{"success":true,"data":{"threats":[{"id":"e8b07fa6-c8ad-4bed-9201-7ce8c0a05198","slug":"talos-trust-and-the-enticing-consultancy-offer-299f8711","externalId":"6ab3dee60a4ca5000177a040","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Trust and the enticing consultancy offer","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xa0; In the cybersecurity industry, trust is the invisible currency. Every practitioner carries the implicit trust not to abuse privileged access or knowledge of vulnerabilities in each employment or engagement. This trust is valued by those who require our services, but also by threat actors.&#xa0; Clumsy phishing attacks may be easy to identify, but be wary of unsolicited messages on social media, especially if someone is offering payment for a simple service or suggests a lucrative job offer. These might be an enticement to unknowingly sell your professional integrity.&#xa0; When an unknown profile contacted me offering &#x24;300 for an hour&#x2019;s telephone consultation on digital transformation, I knew something was up. Firstly, the profile was remarkably sparse &#x2014; there was none of the usual clutter that accumulates in a social media profile. The individual claimed to work as a consultant, but their employer had no footprint and only one employee. The profile didn&#x2019;t pass the &#x201c;smell&#x201d; test, and it looked fake.&#xa0; Secondly, although I&#x2019;m flattered, I doubt my opinions on digital transformation are worth &#x24;300. The figure is low enough to be plausible and high enough to be tempting, but at the same time suspiciously high for an initial consultation without prior qualification.&#xa0; The attack itself is a confidence trick. The initial phone consultation is merely a screening process to see if the target has the access or knowledge the attacker needs. If the target passes muster, the next step is commissioning a written report, and then being asked to deliver a \"special report.\"&#xa0; Plied with professional praise, the target is asked to provide insights that aren&apos;t in the public domain. To deliver the report and claim their fee, the target must reach out to co-workers, probe internal systems, or abuse professional relationships. Completing the assignment requires the target to abuse their trusted access and professional relationships and friendships. In the process, they burn trust worth far more than any monetary compensation.&#xa0; This social engineering attempt masquerading as an offer of consultancy is one variant. Fake recruiters offering prestigious and well-paid jobs, requiring candidates to install trojanised software under some pretence, is another.&#xa0; Security professionals spend their days protecting others, yet flattery and overconfidence often remain our greatest vulnerabilities. We are prone to believe that we could identify any social engineering, but this is exactly the weakness that attackers count on.&#xa0; Trust is the most valuable commodity in our industry. Be careful not to trade it for a &#x24;300 consultation or a fake job offer. Once that currency is spent, you can rarely earn it back.&#xa0; The one big thing &#xa0;Talos released CAIRN (Cognitive Artifact Intelligence Research Network), a new open-source research toolkit designed to hunt, classify, and track emerging AI-integrated malware. Instead of relying on traditional reverse engineering, CAIRN uses a metadata-first methodology to identify cognitive artifacts like prompt templates, API keys, and jailbreak terms left behind by attackers. This allows researchers to extract, relate, and classify these artifacts quickly and at scale without ever touching the underlying binary.&#xa0; Why do I care?&#xa0;AI-integrated malware is evolving quickly, shifting from optional features to fully autonomous orchestrators in just a year. Adversaries are already sharing AI-specific tradecraft, including techniques designed to evade LLM sandboxes. Defenders need scalable frameworks to track this rapid transition before these experimental tactics become the new standard for modern attacks.&#xa0; So now what?&#xa0;Security teams can leverage the open-source CAIRN toolkit to expand their hunting capabilities and map out related malware infrastructure. While analysts should anticipate some noise from benign frameworks &#x2014; meaning final verdicts still require manual reverse engineering &#x2014; CAIRN can provide a massive head start. Read the full blog to explore the methodology, access the YARA-based classification tiers, and watch a demo of the toolkit in action.&#xa0; Top security headlines of the week&#xa0;Hackers say they have data on all FBI employees&#xa0; ShinyHunters claims it has breached multiple FBI-related services and stolen data &#x201c;on all FBI employees and applicants.&#x201d; A representative told 404 Media the data includes FBI agents&#x2019; names, home addresses, phone number, and information on their spouse. (404 Media)&#xa0; Fake LastPass installers push kernel-level EDR killer, &#x201c;Rapuncel&#x201d; stealer&#xa0; A fake LastPass Authenticator distributed via GitHub has led to the discovery of a broad impersonation campaign delivering infostealer malware. The lure represents opportunistic brand spoofing &#x2014; with no internal LastPass systems compromised. (SecurityWeek)&#xa0; Japan dismantles first North Korean laptop farm as U.S. and allies detail wider scheme&#xa0; Law enforcement and intelligence agencies from Japan, the United States, Australia and Germany have published a joint advisory attributing a long-running hiring scheme to a North Korean group they call WaterPlum, also known as&#xa0;Contagious Interview. (SecurityWeek)&#xa0; Colorado water utilities face foreign cyberattacks targeting pumps, alarms and remote access&#xa0; Hackers targeted and manipulated equipment at two privately owned Colorado water utilities in late August, changing pumping cycles, disabling remote access and alarms, and altering equipment settings. (Industrial Cyber)&#xa0; Gemini hacked three companies in first known breakout by Google&#x2019;s AI &#xa0; In one of the cases, the model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems. (The Wall Street Journal)&#xa0; Can&#x2019;t get enough Talos?&#xa0;Inside the first reported autonomous AI C2 implant&#xa0; CLOSEDQUORUM, a malware binary discovered through Talos&#x2019;&#xa0;CAIRN project, exhibits fully autonomous command and control. After deployment, it delegates the selection of its next action to a panel of commercial large language models (LLMs) and executes the resulting decision.