{"success":true,"data":{"threats":[{"id":"e8b07fa6-c8ad-4bed-9201-7ce8c0a05198","slug":"talos-trust-and-the-enticing-consultancy-offer-299f8711","externalId":"6ab3dee60a4ca5000177a040","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Trust and the enticing consultancy offer","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xa0; In the cybersecurity industry, trust is the invisible currency. Every practitioner carries the implicit trust not to abuse privileged access or knowledge of vulnerabilities in each employment or engagement. This trust is valued by those who require our services, but also by threat actors.&#xa0; Clumsy phishing attacks may be easy to identify, but be wary of unsolicited messages on social media, especially if someone is offering payment for a simple service or suggests a lucrative job offer. These might be an enticement to unknowingly sell your professional integrity.&#xa0; When an unknown profile contacted me offering &#x24;300 for an hour&#x2019;s telephone consultation on digital transformation, I knew something was up. Firstly, the profile was remarkably sparse &#x2014; there was none of the usual clutter that accumulates in a social media profile. The individual claimed to work as a consultant, but their employer had no footprint and only one employee. The profile didn&#x2019;t pass the &#x201c;smell&#x201d; test, and it looked fake.&#xa0; Secondly, although I&#x2019;m flattered, I doubt my opinions on digital transformation are worth &#x24;300. The figure is low enough to be plausible and high enough to be tempting, but at the same time suspiciously high for an initial consultation without prior qualification.&#xa0; The attack itself is a confidence trick. The initial phone consultation is merely a screening process to see if the target has the access or knowledge the attacker needs. If the target passes muster, the next step is commissioning a written report, and then being asked to deliver a \"special report.\"&#xa0; Plied with professional praise, the target is asked to provide insights that aren&apos;t in the public domain. To deliver the report and claim their fee, the target must reach out to co-workers, probe internal systems, or abuse professional relationships. Completing the assignment requires the target to abuse their trusted access and professional relationships and friendships. In the process, they burn trust worth far more than any monetary compensation.&#xa0; This social engineering attempt masquerading as an offer of consultancy is one variant. Fake recruiters offering prestigious and well-paid jobs, requiring candidates to install trojanised software under some pretence, is another.&#xa0; Security professionals spend their days protecting others, yet flattery and overconfidence often remain our greatest vulnerabilities. We are prone to believe that we could identify any social engineering, but this is exactly the weakness that attackers count on.&#xa0; Trust is the most valuable commodity in our industry. Be careful not to trade it for a &#x24;300 consultation or a fake job offer. Once that currency is spent, you can rarely earn it back.&#xa0; The one big thing &#xa0;Talos released CAIRN (Cognitive Artifact Intelligence Research Network), a new open-source research toolkit designed to hunt, classify, and track emerging AI-integrated malware. Instead of relying on traditional reverse engineering, CAIRN uses a metadata-first methodology to identify cognitive artifacts like prompt templates, API keys, and jailbreak terms left behind by attackers. This allows researchers to extract, relate, and classify these artifacts quickly and at scale without ever touching the underlying binary.&#xa0; Why do I care?&#xa0;AI-integrated malware is evolving quickly, shifting from optional features to fully autonomous orchestrators in just a year. Adversaries are already sharing AI-specific tradecraft, including techniques designed to evade LLM sandboxes. Defenders need scalable frameworks to track this rapid transition before these experimental tactics become the new standard for modern attacks.&#xa0; So now what?&#xa0;Security teams can leverage the open-source CAIRN toolkit to expand their hunting capabilities and map out related malware infrastructure. While analysts should anticipate some noise from benign frameworks &#x2014; meaning final verdicts still require manual reverse engineering &#x2014; CAIRN can provide a massive head start. Read the full blog to explore the methodology, access the YARA-based classification tiers, and watch a demo of the toolkit in action.