I don’t mind loud. Loud is fine. But eight hours of noise at high levels is stressful. So, I use my Apple AirPods in noise cancelling mode, and it keeps even a massive conference like CLUS to a very manageable dull roar. If you own a pair, or any earplugs, trust me. Use them. It’s not going to shut out the world, but it will give you more stamina in an environment with bright lights and loud noises.

With that much stimuli for an extended period, you must create some space for yourself. Conferences that have quiet or chill spaces, shout out to you! A place for humans to find a moment of rest in the endurance contest that is a technology convention is a wonderful thing.

So what is the vibe at CLUS? AI. All the AI. Not from a product perspective, but from an infrastructure and security perspective. How do folks plan to move and manage that much data, especially in an agentic world? It’s a hot debate, given what I’ve listened to so far. Every business is struggling with it in their own ways, and conferences like CLUS are good opportunities to put those companies in the same room and ideate on ways to process and defend in an AI world. We’re talking many hundreds of zettabytes of data daily, the kind of data pipelines the entire world runs on. At that scale, the challenge is just wild and almost incomprehensible. I’m glad I could help and be a part of those discussions.

As the summer starts, the great patchening is coming as vendors start issuing rapid patches and CVE advisories. This is the quiet before the storm, so enjoy these cute dog photos! Black Hat and DEF CON are around the corner, as well! And always find time during these fire drills to take care of yourself, and if you can, pet some dogs.

The one big thing 

Cisco Talos is expanding our Threat Hunting program to proactively track down advanced adversaries who deliberately slip past traditional detection thresholds. By combining AI-driven telemetry analysis with human expert validation, we continuously hunt for hidden threats across endpoint, network, and identity data. This hypothesis-driven approach allows us to identify complex intrusions — like a recent KongTuke command-and-control (C2) discovery — before a formal detection signature even exists. 

Why do I care? 

Most security tools operate on a simple principle: If a known-bad pattern appears, fire an alert. But as threat actors increasingly leverage AI to move faster and intentionally stay under the radar, relying solely on automated alerts leaves massive blind spots. Hypothesis-driven hunting addresses this gap by correlating weak signals across an environment, allowing defenders to piece together ambiguous anomalies and uncover sophisticated intrusions that would otherwise go unnoticed. 

So now what? 

If your team lacks the dedicated headcount for continuous hunting, Cisco Talos Threat Hunting can bridge the gap. Reach out to your Cisco account team, explore our new dedicated portal in Cisco Security Cloud Control, and read the full blog for a detailed breakdown of our recent KongTuke C2 investigation. 

Top security headlines of the week 

Global stock exchange hit by monthslong email campaign 
A threat actor got a near-continuous view into an influential finance executive's email inbox, thanks to clever use of legitimate, native Windows tools. (Dark Reading

One-click GitHub dev attack lets attackers steal full GitHub OAuth tokens 
The vulnerability allows attackers to install malicious VS Code extensions that steal GitHub OAuth tokens when they are passed to GitHub.dev by exploiting a message-passing mechanism between the main VS Code window and webviews. (The Hacker News

FBI-flagged phishing kit “Kali365” expands its reach 
Once targeting just Microsoft 365, the phishing-as-a-service platform now aims at AWS, Okta, and Russian platforms, while relying on device code phishing. (Dark Reading

Dozens of Red Hat packages backdoored through its official NPM channel 
Official Red Hat NPM accounts have been compromised and used to push a malicious worm that spreads from machine to machine, where it pilfers sensitive credentials in hopes of stealing yet more confidential data, researchers said. (Ars Technica

“HTTP/2 Bomb” exploit knocks web servers offline in seconds 
The attack potentially affects over 880,000 websites that support HTTP/2 and run default NGINX, Apache HTTPD, Microsoft IIS, Envoy, or Cloudflare Pingora configurations. (SecurityWeek

Can’t get enough Talos? 

Winning the cyber marathon with Tony Giandomenico 
In the high-speed world of cybersecurity, the difference between a breach and a breakthrough often comes down to endurance. Tony Giandomenico, Senior Director of Product Management with Cisco Talos, joins me to discuss Talos Threat Hunting, the challenges of leading major product launches, and the grueling discipline of Ironman triathlons. 

