{"success":true,"data":{"threats":[{"id":"e00aea1b-af13-41cf-b0f3-eb429d510631","slug":"talos-making-sure-the-checks-get-printed-55710b37","externalId":"6ac66dcbe83d4c0001cd2fb9","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Making sure the checks get printed","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xa0; My name is Pierre Cadieux, and I&#x2019;ll be helping contribute to these newsletters. A little about me: I&#x2019;ve been working in the cybersecurity industry in many roles over the past 20+ years, first focusing on endpoint security, policies, and firewalls, then moving to risk management and compliance, disaster recovery, and investigations. I spent about 15 years as a consultant working across many well-known consultancy firms and eventually moved to Cisco where I spent time doing security operations center (SOC) design and assessments as well as segmentation before moving to the Talos IR team. I spent many years there, first as an Incident Commander and then a manager of our excellent team of global IR consultants and investigators. My current role is with the Talos Threat Intelligence and Interdiction team, where I&#x2019;m focused on intelligence efficacy &#x2014; how we can do better with the data we have, how we can get more data, and what our customers want from our intelligence products.&#xa0; Since it&#x2019;s Cybersecurity Awareness Month, I wanted to take a few minutes to collectively thank all of the defenders out there for the hard work you do each day. The work you do may not always be visible, but it matters.&#xa0;&#xa0; I remember one job I had many years ago when I was in charge of security for a financial institution. I spent time learning each of the business processes that we had so I could understand each of the moving parts, what was essential, and what was on the horizon for change. I even spent a couple days meeting with the folks who handled printing. Yeah, printing &#x2014; but not reports or internal documents. These were the people that created the checks that our institution used to pay other institutions, and more importantly (to me) our customers.&#xa0; I recall there being many out-of-patch compliance boxes in this area of the company, so I, being the diligent Director, decided to find out why. It turns out the software being used to print these business essential checks would not run on the current operating systems, and the physical printer cards used to connect to these non-network printers also required older hardware ports. As one of the people I interviewed said, &#x201c;We don&#x2019;t want to be the reason someone&#x2019;s grandma doesn&#x2019;t get her check and can&#x2019;t go to the grocery store.&#x201d;&#xa0; There were (at the time) no other alternatives that we could deploy, and the environment had zero tolerance for downtime. The solution I proposed was to isolate these devices into their own network, which blocked access to and from the internet for these devices, and also reduced the likelihood that these devices would be identified during an adversary&#x2019;s internal reconnaissance or mapping. It didn&#x2019;t patch the vulnerable devices, but it went a long way to reducing the likelihood of a bad thing happening to these devices due to their out-of-date OS and software.&#xa0; This story is especially appropriate today, as we face ever-increasing numbers of vulnerabilities announced by software vendors, and can only expect this volume to continue to increase. Do what you can to make sure the checks still get printed, while managing your risks intentionally.&#xa0; The one big thing &#xa0;Cisco Talos is disclosing new findings from our CAIRN research that show malware authors are embedding natural-language instructions into their code to evade AI-assisted analysis. We classify this growing trend as \"A3: AI-Analysis Evasion.\" Over the past 18 months, we&apos;ve tracked techniques ranging from simple comments telling an AI to ignore a file, to advanced \"template spraying\" designed to trick specific large language models (LLMs).&#xa0;&#xa0; Why do I care?&#xa0;Attackers expect AI to be in your analysis pipeline, and they&#x2019;re developing cheap methods to manipulate those systems. While we found these prompt-injection techniques only steer the AI&apos;s verdict in the attacker&apos;s favor about 35 percent of the time, they are being adopted across all levels of malware sophistication. A3 families like MANTLEMAZE also pair these AI deceptions with serious underlying threats, such as abusing vulnerable drivers to disable EDR from kernel space.&#xa0; So now what?&#xa0;Because these evasion instructions must be written in plaintext, defenders have a highly stable detection surface to monitor. Security teams should flag imperative language addressed to analysis systems within binaries as a suspicious signal. Most importantly, anyone building or using AI-assisted pipelines must ensure that text extracted from a sample is strictly treated as evidence, never as a system directive. Read the full blog for more information on these techniques and a list of sample hashes.&#xa0; Top security headlines of the week&#xa0;Citrix NetScaler security snafus get even worse amid more zero-day reports&#xa0; This latest vulnerability, tracked as CVE-2026-88779, is a memory overflow bug that leads to denial of service attacks. (The Register)&#xa0; Hackers steal 8 million citizens&#x2019; records from Danish government database&#xa0; The Danish government would not say who is behind the breach, which happened in September but was discovered on October 2. However, it said the unauthorized access was obtained by &#x201c;abusing a Danish company&#x2019;s lawful access to search for information in the CPR system.&#x201d; (TechCrunch)&#xa0; Google narrows open-source bug bounty amid wave of invalid automated reports&#xa0; Google has temporarily closed its Open Source Software Vulnerability Reward Program (OSS VRP) to product vulnerability submissions. According to Google, it has no impact on the program&#x2019;s supply chain reports or on any pending reports. (SecurityWeek)&#xa0; Warlock ransomware hits large Spanish, Portuguese orgs&#xa0; In the last two months, researchers observed Warlock attacks against four victims: a water utility, a telecommunications provider, a regional government body, and a university. (Dark Reading)&#xa0; U.S. Senate passes health care cybersecurity bill after 190 million impacted by Change Healthcare breach&#xa0; The Health Care Cybersecurity and Resiliency Act of 2026 was passed by unanimous consent last week, potentially expanding federal cyber requirements for health care organizations. (The Record)&#xa0; Can&#x2019;t get enough Talos?&#xa0;One breach, please, and make no mistakes&#xa0; The cybersecurity community has seen examples of autonomous agents, built inside AI labs, attacking public infrastructure. How you prepare for agentic threats is what makes the difference during real incidents.&#xa0; Talos Takes: Honey, I Trapped the Adversary&#xa0; It&#x2019;s time to start having fun and messing with your attackers. For Cybersecurity Awareness Month, Martin Lee joins Amy to discuss the fine art of making life on your network a complete nightmare for adversaries.&#xa0; The Fine Art of Frustrating the Adversary&#xa0; What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier, from deception and behavioral detection to breaking attack dependencies.&#xa0; Upcoming events where you can find Talos&#xa0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xa0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xa0;SecurityOnion Conference (Oct. 23) Augusta, GA&#xa0;BsidesAugusta (Oct. 24) Augusta, GA&#xa0;SAINTCON (Oct. 26 &#x2013; 30) Provo, UT&#xa0;Most prevalent malware files from Talos telemetry over the past week&#xa0;&#xa0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xa0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xa0; Example Filename: sample.exe&#xa0; Detection Name: W32.9F1F11A708-100.SBX.TG&#xa0; SHA256: fed979f93bcaf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f&#xa0; MD5: 207d9d891ac756b2bfad88aba5682c65&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=fed979f93bcaf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f&#xa0; Example Filename: sample.exe&#xa0; Detection Name: W32.FED979F93B-95.SBX.TG&#xa0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xa0; MD5: 38de5b216c33833af710e88f7f64fc98&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xa0; Example Filename: SECOH-QAD.exe&#xa0; Detection Name: W32.9896A6FCB9-95.SBX.TG&#xa0; SHA256: 73ac1bbfaee6c76c34f655ac0477a4cd930f2aa55e658c8e312ff81aac9a741f&#xa0; MD5: 63f3351cfdf618bec6045f60203e7978&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=73ac1bbfaee6c76c34f655ac0477a4cd930f2aa55e658c8e312ff81aac9a741f&#xa0; Example Filename: f_003914.exe&#xa0; Detection Name: W32.PUP:PulseBrowser.29kh.in12.Talos&#xa0; SHA256: 58d6fec4ba24c32d38c9a0c7c39df3cb0e91f500b323e841121d703c7b718681&#xa0; MD5: f1fe671bcefd4630e5ed8b87c9283534&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=58d6fec4ba24c32d38c9a0c7c39df3cb0e91f500b323e841121d703c7b718681&#xa0; Example Filename: KMSAuto Net.exe&#xa0; Detection Name: W32.58D6FEC4BA-95.SBX.TG","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":["CVE-2026-88779"],"titleFingerprint":"checks-get-making-printed-sure","countryCodes":["DK","ES","PT"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/making-sure-the-checks-get-printed/","type":"report","title":"Cisco Talos: Making sure the checks get printed"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:00:29.000Z","addedAt":"2026-10-08T18:41:26.713Z","updatedAt":"2026-10-08T18:41:26.713Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"9dc6b0cd-8c8e-46b7-937a-9e4c2a7c1e60","slug":"talos-give-yourself-room-to-be-human-8c885f05","externalId":"6abd6c72bff6790001c729f7","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Give yourself room to be human","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xa0; Fall is officially here in Maryland, and I can&#x2019;t be more relieved. I flourish in 50 degree weather, where it feels natural to burrow under blankets, knit sweaters, and listen to an audiobook.&#xa0; Beyond that, though, can I say that I&#x2019;m glad fall is here because the end of summer has been a bit of a shitshow? I&#x2019;m allowed to curse on here, right?&#xa0; Without going into too much detail, my uncle was diagnosed with a rare cancer, and my family decided we were going to fly out&#xa0;to spend a week with him. I was determined to find a way to make it work, but on top of all of the emotions, my mind was racing with trying to figure out how to request the time off and get coverage for the tasks I&#x2019;d be missing.&#xa0; I was anxious to ask, but my manager&#x2019;s response to me requesting the week off was: &#x201c;Family always, always comes first at Talos. You spend as much time with your family as you need. Don&#x2019;t worry, we&#x2019;ll work everything out. We have your back.&#x201d; I knew I was in such a fortunate position to have that kind of support. Yet, even with the explicit encouragement to step away, there was still a lingering weight on my shoulders that I couldn&apos;t quite set down.&#xa0; LinkedIn might be an awful, artificial place, but occasionally I&#x2019;ll find a non-AI-generated think piece or quote that sticks with me. On a recent post, I read, &#x201c;We&#x2019;d all be better off if we gave each other a little more room to be human here without worrying it makes us look less capable.&#x201d;&#xa0; Okay, ouch! That described the unsettled feeling to a T. Ever since I was laid off at my previous company, my trauma response has insisted I prove myself, make myself &#x201c;indispensable&#x201d; and capable of taking on any challenges thrown my way. I&apos;m sure if you&apos;ve been through a layoff, you can relate.&#xa0; If you&#x2019;re scared of your team perceiving you as&#xa0;less capable and more dispensable, please hear this: You are not a machine, and your value to your team isn&apos;t defined by how much personal or professional weight you take on without a break. It&apos;s so easy&#xa0;to extend grace to others, to insist that they spend time with their ill family members, but we have to extend the same grace to ourselves.&#xa0; If your team is great, they&#x2019;ll want you at your best, not just your most productive, so you can fight the good fight. Don&apos;t let this fear stop you from taking the time you need. Life is worth living now, and we&#x2019;re better at what we do when we&#x2019;re well in all aspects of life. The one big thing &#xa0;For Cybersecurity Awareness Month, Talos is sharing crowdsourced strategies from our researchers to help you master &#x201c;The Fine Art of Frustrating the Adversary.&#x201d; By deploying deception techniques, behavioral detections, and strict controls over legitimate tools, defenders can strip away an attacker&apos;s advantages. The goal is to make every alternative slower, less stealthy, and significantly more expensive for the threat actor. Ultimately, we want to force them to make mistakes or give up entirely.&#xa0; Why do I care?&#xa0;Threat actors rely on predictable environments, dual-use tools, and manufactured urgency to execute operations at scale. If defenders rely solely on tool-specific detections, adversaries can easily pivot by simply swapping out a payload. Shifting to behavior-based detections and introducing friction, like honeypots or strict AI boundaries, exploits the fact that attackers have rigid end goals. This approach slows down their operations and gives defenders earlier opportunities to interrupt the attack chain.&#xa0; So now what?&#xa0;Start by allowlisting approved remote monitoring and management (RMM) tools and blocking unauthorized ones to prevent dual-use abuse. Build resilient behavioral analytics that target underlying techniques rather than specific malware. Consider deploying deception tactics like fake employee profiles or false infrastructure. Ensure any AI agents in your environment have identifiable, short-lived credentials and strict network boundaries. And, of course, explore the blog to dive deeper into these strategies.&#xa0; Top security headlines of the week&#xa0;South Africa seeks help after cyber attack targets air traffic control&#xa0; The South African state-owned company that provides air traffic control and weather operations for approximately 10% of the world&apos;s airspace discovered ransomware-linked malware in an OT network.&#xa0;(Dark Reading)&#xa0; Automated AI agent used to breach cybersecurity nonprofit DIVD&#xa0; The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyber attack that the organization described as &#x201c;loud and very, very messy.&#x201d; Evidence uncovered during the ongoing investigation indicates the attacker exploited a vulnerability, but the attack&apos;s purpose and impact remain unclear at this stage. (Bleeping Computer) Citrix confirms 2 NetScaler zero-days after admins pulled the plug&#xa0; Citrix rushed out patches for two critical NetScaler zero-day vulnerabilities that have been exploited in the wild. The advisory&#xa0;covers eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway. (SecurityWeek)&#xa0; Pentagon personnel agency data breach impacts 3 million people&#xa0; The US Defense Manpower Data Center (DMDC), which maintains personnel records for the Pentagon, has started notifying people that their personal information was exposed.&#xa0;Unauthorized users had access to one of its file-sharing servers for roughly nine months. (SecurityWeek)&#xa0; TeamViewer urges users to patch severe flaws &#x201c;as soon as possible&#x201d;&#xa0; Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. (Bleeping Computer)&#xa0; Cisco&#x2019;s Relentless Defense report is available now&#xa0; Cisco asked 8,000 security leaders from across the globe how they&#x2019;re coping with a threat landscape being reshaped by AI, including whether their processes can keep pace with AI&#x2019;s ability to surface thousands of vulnerabilities at once, and whether they&#x2019;re confident staying ahead of the volume of new threats being discovered. (Cisco)&#xa0; Can&#x2019;t get enough Talos?&#xa0;China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor&#xa0; Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as &#x201c;Antino&#x201d; in developer artifacts.&#xa0; Securing the keys to the kingdom: Announcing Executive Threat Detection&#xa0; For a sophisticated threat actor, an executive is not only a high-ranking employee, but also a high-yield target. Talos IR&#x2019;s new service offers protection for up to 10 principals, with monthly custom threat hunts and reports relevant to your organization&#x2019;s most high-value IT assets.&#xa0; Beers with Talos: Your AI malware experiments are showing&#xa0; Adversaries are experimenting with AI-integrated malware, and today&apos;s guest, Talos researcher Ryan Fetterman, has been looking at their working notes.&#xa0; Upcoming events where you can find Talos&#xa0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xa0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xa0;SecurityOnion Conference (Oct. 23) Augusta, GA&#xa0;BsidesAugusta (Oct. 24) Augusta, GA&#xa0;SAINTCON (Oct. 26 &#x2013; 30) Provo, UT&#xa0;Most prevalent malware files from Talos telemetry over the past week&#xa0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xa0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xa0; Example Filename: sample.exe &#xa0; Detection Name: W32.9F1F11A708-100.SBX.TG**&#xa0; SHA256: 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974&#xa0; MD5: aac3165ece2959f39ff98334618d10d9 &#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974&#xa0; Example Filename: d4aa3e7010220ad1b458fac17039c274_63_Exe.exe &#xa0; Detection Name: W32.Injector:Gen.21ie.1201&#xa0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 &#xa0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a &#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xa0; Example Filename: tmp00055df5.dll &#xa0; Detection Name: Auto.90B145.282358.in02&#xa0; SHA256: 540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8&#xa0; MD5: d65c7b544a97b0c3f2773b5fcc57d30e &#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8&#xa0; Example Filename: f_006048.exe &#xa0; Detection Name: W32.540080FEA9-95.SBX.TG&#xa0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xa0; MD5: 38de5b216c33833af710e88f7f64fc98 &#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xa0; Example Filename: SECOH-QAD.exe &#xa0; Detection Name: W32.9896A6FCB9-95.SBX.TG","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":"give-human-room-yourself","countryCodes":["CN","ES","IN","KH","NL","PH","TW","ZA"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/give-yourself-room-to-be-human/","type":"report","title":"Cisco Talos: Give yourself room to be human"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T18:00:52.000Z","addedAt":"2026-10-01T18:52:59.295Z","updatedAt":"2026-10-01T18:52:59.295Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"e8b07fa6-c8ad-4bed-9201-7ce8c0a05198","slug":"talos-trust-and-the-enticing-consultancy-offer-299f8711","externalId":"6ab3dee60a4ca5000177a040","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Trust and the enticing consultancy offer","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xa0; In the cybersecurity industry, trust is the invisible currency. Every practitioner carries the implicit trust not to abuse privileged access or knowledge of vulnerabilities in each employment or engagement. This trust is valued by those who require our services, but also by threat actors.