๐Ÿ”’
There are new articles available, click to refresh the page.
Before yesterdayCisco Talos

Threat Source newsletter (Sept. 2, 2021)

2 September 2021 at 18:00
Newsletter compiled by Jon Munshaw.Good afternoon, Talos readers.ย ย  If you haven't seen already, our blog has a lot of cool and new stuff this week. We first dove into the world of proxyware on Tuesday (aka internet-sharing applications). Attackers are hiding in this newly popular...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Beers with Talos, Ep. #109: We have not secured our society โ€” Or, working out a conference talk in realtime

2 September 2021 at 20:33
Beers with Talos (BWT) Podcast episode No. 109 is now available. Download this episode and subscribe to Beers with Talos:Apple Podcastsย Google PodcastsSpotifyย ย StitcherIf iTunes and Google Play aren't your thing, clickย here. Most of the Beers with Talos guys got a chance to take...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Talos Takes Ep. #66: Dude, where's my bandwidth?

3 September 2021 at 13:09
By Jon Munshaw. The latest episode of Talos Takes is available now. Download this episode and subscribe to Talos Takes using the buttons below, or visit theย Talos Takes page. โ€œProxywareโ€ sounds like a complicated topic that youโ€™re too afraid to ask about. But really, itโ€™s just software that...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Threat Roundup for August 27 to September 3

3 September 2021 at 16:57
Today, Talos is publishing a glimpse into the most prevalent threats we've observed between Aug. 27 and Sept. 3. As with previous roundups, this post isn't meant to be an in-depth analysis. Instead, this post will summarize the threats we've observed by highlighting key behavioral characteristics,...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Vulnerability Spotlight: Heap buffer overflow vulnerability in Ribbonsoft dxflib library

7 September 2021 at 15:56
Lilith >_> of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.ย  Cisco Talos recently discovered an exploitable heap-based buffer overflow vulnerability in Ribbonsoftโ€™s dxflib library that could lead to code execution.ย  The dxflib library is a C++ library utilized by...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Talos release protection against zero-day vulnerability (CVE-2021-40444) in Microsoft MSHTML

13 September 2021 at 17:45
Cisco Talos released new SNORTยฎ rules Thursday to protect against the exploitation of a zero-day vulnerability in Microsoft MSHTML that the company warns is being actively exploited in the wild.ย  Users are encouraged to deploy SIDs 58120 โ€“ 58129, Snort 3 SID 300049 and ClamAV signature ID:...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Threat Source newsletter (Sept. 9, 2021)

9 September 2021 at 18:00
Newsletter compiled by Jon Munshaw.Good afternoon, Talos readers.ย ย  The biggest security news this week is no doubt another Microsoft zero-day. On the heels of PrintNightmare and multiple Exchange Server vulnerabilities comes a code execution vulnerability in MSHTML, the rendering engine...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Talos Takes Ep. #67: What a leaked playbook tells us about the Conti ransomware group

10 September 2021 at 14:20
By Jon Munshaw. The latest episode of Talos Takes is available now. Download this episode and subscribe to Talos Takes using the buttons below, or visit theย Talos Takes page. There's a lot to take apart in the recently leaked Conti ransomware playbook. After a disgruntled member of the...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Threat Roundup for September 3 to September 10

10 September 2021 at 19:03
Today, Talos is publishing a glimpse into the most prevalent threats we've observed between Sept. 3 and Sept. 10. As with previous roundups, this post isn't meant to be an in-depth analysis. Instead, this post will summarize the threats we've observed by highlighting key behavioral characteristics,...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Vulnerability Spotlight: Code execution vulnerability in Nitro Pro PDF

13 September 2021 at 14:12
A Cisco Talos team member discovered these vulnerabilities. Blog by Jon Munshaw.ย  Cisco Talos recently discovered a vulnerability in the Nitro Pro PDF reader that could allow an attacker to execute code in the context of the application.ย  Nitro Pro PDF is part of Nitro Softwareโ€™s...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Downtime on Talos Intelligence

14 September 2021 at 13:23
TalosIntelligence.com will be down for a short time on Sept. 17 around 10 a.m. ET while we perform some routine maintenance on the site.ย  We apologize for any inconvenience this may cause. We expect the interruption will only last for about 30 minutes.ย ย 

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Microsoft Patch Tuesday for Sept. 2021 โ€” Snort rules and prominent vulnerabilities

14 September 2021 at 17:33
By Jon Munshaw, with contributions from Holger Unterbrink.ย  Microsoft released its monthly security update Tuesday, disclosing 85 vulnerabilities across the companyโ€™s firmware and software. This monthโ€™s release is headlined by an official patch for the critical remote code execution...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Operation Layover: How we tracked an attack on the aviation industry to five years of compromise

16 September 2021 at 17:48
By Tiago Pereira and Vitor Ventura. Cisco Talos linked the recent aviation targeting campaigns to an actor who has been targeting the aviation industry for two years.The same actor has been running successful malware campaigns for more than five years.Although always using commodity malware, the...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Threat Source newsletter (Sept. 16, 2021)

16 September 2021 at 18:00
Newsletter compiled by Jon Munshaw.Good afternoon, Talos readers.ย ย  It's a bird, it's a plane, it's a rat! We've been tracking a series of trojans targeting the aviation industry, and trying to lure victims in by sending them spam related to flight itineraries and other transportation...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Talos Takes Ep. #68: The various pivots and pitfalls in a malware investigation

17 September 2021 at 14:39
By Jon Munshaw. The latest episode of Talos Takes is available now. Download this episode and subscribe to Talos Takes using the buttons below, or visit theย Talos Takes page. On this week's episode, Vitor Ventura from our research team walks through his recent work on connecting several...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Threat Roundup for September 10 to September 17

17 September 2021 at 20:28
Today, Talos is publishing a glimpse into the most prevalent threats we've observed between Sept. 10 and Sept. 17. As with previous roundups, this post isn't meant to be an in-depth analysis. Instead, this post will summarize the threats we've observed by highlighting key behavioral...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines

News summary Cisco Talos recently discovered a new backdoor used by the Russian Turla APT group.We have seen infections in the U.S., Germany and, more recently, in Afghanistan. It is likely used as a stealth second-chance backdoor to keep access to infected devicesIt can be used to download, upload...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Operation โ€œArmor Piercer:โ€ Targeted attacks in the Indian subcontinent using commercial RATs

23 September 2021 at 17:45
By Asheer Malhotra, Vanja Svajcer and Justin Thattil. Cisco Talos is tracking a campaign targeting government personnel in India using themes and tactics similar to APT36 (aka Mythic Leopard and Transparent Tribe).This campaign distributes malicious documents and archives to deliver the Netwire...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Vulnerability Spotlight: Information disclosure vulnerability in D-LINK DIR-3040 mesh router

23 September 2021 at 15:00
Dave McDaniel of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw. Cisco Talos recently discovered an exploitable information disclosure vulnerability in the D-LINK DIR-3040 smart WiFi mesh router that could allow an adversary to eventually turn off the device or remove other...

[[ This is only the beginning! Please visit the blog for the complete entry ]]
โŒ