When synthetic logs don’t lie: Generating coherent attack stories for better detection 
Are your detection rules failing because your test data lacks the nuance of a real-world network?  In this episode of Talos Takes, Amy sits down with David Bianco to discuss why traditional synthetic data often falls short and how his new open-source project, EvidenceForge, is changing the game. 

Upcoming events where you can find Talos 

Most prevalent malware files from Talos telemetry over the past week 

SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
MD5: 2915b3f8b703eb744fc54c81f4a9c67f  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 
Example Filename: VID001.exe  
Detection Name: Win.Worm.Coinminer::1201 

SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
MD5: 38de5b216c33833af710e88f7f64fc98  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
Example Filename: sample.exe 
Detection Name: Win.Tool.Procpatcher::1201 

SHA256: c0ad494457dcd9e964378760fb6aca86a23622045bca851d8f3ab49ec33978fe 
MD5: bf9672ec85283fdf002d83662f0b08b7  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c0ad494457dcd9e964378760fb6aca86a23622045bca851d8f3ab49ec33978fe 
Example Filename: f_000b97.html  
Detection Name: W32.C0AD494457-95.SBX.TG 

SHA256: afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 
MD5: cc4d231df34e57f59eb970353c7d9de2  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638  
Example Filename: AutoPico.exe  
Detection Name: PUA.Win.Tool.Kmsactivator:: 

SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 
MD5: 7bdbd180c081fa63ca94f9c22c457376  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 
Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe  
Detection Name: Win.Dropper.Miner::95.sbx.tg**

Less panic patching, more precision

Less panic patching, more precision

Welcome to this week's edition of the Threat Source newsletter. 

Recently, Martin closed his introduction with a warning: Ready or not, the time of much patching is coming. I've been chewing on that one for a while because I'm rethinking my own enrichment pipelines along these lines, and the questions Martin raised are the ones I keep running into — with one or two ideas on what practitioners can actually do about it. 

Honestly speaking, most of us are still prioritising the wrong way. CVSS has been the default for over a decade — but it only answers one question: How bad could this be in theory? It's a severity score, not a risk score. A CVSS 9.8 on something nobody is exploiting (and nobody ever will) is a very different problem from a CVSS 7.2 that's being weaponised in the wild this morning. If your patch queue is sorted purely by CVSS, you'respending finite operations capacity on hypotheticals. 

This is where EPSS (Exploit Prediction Scoring System) earns its place next to CVSS. EPSS is a probability — between 0 and 1 — that a given CVE will be exploited in the next 30 days, based on real-world signals. The two answer different questions:

Feature 

CVSS 

EPSS 

Focus 

Severity (impact) 

Risk (likelihood of exploitation) 

Nature 

Static (usually) 

Dynamic (updated daily) 

Output 

0.0 to 10.0 score 

0.0 to 1.0 probability 

Primary use 

Assesses technical impact 

Prioritizes remediation 



CVSS tells you how bad it would be if exploited. EPSS tells you how likely it is to actually happen to you soon. Used together, a high CVSS and a high EPSS is your "drop everything" pile, while a high CVSS and a very lowEPSS can probably wait behind a medium with an EPSS of 0.7. That single change in triage logic can meaningfully shrink the patch backlog without weakening your posture. 

The second ingredient is knowing what is actually being exploited — and here, many teams default to CISA's KEV catalog. KEV is excellent, and I've quoted KEV numbers in this newsletter more times than I can count. CISA contributes as an Authorized Data Publisher (ADP) in the CVE Program, enriching records alongside the original CNA's data. That model works well, but it's also why KEV is structurally centralized, conservative in what it admits, and naturally scoped to what U.S. federal visibility surfaces. For a global practitioner — and writing this from Germany, I notice — "Is this being exploited?" deserves a broader lens. 

That broader lens is starting to take shape with GCVE (Global CVE), a decentralized approach to vulnerability identification and enrichment. Two properties matter for the surge that's coming: 

  1. Speed of enrichment. Because GCVE is decentralized, enrichment data — references, affected products, exploit indicators — doesn't have to wait in a single queue. In practice, actionable context arrives meaningfully faster than the traditional NVD pipeline, which has visibly struggled with backlog over the past two years. 
  2. Broader exploitation signal. Rather than a single authoritative list of what is being exploited, GCVE makes room for multiple sources of exploitation evidence to surface against the same identifier. That gives defenders outside the U.S. (and frankly, inside it too) a more complete picture than KEV alone. 