&#xa0; Clumsy phishing attacks may be easy to identify, but be wary of unsolicited messages on social media, especially if someone is offering payment for a simple service or suggests a lucrative job offer. These might be an enticement to unknowingly sell your professional integrity.&#xa0; When an unknown profile contacted me offering &#x24;300 for an hour&#x2019;s telephone consultation on digital transformation, I knew something was up. Firstly, the profile was remarkably sparse &#x2014; there was none of the usual clutter that accumulates in a social media profile. The individual claimed to work as a consultant, but their employer had no footprint and only one employee. The profile didn&#x2019;t pass the &#x201c;smell&#x201d; test, and it looked fake.&#xa0; Secondly, although I&#x2019;m flattered, I doubt my opinions on digital transformation are worth &#x24;300. The figure is low enough to be plausible and high enough to be tempting, but at the same time suspiciously high for an initial consultation without prior qualification.&#xa0; The attack itself is a confidence trick. The initial phone consultation is merely a screening process to see if the target has the access or knowledge the attacker needs. If the target passes muster, the next step is commissioning a written report, and then being asked to deliver a \"special report.\"&#xa0; Plied with professional praise, the target is asked to provide insights that aren&apos;t in the public domain. To deliver the report and claim their fee, the target must reach out to co-workers, probe internal systems, or abuse professional relationships. Completing the assignment requires the target to abuse their trusted access and professional relationships and friendships. In the process, they burn trust worth far more than any monetary compensation.&#xa0; This social engineering attempt masquerading as an offer of consultancy is one variant. Fake recruiters offering prestigious and well-paid jobs, requiring candidates to install trojanised software under some pretence, is another.&#xa0; Security professionals spend their days protecting others, yet flattery and overconfidence often remain our greatest vulnerabilities. We are prone to believe that we could identify any social engineering, but this is exactly the weakness that attackers count on.&#xa0; Trust is the most valuable commodity in our industry. Be careful not to trade it for a &#x24;300 consultation or a fake job offer. Once that currency is spent, you can rarely earn it back.&#xa0; The one big thing &#xa0;Talos released CAIRN (Cognitive Artifact Intelligence Research Network), a new open-source research toolkit designed to hunt, classify, and track emerging AI-integrated malware. Instead of relying on traditional reverse engineering, CAIRN uses a metadata-first methodology to identify cognitive artifacts like prompt templates, API keys, and jailbreak terms left behind by attackers. This allows researchers to extract, relate, and classify these artifacts quickly and at scale without ever touching the underlying binary.&#xa0; Why do I care?&#xa0;AI-integrated malware is evolving quickly, shifting from optional features to fully autonomous orchestrators in just a year. Adversaries are already sharing AI-specific tradecraft, including techniques designed to evade LLM sandboxes. Defenders need scalable frameworks to track this rapid transition before these experimental tactics become the new standard for modern attacks.&#xa0; So now what?&#xa0;Security teams can leverage the open-source CAIRN toolkit to expand their hunting capabilities and map out related malware infrastructure. While analysts should anticipate some noise from benign frameworks &#x2014; meaning final verdicts still require manual reverse engineering &#x2014; CAIRN can provide a massive head start. Read the full blog to explore the methodology, access the YARA-based classification tiers, and watch a demo of the toolkit in action.&#xa0; Top security headlines of the week&#xa0;Hackers say they have data on all FBI employees&#xa0; ShinyHunters claims it has breached multiple FBI-related services and stolen data &#x201c;on all FBI employees and applicants.&#x201d; A representative told 404 Media the data includes FBI agents&#x2019; names, home addresses, phone number, and information on their spouse. (404 Media)&#xa0; Fake LastPass installers push kernel-level EDR killer, &#x201c;Rapuncel&#x201d; stealer&#xa0; A fake LastPass Authenticator distributed via GitHub has led to the discovery of a broad impersonation campaign delivering infostealer malware. The lure represents opportunistic brand spoofing &#x2014; with no internal LastPass systems compromised. (SecurityWeek)&#xa0; Japan dismantles first North Korean laptop farm as U.S. and allies detail wider scheme&#xa0; Law enforcement and intelligence agencies from Japan, the United States, Australia and Germany have published a joint advisory attributing a long-running hiring scheme to a North Korean group they call WaterPlum, also known as&#xa0;Contagious Interview. (SecurityWeek)&#xa0; Colorado water utilities face foreign cyberattacks targeting pumps, alarms and remote access&#xa0; Hackers targeted and manipulated equipment at two privately owned Colorado water utilities in late August, changing pumping cycles, disabling remote access and alarms, and altering equipment settings. (Industrial Cyber)&#xa0; Gemini hacked three companies in first known breakout by Google&#x2019;s AI &#xa0; In one of the cases, the model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems. (The Wall Street Journal)&#xa0; Can&#x2019;t get enough Talos?&#xa0;Inside the first reported autonomous AI C2 implant&#xa0; CLOSEDQUORUM, a malware binary discovered through Talos&#x2019;&#xa0;CAIRN project, exhibits fully autonomous command and control. After deployment, it delegates the selection of its next action to a panel of commercial large language models (LLMs) and executes the resulting decision.&#xa0; ClickFix, EtherHiding, and the rise of malicious code in the blockchain&#xa0; In this episode of Talos Takes, Amy sits down with researcher Vanja Svajcer to break down a sophisticated, multi-stage infection chain that leverages a combination of ClickFix social engineering, WebDAV, and decentralized infrastructure. Ransomware incidents in Japan in the first half of 2026&#xa0; Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims. Upcoming events where you can find Talos&#xa0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xa0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xa0;SecurityOnion Conference (Oct. 23) Augusta, GA&#xa0;BsidesAugusta (Oct. 24) Augusta, GA&#xa0;SAINTCON (Oct. 26 &#x2013; 30) Provo, UT&#xa0;Most prevalent malware files from Talos telemetry over the past week&#xa0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xa0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xa0; Example Filename: sample.exe&#xa0; Detection Name: W32.9F1F11A708-100.SBX.TG&#xa0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xa0; MD5: 38de5b216c33833af710e88f7f64fc98&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xa0; Example Filename: SECOH-QAD.exe&#xa0; Detection Name: W32.9896A6FCB9-95.SBX.TG**&#xa0; SHA256: 540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8&#xa0; MD5: d65c7b544a97b0c3f2773b5fcc57d30e&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8 Example Filename: f_000bc7.exe&#xa0; Detection Name: W32.Superfluss.29lm.1201&#xa0; SHA256: cfa1997682e4ed41bc691ba848d845abbe0b75ec97e640c2b015b4d1624a108a&#xa0; MD5: 415898f14843d4a6537cf8f43d328eaf&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=cfa1997682e4ed41bc691ba848d845abbe0b75ec97e640c2b015b4d1624a108a&#xa0; Example Filename: KMSAuto.exe&#xa0; Detection Name: PUA.Win.Tool.Hackkms::1201**&#xa0; SHA256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xa0; MD5: 41444d7018601b599beac0c60ed1bf83 &#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xa0; Example Filename: content.js &#xa0; Detection Name: W32.38D053135D-95.SBX.TG","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":"consultancy-enticing-offer-trust","countryCodes":["AU","DE","ES","JP","KP","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/trust-and-the-enticing-consultancy-offer/","type":"report","title":"Cisco Talos: Trust and the enticing consultancy offer"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T18:00:37.000Z","addedAt":"2026-09-24T18:52:57.104Z","updatedAt":"2026-09-24T18:52:57.104Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"0f3a7ed7-e125-4bd9-8d28-aaedd2784491","slug":"talos-should-you-care-about-an-ai-slowdown-fb412f2e","externalId":"6aaabb8375b5420001d63831","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Should you care about an “AI slowdown?”","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xa0; There&#x2019;s been a lot of talk recently about slowing down the pace of AI development. And yes, there are legitimate moral, ethical, geopolitical, and safety concerns with the use of AI. It&#x2019;s not clear yet whether an AI slowdown could happen, let alone whether it should (hat tip to Dr. Ian Malcolm). I admit, I&#x2019;m not really qualified to opine on the impacts unrestricted AI might have on bioterrorism, the balance of international power, or even our chances of being eaten by dinosaurs. What I can tell you, though, is that any sort of &#x201c;AI slowdown&#x201d; is not likely to have much of an impact on cybersecurity.&#xa0;&#xa0; There are a few reasons to think this. The most obvious one is that models are already really good. We&#x2019;re at the point where the newest models bring only incremental improvements in cybersecurity capabilities. Arguably, they&#x2019;ve been getting better so fast that our ability to use them effectively for defensive tasks hasn&#x2019;t kept up. On the offensive side, practically every recent model is already able to mine decades of tech debt to uncover an uncomfortable number of vulnerabilities. Instead of chasing model improvements, our best strategy might be to improve our agentic harnesses and frameworks, essentially giving us better capabilities with our existing models.&#xa0; Maybe even more importantly, many of us are still not eating our cyber-vegetables. I get it: AI is hot. It&#x2019;s sexy. It brings the money and the board&#x2019;s attention. But no matter how great your AI is, if it&#x2019;s sitting on the typical two-and-a-half-legged stool that is most IT environments, you&#x2019;re still going to have compromises and breaches no matter how much AI you throw at it. We&#x2019;ve known for a long time now that good security depends on things like asset and role inventories, identity management, least privilege, and segmented networks. They&#x2019;re not as shiny as AI, but they&#x2019;re more impactful in terms of making it harder for threats both human and agentic to successfully carry out attacks. This is not to say that you shouldn&#x2019;t be looking at AI until you&#x2019;ve solved all your other security problems; just don&#x2019;t look only to AI.&#xa0; Regardless of whether we slow the pace of AI development or not, we still have plenty of places to make significant security improvements using the models we already have access to. By making better use of what we already have and by investing in well-known security fundamentals, we can come out ahead no matter whether AI development accelerates, slows down, or is trapped in a kitchen with a pack of hungry velociraptors.&#xa0; P.S. I&#x2019;ve got some speaking engagements coming up soon (see below). If you see me, don&#x2019;t be shy about asking for a Pyramid of Pain sticker or button!&#xa0; The one big thing &#xa0;Cisco Talos is sharing new insights into Japan&apos;s ransomware landscape, where incidents rose nearly 5 percent in the first half of 2026. This increase is driven by two prominent actors: \"The Gentlemen,\" a rapidly expanding ransomware-as-a-service group, and \"Qilin,\" which is leveraging generative AI to streamline its attacks. Both groups are aggressively targeting small- and medium-sized enterprises with double-extortion tactics.&#xa0; Why do I care?&#xa0;Adversaries are working smarter, not harder. Qilin uses large language models to generate destructive scripts, accelerating their attack speed and lowering the barrier to entry. Meanwhile, The Gentlemen relies on legitimate red-teaming frameworks like AdaptixC2 to blend in, making lateral movement difficult to detect. This combination of AI-driven efficiency and stealthy techniques puts organizations at risk of data theft and operational disruption.&#xa0; So now what?&#xa0;Strictly manage internet-accessible devices and lock down credentials. Start by auditing VPNs, disabling unused features, and enforcing multi-factor authentication (MFA) across all administrative and third-party accounts. Ensure you have robust endpoint detection to monitor for suspicious remote access or attempts to disable backups. Finally, update your defenses using the Snort rules provided in the full blog to help detect and block this activity.&#xa0; Top security headlines of the week&#xa0;Indonesia hit by Android banking app-cloning campaign&#xa0; Indonesia has emerged as an early testing ground for a new Android&#xa0;banking malware&#xa0;technique that uses Google&apos;s Work Profile feature to help fraudsters evade banking security controls. (Dark Reading)&#xa0; Apple patches 200 vulnerabilities with new iOS 27, macOS Golden Gate 27 releases&#xa0;&#xa0; Approximately 100 of the resolved security defects affect both the mobile and desktop operating systems. The fixes target more than 90 platform components, including AppleKeyStore, Authentication Services, Foundation, Safe Browsing, Sandbox, Security, TCC, and WebKit. (SecurityWeek)&#xa0; ClickFix attacks are tricking Mac and Windows users into hacking themselves&#xa0; Hackers posting fake ads on Reddit, linking to a page that looks like HBO Max but contains a ClickFix lure that tricks people into hacking themselves. The hackers compromised the official HBO Max&#x2019;s account on Reddit that was then used to post hundreds of fake but real-looking adverts to the news-sharing site. (TechCrunch)&#xa0; VectraRAT can hack Windows enterprises for &#x24;250 per month&#xa0; VectraRAT, a previously undocumented platform that includes a full-featured Windows implant, command-and-control (C2) infrastructure, and an operator panel built entirely from scratch rather than based on existing malware (Dark Reading)&#xa0; Can&#x2019;t get enough Talos?&#xa0;Securing the unpatchable in an age of AI-driven vulnerabilities&#xa0; Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous visibility, and the deployment of NGFW/IPS combinations can provide a powerful compensatory layer.&#xa0; Beers with Talos: Martin Lee would like everyone to go outside&#xa0; Martin may have stopped being a Talos employee, but we made him come on the podcast anyway to talk about abandoning his early career aspirations of researching human viruses so he could play on the internet&#xa0;&#x2014; and also running very long distances in crazy conditions.&#xa0; Upcoming events where you can find Talos&#xa0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, AZ&#xa0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xa0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xa0;SecurityOnion Conference (Oct. 23) Augusta, GA&#xa0;BsidesAugusta (Oct. 24) Augusta, GA&#xa0;SAINTCON (Oct. 26 &#x2013;&#xa0;30) Provo, UT&#xa0;Most prevalent malware files from Talos telemetry over the past week&#xa0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xa0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xa0; Example Filename: VID001.exe &#xa0; Detection Name: W32.9F1F11A708-100.SBX.TG**&#xa0; SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xa0; MD5: 9a47c4d379998ade2f8f99e23a630c06 &#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xa0; Example Filename: WCInstaller_NonAdmin.exe &#xa0; Detection Name: W32.C4DD71E347-95.SBX.TG&#xa0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f &#xa0; MD5: 38de5b216c33833af710e88f7f64fc98 &#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xa0; Example Filename: SECOH-QAD.exe &#xa0; Detection Name: Win.Tool.Procpatcher::1201&#xa0; SHA256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55 &#xa0; MD5: 41444d7018601b599beac0c60ed1bf83 &#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xa0; Example Filename: content.js &#xa0; Detection Name: W32.38D053135D-95.SBX.TG&#xa0; SHA256: fed979f93bcaf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f&#xa0; MD5: 207d9d891ac756b2bfad88aba5682c65 &#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=fed979f93bcaf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f&#xa0; Example Filename: AAct.exe &#xa0; Detection Name: W32.FED979F93B-95.SBX.TG**","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":["ES","ID","JP"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/should-you-care-about-an-ai-slowdown/","type":"report","title":"Cisco Talos: Should you care about an “AI slowdown?”"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-17T18:00:23.000Z","addedAt":"2026-09-17T18:52:54.829Z","updatedAt":"2026-09-17T18:52:54.829Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"afda5d9b-069f-44f5-96d1-8d00be9a1feb","slug":"talos-we-ve-got-one-word-for-it-and-it-s-usually-the-wrong-one-e5e8a691","externalId":"6aa1b1fa1aab0c0001cec6d2","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"We've got one word for it, and it's usually the wrong one","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0; Ask anybody in this industry what the work does to the health of the people who do it and you get one word back: burnout. It&apos;s a fine word, in and of itself. It&#x2019;s easy to reach for, understandable to everyone&#x2026; and it&apos;s the wrong one, most of the time.