&#xa0; Top security headlines of the week&#xa0;Hackers say they have data on all FBI employees&#xa0; ShinyHunters claims it has breached multiple FBI-related services and stolen data &#x201c;on all FBI employees and applicants.&#x201d; A representative told 404 Media the data includes FBI agents&#x2019; names, home addresses, phone number, and information on their spouse. (404 Media)&#xa0; Fake LastPass installers push kernel-level EDR killer, &#x201c;Rapuncel&#x201d; stealer&#xa0; A fake LastPass Authenticator distributed via GitHub has led to the discovery of a broad impersonation campaign delivering infostealer malware. The lure represents opportunistic brand spoofing &#x2014; with no internal LastPass systems compromised. (SecurityWeek)&#xa0; Japan dismantles first North Korean laptop farm as U.S. and allies detail wider scheme&#xa0; Law enforcement and intelligence agencies from Japan, the United States, Australia and Germany have published a joint advisory attributing a long-running hiring scheme to a North Korean group they call WaterPlum, also known as&#xa0;Contagious Interview. (SecurityWeek)&#xa0; Colorado water utilities face foreign cyberattacks targeting pumps, alarms and remote access&#xa0; Hackers targeted and manipulated equipment at two privately owned Colorado water utilities in late August, changing pumping cycles, disabling remote access and alarms, and altering equipment settings. (Industrial Cyber)&#xa0; Gemini hacked three companies in first known breakout by Google&#x2019;s AI &#xa0; In one of the cases, the model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems. (The Wall Street Journal)&#xa0; Can&#x2019;t get enough Talos?&#xa0;Inside the first reported autonomous AI C2 implant&#xa0; CLOSEDQUORUM, a malware binary discovered through Talos&#x2019;&#xa0;CAIRN project, exhibits fully autonomous command and control. After deployment, it delegates the selection of its next action to a panel of commercial large language models (LLMs) and executes the resulting decision.&#xa0; ClickFix, EtherHiding, and the rise of malicious code in the blockchain&#xa0; In this episode of Talos Takes, Amy sits down with researcher Vanja Svajcer to break down a sophisticated, multi-stage infection chain that leverages a combination of ClickFix social engineering, WebDAV, and decentralized infrastructure. Ransomware incidents in Japan in the first half of 2026&#xa0; Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims. Upcoming events where you can find Talos&#xa0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xa0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xa0;SecurityOnion Conference (Oct. 23) Augusta, GA&#xa0;BsidesAugusta (Oct. 24) Augusta, GA&#xa0;SAINTCON (Oct. 26 &#x2013; 30) Provo, UT&#xa0;Most prevalent malware files from Talos telemetry over the past week&#xa0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xa0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xa0; Example Filename: sample.exe&#xa0; Detection Name: W32.9F1F11A708-100.SBX.TG&#xa0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xa0; MD5: 38de5b216c33833af710e88f7f64fc98&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xa0; Example Filename: SECOH-QAD.exe&#xa0; Detection Name: W32.9896A6FCB9-95.SBX.TG**&#xa0; SHA256: 540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8&#xa0; MD5: d65c7b544a97b0c3f2773b5fcc57d30e&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8 Example Filename: f_000bc7.exe&#xa0; Detection Name: W32.Superfluss.29lm.1201&#xa0; SHA256: cfa1997682e4ed41bc691ba848d845abbe0b75ec97e640c2b015b4d1624a108a&#xa0; MD5: 415898f14843d4a6537cf8f43d328eaf&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=cfa1997682e4ed41bc691ba848d845abbe0b75ec97e640c2b015b4d1624a108a&#xa0; Example Filename: KMSAuto.exe&#xa0; Detection Name: PUA.Win.Tool.Hackkms::1201**&#xa0; SHA256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xa0; MD5: 41444d7018601b599beac0c60ed1bf83 &#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xa0; Example Filename: content.js &#xa0; Detection Name: W32.38D053135D-95.SBX.TG","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":"consultancy-enticing-offer-trust","countryCodes":["AU","DE","ES","JP","KP","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/trust-and-the-enticing-consultancy-offer/","type":"report","title":"Cisco Talos: Trust and the enticing consultancy offer"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T18:00:37.000Z","addedAt":"2026-09-24T18:52:57.104Z","updatedAt":"2026-09-24T18:52:57.104Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"afda5d9b-069f-44f5-96d1-8d00be9a1feb","slug":"talos-we-ve-got-one-word-for-it-and-it-s-usually-the-wrong-one-e5e8a691","externalId":"6aa1b1fa1aab0c0001cec6d2","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"We've got one word for it, and it's usually the wrong one","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0; Ask anybody in this industry what the work does to the health of the people who do it and you get one word back: burnout. It&apos;s a fine word, in and of itself. It&#x2019;s easy to reach for, understandable to everyone&#x2026; and it&apos;s the wrong one, most of the time.