Pair that with EPSS on top of CVSS, and you end up with a triage stack that is faster, broader, and probability-informed rather than only severity. 

None of this removes the patching workload that is coming, but it does change which patches you sprint on at 2:00 a.m. and which ones can ride the normal cycle. Before the surge arrives, that's a worthwhile thing to get right.

The one big thing 

Cisco Talos released EvidenceForge, a new open-source tool designed to generate highly realistic, correlated synthetic security logs. This tool solves the chronic shortage of high-quality, labeled datasets needed to train threat hunters and validate detection logic. By using a single canonical event model and AI-assisted scenario authoring, EvidenceForge ensures causal and temporal consistency across more than 20 log formats. 

Why do I care? 

Relying on heavily scrubbed public datasets or red team engagements often leaves security teams with incomplete telemetry. While most synthetic generators spit out independent events that fail to tell a coherent story, EvidenceForge injects realistic background noise, red herrings, and proper causal sequencing into the mix. This allows your team to work with synchronized datasets that (more) accurately mimic real-world network visibility without the compliance headaches of using production data. 

So now what? 

Security teams can head over to GitHub to clone the EvidenceForge repository and use its guided conversation feature to build custom attack scenarios. Defenders can then use these newly generated datasets to build robust SOC analyst training programs, stress-test a new SIEM, and validate detection pipelines before they touch a production environment. You can find the full details and the link to the open-source repository in the blog post

Top security headlines of the week 

Lawmakers demand answers as CISA tries to contain data leak 
Lawmakers are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after a contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub account. (KrebsOnSecurity

Over 5,500 GitHub repositories infected in “Megalodon” supply chain attack 
The campaign relies on GitHub Actions workflows containing a payload designed to steal credentials, keys, tokens, and other secrets. The workflows were injected through over 5,700 malicious commits pushed to the impacted repositories on May 18. (SecurityWeek

Authorities seized 800 servers of hosting company used to launch cyber attacks 
The investigation centers on a web hosting company established on Feb. 10, 2022, weeks before Russia invaded Ukraine. The infrastructure was allegedly used to support cyber attacks, disinformation campaigns, and sanctions evasion linked to Russia. (CyberSecurityNews

Content delivery exploit opens websites to brand hijacking 
The Underminr domain-fronting attack allows threat actors to modify web requests and leverage trusted websites to cloak malicious activity. (Dark Reading

Cisco’s risk-based vulnerability disclosure in the age of AI 
Cisco is adapting its vulnerability disclosure practices, focusing on increasing the visibility of detailed technical information for vulnerabilities that are critical, actively exploited, or have a higher likelihood of exploitation. (Cisco blog

Can’t get enough Talos? 

DICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heap 
Hospitals rely on DICOM-based PACS systems, and those systems often automatically ingest files received over the network. Our latest white paper presents a concrete case study demonstrating the creation of a heap overflow vulnerability through the exploitation of the DICOM file format. 

MediaArea heap-based buffer overflow vulnerabilities 
MediaArea produces digital media analysis open-source software, as well as support tools for file investigation. Talos discovered four vulnerabilities in MediaInfoLib, which provides a UI for technical and tag data for video and audio media files.

Breaking things to keep them safe with Philippe Laulheret 
From his memorable experiment using a green onion to bypass a biometric fingerprint reader to his experience on the frontlines of cybersecurity, Philippe shares the journey that led him to vulnerability research. 