&#xa0; ClickFix, EtherHiding, and the rise of malicious code in the blockchain&#xa0; In this episode of Talos Takes, Amy sits down with researcher Vanja Svajcer to break down a sophisticated, multi-stage infection chain that leverages a combination of ClickFix social engineering, WebDAV, and decentralized infrastructure. Ransomware incidents in Japan in the first half of 2026&#xa0; Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims. Upcoming events where you can find Talos&#xa0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xa0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xa0;SecurityOnion Conference (Oct. 23) Augusta, GA&#xa0;BsidesAugusta (Oct. 24) Augusta, GA&#xa0;SAINTCON (Oct. 26 &#x2013; 30) Provo, UT&#xa0;Most prevalent malware files from Talos telemetry over the past week&#xa0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xa0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xa0; Example Filename: sample.exe&#xa0; Detection Name: W32.9F1F11A708-100.SBX.TG&#xa0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xa0; MD5: 38de5b216c33833af710e88f7f64fc98&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xa0; Example Filename: SECOH-QAD.exe&#xa0; Detection Name: W32.9896A6FCB9-95.SBX.TG**&#xa0; SHA256: 540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8&#xa0; MD5: d65c7b544a97b0c3f2773b5fcc57d30e&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8 Example Filename: f_000bc7.exe&#xa0; Detection Name: W32.Superfluss.29lm.1201&#xa0; SHA256: cfa1997682e4ed41bc691ba848d845abbe0b75ec97e640c2b015b4d1624a108a&#xa0; MD5: 415898f14843d4a6537cf8f43d328eaf&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=cfa1997682e4ed41bc691ba848d845abbe0b75ec97e640c2b015b4d1624a108a&#xa0; Example Filename: KMSAuto.exe&#xa0; Detection Name: PUA.Win.Tool.Hackkms::1201**&#xa0; SHA256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xa0; MD5: 41444d7018601b599beac0c60ed1bf83 &#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xa0; Example Filename: content.js &#xa0; Detection Name: W32.38D053135D-95.SBX.TG","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":"consultancy-enticing-offer-trust","countryCodes":["AU","DE","ES","JP","KP","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/trust-and-the-enticing-consultancy-offer/","type":"report","title":"Cisco Talos: Trust and the enticing consultancy offer"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T18:00:37.000Z","addedAt":"2026-09-24T18:52:57.104Z","updatedAt":"2026-09-24T18:52:57.104Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"5852b5b2-e32d-4159-a674-3e047dc10b24","slug":"talos-is-cyber-missing-the-marque-15cf407b","externalId":"6a85fc54525abf0001b0e37f","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Is Cyber missing the Marque?","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0;&#xA0; Hello friend.&#xA0;&#xA0; I&#x2019;m Mick.&#xA0;&#xA0; This is my first Threat Source newsletter, so I should probably introduce myself before I start telling you all the things I think you should be paying attention to. With assistance from an unnamed LLM, my bio reads like this:&#xA0;&#xA0; Mick Baccio is a globally recognized security strategist with a career spanning offensive operations, threat intelligence, and national-level incident response. He currently advises organizations around the world through his role at Talos, helping security leaders improve operations through data-informed approaches. Mick was the first-ever Chief Information Security Officer for a U.S. presidential campaign (2020) and previously served in multiple White House administrations as Threat Intelligence Branch Chief.&#xA0;&#xA0;&#xA0;In his spare time, Mick is the Founder and President of THRUNT&#xAE; Corp, IANS Faculty, and a KC7 Cyber Foundation board member. &#xA0;DEFCon Goon and Purveyor of Fine Experience. &#xA0;Veteran.&#xA0;I also have a cat named qwerty and own too many Air Jordans.&#xA0;&#xA0;&#xA0; I&#x2019;ve spent most of my career somewhere in the intersection of threat intelligence, cybersecurity, government, and the people trying to make sense of all of it. These days, i spend a lot of time thinking about the decisions we make about security ripple outward, often in ways we didn&apos;t consider. Most of my ramblings will probably center around that. There will be threats. There will be intelligence. Occasionally something weird, but always something that caught my eye, and maybe worth checking out.&#xA0;&#xA0;&#xA0; Which brings us this week. I picked a hell of a week to start.&#xA0;&#xA0;&#xA0; Last Wednesday, the White House issued a presidential memorandum titled &#x201C;Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.&#x201D; You should probably read it. The memorandum directs the DOJ and DHS to establish a program that can use private companies to conduct cyber operations against transnational criminal organizations outside the United States &#x2014; beyond providing intelligence and assisting in the investigation. The memorandum explicitly envisions private companies conducting cyber surveillance and cyber effects operations under the direction and delegated authority of the U.S. government.&#xA0; This is a pretty big thing.&#xA0;&#xA0; For years, this industry has debated where line should exist between defending a network and reaching through the wire. We&#x2019;ve debated hack back, active defense, attribution, proportional response, collateral damage, and what roles private companies have in offensive cyber operations. This is absolutely not &#x201C;hack back\" and calling it that misses important oversight built into the memorandum.&#xA0; At the same time, let&#x2019;s be clear about what we are reading. The United States is creating a mechanism for private companies to participate directly in government-authorized offensive cyber operations against systems outside the United States. There will be plenty of debate whether this is good or bad policy; I will leave that for someone else. I&#x2019;m much more interested in the operational questions it creates.&#xA0; Who establishes attribution strongly enough to authorize an operation? What happens when criminal and state infrastructure overlap? What happens when infrastructure is compromised and used as an ORB? Who owns access discovered during one of these operations? How is intelligence collected by a private company handled? What happens when a company conducting these operations also provides security services in that country?&#xA0;&#xA0;&#xA0; Most importantly (in my head): What happens when another country discovers that employees of an American cybersecurity company are conducting offensive operations against infrastructure inside its borders?&#xA0; This is not an argument against disrupting cybercrime. I&#x2019;m all for it. These are questions about what happens when we fundamentally change who gets to do the disrupting.&#xA0; Read the memorandum.&#xA0;&#xA0; Seriously.&#xA0; What we have today is a framework. In 60 days, we should have a much better idea of what this will look like in practice, so circle that on your calendar. The memorandum gives DOJ and DHS 60 days to establish the operating procedures for the program, and no operation can be approved until those procedures are in place.&#xA0; In the area between &#x201C;private cybersecurity company&#x201D; and &#x201C;authorized participant in U.S. offensive cyber operations,&#x201D; the threat model for that company and its employees just changed considerably.&#xA0; The biggest question isn&#x2019;t &#x201C;Does this work?&#x201D;&#xA0; It&#x2019;s whether we&#x2019;ve fully considered what happens if it does.&#xA0; Read the memorandum.&#xA0;&#xA0; And in 60 days, come back and ask again.&#xA0; The one big thing &#xA0;Talos posted two blogs on UAT-10147, a recently discovered Chinese-speaking cybercrime group that uses agentic AI to orchestrate sophisticated post-compromise operations across global web servers. UAT-10147 uses AI to generate operational playbooks, automate exploits, and develop custom malware. This includes the newly identified SPECTRE implant, a cross-platform backdoor featuring a custom Linux kernel rootkit and Bring Your Own Vulnerable Driver (BYOVD) capabilities designed to completely blind endpoint detection and response (EDR) solutions.&#xA0; Why do I care?&#xA0;The integration of agentic AI into offensive workflows means threat actors can now scale complex attacks with ruthless efficiency. UAT-10147 is using AI to dynamically troubleshoot, validate exploit paths, and generate custom rootkits that neutralize organizations&apos; security stacks from the kernel level up. When an adversary can automate their reconnaissance and seamlessly blind your EDR, your window for detection shrinks drastically.