Cisco Talos
talos · B · active
https://blog.talosintelligence.com/
Cisco's threat intelligence team. Has previously returned HTTP 403 on the routine UA (last seen 2026-05-06; recovered 2026-05-07 and confirmed working 2026-05-08). If WebFetch returns 403 again, route through `python3 tools/fetch_source.py url https://blog.talosintelligence.com/` rather than retrying. RSS at /rss/ also works. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch (listing) https://blog.talosintelligence.com/ then webfetch per-article slug URL; if WebFetch 403s, route bridge: python3 tools/fetch_source.py url https://blog.talosintelligence.com/ ; RSS at /rss/ also works. AVOID: Has intermittently 403'd the routine UA in the past — if WebFetch returns 403, go straight to the bridge rather than retrying the same UA.. | 2026-07-05 admiralty audit: B — original Cisco threat-research lab; live. Keep active.
Cited in 22 entries
Citation cadence
Citation days per ISO week (14 weeks of coverage span, total 21).
- Talos analyses threat actors' own AI coding-assistant prompt logs: guardrails fell to unverified permission claims, and the operator's skill — not model access — decided what got built2026-08-05
- Talos IR Trends Q2 2026: ransomware operators ran their command-and-control through legitimate RMM agents, authentication abuse hit two-thirds of engagements, and missing logs stopped root-cause determination outright2026-07-29
- This week's tradecraft converged on hiding command-and-control inside trusted services and native tooling — Graph-API calendars, DNS, the Telegram API, a browser the malware never connects through, and BitLocker instead of a ransomware binary2026-07-26
- msaRAT: Chaos ransomware's Rust RAT builds C2 through the Chrome DevTools Protocol so the malware process never opens a socket2026-07-24
- Cisco Talos: UAT-11795 deploys the Python-based Starland RAT and a bespoke PowerShell C2 implant (WLDR), resolving fallback C2 through a Polygon blockchain dead-drop2026-07-17
- Cisco Talos maps the full taxonomy of Python-package build-time and import-time code execution ("The Serpent's Tongue")2026-07-14
- FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctions2026-07-13
- Threat-actor developments this week: Group-IB reframes Scattered Spider as a decentralised collective, and China- and Iran-nexus edge/ORB tradecraft advances2026-07-12
- Cisco Talos batch disclosure: wolfSSL PKI name-constraint bypasses, GeoVision command injection, and a VTK-DICOM heap overflow (41 CVEs)2026-07-09
- Cisco Talos: China-nexus UAT-7810 expands its ORB network with LONGLEASH/DOGLEASH/JARLEASH via unpatched Ruckus and ASUS routers2026-07-08
- The week's tradecraft converged on abusing trusted primitives — OAuth tokens, signed binaries, native auth APIs and legitimate SaaS2026-07-05
- Cisco Talos: "ARToken" exposes a full BEC-as-a-service toolkit on top of Microsoft 365 device-code phishing2026-07-02
- Research: the trust chain, not the perimeter, was the week's attack surface2026-06-29
- Cisco Talos: a field guide to Windows COM abuse — ITaskService, BITS, WMI and DCOM as EDR-evasion primitives2026-06-28
- Cisco Catalyst SD-WAN Manager CVE-2026-20262: authenticated arbitrary file write to root RCE2026-06-16
- Cisco Talos maps the DICOM-format attack surface against Orthanc PACS — network-ingested medical images as a heap out-of-bounds-write primitive2026-05-31
- Healthcare — administrative and imaging intermediaries remain the soft surface2026-05-25
- Cisco Talos: "demo.pdb" BadIIS variant now a commodity MaaS IIS ISAPI backdoor; lwxat developer alias, builder tool recovered2026-05-20
- UAT-8616 exploits Cisco Catalyst SD-WAN CVE-2026-20182; 10+ clusters exploit companion February 2026 CVEs; CISA Emergency Directive ED-26-03 issued2026-05-15
- Cisco Catalyst SD-WAN: CVE-2026-20182 Authentication Bypass and UAT-8616 Kill Chain2026-05-15
- Cisco Catalyst SD-WAN CVE-2026-20182 — UAT-8616 active, CISA Emergency Directive ED-26-03, 10+ companion-CVE clusters2026-05-11
- UAT-8302 (China-nexus, Talos; SE European government victims)2026-05-04