Upcoming events where you can find Talos 

Most prevalent malware files from Talos telemetry over the past week 

SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
MD5: 2915b3f8b703eb744fc54c81f4a9c67f  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 
Example Filename: VID001.exe  
Detection Name: Win.Worm.Coinminer::1201** 

SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
MD5: 38de5b216c33833af710e88f7f64fc98  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
Example Filename: sample.exe  
Detection Name: Win.Tool.Procpatcher::1201 

SHA256: 5e6060df7e8114cb7b412260870efd1dc05979454bd907d8750c669ae6fcbcfe 
MD5: a2cf85d22a54e26794cbc7be16840bb1 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=5e6060df7e8114cb7b412260870efd1dc05979454bd907d8750c669ae6fcbcfe 
Example Filename: a2cf85d22a54e26794cbc7be16840bb1.exe  
Detection Name: W32.5E6060DF7E-100.SBX.TG 

SHA256: afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 
MD5: cc4d231df34e57f59eb970353c7d9de2 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 
Example Filename: AutoPico.exe 
Detection Name: PUA.Win.Tool.Kmsactivator::1201 

The art of being ungovernable

The art of being ungovernable

Welcome to this week’s edition of the Threat Source newsletter.  

“It takes very little to govern good people. Very little. And bad people can’t be governed at all. Or if they could, I never heard of it.” ― Cormac McCarthy, No Country for Old Men 

Most of my career has been built on dichotomy: striving to be a supportive teammate while also pushing every boundary in front of me. I've often been told to “never do X, only do Y,” but I’ve invariably chosen to do X anyway (even when fraught with peril) to get to the deeper answer. For years, I was told that I should perform in certain ways — instead of in ways that made sense for my brain and way of learning. 

I wasn’t governable, but I wasn’t bad. Just ... challenging. While Sheriff Ed Tom Bell’s view of good vs. bad is compelling, maybe our careers should be defined as “acquiescent” vs. “challenging.” It’s less of an existential crisis that way. 

Over the past few years, I’ve been enjoying the mentoring aspect of my career. One of the things that I love to share with people is that being ungovernable is very challenging early in career; it’snot a favorite of middle management, but it can take you to places that you really want to be (i.e., Talos). The road is going to be longer and much bumpier than your governable cohort, but this is the long con. 

The path to Talos was long and arduous, but I've learned to make my career choices through the lens of the axiom, “If you’re the smartest person in the room, you’re in the wrong room.” It's been the only guidepost I’ve needed. I don’t know that it applies to everyone, because everyone is unique, but it absolutely helps me decide what I want to learn, what I want to dive into, who I want to surround myself with. 

The secret lies in the last comment — it's the people. If you continue to search for the smartest people in the room, you’ll find it and when you do, you’ll find that you aren’t ungovernable — rather, you’re understood. Be ungovernable (but kind) in the short term, find new ways to solve problems, think around solutions in new ways, program in different languages, and be the person in the meeting that says, “I think we should do Y instead, and here’s why.” 

I suspect that this is the same approach many of you already take in your daily roles when identifying threats vs. benign activity, choosing your pivots in hunting, or deciding the priorities in device replacement. It’s a natural direction for the intellectually curious, so be kind, but ungovernable. 

“The future of intelligence must be about search, while the future of ignorance must be about the inability to evaluate information.” ― Patricia Lockwood, No One Is Talking About This 

The one big thing 

Cisco Talos has recently discovered a commodity BadIIS malware variant fueling a thriving malware-as-a-service (MaaS) ecosystem for Chinese-speaking cybercrime groups. Identifiable by its embedded "demo.pdb" strings, this toolset boasts a multi-year development cycle complete with builder tools and persistence mechanisms. Threat actors are leveraging this robust framework to easily execute malicious search engine optimization (SEO) fraud, hijack server content, and redirect traffic to illicit sites. 

Why do I care? 

This is a highly active, commercially driven malware ecosystem. The author constantly pushes rapid updates to introduce new features and actively evade specific security vendors, making it a persistent headache for defenders. Because this BadIISvariant is sold as a commodity tool, it lowers the barrier to entry for cybercriminals, leading to widespread attacks that silently hijack server traffic without triggering obvious alarms. 

So now what? 

Defenders should actively monitor IIS environments for unauthorized traffic redirection, unexpected reverse proxying, or sudden spikes in "503 Service Unavailable" errors. Threat hunting efforts should also target the distinct "demo.pdb" strings and associated Chinese-language folder paths within IIS binaries. Ensure your endpoint detection solutions are updated to catch these reactive evasion tactics, and read the full blog for complete coverage and indicators of compromise (IOCs). 