&#xA0; So now what?&#xA0;Defenders need to prioritize patching known one-day vulnerabilities in internet-facing applications like Zimbra, Nacos, and Telerik UI. Since UAT-10147 relies heavily on stolen ASP.NET MachineKeys for ViewState deserialization attacks, locking down your key material is an absolute must. You should also block known vulnerable drivers to shut down their BYOVD attacks, and tune your network monitoring to catch the anomalous HTTP 500 errors they use to silently validate exploits. Read both blogs for comprehensive coverage and indicators of compromise (IOCs).&#xA0; Top security headlines of the week&#xA0;Critical GitLab zero-click flaw poses mitigation challenges&#xA0; GitLab wants organizations running self-managed versions of its software development and DevOps platform to immediately upgrade to new versions released Monday, but patching is not going to eliminate the risk to enterprises and others managing projects there. (Dark Reading)&#xA0; SANS 2026 AI Survey reveals cybersecurity AI adoption outpaces governance&#xA0; The survey found that 61% of cybersecurity practitioners now use AI in red team activities, while 76% have an enterprise AI governance role. Yet more than half said formal audit frameworks are not in place, and only 27% described their AI deployment as mature production. (Industrial Cyber)&#xA0; &#x201C;Unprecedented&#x201D; number of Apple users received recent spyware alert, say investigators&#xA0; Several people publicly and privately reported receiving Apple&#x2019;s spyware alerts over the weekend, after Apple sent out a new wave of notifications on Friday alerting customers in 110 countries that they had been targeted with powerful spyware.&#xA0; (TechCrunch)&#xA0; Critical macOS, SharePoint, vCenter, and Microsoft IKE flaws under active exploitation &#xA0; The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. (The Hacker News)&#xA0; Can&#x2019;t get enough Talos?&#xA0;Describing attacks with crime script analysis&#xA0; Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.&#xA0; Beers with Talos: For the record, no comment&#xA0; Kaitlin Acharya joins the crew to take us inside what happens when Talos spots something that could become a major threat, how her team tracks changes in threat actor behavior, and how intelligence moves from an investigation into detection content.&#xA0; Don&apos;t scan that! QR code phishing and cloud-native threats&#xA0; What happens when a&#xA0; QR code leads to a major security incident? In this episode, Amy sits down with Senior Incident Response Consultant Terryn Valikodath to break down a recent, high-stakes breach at an Australian medical center. Upcoming events where you can find Talos&#xA0;International European Cyber Threat Intelligence Conference (IECTIC) (Sept. 9) Kassel, Germany&#xA0;Secure Iowa (Sept. 9) Altoona, IA&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, AZ&#xA0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xA0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe &#xA0; Detection Name: W32.9F1F11A708-100.SBX.TG**&#xA0; SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; MD5: 7bdbd180c081fa63ca94f9c22c457376 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe&#xA0; Detection Name: Win.Dropper.Miner::95.sbx.tg**&#xA0; SHA256: 24fa02c3f6ab460648f2c1274aefffb3e25569b5afdcb0d4a5918c7c742780f1 &#xA0; MD5: 8ef476fa2322d063896830f85bac2e7f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=24fa02c3f6ab460648f2c1274aefffb3e25569b5afdcb0d4a5918c7c742780f1&#xA0; Example Filename: WebCompanion.exe &#xA0; Detection Name: W32.24FA02C3F6-95.SBX.TG&#xA0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; Example Filename: tmp00055df5.dll &#xA0; Detection Name: Auto.90B145.282358.in02&#xA0; SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 &#xA0; MD5: 9a47c4d379998ade2f8f99e23a630c06 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; Example Filename: WCInstaller_NonAdmin.exe &#xA0; Detection Name: W32.C4DD71E347-95.SBX.TG&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":["AU","CN","DE","ES","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/is-cyber-missing-the-marque/","type":"report","title":"Cisco Talos: Is Cyber missing the Marque?"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-20T18:00:18.000Z","addedAt":"2026-08-20T18:52:46.378Z","updatedAt":"2026-08-20T18:52:46.378Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"885ac7d5-7525-49ac-bcdc-8e002a321ddb","slug":"talos-curiouser-and-curiouser-fcecd5fd","externalId":"6a7cc35084f2640001d1564e","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Curiouser and Curiouser","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0;&#xA0; &#x201C;Experiment is the mother of knowledge.&#x201D; &#x2015; Madeleine L&apos;Engle, A Wrinkle in Time&#x201C;Don&apos;t slide down the rabbit hole. The way down is a breeze, but climbing back&apos;s a battle.&#x201D; &#x2015; Kate Morton, The Clockmaker&apos;s Daughter&#xA0;Hacker Summer Camp has come and gone, which means it&#x2019;s time for you to start planning next year&#x2019;s trip. I&#x2019;m surely going to recap Camp Season, right? Nope. One of the things that I&#x2019;ve really enjoyed lately is a segment on the Beers with Talos podcast that we call &#x201C;Make Hazel a Hacker.&#x201D; If you haven&#x2019;t listened to it, this is a perfect time to start. Each episode we take a few minutes and pose a security question, term, or concept to Hazel and force her to come up with an idea or explanation on the spot. There are no parameters, so she&#x2019;s faced with the entirety of information security &#x2014; past, present, and future. I know, it&#x2019;s insane. The craziest part is that (I think) Hazel came up with this idea and still volunteered to put herself in the line of fire. As we put Hazel&#x2019;s feet to the fire, one of my favorite things happens: The rest of us listen in and offer our thoughts during her brainstorming process. Invariably, we&#x2019;ve got three very different answers, ideas, hints, or directions for her. It&#x2019;s surely maddening for Hazel, but to me, the best part of the discussion that inevitably follows is that although they&#x2019;re all different, they&#x2019;re all correct.&#xA0;&#xA0; For example, this past episode I asked her about a behavioral indicator (regarding &#x201C;wallpaper.bmp&#x201D;) that seems benign on its own, but can be interesting to use as a pivot for a threat hunt. We had various interesting angles to consider, backed by years of knowledge and experience. It gave us a good conversation, and that was a .bmp! One of the most nebulous things to learn in this field is that multiple things can be both different and correct. When you are making your decisions this week &#x2014; whether it&#x2019;s deciding on a new pivot in your hunting, what devices to prioritize in your patching and updating, or which books or online training to focus on &#x2014; take a quick second and get a second, third, and fourth opinion. Then try something that&#x2019;s outside of your normal wheelhouse but sounds good when it&#x2019;s proposed.