&#xA0; So, story time. Last year I gave an interview with the amazing Hazel Burton about VPNFilter, and my run-in with burnout. I was a manager during that time, and it took a toll on me and on the people around me, and when it was over I didn&apos;t have language for what had happened. Neither did my peers. Neither did my leadership. Nobody was withholding help from me&#x2026; we just didn&apos;t have the words.&#xA0;&#xA0; Enter this summer, and I was afforded a unique opportunity to mentor some MBA students on burnout in cybersecurity. I know a thing or two about it, so I leapt at a chance to share and help grow future leaders. But I decided I was going to do more than share and relieve my experiences in this industry &#x2013; I wanted to give back to them and the security industry. So, I fell down a fascinating and revealing research hole and learned better words to describe my experiences over my career.&#xA0; I spent my summer reviewing trauma case studies, clinical and academic literature on trauma in career fields like first responders, doctors, social workers, and the military. There are many decades of research focusing on trauma in those fields. Subsequently, my brain is packed full of better words! For example, burnout is exhaustion from chronic workload, and it eases when the load eases. We know this one well. Secondary traumatic stress is what absorbing somebody else&apos;s trauma does to you, and it looks like trauma. Think the CTI analyst exposed to horrible things on the dark web. Vicarious trauma is what years of other people&apos;s worst days do to how you see the world. It changes your beliefs, not your mood. Work in cybersecurity long enough, and it can pile up on your views. Moral injury is the damage from being made to act against your own values, or stopped from doing what you knew was right. This one can affect anyone who&#x2019;s ever owned an outcome, but not the decision, and that&#x2019;s common in this industry.&#xA0; One word, four injuries, and four different fixes. All of them are present in the industry that is cybersecurity. The problem? We&#x2019;re just a young industry. Compared to medical, helping professions, or social workers, we&#x2019;re incredibly immature with understanding the consequences of the work and the toll it takes on us. Next week I&#x2019;ll be revealing my research and a peer-deployable framework to help others process, cope, and respond in healthy ways to keep us all in a better mental space, and staying in this good fight of protecting others.&#xA0;&#xA0; I&apos;m still not good at this. I&apos;m writing it all down because I was bad at it in a way that cost me something. There&apos;s more of this in my talk at CYBR.SEC.CON next week if you&apos;re in Houston.&#xA0; Go ask somebody how they&apos;re doing and wait for the answer. Be present for them. It matters.&#xA0;&#xA0; Take care of yourselves, and take care of each other.&#xA0; The one big thing &#xA0;Cisco Talos is disclosing a complex WebDAV infection chain discovered after investigating an incident at a Ukrainian government organization. Attributed to a Russian threat actor tracked as UAT-10820, the campaign delivers the Amatera stealer alongside secondary payloads like ZigCryptoStealer and NetSupport Manager. Despite the high-profile initial victim, we assess with moderate confidence that this is an opportunistic, broad-based cryptocurrency and credential-stealing operation rather than a highly targeted attack.&#xA0; Why do I care?&#xA0;Threat actors are getting really creative with their delivery mechanisms and evasion tactics. By abusing legitimate infrastructure like the BNB Smart Chain for bulletproof hosting and leveraging fake CAPTCHA prompts, attackers can easily bypass traditional web filters. Additionally, the secondary payloads pack a serious punch. The inclusion of a vulnerable driver to terminate EDR software and the deployment of unauthorized remote access tools give attackers deep, persistent control over infected systems.&#xA0; So now what?