Top security headlines of the week 

CISA exposes secrets, credentials in “private” repo 
A researcher discovered a public GitHub repository belonging to CISA that contained 844MB of sensitive data, including plain-text passwords, authentication tokens, and other secrets. (Dark Reading

NYC Health + Hospitals says hackers stole medical data and fingerprints, affecting at least 1.8 million people 
The breach is particularly sensitive because hackers stole biometric information, including fingerprints and palm prints, which affected individuals have for life and cannot replace. (TechCrunch

Bug bounty businesses bombarded with AI slop 
Companies that pay hackers to find flaws in their software are being inundated with low-quality (often false) reports generated by AI, forcing some to suspend the programs altogether. (Ars Technica

Four OpenClaw flaws enable data theft, privilege escalation, and persistence 
The vulnerabilities, collectively dubbed Claw Chain, can permit an attacker to establish a foothold, expose sensitive data, and plant backdoors. (The Hacker News

New NGINX vulnerability allows remote attackers to trigger malicious code 
A new vulnerability in NGINX JavaScript (njs) allows unauthenticated remote attackers to trigger a heap‑based buffer overflow that can lead to denial‑of‑service and, in some conditions, remote code execution in the NGINX worker process. (Cyber Security News

Can’t get enough Talos? 

TP-Link, Photoshop, OpenVPN, Norton VPN vulnerabilities 
Talos’ Vulnerability Discovery & Research team recently disclosed eight vulnerabilities in TP-Link, and one each in Adobe Photoshop, OpenVPN, and Gen Digital's Norton VPN. The vulnerabilities have been patched by their respective vendors. 

Webinar: AI found the problem. Now what? 
Experts from Talos and Cisco Security will examine how AI is changing the game for both defenders and well-resourced adversaries, and why the most persistent risks often remain rooted in unpatched legacy systems. 

Breaking things to keep them safe with Philippe Laulheret 
From his memorable experiment using a green onion to bypass a biometric fingerprint reader to his experience on the frontlines of cybersecurity, Philippe shares the journey that led him to vulnerability research. 

Upcoming events where you can find Talos 

Most prevalent malware files from Talos telemetry over the past week 

 SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
MD5: 2915b3f8b703eb744fc54c81f4a9c67f  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
Example Filename: VID001.exe  
Detection Name: Win.Worm.Coinminer::1201** 

SHA256: d87e8d9d43758ce67a8052cb2334b99cc24f9b0437ee44815f360be0b22d835a  
MD5: 362498c3e71eeaa066a67e4a3f981d1c  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=d87e8d9d43758ce67a8052cb2334b99cc24f9b0437ee44815f360be0b22d835a  
Example Filename: TunMirror.exe  
Detection Name: PUA.Win.Tool.Tunmirror::1201 

SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f  
MD5: 38de5b216c33833af710e88f7f64fc98  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f  
Example Filename: SECOH-QAD.exe  
Detection Name: Win.Tool.Procpatcher::1201 

SHA256: acd55c44b8b0d66d66defed85ca18082c092f048d3621da827fce593305c11fd  
MD5: 0f03f72a92aef6d63eb74e73f8ac201d  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=acd55c44b8b0d66d66defed85ca18082c092f048d3621da827fce593305c11fd  
Example Filename: KMSSS.exe  
Detection Name: PUA.Win.Tool.Hackkms::1201 

SHA256: 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974  
MD5: aac3165ece2959f39ff98334618d10d9  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974  
Example Filename: d4aa3e7010220ad1b458fac17039c274_63_Exe.exe  
Detection Name: W32.Injector:Gen.21ie.1201

The time of much patching is coming

The time of much patching is coming

Welcome to this week’s edition of the Threat Source newsletter. 

Many solutions have been proposed to reduce software bugs: zero-defect mandates, pair programming, formal methods, and mathematical software proofs. The reality is that software engineering is hard. Identifying and fixing bugs before they make it into production code is hard. Source code peer review and extensive unit testing have improved code quality, but bugs still get through. 

Not every bug is a vulnerability, and not every fault that appears to be a vulnerability can be usefully exploited. Nevertheless, through extensive testing and review, a skilled vulnerability researcher can still uncover faults in software that has already undergone rigorous quality assurance. However, skilled vulnerability researchers are a scarce resource and can only review so much software. 