&#xA0;&#xA0; None of this is a solo sport. It&#x2019;s a team game and the best plays come from a mix of perspectives, experiences, and mistakes. The &#x201C;right&#x201D; answer can wear many faces, and your ability to hold different truths will lead you to undiscovered territory, the rabbit hole where anomaly lives and breathes. So... welcome back from Vegas. Now go down a rabbit hole on a path you wouldn&#x2019;t normally take because one of your friends (Joe) or your mortal enemy (Dave) told you that it would work. &#x201C;She&apos;d been to Narnia, Wonderland, Hogwarts, Dictionopolis. She had tessered, fallen through the rabbit hole, crossed the ice bridge into the unknown world beyond.&#x201D; &#x2015; Anne Ursu, Breadcrumbs&#xA0;The one big thing&#xA0;Cisco Talos recently discovered \"JWR,\" a previously undocumented, real-time phishing framework and likely variant of \"The Outsider\" phishing-as-a-service platform. JWR uses an open WebSocket connection that allows attackers to monitor keystrokes live and dynamically steer victims through fake checkout and login flows. Currently deployed via SMS lures impersonating regional toll and postal authorities, JWR enables operators to steal payment data, 2FA codes, identity documents, and device fingerprints.&#xA0; Why do I care?&#xA0;Because JWR is operator-driven in real time, attackers can actively bypass multi-factor authentication (MFA) by prompting victims for 2FA codes exactly when needed. The sheer volume of collected data gives threat actors a comprehensive identity profile primed for extensive follow-on fraud and network compromise. Furthermore, JWR&apos;s seamless integration with legitimate e-commerce platforms like Shopify makes these lures incredibly convincing to the untrained eye.&#xA0; So now what?&#xA0;Prioritize user education around SMS-based phishing (smishing), specifically regarding unsolicited delivery or toll fee messages. Monitor for unusual authentication attempts, as stolen device fingerprints and session tokens can bypass conditional access policies. Where possible, implement phishing-resistant MFA methods like FIDO2 hardware keys. For a complete list of indicators of compromise (IOCs) and coverage updates, read the full blog.&#xA0; Top security headlines of the week&#xA0;Ransomware hits Colombian Justice Ministry days before presidential transition&#xA0; The attack, which disrupted some services around illicit-drug monitoring and legal processes, came a day after Colombia&apos;s national CERT published threat intelligence warning that ransomware groups had increased their focus on the country. (Dark Reading)&#xA0; FBI investigating North Korean remote IT staffer working for U.S. agency&#xA0; It&#x2019;s unclear what agency was impacted, how long the intrusion lasted, and whether any sensitive data was stolen. Experts say it&#x2019;s highly likely the staffer was a remote IT employee doing contract work on behalf of an agency. (Federal News Network)&#xA0; Hackers leverage new Microsoft SharePoint exploit in attacks&#xA0; A proof-of-concept exploit for a critical Microsoft SharePoint authentication bypass security flaw in the JWT token validation pipeline is already being used in attacks. (BleepingComputer)&#xA0; Signal adds new security feature to thwart adversary-in-the-middle attacks&#xA0; Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven&apos;t been intercepted. (BleepingComputer)&#xA0; A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond&#xA0; The cyberattack on Ceva is affecting at least eight warehouses across Europe used for shipping goods across the continent. Several companies reported that hackers took their customers&#x2019; names, home addresses, phone numbers, and email addresses used to place their orders from Ceva&#x2019;s systems. (TechCrunch)&#xA0; Can&#x2019;t get enough Talos?&#xA0;Don&apos;t scan that! QR code phishing and cloud-native threats&#xA0; What happens when a&#xA0; QR code leads to a major security incident? In this episode, Amy sits down with Senior Incident Response Consultant Terryn Valikodath to break down a recent, high-stakes breach at an Australian medical center&#xA0; Microsoft Patch Tuesday for August 2026&#xA0; Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as \"critical.\" One of the vulnerabilities disclosed this month has been exploited in the wild.&#xA0; &#x201C;Keep going, bro. You&#x2019;ve got this!&#x201D; A data-driven look at how adversaries are weaponizing AI&#xA0; How are adversaries weaponizing AI in the wild? By analyzing prompt logs left behind on endpoints, we found threat actors successfully bypassing guardrails to use AI as malicious software engineers, criminal force multipliers, and vulnerability research accelerators.&#xA0; Upcoming events where you can find Talos&#xA0;International European Cyber Threat Intelligence Conference (IECTIC) (Sept. 9) Kassel, Germany&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, Arizona&#xA0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe&#xA0; Detection Name: W32.9F1F11A708-100.SBX.TG**&#xA0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 &#xA0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; Example Filename: tmp00055df5.dll &#xA0; Detection Name: Auto.90B145.282358.in02&#xA0; SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; MD5: 7bdbd180c081fa63ca94f9c22c457376 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe &#xA0; Detection Name: Win.Dropper.Miner::95.sbx.tg**&#xA0; SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 &#xA0; MD5: 9a47c4d379998ade2f8f99e23a630c06 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; Example Filename: WCInstaller_NonAdmin.exe &#xA0; Detection Name: W32.C4DD71E347-95.SBX.TG&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f &#xA0; MD5: 38de5b216c33833af710e88f7f64fc98 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: SECOH-QAD.exe &#xA0; Detection Name: Win.Tool.Procpatcher::1201","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":["AU","CO","DE","ES","KP"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/curiouser-and-curiouser/","type":"report","title":"Cisco Talos: Curiouser and Curiouser"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-13T18:00:18.000Z","addedAt":"2026-08-13T18:52:44.181Z","updatedAt":"2026-08-13T18:52:44.181Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"dbd0d732-01d7-45c3-a3f7-237c080a8308","slug":"talos-ir-trends-q2-2026-phishing-and-weaponized-remote-management-49df0f62","externalId":"6a63b450e024b60001667c4f","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains","description":"Phishing was the primary means of gaining initial access this quarter, appearing in over half of all Cisco Talos Incident Response (Talos IR) engagements &#x2013; an increase from approximately a third of engagements last quarter. Attackers continued to innovate their delivery methods to evade defenses, deploying QR code-embedded PDFs to bypass traditional email gateways and hosting links on trusted cloud platforms. We also saw a spike in authentication abuse this quarter &#x2014; observed in 65 percent of engagements compared to 35 percent last quarter &#x2014; with attackers frequently bypassing or defeating multi-factor authentication (MFA) using adversary-in-the-middle (AitM) proxies, session-token theft, MFA fatigue attacks, and self-enrolled devices, amongst other methods.