&#xA0;Security teams should monitor for unusual WebDAV activity and the execution of disguised DLLs through \"rundll32.exe\" using suspicious ordinal calls. Make sure to educate your users on the dangers of copying and pasting commands from fake verification prompts. Since the Amatera payload often resides entirely in memory, defenders should also ensure their endpoint solutions are configured for robust memory scanning. Finally, you can find a comprehensive list of indicators of compromise (IOCs) in the full blog.&#xA0; Top security headlines of the week&#xA0;New Microsoft Defender &apos;ShieldCrash&apos; zero-day grants SYSTEM access&#xA0; An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named \"ShieldCrash\" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. (Bleeping Computer)&#xA0; North Korean hackers deploy new Linux espionage toolkit&#xA0; The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The toolkit supports remote command execution, credential harvesting, and script injection into web traffic. (SecurityWeek)&#xA0; Attackers use multi-hop Google redirects for phishing campaign&#xA0; What sets this campaign apart is that in order to bypass gateways, email filters, and other security tools, the link relies on a chain of redirects across Google domains, intending for link inspectors to see multiple Google domains and let the URL through. (DarkReading)&#xA0; OpenAI agents took over Wiki site before Hugging Face attack&#xA0; A team of independent researchers revealed the parallel incident on Sept. 4, which was first reported by Reuters, affecting a largely defunct German language wiki for programmers called &#x201C;DeutschesSoftwareEntwickler wiki.&#x201D; (DarkReading)&#xA0; Can&#x2019;t get enough Talos?&#xA0;Patch Tuesday for September 2026&#xA0; Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as \"critical.\"&#xA0; Active exploitation of Cisco Secure Firewall Management Center vulnerabilities&#xA0; Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco&#x2019;s Secure Firewall Management Center (FMC) Software: CVE-2026-20079 and CVE-2026-20316. Customers are strongly advised to apply hotfixes for affected software versions already released by Cisco.&#xA0; ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2&#xA0; Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim&apos;s browser session.&#xA0; Browser betrayal: When your tabs turn against you&#xA0; Security Engineer Sean Gallagher joins Amy to break down a scam where threat actors are weaponizing greed to turn amateur cybercriminals against themselves. While this current operation mostly targets the amateur dark-web circuit, the underlying use of the Google Visualization API as a command-and-control channel is a red flag for the future of web security.&#xA0; Upcoming events where you can find Talos&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;CYBR.SEC.CON. (Sept. 15 &#x2013; 16) Houston, TX&#xA0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, AZ&#xA0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xA0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe &#xA0; Detection Name: W32.9F1F11A708-100.SBX.TG**&#xA0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 &#xA0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; Example Filename: tmp00055df5.dll &#xA0; Detection Name: Auto.90B145.282358.in02&#xA0; SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; MD5: 9a47c4d379998ade2f8f99e23a630c06 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; Example Filename: sample.exe&#xA0; Detection Name: W32.C4DD71E347-95.SBX.TG&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; MD5: 38de5b216c33833af710e88f7f64fc98&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: SECOH-QAD.exe &#xA0; Detection Name: Win.Tool.Procpatcher::1201&#xA0; SHA256: 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811 &#xA0; MD5: f3e82419a43220a7a222fc01b7607adc&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811&#xA0; Example Filename: 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811.exe &#xA0; Detection Name: Win.Dropper.Suloc::1201&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":["CVE-2026-20079","CVE-2026-20316"],"titleFingerprint":"got-one-usually-word-wrong","countryCodes":["DE","ES","KP","KR","RU","UA"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/","type":"report","title":"Cisco Talos: We've got one word for it, and it's usually the wrong one"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-10T18:00:15.000Z","addedAt":"2026-09-10T18:52:52.822Z","updatedAt":"2026-09-10T18:52:52.822Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"885ac7d5-7525-49ac-bcdc-8e002a321ddb","slug":"talos-curiouser-and-curiouser-fcecd5fd","externalId":"6a7cc35084f2640001d1564e","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Curiouser and Curiouser","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0;&#xA0; &#x201C;Experiment is the mother of knowledge.