AI is the great hope for improving software quality. Iterative improvements in AI's ability to find bugs mean that each new version of these systems is better than the last. We’re now at the point where AI, although still not as good as a skilled vulnerability researcher, can scan code to find errors at a scale and speed that human analysis cannot match. Used well, it can identify potential vulnerabilities before they reach production. 

In the long term, this is very good news. Better automated review and analysis of software is how we will improve code quality. However, in the short term, decades of technical debt and latent errors will be uncovered and will need to be addressed. To make things more complex, threat actors will have access to these same tools to search for exploitable vulnerabilities for their own ends. 

The result is likely to be a surge in patches. More vulnerabilities discovered means more fixes released, placing additional pressure on already stretched operations teams. Many of these patches will be urgent; some will address vulnerabilities that are being actively exploited. Without proper planning, the volume of fixes may outpace an organization's capacity to deploy them.

The surge of patches has yet to happen, but the first signs may already be visible. Now is an excellent time to consider how you prioritise patching, apply patches at scale, and manage systems that cannot be patched quickly — or at all. We can reflect on these questions now, and improve our processes, or we can flounder when the surge of patches arrives. Either way, ready or not, the time of much patching is coming. 

The one big thing 

In Cisco Talos’ latest blog, we outline the differences between responding to state-sponsored threat actors and handling commodity ransomware. These advanced adversaries log in using valid credentials and leverage your own trusted tools to remain invisible for months. Because their primary objectives are long-term espionage and pre-positioning rather than immediate financial gain, standard incident response playbooks are entirely inadequate.  

Why do I care? 

State-sponsored actors operate inside your trust boundary and aim to remain completely undetected. They have the patience and resources to map your infrastructure, exploit supply chain vulnerabilities, and blend their lateral movement into routine administrative tasks. If your security architecture assumes internal traffic is inherently trustworthy, these adversaries will exploit that gap to establish deep, persistent access across both IT and operational technology environments. Prematurely containing these threats can even tip off the attacker, causing you to lose critical intelligence and the chance to fully eradicate their foothold.

So now what? 

Shift to a zero trust architecture that continuously verifies access and plans for inevitable failures, starting with maximizing your visibility through centralized log aggregation and enabling Windows command-line and PowerShell script block logging. Prioritize identity management by enforcing multi-factor authentication on all administrative accounts and implementing a tiered access model. Update your incident response playbooks to specifically address living-off-the-land techniques, supply chain compromises, and the complex operational timing required for state-sponsored containment. Read the blog here for more information. 

Top security headlines of the week 

Linux bitten by second severe vulnerability in as many weeks 
The leaked exploit is deterministic, meaning it works precisely the same way each time it’s run and across different Linux distributions. It causes no crashes, making it stealthy to run. Install patches immediately. (Ars Technica

A DOD contractor’s API flaw exposed military course data and service member records 
The issue affected Schemata, an AI-powered virtual training platform used in military and defense settings. According to Strix, an ordinary low-privilege account was able to access data across multiple tenants. (CyberScoop

Fake OpenAI Privacy Filter repo hits No. 1 on Hugging Face, draws 244K downloads 
A malicious repository managed to take a spot in the platform's trending list by impersonating OpenAI's Privacy Filter open-weight model to deliver a Rust-based information stealer to Windows users. (The Hacker News

TanStack, Mistral AI, UiPath hit in fresh supply chain attack 
The same as in previous campaigns, the worm targets sensitive information, including developer credentials, API keys, tokens, cloud credentials and secrets, cryptocurrency wallets, and more. (SecurityWeek

Official CheckMarx Jenkins package compromised with infostealer 
Checkmarx warned over the weekend that a rogue version of its Jenkins Application Security Testing (AST) plugin had been published on the Jenkins Marketplace. (BleepingComputer

Can’t get enough Talos? 

Breaking things to keep them safe with Philippe Laulheret 
From his memorable experiment using a green onion to bypass a biometric fingerprint reader to his experience on the frontlines of cybersecurity, Philippe shares the journey that led him to vulnerability research. 

Inside the SOC: AI-powered DNS defense against ransomware 
Learn how Cisco Talos' advanced AI-driven detection, including domain generation algorithm (DGA) analysis, integrates within Cisco Secure access to proactively identify and predict malicious domains. 