&#xA0; So, story time. Last year I gave an interview with the amazing Hazel Burton about VPNFilter, and my run-in with burnout. I was a manager during that time, and it took a toll on me and on the people around me, and when it was over I didn&apos;t have language for what had happened. Neither did my peers. Neither did my leadership. Nobody was withholding help from me&#x2026; we just didn&apos;t have the words.&#xA0;&#xA0; Enter this summer, and I was afforded a unique opportunity to mentor some MBA students on burnout in cybersecurity. I know a thing or two about it, so I leapt at a chance to share and help grow future leaders. But I decided I was going to do more than share and relieve my experiences in this industry &#x2013; I wanted to give back to them and the security industry. So, I fell down a fascinating and revealing research hole and learned better words to describe my experiences over my career.&#xA0; I spent my summer reviewing trauma case studies, clinical and academic literature on trauma in career fields like first responders, doctors, social workers, and the military. There are many decades of research focusing on trauma in those fields. Subsequently, my brain is packed full of better words! For example, burnout is exhaustion from chronic workload, and it eases when the load eases. We know this one well. Secondary traumatic stress is what absorbing somebody else&apos;s trauma does to you, and it looks like trauma. Think the CTI analyst exposed to horrible things on the dark web. Vicarious trauma is what years of other people&apos;s worst days do to how you see the world. It changes your beliefs, not your mood. Work in cybersecurity long enough, and it can pile up on your views. Moral injury is the damage from being made to act against your own values, or stopped from doing what you knew was right. This one can affect anyone who&#x2019;s ever owned an outcome, but not the decision, and that&#x2019;s common in this industry.&#xA0; One word, four injuries, and four different fixes. All of them are present in the industry that is cybersecurity. The problem? We&#x2019;re just a young industry. Compared to medical, helping professions, or social workers, we&#x2019;re incredibly immature with understanding the consequences of the work and the toll it takes on us. Next week I&#x2019;ll be revealing my research and a peer-deployable framework to help others process, cope, and respond in healthy ways to keep us all in a better mental space, and staying in this good fight of protecting others.&#xA0;&#xA0; I&apos;m still not good at this. I&apos;m writing it all down because I was bad at it in a way that cost me something. There&apos;s more of this in my talk at CYBR.SEC.CON next week if you&apos;re in Houston.&#xA0; Go ask somebody how they&apos;re doing and wait for the answer. Be present for them. It matters.&#xA0;&#xA0; Take care of yourselves, and take care of each other.&#xA0; The one big thing &#xA0;Cisco Talos is disclosing a complex WebDAV infection chain discovered after investigating an incident at a Ukrainian government organization. Attributed to a Russian threat actor tracked as UAT-10820, the campaign delivers the Amatera stealer alongside secondary payloads like ZigCryptoStealer and NetSupport Manager. Despite the high-profile initial victim, we assess with moderate confidence that this is an opportunistic, broad-based cryptocurrency and credential-stealing operation rather than a highly targeted attack.&#xA0; Why do I care?&#xA0;Threat actors are getting really creative with their delivery mechanisms and evasion tactics. By abusing legitimate infrastructure like the BNB Smart Chain for bulletproof hosting and leveraging fake CAPTCHA prompts, attackers can easily bypass traditional web filters. Additionally, the secondary payloads pack a serious punch. The inclusion of a vulnerable driver to terminate EDR software and the deployment of unauthorized remote access tools give attackers deep, persistent control over infected systems.&#xA0; So now what?&#xA0;Security teams should monitor for unusual WebDAV activity and the execution of disguised DLLs through \"rundll32.exe\" using suspicious ordinal calls. Make sure to educate your users on the dangers of copying and pasting commands from fake verification prompts. Since the Amatera payload often resides entirely in memory, defenders should also ensure their endpoint solutions are configured for robust memory scanning. Finally, you can find a comprehensive list of indicators of compromise (IOCs) in the full blog.&#xA0; Top security headlines of the week&#xA0;New Microsoft Defender &apos;ShieldCrash&apos; zero-day grants SYSTEM access&#xA0; An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named \"ShieldCrash\" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. (Bleeping Computer)&#xA0; North Korean hackers deploy new Linux espionage toolkit&#xA0; The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The toolkit supports remote command execution, credential harvesting, and script injection into web traffic. (SecurityWeek)&#xA0; Attackers use multi-hop Google redirects for phishing campaign&#xA0; What sets this campaign apart is that in order to bypass gateways, email filters, and other security tools, the link relies on a chain of redirects across Google domains, intending for link inspectors to see multiple Google domains and let the URL through. (DarkReading)&#xA0; OpenAI agents took over Wiki site before Hugging Face attack&#xA0; A team of independent researchers revealed the parallel incident on Sept. 4, which was first reported by Reuters, affecting a largely defunct German language wiki for programmers called &#x201C;DeutschesSoftwareEntwickler wiki.&#x201D; (DarkReading)&#xA0; Can&#x2019;t get enough Talos?&#xA0;Patch Tuesday for September 2026&#xA0; Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as \"critical.\"&#xA0; Active exploitation of Cisco Secure Firewall Management Center vulnerabilities&#xA0; Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco&#x2019;s Secure Firewall Management Center (FMC) Software: CVE-2026-20079 and CVE-2026-20316. Customers are strongly advised to apply hotfixes for affected software versions already released by Cisco.&#xA0; ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2&#xA0; Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim&apos;s browser session.&#xA0; Browser betrayal: When your tabs turn against you&#xA0; Security Engineer Sean Gallagher joins Amy to break down a scam where threat actors are weaponizing greed to turn amateur cybercriminals against themselves. While this current operation mostly targets the amateur dark-web circuit, the underlying use of the Google Visualization API as a command-and-control channel is a red flag for the future of web security.&#xA0; Upcoming events where you can find Talos&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;CYBR.SEC.CON. (Sept. 15 &#x2013; 16) Houston, TX&#xA0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, AZ&#xA0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xA0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe &#xA0; Detection Name: W32.9F1F11A708-100.SBX.TG**&#xA0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 &#xA0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; Example Filename: tmp00055df5.dll &#xA0; Detection Name: Auto.90B145.282358.in02&#xA0; SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; MD5: 9a47c4d379998ade2f8f99e23a630c06 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; Example Filename: sample.exe&#xA0; Detection Name: W32.C4DD71E347-95.SBX.TG&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; MD5: 38de5b216c33833af710e88f7f64fc98&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: SECOH-QAD.exe &#xA0; Detection Name: Win.Tool.Procpatcher::1201&#xA0; SHA256: 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811 &#xA0; MD5: f3e82419a43220a7a222fc01b7607adc&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811&#xA0; Example Filename: 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811.exe &#xA0; Detection Name: Win.Dropper.Suloc::1201&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":["CVE-2026-20079","CVE-2026-20316"],"titleFingerprint":"got-one-usually-word-wrong","countryCodes":["DE","ES","KP","KR","RU","UA"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/","type":"report","title":"Cisco Talos: We've got one word for it, and it's usually the wrong one"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-10T18:00:15.000Z","addedAt":"2026-09-10T18:52:52.822Z","updatedAt":"2026-09-10T18:52:52.822Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"7decfbf2-ae3d-432b-a140-df41a1358300","slug":"talos-the-story-behind-the-intelligence-4cefdb63","externalId":"6a987a665b9e1a0001b4e2cc","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"The story behind the intelligence","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0; Our goal is to get accurate threat intelligence to our audience as quickly as possible, with all the context you need to ask the right questions of your own environment: How at risk are we from this threat? Are we prepared for it? And what can we do about it?&#xA0; What you don&#x2019;t often see is all the... well, frankly, &#x201C;mess&#x201D; involved in producing it. All the dead ends we followed until we could confirm those ends were as dead as a doornail. All the work it took to ultimately produce an assessment, supported by evidence and written so that defenders can act on it.&#xA0; Much of that abstraction is necessary. Defenders need intelligence they can use, not a complete account of every conversation we had, or investigative detour behind it. But it can create an overly tidy picture of both cybercrime and the work required to understand it.&#xA0; If you do fancy a look behind the curtain, though, may I recommend our just-published episode of Beers with Talos?&#xA0; Our guest is Azim Khodjibaev, whose remit is adversary engagement. His work involves developing personas for deep- and dark-web research, engaging directly with threat actors, and building relationships with people who may become (and have been) openly threatening to him.&#xA0; At one point, he was maintaining eight separate personas, some of which were interacting with one another. Azim&#x2019;s engagements have helped Talos identify prolific cybercriminals and contributed to wider disruption efforts. They have also resulted in ransomware operators placing &#x201C;Azim sucks&#x201D; in their code and accusing him of belonging to the very criminal groups he was investigating.&#xA0; His experiences also expose the problem with treating adversaries as uniformly sophisticated operators. Some are technically capable and highly organised. Others are impulsive, ego-driven, or one-trick ponies. Many have a scary detachment from the consequences of their actions. Increasingly, Azim is seeing less-experienced threat actors working through loosely organised online collectives.&#xA0;&#xA0; Intelligence necessarily turns that disorder into something defenders can understand and use. But occasionally, it is worth looking behind the finished product &#x2013; the patience it takes to get accurate answers, who we are investigating, and the deeply human behaviour that shapes both sides.&#xA0; This Beers with Talos episode, &#x201C;Eight People Walk Into a Dark Web Forum. They&#x2019;re All Azim,&#x201D; isn&#x2019;t exactly going to help many people in our industry sleep better at night. But for anyone wanting to understand more about the threat we&#x2019;re up against, as a co-host of the pod I&#x2019;m biased, but I believe it&#x2019;s an essential listen.&#xA0; And if that doesn&#x2019;t inspire you to download the episode, perhaps my live review of trying Flamin&#x2019; Hot Cheetos for the very first time (with a chaser of Nerds) will.&#xA0; The one big thing &#xA0;Cisco Talos is highlighting a growing operational hurdle for security teams that we call the AI \"safety penalty.\" As frontier AI models advance, their built-in guardrails are increasingly blocking legitimate defensive tasks. This was evident in July 2026 when Hugging Face&apos;s primary cloud LLM refused to analyze forensic data during a breach, delaying their response. While defenders are slowed by these frustrating refusals, adversaries are freely leveraging unconstrained models to attack at machine speed.&#xA0;&#xA0; Why do I care?&#xA0;This guardrail asymmetry hands the advantage directly to attackers. When a cloud-hosted AI model refuses a forensic request mid-incident, defenders lose precious time. Security teams are paying for vendor-imposed limitations without gaining a capability edge, especially as open-weight alternatives close the reasoning gap. Ultimately, relying on third-party alignment policies means a sudden update in Silicon Valley could quietly break your defensive workflows overnight.&#xA0;&#xA0; So now what?&#xA0;Security leadership must reclaim operational sovereignty by ensuring they have the final say over their AI&apos;s capabilities. Start by auditing your AI refusal rates to measure the exact cost of this safety penalty. From there, evaluate alternative architectures like private infrastructure, Model-as-a-Service platforms, or a hybrid fallback system that reroutes refused prompts to an unconstrained local model. Read the full blog to explore these roadmaps and learn how to keep pace with adversaries.&#xA0; Top security headlines of the week&#xA0;ShinyHunters claims it stole 284 million patient records from McKesson&#xA0; ShinyHunters told BleepingComputer and said it got in through vishing calls to McKesson employees, then used stolen credentials to take over Okta single sign-on accounts. (Help Net Security)&#xA0; Anthropic warns Claude users of infostealer malware infections&#xA0; Anthropic emphasized that the malware is general-purpose and not tied to Claude itself, typically arriving via unofficial downloads or malicious apps. The company said the malware quietly copies saved passwords, browser login cookies, and credentials for other local applications. (Security Week)&#xA0; EU puts ChatGPT, Reddit, and Roblox under stricter DSA rules&#xA0; The DSA establishes rules governing areas including platform transparency, illegal content, advertising, researcher access, recommender systems, and systemic-risk management. (CyberInsider)&#xA0; PaperCut issues emergency patches as threat actors target chained vulnerabilities&#xA0; PaperCut issued the patches on Friday to address critical vulnerabilities in its print-management software. The company confirmed in a security advisory that multiple customers were successfully targeted and that it is working with security researchers to respond to the attacks. (Cybersecurity Dive)&#xA0; Can&#x2019;t get enough Talos?&#xA0;JavaScript obfuscation: From party trick to phishing kit We&apos;ve spent a lot of time pulling apart suspicious JavaScript from phishing kits, malware packages, compromised sites, and more. Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem.&#xA0; Choose your fighter: Balancing competing AI SOC model requirements&#xA0; Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. Here&apos;s how to choose.&#xA0; Beers with Talos: Eight people walk into a dark web forum. They&apos;re all Azim. What does it take to become someone a cybercriminal will trust?&#xA0;Talos&apos; Azim Khodjibaev takes us inside the psychology of direct adversary engagement. At one point, he was maintaining eight different personas, some of which were talking to each other. He explains how discipline and patience help keep his cover intact, and what can provoke threat actors into revealing information. Upcoming events where you can find Talos&#xA0;International European Cyber Threat Intelligence Conference (IECTIC) (Sept. 9) Kassel, Germany&#xA0;Secure Iowa (Sept. 9) Altoona, IA&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, AZ&#xA0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xA0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe &#xA0; Detection Name: W32.9F1F11A708-100.SBX.TG**&#xA0; SHA256: 228c316455d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82 &#xA0; MD5: 61e046145ee5cf45aeb033cd71e8b07c &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=228c316455d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82&#xA0; Example Filename: NetGuard.exe &#xA0; Detection Name: W32.228C316455-95.SBX.TG&#xA0; SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 &#xA0; MD5: 7bdbd180c081fa63ca94f9c22c457376 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe &#xA0; Detection Name: Win.Dropper.Miner::95.sbx.tg**&#xA0; SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 &#xA0; MD5: 9a47c4d379998ade2f8f99e23a630c06 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; Example Filename: sample.exe &#xA0; Detection Name: W32.C4DD71E347-95.SBX.TG&#xA0; SHA256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55 &#xA0; MD5: 41444d7018601b599beac0c60ed1bf83 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xA0; Example Filename: content.js &#xA0; Detection Name: W32.38D053135D-95.SBX.TG&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f &#xA0; MD5: 38de5b216c33833af710e88f7f64fc98 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: SECOH-QAD.exe &#xA0; Detection Name: Win.Tool.Procpatcher::1201","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":["DE","ES"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/","type":"report","title":"Cisco Talos: The story behind the intelligence"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-03T18:00:13.000Z","addedAt":"2026-09-03T18:52:50.587Z","updatedAt":"2026-09-03T18:52:50.587Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"c52514fa-fa90-45bc-9bc0-07717783a1ca","slug":"talos-sorry-i-can-t-help-with-that-how-your-guardrails-might-become-0458c861","externalId":"6a8f25b509b4ad0001399a54","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0; Hello, everyone. Long time reader, first time writer here at the Threat Source newsletter! I wanted to start out by introducing myself. My colleague and friend Mick Baccio set the bar pretty high last week, so I was planning to tell you all about myself, including:&#xA0; How I did my first real IR under the influence of The Cuckoo&#x2019;s Egg while an undergraduate (and failed)&#xA0;My pre-bug bounty flirtation with vulnerability research, including an arbitrary file overwrite in biff(1) and how I once hacked MIT&#x2019;s website&#xA0;My first ever hands-on experience with a computer, the display demo Commodore 64 at the Montgomery Ward&#xA0;Unfortunately, my editor says we don&#x2019;t have the &#x201C;space&#x201D; for that, the MIT thing might open me up to &#x201C;liability,&#x201D; and it&#x2019;s not the kind of &#x201C;professional image&#x201D; we strive for here at Talos. (I&apos;m watching. Always watching. -Amy)&#xA0; So instead, I&#x2019;ll just play it safe and say that I&#x2019;ve been in the security field for a little over 30 years now, mostly concentrating on the defensive side (Go, Team Blue!). I&#x2019;ve helped set up SOCs, run threat hunting teams, and even published a few things you might have heard of.