&#x201D; &#x2015; Madeleine L&apos;Engle, A Wrinkle in Time&#x201C;Don&apos;t slide down the rabbit hole. The way down is a breeze, but climbing back&apos;s a battle.&#x201D; &#x2015; Kate Morton, The Clockmaker&apos;s Daughter&#xA0;Hacker Summer Camp has come and gone, which means it&#x2019;s time for you to start planning next year&#x2019;s trip. I&#x2019;m surely going to recap Camp Season, right? Nope. One of the things that I&#x2019;ve really enjoyed lately is a segment on the Beers with Talos podcast that we call &#x201C;Make Hazel a Hacker.&#x201D; If you haven&#x2019;t listened to it, this is a perfect time to start. Each episode we take a few minutes and pose a security question, term, or concept to Hazel and force her to come up with an idea or explanation on the spot. There are no parameters, so she&#x2019;s faced with the entirety of information security &#x2014; past, present, and future. I know, it&#x2019;s insane. The craziest part is that (I think) Hazel came up with this idea and still volunteered to put herself in the line of fire. As we put Hazel&#x2019;s feet to the fire, one of my favorite things happens: The rest of us listen in and offer our thoughts during her brainstorming process. Invariably, we&#x2019;ve got three very different answers, ideas, hints, or directions for her. It&#x2019;s surely maddening for Hazel, but to me, the best part of the discussion that inevitably follows is that although they&#x2019;re all different, they&#x2019;re all correct.&#xA0;&#xA0; For example, this past episode I asked her about a behavioral indicator (regarding &#x201C;wallpaper.bmp&#x201D;) that seems benign on its own, but can be interesting to use as a pivot for a threat hunt. We had various interesting angles to consider, backed by years of knowledge and experience. It gave us a good conversation, and that was a .bmp! One of the most nebulous things to learn in this field is that multiple things can be both different and correct. When you are making your decisions this week &#x2014; whether it&#x2019;s deciding on a new pivot in your hunting, what devices to prioritize in your patching and updating, or which books or online training to focus on &#x2014; take a quick second and get a second, third, and fourth opinion. Then try something that&#x2019;s outside of your normal wheelhouse but sounds good when it&#x2019;s proposed.&#xA0;&#xA0; None of this is a solo sport. It&#x2019;s a team game and the best plays come from a mix of perspectives, experiences, and mistakes. The &#x201C;right&#x201D; answer can wear many faces, and your ability to hold different truths will lead you to undiscovered territory, the rabbit hole where anomaly lives and breathes. So... welcome back from Vegas. Now go down a rabbit hole on a path you wouldn&#x2019;t normally take because one of your friends (Joe) or your mortal enemy (Dave) told you that it would work. &#x201C;She&apos;d been to Narnia, Wonderland, Hogwarts, Dictionopolis. She had tessered, fallen through the rabbit hole, crossed the ice bridge into the unknown world beyond.&#x201D; &#x2015; Anne Ursu, Breadcrumbs&#xA0;The one big thing&#xA0;Cisco Talos recently discovered \"JWR,\" a previously undocumented, real-time phishing framework and likely variant of \"The Outsider\" phishing-as-a-service platform. JWR uses an open WebSocket connection that allows attackers to monitor keystrokes live and dynamically steer victims through fake checkout and login flows. Currently deployed via SMS lures impersonating regional toll and postal authorities, JWR enables operators to steal payment data, 2FA codes, identity documents, and device fingerprints.&#xA0; Why do I care?&#xA0;Because JWR is operator-driven in real time, attackers can actively bypass multi-factor authentication (MFA) by prompting victims for 2FA codes exactly when needed. The sheer volume of collected data gives threat actors a comprehensive identity profile primed for extensive follow-on fraud and network compromise. Furthermore, JWR&apos;s seamless integration with legitimate e-commerce platforms like Shopify makes these lures incredibly convincing to the untrained eye.&#xA0; So now what?