Clustering and reuse of phone numbers in scam emails 
Cisco Talos has recently started to collect and gather intelligence around phone numbers within emails as an additional indicator of compromise (IOC). In this blog, we discuss new insights into in-the-wild phone number reuse in scam emails.   

Upcoming events where you can find Talos 

Most prevalent malware files from Talos telemetry over the past week 

SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
MD5: 2915b3f8b703eb744fc54c81f4a9c67f  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
Example Filename: VID001.exe  
Detection Name: Win.Worm.Coinminer::1201** 

SHA256: 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974  
MD5: aac3165ece2959f39ff98334618d10d9  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974  
Example Filename: d4aa3e7010220ad1b458fac17039c274_63_Exe.exe  
Detection Name: W32.Injector:Gen.21ie.1201 

SHA256: e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba  
MD5: dbd8dbecaa80795c135137d69921fdba  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba  
Example Filename: u112417.dat  
Detection Name: W32.Variant:MalwareXgenMisc.29d4.1201 

SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59  
MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59  
Example Filename: APQ9305.dll  
Detection Name: Auto.90B145.282358.in02

Unplug your way to better code

Unplug your way to better code

Welcome to this week’s edition of the Threat Source newsletter.

Hey, you. Yeah, you! The person endlessly scrolling or typing away at their computer. Did you touch grass today? It's just an expression, but if nature’s your thing, that works just fine.

What I do mean is that due to the nature of the field, cybersecurity is incredibly intangible. You can’t reach out and touch your logs, or the packets traversing your network, or the concept of DNS exfiltration... and if you tried, you’d just feel the smooth surface of your computer screen. (What a boring texture.) Spending all our time in the abstract can create some serious mental fatigue.

My point is that there’s something powerful to be said about engaging with the physical world. When we engage in a tactile hobby, we give our brains a hard reset. By moving from the abstract to the physical, our brains get the time and space to process the complex problems we’ve been staring at, often leading to the “aha!” moment that never comes when you're trying to force it.

The other week, I was working in the Talos office with the Creative team. It was a quiet afternoon, people’s energy sapped by stomachs full of Mediterranean food. That was swiftly interrupted (in the best way) when Joe Marshall came over into our work area with his miniature painting kit, broke it open, and started teaching us how to drybrush 3D-printed figurines. Everyone immediately came alive. While I didn’t partake (I know, “Do as I say, not as I do”), it reminded me of how revitalized I feel when I get outside for a walk during lunch or spend 10 minutes knitting in silence between meetings. There’s nothing to focus on but the feel of the yarn between your fingers, the clacking of the needles, and the repetitive motions that result in a physical object you can wear and fish for compliments about.

Speaking of, do you think the vest I knit is cool? All compliments can be sent to me on LinkedIn, and I refuse to accept any negative comments. (Critiques are fine.)

Unplug your way to better code

Ahem... anyway. Go on a walk without your earbuds, listen to the wind through the leaves, ask a stranger to pet their dog, watch a pigeon bop its head around, and reach out to touch a cool-looking rock or the lichen on a tree. I hear you saying, "That’s some tree-hugging bullshit,” and counter you with, “Just humor me, okay? What’s the worst that could happen?”

If you’re more of an inside person, the goal might be to find a physical anchor for your technical interest. Maybe it’s building a mechanical keyboard from scratch — feeling the weight of the switches and hearing the click of the keycaps. Maybe it’s a complicated LEGO set. Even something as simple as making espresso or organizing your bookshelf can provide that sensory feedback your brain is craving.

If you're not currently facing a life-altering deadline, take 10 minutes and try it now. The rest of the newsletter isn’t going anywhere, I promise.

When you pay attention to the noises you hear, the colors you see, and the textures under your fingertips, you might come back to your laptop refreshed, focused, and ready to solve the next problem.

The one big thing 

Cisco Talos has recently expanded our threat intelligence capabilities to track phone numbers as critical indicators of compromise (IOCs) in scam emails. Our latest research reveals that attackers heavily favor API-driven VoIP numbers to execute high-volume, cost-effective Telephone-Oriented Attack Delivery (TOAD) campaigns. To evade detection, these threat actors rotate through sequential blocks of numbers, use strategic cool-down periods, and recycle the exact same digits across completely unrelated lures and impersonated brands. 