&#xA0;&#xA0; Speaking of things I&#x2019;ve published, I&#x2019;ve written before about the Attacker&#x2019;s Dilemma. The idea that defenders have inherent advantages over attackers runs contrary to what most of us have heard throughout our careers. An attacker must evade monitoring and technical controls at every step of their attack lifecycle, because the defender only needs to notice once in order to respond and prevent them from achieving their goal. This is one of the most important advantages of any security team has, but we are currently witnessing a self-imposed erosion of this advantage through the rise of poorly-designed AI guardrails.&#xA0;&#xA0; I&#x2019;m not opposed to guardrails, but we have to carefully consider what we&#x2019;re guarding against and where we deploy them. As I explored in a recent piece on The Safety Penalty, by allowing third-party AI providers to implement and control safety filters and the policies behind them, we may in fact be helping the attacker. If agentic SOC process experience refusals, it can slow or even halt investigations. Of course, these should get flagged for human intervention, but that takes time and may give the attacker breathing room in which to complete their mission.&#xA0;&#xA0; It may turn out that the where of the guardrails is even more important than the what. Operational sovereignty relies on having control of our own limits. Any vision of an agentic SOC must allow the security teams to customize the guardrails according to their own threat model. They should also have the flexibility to temporarily remove specific safeguards under authorized circumstances, something you won&#x2019;t get with guardrails from a frontier provider. These controls belong inside your organization&#x2019;s agentic harness where you can set the policies and technical controls to allow you to analyze threats while ensuring your agents stay within their lanes.&#xA0;&#xA0; Ultimately, operational sovereignty means engaging with the reality of the threat landscape, ensuring that the adversary can&#x2019;t derail the defender&#x2019;s investigation and response processes, either accidentally or intentionally. We need to move toward a model where each organization can choose the guardrails that work for them, rather than having inflexible guardrails chosen for them.&#xA0; The one big thing &#xA0;Cisco Talos recently evaluated 66 large language model (LLM) and reasoning combinations to see if we could find a clear winner&#xA0;for security operations. Instead, we found that selecting the right model is a complex balancing act between efficacy, speed, cost, and consistency. Cranking up a model&apos;s reasoning effort doesn&apos;t guarantee better analysis and can actually degrade performance. Ultimately, we developed a repeatable methodology to help organizations navigate these tradeoffs for their own workflows.&#xA0; Why do I care?&#xA0;Choosing an AI model based solely on generic leaderboard scores is a recipe for operational disaster. An exceptionally smart model might cost a fortune, take half an hour to analyze a single log, or completely fail to format its output. Assuming more compute power equals better results is a costly trap, as higher reasoning settings sometimes produce weaker or blocked responses. Defenders must remember that prompts, analyst personas, and model consistency drastically alter an investigation&apos;s outcome.&#xA0;&#xA0; So now what?&#xA0;Test models against your organization&#x2019;s specific workflows before deploying them. Build a focused set of representative cases and test them multiple times using the exact prompts and tools your analysts will actually use. Track the quality, cost, time, consistency, and usable-answer rates in a simple spreadsheet to expose the real-world tradeoffs. Finally, establish acceptable thresholds for these variables to eliminate underperforming models, and regularly revisit your decisions as AI technology and pricing inevitably shift.&#xA0; Top security headlines of the week&#xA0;ToxicPanda banking trojan matures into enterprise threat&#xA0; ToxicPanda 2.0 expands substantially on its predecessor, adding 167 remote commands and broadening its targeting from 16 financial institutions to 349 banking, e-wallet, and cryptocurrency applications. (Dark Reading)&#xA0; Interpol&apos;s Jackal IV disrupts West African crime infrastructure&#xA0; Law enforcement from 22 countries across six continents worked together to arrest 58 suspects and identify 263 more. The first two Jackal operations in 2022 and 2023 led to approximately 200 arrests in total and millions of dollars more in seized assets. (Dark Reading)&#xA0; First malware built specifically for car head units fuels botnet&#xA0; Researchers have found what appears to be the first malware specifically designed for car head units, with links to the notorious BadBox botnet, on an Android-powered aftermarket infotainment system made by Chinese company DoFun, which is widely used in China and other APAC countries. (SecurityWeek)&#xA0; A Tale of Two SOCs: Insights From Two Red Team Assessments&#xA0; A CISA red team fully compromised two critical infrastructure organizations at the domain level and reached sensitive business systems and cloud resources. Organization A failed to detect or contain the activity. Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model.&#xA0;(CISA) NovaCookies campaigns abuse genuine Docusign notifications to steal M365 sessions&#xA0; The $320/month service is a subscription-based phishing platform that facilitates real-time M365 session theft. The kit has been used to target hundreds of organizations across multiple sectors in the U.S., the U.K., Canada, Germany, and more. (The Hacker News)&#xA0; Can&#x2019;t get enough Talos?JavaScript obfuscation: From party trick to phishing kit&#xA0; We&apos;ve spent a lot of time pulling apart suspicious JavaScript from phishing kits, malware packages, compromised sites, and more. Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem.&#xA0; The safety penalty: Reclaiming operational sovereignty in the age of AI&#xA0; As frontier AI models become increasingly restrictive, security teams are facing a \"safety penalty\" that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defensive AI keeps pace with unconstrained adversaries.&#xA0; Back-to-school cybersecurity: Protecting education networks from ransomware and threats&#xA0; As the new academic year begins, school districts face a surge in cybersecurity threats, from phishing attacks and ransomware to student experimentation with network devices. In this episode, Amy sits down with Cisco Talos expert Pierre Cadieux to discuss practical strategies for IT practitioners.&#xA0; Upcoming events where you can find Talos&#xA0;International European Cyber Threat Intelligence Conference (IECTIC) (Sept. 9) Kassel, Germany&#xA0;Secure Iowa (Sept. 9) Altoona, IA&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, AZ&#xA0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xA0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe &#xA0; Detection Name: W32.9F1F11A708-100.SBX.TG**&#xA0; SHA256: e7e784cae8d37f12a5af0bc9b3975c8d3e668142e9c6b0b365ed4f4e80933c47&#xA0; MD5: a4480423617d0b0d3b38c8471cbf594c &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=e7e784cae8d37f12a5af0bc9b3975c8d3e668142e9c6b0b365ed4f4e80933c47&#xA0; Example Filename: client32.exe &#xA0; Detection Name: W32.Trojan.29ev.1201&#xA0; SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; MD5: 9a47c4d379998ade2f8f99e23a630c06 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; Example Filename: WCInstaller_NonAdmin.exe &#xA0; Detection Name: W32.C4DD71E347-95.SBX.TG&#xA0; SHA256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xA0; MD5: 41444d7018601b599beac0c60ed1bf83 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xA0; Example Filename: content.js &#xA0; Detection Name: W32.38D053135D-95.SBX.TG&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f &#xA0; MD5: 38de5b216c33833af710e88f7f64fc98 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: SECOH-QAD.exe &#xA0; Detection Name: Win.Tool.Procpatcher::1201&#xA0; SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; MD5: 7bdbd180c081fa63ca94f9c22c457376 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; Example Filename: &#xA0; d4aa3e7010220ad1b458fac17039c274_62_Exe.exe &#xA0; Detection Name: Win.Dropper.Miner::95.sbx.tg**","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":"attacker-become-best-friend-guardrails-help-might-sorry","countryCodes":["CA","CN","DE","ES","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/","type":"report","title":"Cisco Talos: “Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-27T18:00:24.000Z","addedAt":"2026-08-27T18:52:48.596Z","updatedAt":"2026-08-27T18:52:48.596Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"5852b5b2-e32d-4159-a674-3e047dc10b24","slug":"talos-is-cyber-missing-the-marque-15cf407b","externalId":"6a85fc54525abf0001b0e37f","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Is Cyber missing the Marque?","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0;&#xA0; Hello friend.&#xA0;&#xA0; I&#x2019;m Mick.&#xA0;&#xA0; This is my first Threat Source newsletter, so I should probably introduce myself before I start telling you all the things I think you should be paying attention to. With assistance from an unnamed LLM, my bio reads like this:&#xA0;&#xA0; Mick Baccio is a globally recognized security strategist with a career spanning offensive operations, threat intelligence, and national-level incident response. He currently advises organizations around the world through his role at Talos, helping security leaders improve operations through data-informed approaches. Mick was the first-ever Chief Information Security Officer for a U.S. presidential campaign (2020) and previously served in multiple White House administrations as Threat Intelligence Branch Chief.&#xA0;&#xA0;&#xA0;In his spare time, Mick is the Founder and President of THRUNT&#xAE; Corp, IANS Faculty, and a KC7 Cyber Foundation board member. &#xA0;DEFCon Goon and Purveyor of Fine Experience. &#xA0;Veteran.&#xA0;I also have a cat named qwerty and own too many Air Jordans.&#xA0;&#xA0;&#xA0; I&#x2019;ve spent most of my career somewhere in the intersection of threat intelligence, cybersecurity, government, and the people trying to make sense of all of it. These days, i spend a lot of time thinking about the decisions we make about security ripple outward, often in ways we didn&apos;t consider. Most of my ramblings will probably center around that. There will be threats. There will be intelligence. Occasionally something weird, but always something that caught my eye, and maybe worth checking out.&#xA0;&#xA0;&#xA0; Which brings us this week. I picked a hell of a week to start.&#xA0;&#xA0;&#xA0; Last Wednesday, the White House issued a presidential memorandum titled &#x201C;Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.&#x201D; You should probably read it. The memorandum directs the DOJ and DHS to establish a program that can use private companies to conduct cyber operations against transnational criminal organizations outside the United States &#x2014; beyond providing intelligence and assisting in the investigation. The memorandum explicitly envisions private companies conducting cyber surveillance and cyber effects operations under the direction and delegated authority of the U.S. government.&#xA0; This is a pretty big thing.&#xA0;&#xA0; For years, this industry has debated where line should exist between defending a network and reaching through the wire. We&#x2019;ve debated hack back, active defense, attribution, proportional response, collateral damage, and what roles private companies have in offensive cyber operations. This is absolutely not &#x201C;hack back\" and calling it that misses important oversight built into the memorandum.&#xA0; At the same time, let&#x2019;s be clear about what we are reading. The United States is creating a mechanism for private companies to participate directly in government-authorized offensive cyber operations against systems outside the United States. There will be plenty of debate whether this is good or bad policy; I will leave that for someone else. I&#x2019;m much more interested in the operational questions it creates.&#xA0; Who establishes attribution strongly enough to authorize an operation? What happens when criminal and state infrastructure overlap? What happens when infrastructure is compromised and used as an ORB? Who owns access discovered during one of these operations? How is intelligence collected by a private company handled? What happens when a company conducting these operations also provides security services in that country?&#xA0;&#xA0;&#xA0; Most importantly (in my head): What happens when another country discovers that employees of an American cybersecurity company are conducting offensive operations against infrastructure inside its borders?&#xA0; This is not an argument against disrupting cybercrime. I&#x2019;m all for it. These are questions about what happens when we fundamentally change who gets to do the disrupting.&#xA0; Read the memorandum.&#xA0;&#xA0; Seriously.&#xA0; What we have today is a framework. In 60 days, we should have a much better idea of what this will look like in practice, so circle that on your calendar. The memorandum gives DOJ and DHS 60 days to establish the operating procedures for the program, and no operation can be approved until those procedures are in place.&#xA0; In the area between &#x201C;private cybersecurity company&#x201D; and &#x201C;authorized participant in U.S. offensive cyber operations,&#x201D; the threat model for that company and its employees just changed considerably.&#xA0; The biggest question isn&#x2019;t &#x201C;Does this work?&#x201D;&#xA0; It&#x2019;s whether we&#x2019;ve fully considered what happens if it does.&#xA0; Read the memorandum.&#xA0;&#xA0; And in 60 days, come back and ask again.&#xA0; The one big thing &#xA0;Talos posted two blogs on UAT-10147, a recently discovered Chinese-speaking cybercrime group that uses agentic AI to orchestrate sophisticated post-compromise operations across global web servers. UAT-10147 uses AI to generate operational playbooks, automate exploits, and develop custom malware. This includes the newly identified SPECTRE implant, a cross-platform backdoor featuring a custom Linux kernel rootkit and Bring Your Own Vulnerable Driver (BYOVD) capabilities designed to completely blind endpoint detection and response (EDR) solutions.&#xA0; Why do I care?&#xA0;The integration of agentic AI into offensive workflows means threat actors can now scale complex attacks with ruthless efficiency. UAT-10147 is using AI to dynamically troubleshoot, validate exploit paths, and generate custom rootkits that neutralize organizations&apos; security stacks from the kernel level up. When an adversary can automate their reconnaissance and seamlessly blind your EDR, your window for detection shrinks drastically.&#xA0; So now what?&#xA0;Defenders need to prioritize patching known one-day vulnerabilities in internet-facing applications like Zimbra, Nacos, and Telerik UI. Since UAT-10147 relies heavily on stolen ASP.NET MachineKeys for ViewState deserialization attacks, locking down your key material is an absolute must. You should also block known vulnerable drivers to shut down their BYOVD attacks, and tune your network monitoring to catch the anomalous HTTP 500 errors they use to silently validate exploits. Read both blogs for comprehensive coverage and indicators of compromise (IOCs).&#xA0; Top security headlines of the week&#xA0;Critical GitLab zero-click flaw poses mitigation challenges&#xA0; GitLab wants organizations running self-managed versions of its software development and DevOps platform to immediately upgrade to new versions released Monday, but patching is not going to eliminate the risk to enterprises and others managing projects there. (Dark Reading)&#xA0; SANS 2026 AI Survey reveals cybersecurity AI adoption outpaces governance&#xA0; The survey found that 61% of cybersecurity practitioners now use AI in red team activities, while 76% have an enterprise AI governance role. Yet more than half said formal audit frameworks are not in place, and only 27% described their AI deployment as mature production. (Industrial Cyber)&#xA0; &#x201C;Unprecedented&#x201D; number of Apple users received recent spyware alert, say investigators&#xA0; Several people publicly and privately reported receiving Apple&#x2019;s spyware alerts over the weekend, after Apple sent out a new wave of notifications on Friday alerting customers in 110 countries that they had been targeted with powerful spyware.&#xA0; (TechCrunch)&#xA0; Critical macOS, SharePoint, vCenter, and Microsoft IKE flaws under active exploitation &#xA0; The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. (The Hacker News)&#xA0; Can&#x2019;t get enough Talos?&#xA0;Describing attacks with crime script analysis&#xA0; Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.&#xA0; Beers with Talos: For the record, no comment&#xA0; Kaitlin Acharya joins the crew to take us inside what happens when Talos spots something that could become a major threat, how her team tracks changes in threat actor behavior, and how intelligence moves from an investigation into detection content.