&#xA0;Prioritize user education around SMS-based phishing (smishing), specifically regarding unsolicited delivery or toll fee messages. Monitor for unusual authentication attempts, as stolen device fingerprints and session tokens can bypass conditional access policies. Where possible, implement phishing-resistant MFA methods like FIDO2 hardware keys. For a complete list of indicators of compromise (IOCs) and coverage updates, read the full blog.&#xA0; Top security headlines of the week&#xA0;Ransomware hits Colombian Justice Ministry days before presidential transition&#xA0; The attack, which disrupted some services around illicit-drug monitoring and legal processes, came a day after Colombia&apos;s national CERT published threat intelligence warning that ransomware groups had increased their focus on the country. (Dark Reading)&#xA0; FBI investigating North Korean remote IT staffer working for U.S. agency&#xA0; It&#x2019;s unclear what agency was impacted, how long the intrusion lasted, and whether any sensitive data was stolen. Experts say it&#x2019;s highly likely the staffer was a remote IT employee doing contract work on behalf of an agency. (Federal News Network)&#xA0; Hackers leverage new Microsoft SharePoint exploit in attacks&#xA0; A proof-of-concept exploit for a critical Microsoft SharePoint authentication bypass security flaw in the JWT token validation pipeline is already being used in attacks. (BleepingComputer)&#xA0; Signal adds new security feature to thwart adversary-in-the-middle attacks&#xA0; Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven&apos;t been intercepted. (BleepingComputer)&#xA0; A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond&#xA0; The cyberattack on Ceva is affecting at least eight warehouses across Europe used for shipping goods across the continent. Several companies reported that hackers took their customers&#x2019; names, home addresses, phone numbers, and email addresses used to place their orders from Ceva&#x2019;s systems. (TechCrunch)&#xA0; Can&#x2019;t get enough Talos?&#xA0;Don&apos;t scan that! QR code phishing and cloud-native threats&#xA0; What happens when a&#xA0; QR code leads to a major security incident? In this episode, Amy sits down with Senior Incident Response Consultant Terryn Valikodath to break down a recent, high-stakes breach at an Australian medical center&#xA0; Microsoft Patch Tuesday for August 2026&#xA0; Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as \"critical.\" One of the vulnerabilities disclosed this month has been exploited in the wild.&#xA0; &#x201C;Keep going, bro. You&#x2019;ve got this!&#x201D; A data-driven look at how adversaries are weaponizing AI&#xA0; How are adversaries weaponizing AI in the wild? By analyzing prompt logs left behind on endpoints, we found threat actors successfully bypassing guardrails to use AI as malicious software engineers, criminal force multipliers, and vulnerability research accelerators.&#xA0; Upcoming events where you can find Talos&#xA0;International European Cyber Threat Intelligence Conference (IECTIC) (Sept. 9) Kassel, Germany&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, Arizona&#xA0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe&#xA0; Detection Name: W32.9F1F11A708-100.SBX.TG**&#xA0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 &#xA0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; Example Filename: tmp00055df5.dll &#xA0; Detection Name: Auto.90B145.282358.in02&#xA0; SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; MD5: 7bdbd180c081fa63ca94f9c22c457376 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe &#xA0; Detection Name: Win.Dropper.Miner::95.sbx.tg**&#xA0; SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 &#xA0; MD5: 9a47c4d379998ade2f8f99e23a630c06 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; Example Filename: WCInstaller_NonAdmin.exe &#xA0; Detection Name: W32.C4DD71E347-95.SBX.TG&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f &#xA0; MD5: 38de5b216c33833af710e88f7f64fc98 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: SECOH-QAD.exe &#xA0; Detection Name: Win.Tool.Procpatcher::1201","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":["AU","CO","DE","ES","KP"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/curiouser-and-curiouser/","type":"report","title":"Cisco Talos: Curiouser and Curiouser"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-13T18:00:18.000Z","addedAt":"2026-08-13T18:52:44.181Z","updatedAt":"2026-08-13T18:52:44.181Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]}],"pagination":{"page":1,"limit":20,"total":3,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:21:52.854Z","durationMs":14,"filters":{"search":null,"severity":[],"type":[],"country":["KP"],"tag":[],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}