Actor Exploits Microsoft Exchange Server Vulnerabilities, Cortex XDR Blocks Harvesting of CredentialsPalo Alto Unit 42·Jun 6, 13:23 UTC · Jun 6, 2024Vulnerability in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Vice Society: Profiling a Persistent Threat to the Education SectorPalo Alto Unit 42·Jun 5, 17:12 UTC · Jun 5, 2024RansomwareCVE-2021-3452760
Cisco Talos shares insights related to recent cyber attack on CiscoCisco Talos·Aug 10, 19:30 UTC · Aug 10, 2022Ransomware60
IR Q4 2023 trends: Significant increase in ransomware activity found in engagements, while education remains one of the mostCisco Talos·Jan 24, 13:00 UTC · Jan 24, 2024RansomwareCVE-2020-147260
Akira ransomware continues to evolveCisco Talos·Oct 21, 16:50 UTC · Oct 21, 2024Ransomware in the wildCVE-2024-40766CVE-2020-3259CVE-2023-20263+5 CVEs60
5 Steps for Reducing Risk From Leaked CredentialsRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Malware55
Most interesting IR cases in 2023: insider threats and moreKaspersky Securelist·Sep 3, 11:01 UTC · Sep 3, 2024Ransomware60
Unmasking the new persistent attacks on JapanCisco Talos·Mar 6, 11:00 UTC · Mar 6, 2025VulnerabilityCVE-2024-4577160
Incident Response trends Q2 2023: Data theft extortion rises, while healthcare is still mostCisco Talos·Jul 26, 12:00 UTC · Jul 26, 2023Ransomware in the wildCVE-2023-0669CVE-2021-27101CVE-2021-27102+3 CVEs60
IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persistCisco Talos·Apr 22, 10:00 UTC · Apr 22, 2026Phishing & fraud55
Talos Incident Response quarterly threat report — The top malware families and TTPs used in Q2 2021Cisco Talos·Aug 11, 12:00 UTC · Aug 11, 2021Malware55
Compromise assessment in cybersecurity: realKaspersky Securelist·Oct 29, 14:00 UTC · Oct 29, 2024Data breach60
Threat Assessment: BlackByte RansomwarePalo Alto Unit 42·Jun 5, 22:40 UTC · Jun 5, 2024RansomwareCVE-2021-34473CVE-2021-34523CVE-2021-31207160
Lazarus exploit Log4Shell vulnerability to deliver novel RAT malwareHelp Net Security·Dec 12, 00:00 UTC · Dec 12, 2023VulnerabilityCVE-2021-4422860
Chinese Redfly Group Compromised a Nation's Critical Grid in 6The Hacker News·Sep 12, 11:22 UTC · Sep 12, 2023Data breach160
Experts Warn of Surge in Multipurpose MalwareInfosecurity Magazine·Feb 16, 10:00 UTC · Feb 16, 2023Malware55
Hackers are abusing IIS extensions to establish covert backdoorsSecurity Affairs·Jul 27, 20:18 UTC · Jul 27, 2022Malware55
Attacks on web applications spike in third quarter, new Talos IR data showsCisco Talos·Oct 24, 12:00 UTC · Oct 24, 2023Ransomware60
European firm DSIRF behind the attacks with Subzero surveillance malwareSecurity Affairs·Jul 28, 11:04 UTC · Jul 28, 2022MalwareCVE-2022-22047CVE-2021-31199CVE-2021-31201+2 CVEs60
Stop Your Legacy Infrastructure from Hijacking Your AI AgentsThe Hacker News·Jul 20, 06:32 UTC · Jul 20, 2026Exploit / PoC in the wildCVE-2025-2481360
Attivo Networks ThreatStrike functionality helps hide real credentials from attacker toolsHelp Net Security·Sep 9, 00:00 UTC · Sep 9, 2021Ransomware60
UAT-5918 targets critical infrastructure entities in TaiwanCisco Talos·Mar 20, 10:00 UTC · Mar 20, 2025Exploit / PoC60
CISA: Most cyberattacks on gov’ts, critical infrastructure involve valid credentialsThe Record·Jul 26, 01:02 UTC · Jul 26, 2023Vulnerability55
Microsoft issues targeted notification to hospitals vulnerable to Ransomware attacksSecurity Affairs·Apr 2, 07:39 UTC · Apr 2, 2020Ransomware60
How Organizations Can Defend Against Advanced Persistent ThreatsThe Hacker News·Dec 25, 16:44 UTC · Dec 25, 2019Data breach60
Talos IR trends Q3 2024: IdentityCisco Talos·Oct 24, 10:00 UTC · Oct 24, 2024RansomwareCVE-2024-3708560
Lazarus Group's infrastructure reuse leads to discovery of new malwareCisco Talos·Aug 24, 12:04 UTC · Aug 24, 2023MalwareCVE-2022-4796660
China-linked APT Volt Typhoon targets critical infrastructure orgsSecurity Affairs·May 25, 14:13 UTC · May 25, 2023Threat actor60
Digital Threat Detection Tools & Best PracticesRecorded Future·Jan 6, 00:00 UTC · Jan 6, 2026Ransomware60
Twelve: from initial compromise to ransomware and wipersKaspersky Securelist·Sep 20, 13:33 UTC · Sep 20, 2024RansomwareCVE-2021-21972CVE-2021-2200560
Quarterly Report: Incident Response trends from Q3 2021Cisco Talos·Oct 28, 12:00 UTC · Oct 28, 2021RansomwareCVE-2021-3011660
Quarterly Report: Incident Response trends from Spring 2021Cisco Talos·Jun 10, 12:00 UTC · Jun 10, 2021RansomwareCVE-2021-26855CVE-2021-26857CVE-2021-26858+4 CVEs60
Silent breaches are happening right now, most companies have no clueHelp Net Security·Feb 12, 00:00 UTC · Feb 12, 2025Ransomware60
The biggest problem with ransomware is not encryption, but credentialsHelp Net Security·Jan 8, 11:56 UTC · Jan 8, 2024Ransomware60
WebAuthn Passwordless Authentication Now Available for Atlassian ProductsThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2020Data breach60