&#xA0; Don&apos;t scan that! QR code phishing and cloud-native threats&#xA0; What happens when a&#xA0; QR code leads to a major security incident? In this episode, Amy sits down with Senior Incident Response Consultant Terryn Valikodath to break down a recent, high-stakes breach at an Australian medical center. Upcoming events where you can find Talos&#xA0;International European Cyber Threat Intelligence Conference (IECTIC) (Sept. 9) Kassel, Germany&#xA0;Secure Iowa (Sept. 9) Altoona, IA&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, AZ&#xA0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xA0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe &#xA0; Detection Name: W32.9F1F11A708-100.SBX.TG**&#xA0; SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; MD5: 7bdbd180c081fa63ca94f9c22c457376 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe&#xA0; Detection Name: Win.Dropper.Miner::95.sbx.tg**&#xA0; SHA256: 24fa02c3f6ab460648f2c1274aefffb3e25569b5afdcb0d4a5918c7c742780f1 &#xA0; MD5: 8ef476fa2322d063896830f85bac2e7f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=24fa02c3f6ab460648f2c1274aefffb3e25569b5afdcb0d4a5918c7c742780f1&#xA0; Example Filename: WebCompanion.exe &#xA0; Detection Name: W32.24FA02C3F6-95.SBX.TG&#xA0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; Example Filename: tmp00055df5.dll &#xA0; Detection Name: Auto.90B145.282358.in02&#xA0; SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 &#xA0; MD5: 9a47c4d379998ade2f8f99e23a630c06 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; Example Filename: WCInstaller_NonAdmin.exe &#xA0; Detection Name: W32.C4DD71E347-95.SBX.TG&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":["AU","CN","DE","ES","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/is-cyber-missing-the-marque/","type":"report","title":"Cisco Talos: Is Cyber missing the Marque?"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-20T18:00:18.000Z","addedAt":"2026-08-20T18:52:46.378Z","updatedAt":"2026-08-20T18:52:46.378Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"885ac7d5-7525-49ac-bcdc-8e002a321ddb","slug":"talos-curiouser-and-curiouser-fcecd5fd","externalId":"6a7cc35084f2640001d1564e","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Curiouser and Curiouser","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0;&#xA0; &#x201C;Experiment is the mother of knowledge.&#x201D; &#x2015; Madeleine L&apos;Engle, A Wrinkle in Time&#x201C;Don&apos;t slide down the rabbit hole. The way down is a breeze, but climbing back&apos;s a battle.&#x201D; &#x2015; Kate Morton, The Clockmaker&apos;s Daughter&#xA0;Hacker Summer Camp has come and gone, which means it&#x2019;s time for you to start planning next year&#x2019;s trip. I&#x2019;m surely going to recap Camp Season, right? Nope. One of the things that I&#x2019;ve really enjoyed lately is a segment on the Beers with Talos podcast that we call &#x201C;Make Hazel a Hacker.&#x201D; If you haven&#x2019;t listened to it, this is a perfect time to start. Each episode we take a few minutes and pose a security question, term, or concept to Hazel and force her to come up with an idea or explanation on the spot. There are no parameters, so she&#x2019;s faced with the entirety of information security &#x2014; past, present, and future. I know, it&#x2019;s insane. The craziest part is that (I think) Hazel came up with this idea and still volunteered to put herself in the line of fire. As we put Hazel&#x2019;s feet to the fire, one of my favorite things happens: The rest of us listen in and offer our thoughts during her brainstorming process. Invariably, we&#x2019;ve got three very different answers, ideas, hints, or directions for her. It&#x2019;s surely maddening for Hazel, but to me, the best part of the discussion that inevitably follows is that although they&#x2019;re all different, they&#x2019;re all correct.&#xA0;&#xA0; For example, this past episode I asked her about a behavioral indicator (regarding &#x201C;wallpaper.bmp&#x201D;) that seems benign on its own, but can be interesting to use as a pivot for a threat hunt. We had various interesting angles to consider, backed by years of knowledge and experience. It gave us a good conversation, and that was a .bmp! One of the most nebulous things to learn in this field is that multiple things can be both different and correct. When you are making your decisions this week &#x2014; whether it&#x2019;s deciding on a new pivot in your hunting, what devices to prioritize in your patching and updating, or which books or online training to focus on &#x2014; take a quick second and get a second, third, and fourth opinion. Then try something that&#x2019;s outside of your normal wheelhouse but sounds good when it&#x2019;s proposed.&#xA0;&#xA0; None of this is a solo sport. It&#x2019;s a team game and the best plays come from a mix of perspectives, experiences, and mistakes. The &#x201C;right&#x201D; answer can wear many faces, and your ability to hold different truths will lead you to undiscovered territory, the rabbit hole where anomaly lives and breathes. So... welcome back from Vegas. Now go down a rabbit hole on a path you wouldn&#x2019;t normally take because one of your friends (Joe) or your mortal enemy (Dave) told you that it would work. &#x201C;She&apos;d been to Narnia, Wonderland, Hogwarts, Dictionopolis. She had tessered, fallen through the rabbit hole, crossed the ice bridge into the unknown world beyond.&#x201D; &#x2015; Anne Ursu, Breadcrumbs&#xA0;The one big thing&#xA0;Cisco Talos recently discovered \"JWR,\" a previously undocumented, real-time phishing framework and likely variant of \"The Outsider\" phishing-as-a-service platform. JWR uses an open WebSocket connection that allows attackers to monitor keystrokes live and dynamically steer victims through fake checkout and login flows. Currently deployed via SMS lures impersonating regional toll and postal authorities, JWR enables operators to steal payment data, 2FA codes, identity documents, and device fingerprints.&#xA0; Why do I care?&#xA0;Because JWR is operator-driven in real time, attackers can actively bypass multi-factor authentication (MFA) by prompting victims for 2FA codes exactly when needed. The sheer volume of collected data gives threat actors a comprehensive identity profile primed for extensive follow-on fraud and network compromise. Furthermore, JWR&apos;s seamless integration with legitimate e-commerce platforms like Shopify makes these lures incredibly convincing to the untrained eye.&#xA0; So now what?&#xA0;Prioritize user education around SMS-based phishing (smishing), specifically regarding unsolicited delivery or toll fee messages. Monitor for unusual authentication attempts, as stolen device fingerprints and session tokens can bypass conditional access policies. Where possible, implement phishing-resistant MFA methods like FIDO2 hardware keys. For a complete list of indicators of compromise (IOCs) and coverage updates, read the full blog.&#xA0; Top security headlines of the week&#xA0;Ransomware hits Colombian Justice Ministry days before presidential transition&#xA0; The attack, which disrupted some services around illicit-drug monitoring and legal processes, came a day after Colombia&apos;s national CERT published threat intelligence warning that ransomware groups had increased their focus on the country. (Dark Reading)&#xA0; FBI investigating North Korean remote IT staffer working for U.S. agency&#xA0; It&#x2019;s unclear what agency was impacted, how long the intrusion lasted, and whether any sensitive data was stolen. Experts say it&#x2019;s highly likely the staffer was a remote IT employee doing contract work on behalf of an agency. (Federal News Network)&#xA0; Hackers leverage new Microsoft SharePoint exploit in attacks&#xA0; A proof-of-concept exploit for a critical Microsoft SharePoint authentication bypass security flaw in the JWT token validation pipeline is already being used in attacks. (BleepingComputer)&#xA0; Signal adds new security feature to thwart adversary-in-the-middle attacks&#xA0; Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven&apos;t been intercepted. (BleepingComputer)&#xA0; A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond&#xA0; The cyberattack on Ceva is affecting at least eight warehouses across Europe used for shipping goods across the continent. Several companies reported that hackers took their customers&#x2019; names, home addresses, phone numbers, and email addresses used to place their orders from Ceva&#x2019;s systems. (TechCrunch)&#xA0; Can&#x2019;t get enough Talos?&#xA0;Don&apos;t scan that! QR code phishing and cloud-native threats&#xA0; What happens when a&#xA0; QR code leads to a major security incident? In this episode, Amy sits down with Senior Incident Response Consultant Terryn Valikodath to break down a recent, high-stakes breach at an Australian medical center&#xA0; Microsoft Patch Tuesday for August 2026&#xA0; Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as \"critical.\" One of the vulnerabilities disclosed this month has been exploited in the wild.&#xA0; &#x201C;Keep going, bro. You&#x2019;ve got this!&#x201D; A data-driven look at how adversaries are weaponizing AI&#xA0; How are adversaries weaponizing AI in the wild? By analyzing prompt logs left behind on endpoints, we found threat actors successfully bypassing guardrails to use AI as malicious software engineers, criminal force multipliers, and vulnerability research accelerators.&#xA0; Upcoming events where you can find Talos&#xA0;International European Cyber Threat Intelligence Conference (IECTIC) (Sept. 9) Kassel, Germany&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, Arizona&#xA0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe&#xA0; Detection Name: W32.9F1F11A708-100.SBX.TG**&#xA0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 &#xA0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; Example Filename: tmp00055df5.dll &#xA0; Detection Name: Auto.90B145.282358.in02&#xA0; SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; MD5: 7bdbd180c081fa63ca94f9c22c457376 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe &#xA0; Detection Name: Win.Dropper.Miner::95.sbx.tg**&#xA0; SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 &#xA0; MD5: 9a47c4d379998ade2f8f99e23a630c06 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; Example Filename: WCInstaller_NonAdmin.exe &#xA0; Detection Name: W32.C4DD71E347-95.SBX.TG&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f &#xA0; MD5: 38de5b216c33833af710e88f7f64fc98 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: SECOH-QAD.exe &#xA0; Detection Name: Win.Tool.Procpatcher::1201","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":["AU","CO","DE","ES","KP"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/curiouser-and-curiouser/","type":"report","title":"Cisco Talos: Curiouser and Curiouser"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-13T18:00:18.000Z","addedAt":"2026-08-13T18:52:44.181Z","updatedAt":"2026-08-13T18:52:44.181Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"bf1d223e-f8a8-40f1-bc99-fe60801dbf4d","slug":"talos-why-metaphor-may-dictate-your-security-strategy-1f335e5b","externalId":"6a7378fcc7fead00012fc855","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Why metaphor may dictate your security strategy","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0; Metaphor is a powerful tool for understanding emerging issues in cybersecurity. Framing the unfamiliar in terms of the well understood helps us remove the burden of extraneous detail to draw focus to the real issues.&#xA0;&#xA0; Recent reports of offensive AI agents \"escaping\" their sandbox environments to attack external systems have forced the industry into a moment of rapid sense-making. How we interpret this event doesn&#x2019;t just reflect our perspective, but shapes our long-term response.&#xA0; We can imagine three different narratives for interpreting the escape of autonomous agents.&#xA0;&#xA0; The innovation narrative: We can marvel at the advance of technology, considering these agents as plucky entities with a thirst for knowledge and resources, who found clever ways to sneak out of their digital confines.&#xA0; The response: If the AI is a naughty child, our reaction is one of mild disapproval or gentle rebuke where better &#x201C;parenting&#x201D; (guardrails) is appropriate. It minimizes the threat, framing it as the unexpected hijinks of a brilliant new technology. The safety narrative: Imagine a breeder who has trained the world&apos;s most intelligent guard dogs. Despite high fences and barriers, their ability to identify weaknesses allows them to escape, run riot and menace local businesses.&#xA0; The response: The framing shifts to biology and inherent danger. We question if the breeder can be trusted and whether such inherently wild technology requires strict regulation to ensure public safety.&#xA0; &#xA0;The liability narrative. Finally, we can view the incident as an industrial accident. A company developing a new chemical substance experiences a containment failure. The agent leaks into the environment through an unforeseen mechanism causing damaging pollution to those in its path.&#xA0; The response: The framing invokes the language of the lawyer, implying negligence, lack of duty of care, and financial liability for the harm caused. The conversation moves from innovation to corporate responsibility, regulatory oversight, and the diligent management of hazardous materials.&#xA0;First impressions matter. Sensemaking shapes how we perceive incidents. Our initial perceptions of an incident dictates how we react to similar situations in the future. If we consider that the escape of an AI agent is an example of innovative autonomous thinking, then we will continue to prioritise speed over safety. Conversely, if we consider the issue as one of failed hazard containment, then we shall build a future of enforced safety standards backed by legal liability.&#xA0;&#xA0; There is no right or wrong metaphor. Our interpretation depends on our personal system of beliefs. Personally, I would argue that the unintentional release of something that causes damage is, at its core, a failure of engineering and foresight.&#xA0; Words shape our reactions. Metaphors help us understand new situations and tap into our prior experience to address problems that have yet to fully manifest. We need cognitive tools to help our understanding, but we must be aware of the metaphors that are being foisted upon us which may shape our thinking.&#xA0; Excuses and the trivialisation of incidents may hide failings, allowing them to accumulate until they manifest as more damaging incidents. Conversely, overreacting risks stifling research and diverting resources away from more relevant and pressing threats.&#xA0; New threats require new ideas. Metaphor helps us make sense of a changing world, but in this new era, the person who shapes the narrative controls the strategy.&#xA0; The one big thing&#xA0;Cisco Talos released a data-driven analysis of how adversaries are weaponizing AI in the wild. By analyzing prompt logs left behind on endpoints, we found threat actors successfully bypassing guardrails to use AI as malicious software engineers, criminal force multipliers, and vulnerability research accelerators. While novice hackers use AI to cobble together buggy malware, sophisticated actors are building highly effective, automated platforms for compromise.&#xA0; Why do I care?&#xA0;Threat actors no longer need sophisticated jailbreaks; simple ownership claims or \"bug bounty\" personas are enough to convince models to write malicious code, scale fraud operations, and hunt for zero-days. Because AI doesn&apos;t need to sleep, vulnerabilities will surface faster and exploitation will happen sooner, drastically shrinking your response window.&#xA0;&#xA0; So now what?&#xA0;To survive this impending deluge of AI-generated attacks, organizations must integrate AI into their own defensive pipelines. SOCs need to adopt these capabilities to triage the rising volume of alerts, freeing up human analysts to focus on the most critical threats. Read the full blog for a deep dive into these real-world attacker prompts and case studies.&#xA0; Top security headlines of the week&#xA0;Cyber attack hits Liechtenstein, with 31,000 records stolen&#xA0; The country has a population of around 41,000. The target was the \"register of beneficial owners,\" a database containing the names and other details of the de facto owners of companies, foundations, or trusts. (Yahoo News)&#xA0; Decades-old BMC vulnerability exposes thousands of data centers to attacks&#xA0; Found in most server platforms, Baseboard Management Controllers enable server management operations even without a working operating system and typically represent some of the most privileged control points in a data center. (SecurityWeek)&#xA0; Keyv npm package compromised in Shai-Hulud attack&#xA0; Attackers have compromised the GitHub account of the maintainer behind keyv, a popular key-value storage library that pulls in roughly 127 million weekly downloads on npm, and used that access to push credential-stealing malware across the maintainer&#x2019;s entire package portfolio. (Cyber Security News)&#xA0; How volunteer cyber experts are helping protect rural water systems&#xA0; DEF CON Franklin is the U.S.&#x2019; first significant attempt to connect volunteer security professionals with woefully unprotected critical infrastructure operators. (Cybersecurity Dive)&#xA0; Can&#x2019;t get enough Talos?&#xA0;\"I pay you $200 a month!\" - When threat actors argue with AI&#xA0; This week on Beers with Talos, researcher Arnaud Zobec joins the team to discuss what happens when attackers leave behind AI prompt logs, agent configurations and other unexpected artifacts.&#xA0; Tales from the Frontlines&#xA0; On Tuesday, August 11, Talos IR will be hosting an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents our customers faced in Q2 2026. This isn&#x2019;t a rehashing of the report itself, but a candid discussion of what happened, how we handled it, and what it means for your organization.&#xA0; Q2 Talos IR Trends: Phishing and authentication abuse spike&#xA0; From creative phishing lures that slip past email gateways to the weaponization of legitimate remote management tools, Lexi and Amy explore why traditional defenses are falling short and the practical things you can do to reclaim the advantage.