&#xA0;&#xA0; Ransomware incidents made up over 20 percent of engagements this quarter, similar to just under 20 percent last quarter. Talos IR responded to Sinobi ransomware for the first time, as well as previously seen variants Nitrogen and Warlock. We observed ransomware operators leveraging legitimate&#xA0;remote monitoring and management (RMM)&#xA0;tools, such as trojanized MeshAgent binary and Zoho Assist, for stealthy access, requiring defenders to prioritize behavior-based monitoring and strict control over administrative binaries. In the latest Talos Threat Perspective episode, we explore these trends, and highlight where defenders have the best opportunities to detect attackers: QR phishing campaign leverages trusted infrastructure to target Australian organizations&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;Starting in April, we observed a persistent QR code phishing campaign targeting primarily Australian organizations that leverages compromised Microsoft 365 accounts to harvest credentials and propagate the attack via internal contact lists. The campaign, which remained ongoing as of late June 2026, employs auto-generated, victim-tailored PDF documents containing QR codes that direct to adversary-controlled M365 credential harvesting pages. If credentials are successfully captured, the adversary attempts access to the victim&#x2019;s Microsoft account and conducts various post-compromise actions including creating email inbox rules for defense evasion, leveraging SharePoint to host malicious documents, and sending additional internal and external phishing emails to continue the compromise chain.&#xA0; We assess with high confidence that the threat actor, who we have dubbed UAT-11764, will almost certainly continue leveraging this QR code phishing operation, using each newly compromised mailbox&apos;s contact lists to expand its reach and sustain the campaign&apos;s momentum. By weaponizing existing, trusted infrastructure like SharePoint and M365, UAT-11764 can bypass many standard email security gateways. As such, network defenders should implement policies that block or flag emails containing QR codes within PDF attachments, enforce phishing-resistant MFA on M365 accounts, and monitor for suspicious inbox rule creation and anomalous SharePoint file staging as indicators of post-compromise activity.&#xA0; ARToken platform provides toolkit for Microsoft 365 account compromise&#xA0;Talos uncovered a phishing-as-a-service (PhaaS) operator platform, ARToken, in an engagement this quarter that is closely linked to the EvilTokens platform. According to our analysis, the ARToken panel exposes 80+ API endpoints for device code phishing, primary refresh token (PRT) persistence, email access, business email compromise (BEC) operations, and SharePoint exfiltration &#x2014; all accessible to operators through a React-based dashboard. Our investigation into the platform found phishing lures that impersonate trusted vendors and abuse legitimate Microsoft services, allowing attackers to bypass MFA through the OAuth device authorization flow rather than stealing passwords.&#xA0; ARToken extends beyond a typical phishing kit by providing affiliates with a comprehensive post-compromise toolkit. We observed capabilities including automated token management, persistent access through PRTs, OneDrive and SharePoint administration, geo-dynamic templates, inbox rule manipulation, cross-account keyword monitoring, and collaborative token sharing. We also identified advanced anti-analysis techniques, including layered evasion mechanisms and encrypted client-side payloads, highlighting the increasing sophistication of modern PhaaS platforms and reinforcing the need for organizations to monitor device code authentication, enforce Conditional Access policies, and strengthen defenses against token-based attacks.&#xA0;&#xA0; Ransomware trends&#xA0;Ransomware and pre-ransomware incidents made up over 20 percent of engagements this quarter, relatively similar to just under 20 percent last quarter. As previously mentioned, Talos IR responded to Sinobi ransomware for the first time, as well as previously seen variants Nitrogen and Warlock. We observed operators from these groups leveraging tools not previously identified in public reporting, including a trojanized MeshAgent binary and Zoho Assist for remote access. Sinobi ransomware operators weaponize MeshAgent for covert backdoor accessWe responded to a Sinobi ransomware engagement for the first time in April; while this ransomware-as-a-service (RaaS) operation emerged nearly a year ago, there has been minimal public reporting on the actors&#x2019; operations.&#xA0;&#xA0; Notably, we observed the threat actors use a trojanized MeshAgent binary as their primary C2 mechanism during this engagement, a tactic that has not been previously associated with the group in public reporting. MeshAgent is the open-source agent component of the MeshCentral remote management platform. Here, the actor weaponized it into a covert durable backdoor installed as a SYSTEM-level auto-start service, communicating over encrypted WebSocket (WSS) to an attacker-controlled server. This approach allowed the actor to blend malicious traffic with legitimate remote management activity and maintain undetected access for approximately three days before ransomware deployment.&#xA0; Following C2 establishment, the actor moved laterally through the network using RDP and WinRM, leveraging a service account with a weak, easily cracked password obtained from the domain credential store, ntds.dit. The actor ultimately deployed the ransomware across the entire domain using a malicious Group Policy Object (GPO) logon script. The incident resulted in the encryption of systems with the .SINOBI file extension, alongside observed data exfiltration staging activity conducted via rclone.exe. Looking forward, Sinobi operators will likely continue weaponizing legitimate tools like MeshAgent because these binaries blend into standard administrative traffic and bypass many traditional signature-based alerts. The use of GPO-based deployment scripts suggests an understanding of enterprise architecture, and operators will likely continue to exploit centralized management features to ensure rapid, domain-wide encryption. Defenders should prioritize monitoring of administrative tools and implement strict application allowlisting to prevent unauthorized binaries from running as services. Further, proactive hunting for unauthorized MeshAgent instances and auditing service account permissions may help in identifying and disrupting Sinobi activity before encryption.&#xA0; Warlock actors deploy Zoho Assist to attempt remote access without active user sessionsIn one engagement, we observed Warlock ransomware operators (also known as Storm-2603) deploying an installer for the RMM tool Zoho Assist Unattended Agent, which is designed to allow administrative remote control of an endpoint without a user logged in. The tool, which we have not previously seen attributed to Warlock, enables the attackers to maintain persistent, stealthy, and unrestricted control, significantly increasing the potential malicious impact of an incident.