Why do I care? 

Tracking ephemeral sender email addresses is a losing game, but phone numbers are the true operational anchors for these organized scam call centers. Because attackers reuse these numbers across multiple document types and brand impersonations, defenders who cluster this telephony infrastructure can expose the broader network of malicious activity. Understanding these reuse patterns gives defenders a much-needed edge in mapping out and dismantling these operations before users are manipulated into handing over sensitive data. 

So now what? 

Security teams should shift their focus toward clustering scam lures based on shared phone numbers and prioritize real-time reputation monitoring to flag high-risk infrastructure. Deploying an AI-powered email security solution like Cisco Secure Email Threat Defense can also help evaluate different portions of incoming emails to catch these targeted threats. A full list of indicators of compromise (IOCs) associated with these campaigns can be found in the blog.

Top security headlines of the week 

DigiCert revokes certificates after support portal hack 
The attack, the company said in a detailed report, occurred on April 2, when a threat actor targeted DigiCert’s support team with a malicious payload delivered via a customer chat channel, disguised as a screenshot. (SecurityWeek

Ubuntu services hit by outages after DDoS attack 
The DDoS-for-hire service in this case claims to power attacks in excess of 3.5 Tbps, which is about half of the bandwidth of a cyberattack that Cloudflare last year called the “largest DDoS attack ever recorded.” (TechCrunch

Canvas maker Instructure reveals data breach 
Instructure said the actors accessed “certain identifying information of users” at affected institutions, including names, email addresses, student ID numbers, and user communications. (Tech Radar

Exploitation of “Copy Fail” Linux vulnerability begins 
Threat actors are exploiting a recently disclosed Linux kernel vulnerability leading to root shell access, the US cybersecurity agency CISA warns. Dubbed Copy Fail, the security defect impacts all Linux distributions since 2017. (SecurityWeek

Student hacked Taiwan high-speed rail to trigger emergency brakes 
According to local reports, the student halted four trains for 48 minutes by using software-defined radio (SDR) communications and handheld radios to transmit a high-priority “General Alarm” signal, triggering emergency braking procedures. (BleepingComputer

Can’t get enough Talos? 

Tales from the Frontlines 
In this briefing, we’ll share behind-the-scenes insights from the most critical and high-impact incidents we responded to in the last quarter. This isn't a report walkthrough; it's a look at what really happened, how we handled it, and what it means for your organization. 

UAT-8302 and its box full of malware 
Cisco Talos is disclosing UAT-8302, a sophisticated, China-nexus APT group targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025. 

CloudZ RAT potentially steals OTP messages using Pheno plugin 
Cisco Talos discovered an intrusion, active since at least January 2026, where an unknown attacker implanted a CloudZ remote access tool (RAT) and a previously undocumented plugin called “Pheno.” 

The trust paradox: How attackers weaponize legitimate SaaS platforms 
In this episode of Talos Takes, Amy Ciminnisi sits down with researcher Diana Brown to discuss the rise of "platform-as-a-proxy" (PAP) attacks. 

Upcoming events where you can find Talos 

Most prevalent malware files from Talos telemetry over the past week 

SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
MD5: 2915b3f8b703eb744fc54c81f4a9c67f  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
Example Filename: VID001.exe  
Detection Name: Win.Worm.Coinminer::1201** 

SHA256: 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974  
MD5: aac3165ece2959f39ff98334618d10d9  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974  
Example Filename: d4aa3e7010220ad1b458fac17039c274_63_Exe.exe  
Detection Name: W32.Injector:Gen.21ie.1201 

SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59  
MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59  
Example Filename: APQ9305.dll  
Detection Name: Auto.90B145.282358.in02 

SHA256: e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba  
MD5: dbd8dbecaa80795c135137d69921fdba  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba  
Example Filename: u112417.dat  
Detection Name: W32.Variant:MalwareXgenMisc.29d4.1201 

SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 
MD5: 7bdbd180c081fa63ca94f9c22c457376  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91  
Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe  
Detection Name: Win.Dropper.Miner::95.sbx.tg** 

❌