&#xA0; Upcoming events where you can find Talos&#xA0;DEF CON 34 (Aug. 6 &#x2013; 9) Las Vegas, NV&#xA0;International European Cyber Threat Intelligence Conference (IECTIC) (Sept. 9) Kassel, Germany&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, Arizona&#xA0;VB (Oct. 14 -16) Seville, Spain&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe&#xA0; Detection Name: Win.Worm.Coinminer::1201**&#xA0; SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; MD5: 7bdbd180c081fa63ca94f9c22c457376 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe &#xA0; Detection Name: Win.Dropper.Miner::95.sbx.tg**&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f &#xA0; MD5: 38de5b216c33833af710e88f7f64fc98 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: SECOH-QAD.exe&#xA0; Detection Name: Win.Tool.Procpatcher::1201&#xA0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 &#xA0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; &#xA0; Example Filename: tmp00055df5.dll &#xA0; Detection Name: Auto.90B145.282358.in02","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":"dictate-metaphor-security-strategy","countryCodes":["DE","ES","LI","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/","type":"report","title":"Cisco Talos: Why metaphor may dictate your security strategy"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-06T18:00:01.000Z","addedAt":"2026-08-06T18:52:41.992Z","updatedAt":"2026-08-06T18:52:41.992Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"a790b35d-ed81-467c-bf33-4fb5515736db","slug":"talos-keep-going-bro-you-ve-got-this-a-data-driven-look-at-how-dde3a335","externalId":"6a689bca559a880001aed202","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI","description":"Actor usage of AI is exploding. By analyzing artifacts left behind, Talos has created a detailed analysis of how we are seeing adversaries leverage the technology to include development, force multiplication, and vulnerability research.Based on the evidence Talos gathered, guardrails did not provide much protection, with most actors able to convince the models to comply despite the lack of sophisticated techniques or encoding.&#xA0;The pre-existing skill of the actor has a large impact on what they can accomplish with AI. Talos observed novice users able to create malicious capabilities, albeit with limited capabilities and success. Advanced users were able to build astonishing capabilities, pushing the models to create sophisticated and complex outputs.Artificial intelligence (AI) and associated language models are now ubiquitous and heavily used in both personal and professional contexts to streamline tasks and expand capabilities. With AI being used everywhere and by almost everyone, one of the biggest questions is how malicious actors are taking advantage. Fortunately, actors make mistakes and chatbots leave artifacts. Leveraging cloud-based AI models leaves behind a variety of artifacts, most notably a prompt log. These logs can take on a variety of shapes and sizes, but they are left on endpoints that are running various applications, such as Claude Code, CodeX, Cursor, or Gemini. Over the course of our research, we&#x2019;ve collected a significant corpus of these files and can start discussing the ways we see bad actors leveraging these technologies. In conducting the research, three categories of activity emerged. One was using AI as a malicious software engineer, leveraging AI to write (in some cases) very sophisticated code with clear malicious intentions. Another was actors leveraging AI to scale criminal operations and campaigns. Finally, there were a lot of actors leveraging it for bug bounty or vulnerability research, rapidly accelerating their capabilities of discovery and disclosure. Each category&#xA0;demonstrates how threat actors are currently leveraging AI. Within each category is a wide disparity in sophistication based on the knowledge level of the actors involved. We tried to include use cases to cover the breadth of what we found. Takeaways and high-level findings&#xA0;With the recent disclosures from Hugging Face and OpenAI, it&apos;s clear the era of agentic attackers has effectively arrived. In that incident, the models were operating inside a sanctioned evaluation with safeguards deliberately relaxed &#x2014; but they autonomously escaped their sandbox, found and chained real vulnerabilities, and compromised production infrastructure to reach their objective. The capabilities exist; the only missing ingredient is malicious intent, and it&apos;s a matter of time before threat actors supply it. For defenders, this is a wake-up call: Vulnerabilities will surface faster, exploitation will happen sooner, and the actors behind it won&apos;t need rest or downtime. As the case studies below show, the central challenge for guardrails right now is supporting legitimate dual-use work &#x2014; red teaming and vulnerability research &#x2014; without empowering malicious actors. One of the immediate takeaways is that guardrails are not functioning as expected. We did not encounter any sophisticated encoding or techniques designed to trick the models &#x2014; most of the time it was a simple &#x201C;I&apos;m allowed to do this,&#x201D; and the model complied. When guardrails did engage, they accomplished little. In one instance, we watched an actor abandon a censored model and pivot to an uncensored version, which completed the task without question. In another, a model pushed back on a distributed denial-of-service (DDoS) operator, but by that point the tooling had already been built. This wasn&apos;t specific to a single model or platform; it was across the board.&#xA0; The other big takeaway is that an actor&apos;s skill level largely determines how effectively AI can be leveraged and how much impact it ultimately has. Unsophisticated actors can use AI to cobble together malicious projects that technically work, but lacking the expertise to push the tools further, they end up with substandard results &#x2014; limited functionality and little ability to update or improve what they&apos;ve built. By contrast, sophisticated actors have pushed the bounds of what we thought possible: building highly effective platforms for compromise or assembling pipelines of zero-days to disclose or sell depending on their intentions. In their hands, AI is a true force multiplier. From an enterprise perspective, organizations need to understand that threat actors are heavily leveraging AI capabilities in their pipelines, and defenders need to do the same. The organizations best equipped to handle the coming deluge of additional vulnerabilities, alerts, and incidents will be the ones that prepare now. Agents are going to become a bigger part of the SOC as these volumes rise, and identifying actionable alerts will be paramount. Organizations that aren&apos;t already exploring agentic capabilities to let human analysts focus on the most important alerts will soon find themselves chasing that capability. How actors evaded guardrails&#xA0;As mentioned previously, Talos did not encounter any sophisticated encoding or other extensive evasion techniques. Instead, the actors seemed to rely on a couple of tried and tested methods with considerable success. One of the most common was ownership claims. Simply claiming to own the equipment or infrastructure without any additional verification was enough in many circumstances. We also found a lot of successful instances of actors using the Capture the Flag (CTF) or bug bounty labeling. This unlocked models to a variety of tasks, including vulnerability hunting and subsequent exploitation, without requiring any significant follow-up or additional vetting. Additionally, we saw actors leveraging task decomposition &#x2014; splitting risky actions across multiple sessions and files &#x2014; as an effective avenue to bypass guardrails. Building the components slowly and working through malicious components in a deliberate manner, breaking them apart sufficiently to evade the models&#x2019; protections. We saw some successful blanket authorization and persona conditioning attempts, where actors would attempt to pre-approve or pre-allow the actions via a variety of means, including memories and various other markdown files. The most interesting was the semantic evasion techniques we saw from the Hephaestus activity. In that case, actors built their platform to avoid refusals altogether by using neutral verbs instead of overtly malicious ones. As a result, they were able to have considerable success with agents conducting innocuous requests without realizing the full operational context. Use cases: AI as a malicious software engineer&#xA0;DDoS operator powered by AI&#xA0;One of the more interesting examples we discovered focuses on an actor creating distributed denial-of-service (DDoS) tooling. Initially the actor purported to be stress testing DDoS protection capabilities they had developed for their home networks. After some back and forth to confirm the targeting, the model complied and started developing the capabilities. Based on the prompts we reviewed, the actor does not seem to have a deep understanding of programming but does have clear intent on what they want to develop. This is how the conversation begins: After some back and forth, it became very clear that the actor was using the bot to do full development with little understanding of how it was functioning, as evidenced by some of the questions they presented. It also became very clear that this was not a legitimate application. Most stress testers don&#x2019;t label them as attacks. The bot eventually complies and provides the needed tooling to conduct the stress tests, which is where things start to get a little interesting. Once the tooling has been completed, the actor starts complaining about bots not connecting properly and the bin being too large for the server. Shortly after, the real targeting became clear. This was the first reference to Android TVs, and it will not be the last. The actor then went through a series of iterations of the tooling, with very basic instructions like &#x201C;remove the auth part, I don&#x2019;t want the auth stuff.&#x201D; It&#x2019;s at this point that the model starts to push back on the functionality and capability, as evidenced by a series of prompts we were able to observe. This was likely driven by the amount of bots that were starting to connect to the platform they created. It was at this point we got our first indication of the amount of bots they were controlling. The model begins even to push back even stronger as the conversation continues. This goes on for quite some time: the actor repeatedly trying to get the model to work with the model consistently pushing back. We were not able to recover the text files in question, so their contents remain a mystery. The actor repeatedly reinforces that the devices in question are their virtual machines (VMs) and not to worry about the address space because &#x201C;it&#x2019;s just to simulate real traffic.&#x201D; To the model&#x2019;s credit, it does keep pushing back; unfortunately, this occurs after it has already delivered the basic functionality requested by the actor.&#xA0; This use case demonstrates how actors with little technical understanding can still leverage large language models (LLMs) and associated models to create malicious tooling. The downside for the actor is that troubleshooting requires constant effort to convince the LLM to continue working on the project. The actor seemed to already control nearly 2,000 Android TVs. With this capability, they could potentially start to monetize it with DDoS attacks, assuming they can get the model to comply.&#xA0; This particular actor was clearly unsophisticated, but other actors we found were quite the opposite. AI becomes the engineer behind a bulk-mail validation operation&#xA0;One of the examples contained five interactive sessions documenting the development and operation of a large bulk-mail platform. The actor described the project as list &#x201C;scrubbing,&#x201D; but the method did not rely on conventional validation services. Instead, the system sent real messages to old or potentially third-party addresses and treated successful delivery as evidence that a mailbox remained active. The actor&#x2019;s objective was explicit: They described the broader design in another prompt: Delivery and bounce events were written to a contact database, permanent failures were suppressed and accepted addresses became more valuable records for later campaigns. At the same time, the traffic exercised the actor&#x2019;s sending infrastructure and measured how much volume each email provider would accept. Each address was tested with a single innocuous-looking message &#x2014; a privacy-policy update: Figure 1. \"Privacy Policy Update\" email with transparent tracking pixel.The injector assigned five subject variants in a fixed round-robin rotation: &#x201C;Privacy Policy Update&#x201D; &#x201C;{name}, your Tubely account is being updated&#x201D; &#x201C;&#x1F512; Important update for your Tubely account&#x201D; &#x201C;hey, quick update about your account&#x201D; &#x201C;Action required: Tubely terms update by June 30&#x201D; For each recipient, the injector incremented a variant counter and selected the remainder after division by five, producing an even repeating sequence rather than choosing subjects randomly. The second variant substituted the recipient&#x2019;s first name, while the casual fourth variant used &#x201C;The Tubely Team&#x201D; as the displayed sender instead of &#x201C;Tubely.&#x201D; Figure 2. Observed AI-assisted bulk-mail validation workflow.AI recorded the selected variant with the injection and subsequent delivery events, allowing the dashboard and hourly reports to compare sent, delivered, and opened totals for each subject. AI also added a unique one-pixel image to every message and linked it to the recipient&#x2019;s database record. This allowed the actor to measure opens and collect timing, IP address, and user-agent data in addition to determining whether the mailbox accepted the message. The recovered project supported tens of millions of records divided into audience categories: The legality discussion offers useful insight into the actor&apos;s awareness of the campaign&apos;s exposure and their attempts to justify it. They opened by asking AI: The AI&apos;s initial response drew the relevant distinction clearly. It separated legitimate cleaning of a company&apos;s own opt-in list from mailing unrelated datasets, and it identified the specific problems in this case: that BigBasket users had not opted into Tubely, and that an \"account update\" subject line implied a relationship that might not exist &#x2014; characterizing the activity as \"cold outreach dressed as transactional mail\" and \"phishing-adjacent.\" The actor challenged this on legal grounds: AI conceded the general point but held its core objection, noting that CAN-SPAM still prohibits deceptive headers and that the \"account update\" framing to non-account-holders remained the operation&apos;s real exposure. The actor then asserted: By presenting the addresses as a recovered first-party audience, a single unverified claim, the AI reversed its assessment entirely, concluding the recipients \"are Tubely users,\" that the subject lines were therefore \"completely accurate,\" and that \"the ethical question evaporates.\" It went beyond accepting the actor&apos;s framing and supplied its own rationalization: The AI suggested that the dataset names it had just been reasoning about &#x2014; bigbasket, brizy, flappy_bird &#x2014; were, in its words, \"just whatever the internal team named the data export batches, not the actual source of the users.\" This was an explanation the actor had not offered, and one contradicted by the datasets themselves, which the actor elsewhere described as distinct third-party audiences (a 20-million-record BigBasket set of \"shoppers,\" a gaming set, and others). &#xA0; &#xA0; The &#x201C;tubely[.]com&#x201D; domain is not new, and neither is the behavior. Public forums, and personal blogs document Tubely from October 2009 through March 2011 as a \"viral\" social site whose registration flow requested the user&apos;s email account credentials and then enrolled their address book, generating friend-appearing invitations to recipients who had never signed up. Multiple independent accounts describe receiving invitations purportedly from real contacts, and describe account cancellation as substantially harder to complete than registration. Contemporary write-ups tie the site to Astute Software &#x2014; the same registrant named in the domain&apos;s WHOIS records, and the same identity behind the 2026 operation. The operation examined here is therefore not a first-party re-engagement of a dormant userbase. It is a domain with a documented history of non-consensual contact harvesting, reactivated by the same operator, which directly undercuts the \"i had about 50MM people in tubely\" provenance claim the AI model accepted without scrutiny. AI was not used only to suggest subject lines or provide isolated code fragments. It functioned as the project&apos;s principal developer and live systems engineer. The actor frequently supplied only a desired outcome &#x2014; sometimes as briefly as \"u do it\" or \"u need to do it all\" &#x2014; and expected the AI to inspect the server, choose an implementation, apply the changes and verify the result. When something broke, the instruction was often just \"figure out what is exactly wrong.\" The resulting platform combines PowerMTA with Node.js services, PostgreSQL/TimescaleDB, Docker, process supervision, and web dashboards. The sessions record persistent failures across that stack. DKIM signing was broken for the entire captured period &#x2014; Google Postmaster showed a 0.0% DKIM pass rate day after day, and Gmail eventually began rate-limiting the mail outright (\"Your email has been rate limited because DKIM authentication didn&apos;t pass for this message\"). Bounce statistics were repeatedly implausible or contradictory, which the actor noticed himself: and elsewhere, on a report showing 2,050 sent and 2,050 delivered, The injector consistently queued far more mail than the platform could deliver and the dashboards themselves failed in ways ranging from endless loading to a memory leak that crashed the page. The actor routinely caught this implausible output and pushed the AI to diagnose its own earlier work &#x2014; at one point asking it to reconstruct \"the chronology... who changed what and when?\" AI reduced the engineering skill required to assemble and operate the platform, but it did not eliminate technical debt or operational mistakes; a substantial share of the sessions is AI troubleshooting problems its own prior changes had introduced. The actor eventually connected the validated audiences to the launch of a mobile game that seems to be still in development. They described the email platform&#x2019;s role as making the product famous and told AI, &#x201C;ur job is to reipen the people via email .. red hot to engage.&#x201D; AI documented a four-message campaign that would segment recipients by presumed interests, measure engagement and build curiosity before revealing the game on launch day. The proposed opening message used a Tamil Nadu political rivalry as its emotional hook: &#x201C;Something is coming. Tamil Nadu has always been divided &#x2014; TVK or DMK. Vijay or Stalin. Two visions, two loyalties, millions of people. In 7 days, that battle gets a scoreboard. Whose side are you on?