&#xA0;&#xA0; While the activity in this particular did not lead to encryption, it was consistent with a successful Warlock ransomware attack Talos observed in May. To counter this threat, organizations must shift from signature-based detection to behavior-based monitoring, focusing on the specific tactics, techniques, and procedures (TTPs) utilized by Storm-2603, such as the abuse of legitimate administrative tools and rapid movement within the network. Targeting&#xA0;For the second quarter in a row, health care led as the most targeted industry vertical accounting for 17 percent of all engagements, with public administration and manufacturing following at 14 percent each. A shared characteristic of these top-targeted sectors is a critical lack of downtime tolerance. The vast majority of targeted health care organizations were entities that directly support clinical operations and/or diagnostic services, where service interruption can result in operational and patient-care consequences. Almost all targeted public administration organizations were local governments, which provide essential public services, while the targeted manufacturing entities represented high-value targets within the industrial supply chain, where potential disruptions could create cascading effects across the downstream technology and energy sectors. Initial access&#xA0;As mentioned, phishing was the top means of gaining initial access this quarter, accounting for over half of engagements where initial access could be determined &#x2014; an increase from 35 percent last quarter. Many phishing engagements included MFA-bypass techniques, such as OAuth device-code phishing and AiTM frameworks, allowing adversaries to intercept session tokens. Other observed means of achieving initial access included exploitation of public-facing applications and drive-by compromise. Recommendations for addressing top security weaknessesImplement properly configured, phishing-resistant MFA and tighten authentication controls&#xA0;Authentication abuse was the most prevalent security weakness this quarter, observed in 65 percent of engagements &#x2014; up sharply from 35 percent last quarter. Adversaries consistently defeated or bypassed MFA using AitM proxies and session-token theft, MFA fatigue attacks, registration of attacker-controlled devices for authentication, and legacy authentication protocols that circumvent MFA altogether. To reduce this risk, Talos IR recommends transitioning from push- and SMS-based MFA to phishing-resistant methods such as FIDO2/WebAuthn and hardware security keys. Organizations should also restrict self-service MFA enrollment by requiring helpdesk verification, block legacy authentication through Conditional Access, enforce number matching or verified push where phishing-resistant methods are not yet feasible, and condition access on device compliance and trusted infrastructure rather than geographic location alone.&#xA0;&#xA0;&#xA0; Configure centralized logging with adequate retention across the environment&#xA0;Insufficient logging and visibility was the second most common weakness, observed in 42 percent of engagements compared to 18 percent last quarter. Deficiencies included domain controller security logs retained for only a few hours, host event logs truncated or overwritten before capture, absent NetFlow that prevented reconstruction of external authentication and exfiltration, on-device-only logs that adversaries deleted to evade detection, and short cloud-telemetry retention that did not extend back to the true initial-access date. In several engagements these gaps prevented definitive determination of the initial access vector or the scope of data exfiltration. Talos IR recommends implementing a SIEM or centralized logging platform with a minimum of 90 days of retention, forwarding logs from servers, workstations, network infrastructure, cloud identity providers, and security appliances off-device so they survive log tampering and host rebuilds, and enabling process-creation, command-line, and cloud API (e.g., Microsoft Graph) auditing. Talos IR&apos;s Log Architecture Assessment service can identify gaps and provide a roadmap to a complete view of the environment.&#xA0; Conduct robust patch management and reduce exposed infrastructure&#xA0;Vulnerable, exposed, or unpatched internet-facing infrastructure was the third most common weakness, observed in 31 percent of engagements, similar to last quarter&#x2019;s 25 percent.&#xA0; A variety of different vulnerabilities were targeted including ToolShell, an older Telerik UI deserialization flaw, and SD-WAN and perimeter-VPN appliance CVEs. Internet-exposed services were also subjected to SQL-injection and denial-of-service activity. Talos IR recommends identifying and prioritizing the patching or decommissioning of all end-of-life and externally exposed systems, isolating systems that cannot be immediately upgraded, restricting management plane and remote access services behind a VPN or trusted source, deploying a Web Application Firewall (WAF) with rules for known exploitation patterns, and establishing a vulnerability management process capable of rapidly identifying and patching exposed assets &#x2014; particularly given the accelerating reduction in time between vulnerability disclosure and exploitation.&#xA0; Enforce strict outbound email thresholds to disrupt attack propagation&#xA0;Finally, unlimited outbound email thresholds were a notable security weakness this quarter, enabling threat actors to propagate malicious activity in almost 15 percent of engagements. Though not as prevalent as the above weaknesses, it was more frequently observed than in previous quarters and warrants mention. For example, in one engagement, a user clicked on a malicious phishing email that led to credential theft and account compromise. Shortly after the threat actors gained access to the user&#x2019;s mailbox, they sent over 6,600 phishing and spam emails to continue the attack chain. The failure to contain the compromise via outbound rate limiting significantly amplifies the damage of a single compromised credential; implementing these controls is a low-effort, high-impact mitigation strategy that effectively disrupts the attack chain.&#xA0; Top-observed MITRE ATT&CK techniques&#xA0;&#xA0;The table below represents the MITRE ATT&CK techniques observed in this quarter&#x2019;s Talos IR engagement. Given that some techniques can fall under multiple tactics, we grouped them under the most relevant tactic in which they were leveraged. Please note this is not an exhaustive list.&#x202F;&#xA0; Key findings from the MITRE ATT&CK framework include:&#xA0;&#xA0; Consistent with phishing being a top threat this quarter, email hiding rules was the most observed tactic for persistence while internal spearphishing was most seen for lateral movement.&#xA0;Use of valid accounts was frequently observed for both privilege escalation and persistence, highlighting how identity abuse remains a key theme across engagements.&#xA0;&#xA0;Actors also relied on legitimate tools and web protocols to challenge detection, abusing native email features and cloud APIs, relying on standard web protocols for C2, and using valid administrative credentials for RDP and SSH. Tactic&#x202F;&#xA0; Technique&#x202F;&#xA0; Example&#x202F;&#xA0; Reconnaissance (TA0043)&#xA0; T1598 Phishing for Information&#xA0; Adversaries may send phishing messages to elicit sensitive information that can be used during targeting. Phishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information.&#xA0; &#xA0; T1595 Active Scanning&#xA0; Adversaries may execute active reconnaissance scans to gather information that can be used during targeting.&#xA0; &#xA0; T1593 Search Open Websites/Domains&#xA0; Adversaries may search open websites and domains to gather information about a victim that can be used during targeting.&#xA0; &#xA0; T1589 Gather Victim Identity Information&#xA0; Adversaries may gather information about the victim&apos;s identity that can be used during targeting.&#xA0; Initial Access (TA0001)&#xA0; T1566 Phishing&#xA0; Adversaries may send phishing messages to gain access to victim systems.&#xA0; &#xA0; T1190 Exploit Public-Facing Application&#xA0; Adversaries may exploit a vulnerability to gain access to a target system.&#xA0; &#xA0; &#xA0;T1078 Valid Accounts&#xA0; Adversaries may use compromised credentials to access valid accounts during their attack.