๐Ÿ”’
There are new articles available, click to refresh the page.
Before yesterdayCisco Talos

Threat Roundup for August 13 to August 20

Today, Talos is publishing a glimpse into the most prevalent threats we've observed between Aug. 13 and Aug. 20. As with previous roundups, this post isn't meant to be an in-depth analysis. Instead, this post will summarize the threats we've observed by highlighting key behavioral characteristics,...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Threat Source newsletter (Aug. 26, 2021)

26 August 2021 at 18:00
Newsletter compiled by Jon Munshaw.Good afternoon, Talos readers.ย ย  We have RATs on RATs on RATs over the past few weeks. And last week, we found a few more heading to Latin America to target users and try to steal their login credentials. The threat actor in this case has some compelling...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Talos Takes Ep: #65: How several RAT campaigns in Latin America are connected

27 August 2021 at 11:33
By Jon Munshaw. The latest episode of Talos Takes is available now. Download this episode and subscribe to Talos Takes using the buttons below, or visit theย Talos Takes page. As more people around the world start to get vaccinated against COVID-19, travel is becoming easier, especially during...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Threat Roundup for August 20 to August 27

Today, Talos is publishing a glimpse into the most prevalent threats we've observed between Aug. 20 and Aug. 27. As with previous roundups, this post isn't meant to be an in-depth analysis. Instead, this post will summarize the threats we've observed by highlighting key behavioral characteristics,...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Attracting flies with Honey(gain): Adversarial abuse of proxyware

By Edmund Brumaghin and Vitor Ventura. With internet-sharing applications, or "proxyware," users download software that allows them to share a percentage of their bandwidth with other internet users for a fee, with the companies that created this software acting as a go-between.As proxyware has...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Translated: Talos' insights from the recently leaked Conti ransomware playbook

2 September 2021 at 12:29
By Caitlin Huey, David Liebenberg, Azim Khodjibaev, and Dmytro Korzhevin. Executive summary Cisco Talos recently became aware of a leaked playbook that has been attributed to the ransomware-as-a-service (RaaS) group Conti. Talos has a team of dedicated, native-level speakers that translated these...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Threat Source newsletter (Sept. 2, 2021)

2 September 2021 at 18:00
Newsletter compiled by Jon Munshaw.Good afternoon, Talos readers.ย ย  If you haven't seen already, our blog has a lot of cool and new stuff this week. We first dove into the world of proxyware on Tuesday (aka internet-sharing applications). Attackers are hiding in this newly popular...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Beers with Talos, Ep. #109: We have not secured our society โ€” Or, working out a conference talk in realtime

2 September 2021 at 20:33
Beers with Talos (BWT) Podcast episode No. 109 is now available. Download this episode and subscribe to Beers with Talos:Apple Podcastsย Google PodcastsSpotifyย ย StitcherIf iTunes and Google Play aren't your thing, clickย here. Most of the Beers with Talos guys got a chance to take...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Talos Takes Ep. #66: Dude, where's my bandwidth?

3 September 2021 at 13:09
By Jon Munshaw. The latest episode of Talos Takes is available now. Download this episode and subscribe to Talos Takes using the buttons below, or visit theย Talos Takes page. โ€œProxywareโ€ sounds like a complicated topic that youโ€™re too afraid to ask about. But really, itโ€™s just software that...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Threat Roundup for August 27 to September 3

3 September 2021 at 16:57
Today, Talos is publishing a glimpse into the most prevalent threats we've observed between Aug. 27 and Sept. 3. As with previous roundups, this post isn't meant to be an in-depth analysis. Instead, this post will summarize the threats we've observed by highlighting key behavioral characteristics,...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Vulnerability Spotlight: Heap buffer overflow vulnerability in Ribbonsoft dxflib library

7 September 2021 at 15:56
Lilith >_> of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.ย  Cisco Talos recently discovered an exploitable heap-based buffer overflow vulnerability in Ribbonsoftโ€™s dxflib library that could lead to code execution.ย  The dxflib library is a C++ library utilized by...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Talos release protection against zero-day vulnerability (CVE-2021-40444) in Microsoft MSHTML

13 September 2021 at 17:45
Cisco Talos released new SNORTยฎ rules Thursday to protect against the exploitation of a zero-day vulnerability in Microsoft MSHTML that the company warns is being actively exploited in the wild.ย  Users are encouraged to deploy SIDs 58120 โ€“ 58129, Snort 3 SID 300049 and ClamAV signature ID:...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Threat Source newsletter (Sept. 9, 2021)

9 September 2021 at 18:00
Newsletter compiled by Jon Munshaw.Good afternoon, Talos readers.ย ย  The biggest security news this week is no doubt another Microsoft zero-day. On the heels of PrintNightmare and multiple Exchange Server vulnerabilities comes a code execution vulnerability in MSHTML, the rendering engine...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Talos Takes Ep. #67: What a leaked playbook tells us about the Conti ransomware group

10 September 2021 at 14:20
By Jon Munshaw. The latest episode of Talos Takes is available now. Download this episode and subscribe to Talos Takes using the buttons below, or visit theย Talos Takes page. There's a lot to take apart in the recently leaked Conti ransomware playbook. After a disgruntled member of the...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Threat Roundup for September 3 to September 10

10 September 2021 at 19:03
Today, Talos is publishing a glimpse into the most prevalent threats we've observed between Sept. 3 and Sept. 10. As with previous roundups, this post isn't meant to be an in-depth analysis. Instead, this post will summarize the threats we've observed by highlighting key behavioral characteristics,...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Vulnerability Spotlight: Code execution vulnerability in Nitro Pro PDF

13 September 2021 at 14:12
A Cisco Talos team member discovered these vulnerabilities. Blog by Jon Munshaw.ย  Cisco Talos recently discovered a vulnerability in the Nitro Pro PDF reader that could allow an attacker to execute code in the context of the application.ย  Nitro Pro PDF is part of Nitro Softwareโ€™s...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Downtime on Talos Intelligence

14 September 2021 at 13:23
TalosIntelligence.com will be down for a short time on Sept. 17 around 10 a.m. ET while we perform some routine maintenance on the site.ย  We apologize for any inconvenience this may cause. We expect the interruption will only last for about 30 minutes.ย ย 

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Microsoft Patch Tuesday for Sept. 2021 โ€” Snort rules and prominent vulnerabilities

14 September 2021 at 17:33
By Jon Munshaw, with contributions from Holger Unterbrink.ย  Microsoft released its monthly security update Tuesday, disclosing 85 vulnerabilities across the companyโ€™s firmware and software. This monthโ€™s release is headlined by an official patch for the critical remote code execution...

[[ This is only the beginning! Please visit the blog for the complete entry ]]

Operation Layover: How we tracked an attack on the aviation industry to five years of compromise

16 September 2021 at 17:48
By Tiago Pereira and Vitor Ventura. Cisco Talos linked the recent aviation targeting campaigns to an actor who has been targeting the aviation industry for two years.The same actor has been running successful malware campaigns for more than five years.Although always using commodity malware, the...

[[ This is only the beginning! Please visit the blog for the complete entry ]]
โŒ