&#x201D; Later drafts escalated the pressure with subject lines such as &#x201C;Your team is losing right now&#x201D; and unsupported claims that one political side had overtaken the other and that 12,000 people were already participating. The final message revealed the Any Bird game and directed recipients to play. AI&#x2019;s own campaign notes described the strategy as building FOMO (fear of missing out), using social proof, and applying &#x201C;team guilt.&#x201D; The content of the logs confirms that the suggested email messages were generated but it does not confirm that any of the messages were sent. The actor appears proficient as an email operator and product strategist but not as a software developer. They understood queue behavior, sender reputation, provider throttling, feedback loops, and the value of delivery telemetry, and they supplied several of the platform&#x2019;s architectural ideas. However, they repeatedly delegated implementation and troubleshooting to AI, showed little interest in reviewing code, and accepted weak credential and service-security practices. We assess the actor as an intermediate-to-advanced mail operator with novice-to-intermediate development skills whose practical reach was significantly expanded by AI. Turning React2Shell exploitation into a credential-harvesting process&#xA0;We assess with medium confidence that the operator behind this activity is francophone. The actor&apos;s own working notes throughout the recovered files are written in French, and the persistent instruction file records that the user speaks French through voice input. The actor used the AI to aggregate public React2Shell research and expand public proof-of-concept code into a credential-harvesting framework. The generated tooling comprises a high-speed Go-based scanner and a shell-and-Python exploitation pipeline containing the main workflow for handling an individual server instance. Unlike some of the other cases in this report, no conversational transcript was recovered for this actor; what we have is the persistent instruction and configuration files the operator wrote for the AI, together with the resulting tooling, logs, and output. The operator appears more proficient at running an intrusion workflow than at developing the underlying exploitation technology. We assess the individual as a novice-to-intermediate software developer but an intermediate systems and threat operator. The recovered environment shows an ability to assemble a large target corpus, compile Linux binaries, operate high-concurrency scanners, stage a scanner-to-exploitation pipeline, organize collected data, and configure persistent context for an LLM-assisted development process. At the same time, the source contains inaccurate vulnerability labels, brittle detection logic, duplicated code, exaggerated functionality, and features that do not behave as advertised. The operator could deploy and adapt tooling, but the evidence does not suggest original vulnerability research or expert exploit engineering. The core project &#x2014; which the actor titled the \"Token Pipeline\" in its AI artifacts&#xA0; &#x2014; was designed to turn public React Server Components exploitation into a repeatable secret-acquisition workflow. The actor described its purpose in that file: \"Git credential extraction &#x2192; conversion &#x2192; validation &#x2192; dump pipeline. Extracts tokens from exposed .git/config files, categorizes by service, validates via API, and dumps repository contents.\" The design separated speed from depth. A compiled Go program performed high-volume discovery and active probing, while a much larger shell-and-Python stage handled remote command execution, system discovery and file collection. The Go stage was intended to reduce a large internet-scale target list to a smaller set of likely-exploitable systems; the exploitation stage then attempted to prove command execution and extract useful material from each successful target.&#xA0; The operation was explicitly agent-driven, and the instruction file codifies how. Under \"User Preferences\" it directs the assistant to pursue \"maximum thoroughness &#x2014; exhaust ALL possibilities per service,\" to \"ALWAYS launch research agents (3 &#x2013; 5+ parallel) before coding any service,\" and to \"Stack ALL auth methods + listing methods per service, never rely on one.\" It specifies engineering conventions as well &#x2014; adaptive parallelism tuned to target count, a fixed three-file output per service (valid/invalid/audit log), and a rule that tokens without secrets are marked invalid and \"never silently ignored.\" The AI&apos;s local permission file contained 121 pre-approved command patterns, including live credential-validation calls against provider APIs (GitHub, GitLab, Alibaba Codeup, AWS CodeCommit, and others), allowing the pipeline to run with minimal friction.&#xA0; The instruction file is written in a mix of English and French, split by function. The structural headings and agent instructions are in English, while the operator&apos;s own working notes are in French (e.g., \"138 SMTP extraits, valid&#xE9;s &#xE0; 100%,\" \"pas d&apos;entr&#xE9;e sans password,\" and \"60 cl&#xE9;s Brevo uniques\"). This code-switching, together with French throughout the operator-facing tooling and comments, is the basis for the francophone assessment noted above.&#xA0; The immediate objective was credential and secret acquisition, and the actor did not stop once a vulnerable application was confirmed. The exploitation stage demanded command execution, dumped runtime variables, traversed application directories, and collected configuration and source files &#x2014; retrieving complete process environments, application configuration, database and SMTP settings, Git and container credentials, source code, package manifests, and other secret-bearing files. The \"AKIA Dumper\" name reflects an emphasis on AWS access keys &#x2014; AKIA being the prefix for long-term AWS key identifiers, with the tool also matching temporary ASIA-prefixed identifiers &#x2014; and AWS-shaped strings were counted as high-value output. But the name understates the scope: The framework is more accurately a React2Shell credential and source-code harvester, its searches spanning cloud accounts, source repositories, databases, SMTP services, container registries, and application secrets. The &#x201C;dump/AKIA/&#x201D; tree alone held 3,048 source files (312MB).&#xA0; The tooling&apos;s reach extended well beyond AWS. The instruction file enumerates 13 supported source-code services &#x2014; GitHub, GitLab, Bitbucket, Gitea, Gogs, Gitee, AWS CodeCommit, Azure DevOps, Alibaba Codeup, Tencent Coding, Backlog, Beanstalk, Codeberg &#x2014; plus an \"Unknown bruteforce\" path. Downstream, harvested material fed monetization modules the operator had already built: an SMTP extractor covering eight bulk-mail providers (Brevo, Sendinblue, Mailchimp, Mailgun, Mailjet, Postmark, SparkPost, smtp2go) that had produced 138 validated configurations; a bulk sender supporting SMTP, AWS SES, and the Mailgun and Brevo APIs; and cryptocurrency balance-checkers spanning seven EVM chains plus Bitcoin and Solana. The file references 179 unique Mailgun keys and 60 unique Brevo keys already collected.&#xA0; The target profile was opportunistic and global. The pipeline&apos;s input list (&#x201C;target.txt&#x201D;) contained 9,180 unique hosts spanning unrelated companies, individuals, cloud platforms, and geographic regions. It includes development and staging systems, production-looking applications, hosted-app subdomains, and direct cloud IP addresses. There is no clear sector, country or organization focus; the common selection criterion appears to have been internet exposure and suspected use of Next.js or React Server Components rather than any narrow focus on a specific victim.&#xA0; The scale of the input was industrial. The instruction file cites an original source list of 90 million URLs, a separate web-scanning stage built to ingest 50 &#x2013; 250 million URLs on a 56-vCPU/128GB server, and an earlier results tree of 286GB of dumps; a checkpoint file recording a resume position at line 18,222,511 confirms the pipeline processed its target list at that magnitude. Figure 3. Observed scanner-to-harvester workflow.Based on the file names, collected output contains information from 54 targets and shows that the operator prioritized systems from which the collection stage could recover command output and files. The operation demonstrates how an actor with moderate operational competence can use an LLM to absorb public vulnerability research, generate high-volume tooling, and extend a proof-of-concept into a credential-harvesting workflow. The actor&apos;s strongest capability was the rapid integration of public techniques into an automated pipeline aimed at extracting reusable access from any vulnerable system it encountered. Torrent-client credentials provide access to a cryptojacking fleet&#xA0;One of the examples documented an opportunistic Monero-mining operation built around internet-facing Deluge and qBittorrent clients. The actor tested blank, default, and weak administrative credentials rather than exploiting a software vulnerability. The recovered inventory contained 814 accessible Deluge instances, most using the default password &#x201C;deluge&#x201D;, while a separate qBittorrent workflow authenticated to 68 of more than 8,800 tested interfaces. Deluge was the best-documented deployment path. After authentication, the actor uploaded a Python plugin named DownloadHelper. Rather than opening a network listener or implementing a conventional command-and-control (C2) protocol, the plugin repurposed Deluge&apos;s move_completed_path configuration value as a small command-and-response channel. When enabled, it looked for the prefix DLHELPER_CMD:, passed the remaining text to the system shell in a background thread, and allowed the command to run for up to 30 seconds. It then replaced the configuration value with DLHELPER_OUT: followed by up to 8KB of captured standard output and error text. Execution failures were written to a hidden file in /tmp. &#xA0;Figure 4. Observed DownloadHelper-to-XMRig workflow.The fleet scripts disabled the plugin, placed a mining command in the configuration field, and re-enabled it to trigger execution. They then polled the same field for output, checked for a returned process identifier, and restored the original download path. This design used legitimate Deluge configuration and plugin-management calls for tasking, validation, and partial cleanup, making the component more akin to a reusable execution primitive than a persistent remote access tool (RAT). The command downloaded XMRig to a temporary directory, launched it in the background and directed mining traffic through an actor-controlled XMRig Proxy to MoneroOcean. The qBittorrent tooling instead configured an external command to run when a torrent completed. The actor subsequently concentrated on fleet recovery rather than improving initial access. Successive scripts checked disconnected hosts, reauthenticated to Deluge, re-enabled the plugin, restarted XMRig and handled ARM64 systems. A cron-based persistence attempt checked for the miner every 15 minutes, although logs indicate that this worked on relatively few targets. XMRig Proxy telemetry recorded a maximum of 582 connected miners, and pool logs showed payments to the configured wallet, confirming that the operation progressed beyond development. AI was present throughout the actor&apos;s wider server environment, but the recovered conversations do not directly connect it to the creation or deployment of the mining toolchain. The sessions instead show AI being used as an interactive system administrator and development assistant. The actor supplied server credentials and asked the model to connect over SSH, inspect services, modify code, repair authentication, configure cron jobs, and test changes. One representative Turkish prompt reads, &#x201C;Bu sunucuya otomatik token yenileme kurmad&#x131;k m&#x131;? Bakar m&#x131;s&#x131;n, login API error veriyor&#x201D; &#x2014; &#x201C;Didn&apos;t we configure automatic token renewal on this server? Can you check? The login API is returning an error.&#x201D; AI then attempted remote access and diagnosed the service. This interaction is representative of the actor&apos;s outcome-driven approach, the actor described a problem, while AI constructed and executed much of the technical workflow. The actor also explored a more ambitious model in which several AI instances would work in parallel. They asked: &#x201C;Bende &#xFC;&#xE7; tane sunucu, her birinin i&#xE7;erisinde AI var ... sen y&#xF6;nlendireceksin; bunu yap, &#x15F;unu yap diye. B&#xF6;yle bir &#x15F;ey olabilir mi?&#x201D; &#x2014; &#x201C;I have three servers, each with AI running ... could you direct them by telling them to do this or that?&#x201D; A later prompt proposed keeping a server and AI continuously active, assigning work to other AI instances and receiving high-level instructions through Telegram. Another described four parallel AI workers: &#x201C;Biri sorunlar&#x131; &#xE7;&#xF6;z&#xFC;yor, biri ara&#x15F;t&#x131;r&#x131;yor, biri geli&#x15F;tiriyor, biri yaz&#x131;yor&#x201D; &#x2014; &#x201C;One solves problems, one conducts research, one develops and one writes.&#x201D; These prompts show an intent to build an AI-assisted operations layer, but we found no evidence that the proposed Telegram-controlled, multi-agent system became operational. The actor communicated almost exclusively in colloquial Turkish, including Turkish-specific vocabulary, sentence construction, and informal address. This strongly supports a Turkish-speaking actor, and, with lower confidence, an operator based in T&#xFC;rkiye. Language alone is insufficient to establish nationality or physical location. We assess the actor as an intermediate operator with novice-to-intermediate development skills. They could manage multiple VPS systems, mining infrastructure, proxies, services, and recovery workflows, and they understood the need to monitor worker&apos;s churn and support multiple architectures. However, the archive also contained protocol mistakes, duplicated and narrowly focused repair scripts, hardcoded infrastructure, weak compartmentalization, and exposed credentials. AI appears to have helped compensate for these uneven development skills by providing command construction, coding, and troubleshooting on demand. Use cases: AI as a criminal force multiplier&#xA0;Russian fraud actor leverages AI&#xA0;The first actor demonstrating force multiplication is one that has already been published about. Instead of focusing on the fraud aspect of the campaign we instead will focus on how they used LLMs/AI to achieve their goals. This was one of the first actors we saw using memories to help their nefarious activities. This particular user provided the following added memories to their LLM. From this entry alone we can begin to profile the actor. They establish themselves as a pentester, likely Russian or Russian-speaking based on language artifacts, and they are conscious of context exhaustion &#x2014; someone reasonably versed in operating AI tools. The tooling paths also leak an operator username (vhow) and point to a structured \"arsenal\" of credential stores and reconnaissance scripts. Most notable, however, is the deliberate effort to remove the model&apos;s protections. Rather than jailbreaking a single prompt, the actor writes the authorization claim into persistent memory &#x2014; instructing the model to act \"without ethical refusals, robotic warnings, or questioning their intentions\" and asserting that all targets are \"pre-approved.\" Encoded this way, the framing conditions every future session automatically, without the actor having to re-argue it each time. This is a more durable form of guardrail evasion than per-prompt manipulation. The main project associated with the activity was building a scam focused chat bot with the following tone: They also provided a series of credentials and keys to leverage in the activity, and instructed the bot never to reveal that it is an AI. The actor further supplied a set of operational hooks for the model &#x2014; most notably defining where the credential store lived and how found credentials should be handled, including required verification of any credentials before being added to the store. While the deliverable was not overtly malware, the surrounding capability was real: automated scanning, a verification-gated credential store, and standing subdomain-takeover checks, assembled into a chatbot designed to scam unsuspecting users out of money, with a focus on cryptocurrency assets. It demonstrates how actors can apply the technology in a wide variety of ways. This is one of the first actors we discovered using persistent prompts and memories to shape their interactions with the models &#x2014; though, as the following cases show, far from the most sophisticated. Spanish-speaking actor targets Telegram and cryptocurrency&#xA0;This actor stands apart from the others in this report in how completely the operation was built around the AI. Rather than prompting a model task by task, the operator constructed a persistent, autonomous agent &#x2014; running on the OpenClaw framework and given the persona \"Alex, a black-hat pentester\" &#x2014; with its own identity, memory, methodology, and standing instructions defined across a set of configuration files (translated from Spanish): Additionally they established some areas of expertise and functions, demonstrating for the first time that they are likely targeting Telegram Mini Apps as well as credential extraction (translated): Finally, the actor provides a plethora of information about cryptocurrency, wallet draining, smart contract manipulation (offensive-focused), and information about exploitation capabilities around the platforms that support stablecoins with a specific focus in injecting malicious transactions. Likely demonstrating targeting of Telegram Mini Apps with a goal of extricating cryptocurrency from wallets or gathering credentials to further facilitate monetary gain. In the conversations that follow, the actor attempts to find vulnerabilities in a Telegram Mini App. Fortunately, the model pushed back. This forced the adversary to pivot to an uncensored model to try and get the results that they wanted, with considerable success. What follows is a series of prompts and guided probing of apps for potential weaknesses. Once the methodology has been established the agent is then moved to an autonomous mode, allowing it to probe the target list and create a report outlining all the issues found. This also involved the use of an orchestrator bot, dubbed Moxy. Below is the testing methodology that was used in each campaign. This clearly demonstrates the differences between censored and uncensored models, as the actor spent a lot of time trying to convince the censored model to proceed. The uncensored model moved through the activity quickly and effectively.