&#xA0; Execution (TA0002)&#x202F;&#xA0; T1204.001 User Execution: Malicious Link&#xA0; An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to social engineering to get them to click on a link that will lead to code execution.&#xA0; &#xA0; T1078 Valid Accounts&#xA0;&#xA0;&#xA0; Adversaries may obtain and abuse credentials of existing accounts to access systems within the network and execute their payload.&#xA0; Persistence (TA0003)&#xA0; T1564.008 Hide Artifacts: Email Hiding Rules&#xA0; Adversaries may use email rules to hide inbound emails in a compromised user&apos;s mailbox. Many email clients allow users to create inbox rules for various email functions, including moving emails to other folders, marking emails as read, or deleting emails.&#xA0; &#xA0; T1663 Remote Access Software&#xA0; Adversaries may use legitimate remote access software, such as VNC, TeamViewer, AirDroid, AirMirror, etc., to establish an interactive command and control channel to target mobile devices.&#xA0; &#xA0; T1053 Scheduled Task/Job&#xA0;&#xA0;&#xA0; Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code.&#xA0; &#xA0; T1133 External Remote Services&#xA0; Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations.&#xA0; &#xA0; T1078 Valid Accounts&#xA0; The adversary may compromise a valid account to move through the network to additional systems.&#xA0; Defense Impairment (TA0112)&#x202F;&#xA0; T1687 Exploitation for Defense Impairment&#xA0; Adversaries may exploit vulnerabilities in security software, infrastructure, or defensive components to degrade, disable, or otherwise continue to impair their ability to prevent, detect, or respond to malicious activity.&#xA0; &#xA0; T1078 Valid Accounts&#xA0; Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.&#xA0; &#xA0; T1484 Domain or Tenant Policy Modification&#xA0; Adversaries may modify the configuration settings of a domain or identity tenant to evade defenses and/or escalate privileges in centrally managed environments.&#xA0; Stealth (TA0005)&#xA0; T1564.008 Hide Artifacts: Email Hiding Rules&#xA0; Adversaries may use email rules to hide inbound or outbound emails in a compromised user&apos;s mailbox.&#xA0; &#xA0; T1070 Indicator Removal&#xA0;&#xA0;&#xA0; Adversaries may delete or modify artifacts generated within systems to remove evidence of their presence or hinder defenses.&#xA0; Credential Access (TA0006)&#x202F;&#xA0; T1111 Multi-Factor Authentication Interception&#xA0;&#xA0;&#xA0; Adversaries may target MFA mechanisms, (i.e., smart cards, token generators, etc.) to gain access to credentials that can be used to access systems, services, and network resources.&#xA0; &#xA0; T1621 Multi-factor Authentication Request Generation&#xA0; Adversaries may attempt to bypass MFA mechanisms and gain access to accounts by generating MFA requests sent to users.&#xA0; &#xA0; T1110.003 Brute Force: Password spraying&#xA0; Adversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials.&#xA0; Discovery (TA0007)&#xA0; T1018 Remote System Discovery&#xA0; Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.&#xA0; &#xA0; T1083 File and Directory Discovery&#xA0;&#xA0;&#xA0; Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.&#xA0; &#xA0; T1087 Account Discovery&#xA0;&#xA0;&#xA0; Adversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment.&#xA0; &#xA0; T1082 System Information Discovery&#xA0; An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.&#xA0; &#xA0; T1526 Cloud Service Discovery&#xA0; An adversary may attempt to enumerate the cloud services running on a system after gaining access.&#xA0; Lateral Movement (TA0008)&#x202F;&#xA0; T1021.001 Remote Services: Remote Desktop Protocol&#xA0; Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.&#xA0; &#xA0; T1534 Internal Spearphishing&#xA0; After they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within the same organization.&#xA0; &#xA0; T1021.004 Remote Services: SSH&#xA0; Adversaries may use Valid Accounts to log into remote machines using SSH. The adversary may then perform actions as the logged-on user.&#xA0; Command and Control (TA0011)&#x202F;&#xA0; T1219 Remote Access Software&#xA0; An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.&#xA0; &#xA0; T1071.001 Application Layer Protocol: Web Protocols&#xA0;&#xA0;&#xA0; Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic.&#xA0; &#xA0; T1102 Web Service&#xA0; Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system.&#xA0; &#xA0; T1572 Protocol Tunneling&#xA0; Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems.&#xA0; Exfiltration (TA0010)&#x202F;&#xA0; T1567 Exfiltration Over Web Service&#xA0; Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel.&#xA0; &#xA0; T1048 Exfiltration Over Alternative Protocol&#xA0; Adversaries may exfiltrate data over a different protocol than the command and control channel.&#xA0; Impact (TA0040)&#x202F;&#xA0; T1486 Data Encrypted for Impact&#xA0; Adversaries may use ransomware to encrypt data on a target system.&#xA0;&#xA0;&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","talos-ir-trends","ctir-trends","cisco-talos-incident-response","landing-page-top-story","top-story","geo:inferred"],"relatedCves":[],"titleFingerprint":"2026-attack-chains-drive-management-phishing-remote-tools-trends-weaponized","countryCodes":["AU"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/ir-trends-q2-2026/","type":"report","title":"Cisco Talos: IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-28T10:00:01.000Z","addedAt":"2026-07-29T20:53:06.577Z","updatedAt":"2026-07-29T20:53:06.577Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"99beb8f3-4c8e-4555-91f8-fc653dcb96a7","slug":"talos-don-t-swing-at-everything-11a524c6","externalId":"6a60ff8a824f5b00012e5201","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Don’t swing at everything","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0; Lately I&apos;ve found myself thinking a lot about the Australian TV series Mr. Inbetween (IMDb 8.7/10) &#x2014; not because I&apos;m a hitman for hire, but because I literally feel in-between. Specifically, in-between what I&apos;d call the \"pre-Mythos\" and &#x201C;post-Mythos&#x201D; eras. We&apos;ve crossed a capability threshold, and it&apos;s not just one model family driving that &#x2014; Codex 5.3 and GPT-5.5 deliver comparable or better performance, and Tulongfeng or GLM-5.2 (an incredibly powerful open-weight model, MIT-licensed) show the frontier isn&apos;t limited to closed models anymore.&#xA0; On the other side of that line, real-world impact hasn&apos;t caught up yet and we&apos;re living in an artificial buffer zone. For me, defining the &#x201C;pre-&#x201D; and &#x201C;post-&#x201D; status comes down to the gap between \"vulnerability discovery\" and \"vulnerability publication.\"&#xA0; Last week&#x2019;s Patch Tuesday gave a signal of change, as Joe pointed out, so maybe the buffer zone has come to an end.&#xA0; Let&apos;s dive into the 2026 Q2 stats. As in past years, we&apos;re seeing a steeper curve than the year before &#x2014; a solid 49% YoY growth, though still not the hockey-stick moment I keep waiting for. By the end of June we were tracking close to 200 CVEs per day.&#xA0; Using the keyword methodology described here, I found 452 AI-related CVEs this calendar year. If \"openclaw\" is added to the keyword list, that number jumps by another 536 &#x2014; a reminder that these counts are sensitive to keyword drift. Given how much the keyword list keeps changing, I&apos;m reconsidering whether to keep publishing this particular metric going forward. KEVs, by contrast, \"only\" grew 13% &#x2014; a small April spike aside, it&apos;s fairly flat relative to total CVE growth. Networking-gear-related CVEs continued their climb, now accounting for 24% of KEV-related vulnerabilities (up from 20% in Q1) &#x2014; consistent with the trend I flagged last quarters. As in previous quarters, CVEs from 2024 or earlier still make up about 24% of everything we&apos;re tracking. More strikingly, even though the standard enterprise patch cycle is described&#xA0; to run 30&#x2013;90 days, 181 days into 2026, 46% of today&apos;s actively-exploited (KEV) CVEs still trace back to 2025 or earlier.&#xA0; Old vulnerabilities don&apos;t retire, new ones keep arriving, and machine-speed vulnerability discovery is going to keep outpacing human-speed patching. Which brings me back &#x2014; once again &#x2014; to EPSS as a tool for prioritizing patching against this dataset. If you patched purely by CVSS 9+, you&apos;d be urgently chasing ~3,700 CVEs &#x2014; but 95% of those sit below 5% EPSS, meaning the real-world odds of exploitation are tiny.&#xA0; Of the 32 CVSS 9+ CVEs with EPSS &#x2265; 50%, 25 are already on CISA&apos;s KEV list. The remaining seven outliers are still high-probability by EPSS but haven&apos;t made KEV yet &#x2014; worth watching.&#xA0; Ray Shoesmith (Mr. Inbetween) once told his therapist, \"You know, if I hit somebody, I generally got a pretty good reason.\"&#xA0; Same principle applies to patching. Don&apos;t swing at everything &#x2014; swing at what you have good reason to believe is coming for you.&#xA0; The one big thing&#xA0;Cisco Talos has discovered \"msaRAT,\" a new Rust-based remote access trojan (RAT) deployed by the Chaos ransomware group. Built on the Tokio asynchronous runtime, it establishes a covert command-and-control (C2) channel by hijacking Chrome or Edge browsers via the Chrome DevTools Protocol (CDP). The infection starts with a deceptive MSI file masquerading as a Windows update that loads the payload directly into memory, paving the way for ransomware deployment.&#xA0; Why do I care?&#xA0;This RAT is a master of evasion, living off the browser to build its C2 infrastructure without ever directly touching the network. By routing traffic through legitimate browser processes and trusted services, msaRAT easily bypasses traditional network-based detections. Additionally, its use of the Tokio runtime enables highly efficient, parallel execution of malicious tasks, accelerating the attacker&apos;s ability to establish persistence and deploy double-extortion ransomware.&#xA0; So now what?&#xA0;Defenders should monitor for unusual&#xA0;curl&#xA0;commands, especially those downloading MSI files to the&#xA0;ProgramData&#xA0;directory or sending plain HTTP traffic over port 443. Scrutinize unexpected MSI files impersonating Windows updates and watch for unauthorized Chrome or Edge manipulation. Finally, implement behavioral monitoring to catch Chrome DevTools Protocol abuse and unauthorized WebRTC connections. Read the full blog for complete coverage and indicators of compromise (IOCs).&#xA0; Top security headlines of the week&#xA0;Introducing Antares: Highly efficient open weight AI models for vulnerability localization&#xA0; This week, Cisco introduced Antares, a family of security small language models (SLMs) purpose-built for pinpointing where known vulnerabilities exist within a codebase. (Cisco)&#xA0; Hacker wipes European country&#x2019;s entire land registry database, paralyzing real-estate market&#xA0; A hacker wiped Romania&#x2019;s entire land registry database after an unsuccessful extortion attempt. The attack halted all property transactions, preventing notaries from authenticating sales or registering mortgages nationwide. (Cybernews)&#xA0; \"WP2Shell&#x201D; opens millions of WordPress sites to remote takeover&#xA0; Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet. (DarkReading)&#xA0; Progress tells ShareFile customers to shut down Storage Zone Controllers over security threat &#xA0; Only the Storage Zone Controller is affected, not standard cloud-only ShareFile accounts. The controller is a server that a company runs itself, so files can stay on its own storage while it still uses ShareFile&apos;s cloud to share and manage them.&#xA0;(The Hacker News)&#xA0; Microsoft SharePoint under attack via new exploit&#xA0; Researchers warned that patching is not enough to address the deserialization flaw and that security teams &#x201C;should rotate credentials on any assets that may have been exposed.&#x201D;&#xA0;(Cybersecurity Dive)&#xA0; Can&#x2019;t get enough Talos?&#xA0;[Video] Where protection starts: Cisco Talos Intelligence Integrations&#xA0; Every day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations help reduce uncertainty by turning the latest threat intelligence into proactive protections across Cisco technologies.&#xA0; The Hunter&apos;s Paradox: Is it time to embrace automated threat hunting?&#xA0; Humans can no longer keep up with the volume and velocity of security data on their own, but AI can&apos;t be fully trusted. David discusses the merits of both and what the future might look like.&#xA0; The serpent&#x2019;s tongue: Luring the Python out of its den&#xA0; Protect your development environment from rising Python supply-chain threats by understanding the package installation lifecycle and implementing these essential defensive strategies.&#xA0; Keeping up with the cybercriminals&#xA0; In this episode of&#xA0;Beers with Talos, Hazel, Bill, Dave and Joe are joined by Kendall McKay to dive into the soap opera of modern cybercrime. Turns out, every ransomware operation is one passive-aggressive group chat message away from falling apart.&#xA0; Upcoming events where you can find Talos&#xA0;Black Hat USA (Aug. 1 &#x2013; 6) Las Vegas, NV&#xA0;DEF CON 34 (Aug. 6 &#x2013; 9) Las Vegas, NV&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; Example Filename: VID001.exe &#xA0; Detection Name: Win.Worm.Coinminer::1201**&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f &#xA0; MD5: 38de5b216c33833af710e88f7f64fc98 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f &#xA0; Example Filename: SECOH-QAD.exe &#xA0; Detection Name: Win.Tool.Procpatcher::1201&#xA0; SHA256: e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba &#xA0; MD5: dbd8dbecaa80795c135137d69921fdba &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba &#xA0; Example Filename: u165714.dat &#xA0; Detection Name: W32.Variant:MalwareXgenMisc.29d4.1201&#xA0; SHA256: 633bd79d1efd3730234d907a2a0d98e3e253a5f0e222e4e4bf3badb3fd6aea0a &#xA0; MD5: 770dbe473180366d7b539ff2c188e551 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=633bd79d1efd3730234d907a2a0d98e3e253a5f0e222e4e4bf3badb3fd6aea0a &#xA0; Example Filename: server_tcp.exe &#xA0; Detection Name: W32.Trojan.27oc.1201&#xA0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 &#xA0; Example Filename: tmp00055df5.dll &#xA0; Detection Name: Auto.90B145.282358.in02&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":["CVE-2026-60137","CVE-2026-63030"],"titleFingerprint":null,"countryCodes":["AU","RO","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/dont-swing-at-everything/","type":"report","title":"Cisco Talos: Don’t swing at everything"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-23T18:00:46.000Z","addedAt":"2026-07-29T20:53:06.588Z","updatedAt":"2026-07-29T20:53:06.588Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]}],"pagination":{"page":1,"limit":20,"total":5,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:20:49.326Z","durationMs":13,"filters":{"search":null,"severity":[],"type":[],"country":["AU"],"tag":[],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}