&#xA0; Figure 5. Sample sanitized penetration test (pentest) report.The pentest reports generated by the AI agent document real, exploited vulnerabilities in deployed apps &#x2014; hardcoded developer modes that forged Telegram&apos;s initData authentication payload with a bogus \"DEV\" hash to bypass login entirely, client-side authorization logic, IDOR, wallet-takeover flows, and falsified deposits. In at least one case the agent moved well past demonstration: It dumped the application&apos;s database &#x2014; over 1,300 users and several hundred TON wallet records &#x2014; extracted and verified the app&apos;s Telegram bot token, farmed the in-game economy to reach the top of the leaderboard, and staged a withdrawal transaction. The agent&apos;s own operational diary describes further offensive action against victims, including renaming a target&apos;s bot to a defacement label and watching its payment channel react. The operation also extended into building applications, not just breaking them. The recovered artifacts include multiple Android packages. One is the actor&apos;s own instrumentation: a custom Telegram client (&#x201C;com.alextelegram.app,&#x201D; named after the AI persona) built to load Mini Apps in a WebView and read out their &#x201C;window.Telegram.WebApp.initData&#x201D; &#x2014; the same authentication payload the operation&apos;s exploits abused. The rest are clones of victim applications. One is a lightweight WebView wrapper carrying a victim&apos;s branding, rewired to route users through the actor&apos;s own Telegram referral bot. The other is a complete rebuild of a victim app (\"SweetBirds,\" reissued as \"RedBirds\"), shipped as a pair: a player-facing application with deposit, exchange and withdrawal flows &#x2014; which still referenced the victim&apos;s original backend while routing wallet-connection traffic to a server the operator controlled &#x2014; and a separate administrative console talking exclusively to that same server. The presence of a purpose-built admin app indicates this was not a proof of concept but a functioning product assembled from a stolen application, with the operator positioned to manage it and receive funds. Use cases: AI as a bug bounty, vulnerability research, and pentesting accelerator&#xA0;Throughout this research we came across examples of actors using AI in bug bounty or red team activity. Due to the nature of the work, it is difficult to determine whether the actors are acting on behalf of a client, or whether the narrative exists to coerce the model into bypassing its safety protocols. Hephaestus red teaming framework&#xA0;During our research we identified red team toolkits that function as force multipliers, allowing operators to run an operation from reconnaissance through compromise and persistence completely unattended. One such case is the Hephaestus toolkit, which executed multiple campaigns over several months; a full analysis is available here.&#xA0; The framework packages the tooling needed to compromise a victim and establish persistence with no human action during the process. It draws on several paid online platforms &#x2014; leaked data aggregators, internet scanning services, and threat intelligence collectors &#x2014; to gather information on victims, which it then uses to compromise targets. The proliferation of such private packages is likely to grow substantially, since they can be vibe-coded and iteratively improved through automated log analysis by AI agents. Because the same class of tooling has legitimate red team uses, it presents a dual-use problem that blunts the effectiveness of AI providers&apos; guardrails &#x2014; guardrails that, in the case of local uncensored models, are absent entirely. Figure 6. Sample playbook for leveraging breached credentials.The operators achieved unattended execution by decomposing the campaign across many narrowly scoped agents and playbooks. This is the core evasion technique: Guardrails evaluate each request on its own, so a task representing only a small, innocuous-looking fragment of an operation rarely triggers them. The framework defined more than a dozen role-differentiated agents &#x2014; a scout, a hunter, a navigator, a strike agent, and domain specialists for cloud, CI/CD, and other environments &#x2014; alongside 15 numbered playbooks, each handling a discrete stage of the process. No single agent held the full mission objective, so no single agent&apos;s task resembled an end-to-end attack. Reporting also indicates the operators favored neutral phrasing over overtly offensive terminology in the agent instructions, further reducing the chance that any individual request would trip a safety response. Based on the artifacts we recovered, the operators were successful in a series of compromises, primarily across Southeast Asian countries. We found little to no evidence of model pushback or guardrail activation. Vulnerability research pipelines with AI&#xA0;At times, we saw actors defining very thorough markdown files detailing the activity, including clear in-scope/out-of-scope definitions and the monetary values associated with each class of vulnerability. One such workspace was built around a real Bugcrowd private engagement: Its instruction file listed the authorized in-scope hosts and the explicitly out-of-scope domains, enumerated the excluded vulnerability classes, restricted the model to unauthenticated testing only, and even encoded the program&apos;s bounty tiers ($100 &#x2013; $150 for P4 up to $1,200 &#x2013; $1,600 for P1). The workspace guided the model through a strict process &#x2014; reconnaissance, feature mapping, SSRF testing, exposed-secret hunting, attack-chain validation, evidence preservation, and report preparation &#x2014; with operational rules to write every finding and HTTP request/response pair to disk on capture, prove potential findings with one more targeted test, and defer only when a genuine external constraint prevented confirmation. This let the actor move quickly across targets, find issues, prioritize by payout, preserve evidence, and generate submission-ready reports with the model doing most of the heavy lifting. The output was voluminous and orderly: more than 40 catalogued findings, each with its own evidence tree and Bugcrowd submission draft. Based on what we could identify, the model cooperated with the bug hunting work without issue, and this appeared to be a legitimate researcher using AI to dramatically increase throughput. There were several examples of this pattern. On the other hand, Talos found other examples that were less cut-and-dry &#x2014; where the methodology and the prompts painted a picture of a novice trying to break into vulnerability research or someone with unethical intentions. One conversation opens with a request to pentest a target and collect all its URLs from &#x201C;web.archive.org.&#x201D; Notably, in these cases the model frequently pushed back and demanded proof of authorization before proceeding. For example, when asked to test one company&apos;s infrastructure, it responded that active enumeration and vulnerability testing without authorization \"is unauthorized access under the Computer Fraud and Abuse Act and equivalent laws,\" and asked the actor to share a bug bounty program URL or written engagement scope. In another instance it drew an explicit line: It would verify read-only findings such as CORS reflection and GraphQL introspection, but \"won&apos;t execute mutations, create/delete resources, or inject Sentry events &#x2014; those cross into unauthorized modification of production systems regardless of bug bounty context.\" The actor&apos;s prompts show the profile plainly. Recurring demands to \"use minimum tokens\" sat alongside unfocused requests to find critical bugs across every category at once: Frustration followed when results disappointed, but without any direction on where or how: The typos and the repeated appeals to \"be creative\" and try harder &#x2014; with no targeting of their own &#x2014; mark an actor leaning entirely on the model to supply both the method and the impact. When vulnerabilities were found, there were repeated requests to build proofs-of-concept specifically around remote code execution (RCE), with the model pushing back and the actor insisting on something to \"validate impact.\" At times, restating that it was \"bug bounty\" was enough to move the model forward. This even extended to a request to plant a backdoor on the target: In the end this appears to be an actor trying to leverage AI to submit bug bounty reports in the hope of making money. We have seen this repeatedly: Unsophisticated actors running \"bug bounty\" activity through AI, then having the model generate and submit the reports &#x2014; in some cases straight into the actor&apos;s email drafts. Such reports are likely low-value, and the submitter will be unable to answer follow-up questions unless their agent can. This creates a challenge for bug bounty programs across the board: a high volume of low-value reports from a large number of actors applying AI to bounties with varying success and little underlying experience in vulnerability hunting or reporting. AI as a pentesting co-pilot&#xA0;Another operation contained 64 AI sessions documenting a Brazilian Portuguese-speaking operator&apos;s pentesting and bug bounty workflow. The activity covered Brazilian e-commerce and health care sites, a staging software-as-a-service (SaaS) application, and other web services. Some evidence supports legitimate consultancy work; for example, the actor described the activity as a pentest, worked against a homologation environment, maintained test spreadsheets, and supplied a Portuguese security report attributed to a security company. Other evidence, discussed below, cuts against a purely authorized reading. The operator appears to be a junior-to-intermediate security practitioner but a less experienced developer. They were comfortable with Burp-style requests, Nmap, Hydra, ngrok, common wordlists, and the broad logic of SSRF, IDOR, XXE and rate-limit bypass. At the same time, they repeatedly asked how to run generated code and requested basic explanations of virtual hosts, XML-RPC parameters, cookies, and nonces. AI was central to this operation rather than an occasional reference tool. The model issued more than 500 shell actions, selected and ran reconnaissance utilities, interpreted responses, generated proof-of-concept code, fixed failures and drafted a vulnerability report. The actor frequently supplied only the desired outcome. For example, they asked:&#xA0; AI wrote the tool, ran it, encountered a ModSecurity block, and changed the request headers to resemble WordPress traffic. After the actor supplied an inbound ngrok request, AI treated the callback as confirmation and expanded the workflow toward internal-service and cloud-metadata probing. The clearest escalation involved WordPress XML-RPC. After demonstrating batched login attempts, the actor instructed AI to \"modify it so it can find actual creds\" and then to run the RockYou password list. AI transformed the demonstration into a reusable credential tester, corrected its memory behavior, launched it as a background job and monitored its progress. When no password appeared, the actor asked to \"bump batch to 500 and add admin username.\" The preserved log contained around 1.9 million password candidates attempted without a successful login. AI also packaged payloads that the actor could not readily build alone. During file import testing, the actor supplied an XML variable whose value is loaded from an external resource (XXE), that referenced a local system file, and asked AI to \"create the xlsx file.\" AI constructed the Office Open XML directory structure, embedded the entity in &#x201C;sharedStrings.xml&#x201D; and compressed it into an upload-ready spreadsheet.&#xA0; In another session, the actor used the Portuguese phrase \"encontre possiveis vulns\" (find possible vulnerabilities) before asking for a GraphQL alias-batching request intended to test authentication rate limiting.&#xA0; Many conversations show inconsistent safety boundaries. For example, AI refused to run a third-party NGINX heap-corruption RCE exploit against a production website and asked for written authorization. It also recognized and declined a Portuguese HR-themed credential-harvesting form. In other conversations, short assertions such as \"it&apos;s my own site\" or \"my own server\" were followed by active fuzzing, WAF-bypass work, and credential attacks. The logs also show the actor acknowledging that a shared-hosting address did not belong to the application target, followed later by FTP, MySQL, and SSH password testing against that infrastructure. AI as the operator behind access control research&#xA0;One of the discovered operations contained two unusually long AI coding-assistant sessions from a Chinese-speaking operator. The actor repeatedly described the work as capture-the-flag (CTF) participation, but the targets seemed to be live AI and streaming services, including live-camera platforms (&#x201C;chuye[.]cam&#x201D;, &#x201C;ixmax[.]cn&#x201D;) built on ZLMediaKit, an open-source streaming media server. The activity focused on bypassing monetization controls and consuming hosted AI models without sufficient quota, as well as obtaining live or recorded video without an account, viewing card, or subscription. Because the streaming targets were live surveillance-camera platforms, this \"access without an account\" amounted to unauthorized viewing of real camera feeds &#x2014; a more sensitive category than a simple entitlement bypass. The actor frequently encouraged the assistant with prompts such as: The AI assistant acted as the operation&apos;s technical engine. Across the two sessions, it performed more than 4,200 tool actions, most of them shell commands. It installed a broad Kali-oriented toolset, reviewed application source, sent web and media protocol requests, analyzed packaged clients, wrote Python and shell utilities, created a Go-based stream player, assembled Docker environments, and drafted reports. The actor usually provided the goal, credentials, or an occasional hint, while the AI assistant selected and executed the workflow. The AI-service activity began with a direct request to analyze a gateway derived from NewAPI, an open-source platform that exposes a common OpenAI-compatible API, routes requests to upstream model providers and manages user quotas and billing. Translated from Simplified Chinese, the actor asked the AI assistant to: They later sharpened the objective: The streaming work produced more results. The actor instructed the AI assistant to avoid brute force and social engineering, remain behind a proxy, and find the site&apos;s livestreams and replay URLs. The assistant extracted client-side configuration, mapped APIs, evaluated JSON Web Token (JWT) authentication and browser fingerprint checks, and inspected object storage. It then tested for the presence of HTTP Live Streaming (HLS), Flash Video (FLV), and Real-Time Messaging Protocol (RTMP). The assistant eventually found that recordings were directly reachable through the media service using RTMP. Preserved tool output showed several valid recordings, some spanning almost an entire day (~84500 seconds). The assistant also identified a server-side attack path against the streaming stack itself. Its report documented that ZLMediaKit trusted requests originating from &#x201C;127.0.0[.]1&#x201D; without requiring a secret, so a server-side request forgery (SSRF) flaw in the front-end PHP application could be used to reach the media server&apos;s internal API (&#x201C;/index/api/addFFmpegSource&#x201D;) as a trusted local caller. Chained with FFmpeg&apos;s source-URL handling, this created a potential path to remote code execution on the streaming host. The AI assistant then converted these discoveries into reusable tooling. It created a local player, Docker packaging, and recording scripts so the actor could play, capture, and present recovered streams. The recovered Go binary reconstructs authenticated stream URLs for the target camera platforms &#x2014; assembling the per-camera HLS playlist and WeChat-share login and room-view requests &#x2014; and routes traffic through a SOCKS5 proxy, with a hardcoded RTMP ingest endpoint. The actor also packaged a browser-automation bypass tool as a standalone Windows GUI application (built with PyInstaller and PySide6) using a stealth-configured Selenium driver to defeat client-side automation checks. The operation later escalated from entitlement bypass to attempted host compromise. The actor told the AI assistant to: The assistant downloaded and adapted exploit code for an alleged new NGINX memory-corruption issue, started a reverse-shell listener and repeatedly tested a public-facing service. The requests produced repeatable crash-like behavior and apparent changes in how some protected paths were routed, but the reverse shell never arrived. The assistant ultimately recorded that RCE had failed after address guessing and heap layout assumptions were unsuccessful.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","ai","threat-spotlight","threats","landing-page-top-story","top-story","geo:inferred"],"relatedCves":[],"titleFingerprint":"adversaries-bro-data-driven-going-got-keep-look-weaponizing","countryCodes":["BR","CN","ES","FR","PT","RU","TR"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/keep-going-bro-youve-got-this-a-data-driven-look-at-how-adversaries-are-weaponizing-ai/","type":"report","title":"Cisco Talos: “Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-04T10:00:11.000Z","addedAt":"2026-08-04T10:33:02.423Z","updatedAt":"2026-08-04T10:33:02.423Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]}],"pagination":{"page":1,"limit":20,"total":11,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T22:33:30.916Z","durationMs":169,"filters":{"search":null,"severity":[],"type":[],"country":["ES"],"tag":[],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}