Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAMCisco Talos·Feb 20, 13:00 UTC · Feb 20, 2024Malware30
New Zardoor backdoor used in long-term cyber espionage operation targeting an Islamic organizationCisco Talos·Feb 8, 14:10 UTC · Feb 8, 2024Malware42
Operation Blacksmith: Lazarus targets organizations worldwide using novel TelegramCisco Talos·Dec 11, 13:50 UTC · Dec 11, 2023Threat actorCVE-2021-4422860
New SugarGh0st RAT targets Uzbekistan government and South KoreaCisco Talos·Nov 30, 13:00 UTC · Nov 30, 2023Malware30
Understanding the Phobos affiliate structure and activityCisco Talos·Nov 17, 13:01 UTC · Nov 17, 2023Ransomware57
Kazakhstan-associated YoroTrooper disguises origin of attacks as AzerbaijanCisco Talos·Oct 25, 12:01 UTC · Oct 25, 2023Vulnerability130
What to know about the HTTP/2 Rapid Reset DDoS attacksCisco Talos·Oct 11, 23:06 UTC · Oct 11, 2023VulnerabilityCVE-2023-4448735
Qakbot-affiliated actors distribute Ransom Knight malware despite infrastructure takedownCisco Talos·Oct 5, 11:00 UTC · Oct 5, 2023Malware42
New ShroudedSnooper actor targets telecommunications firms in the Middle East with novel ImplantsCisco Talos·Sep 19, 12:00 UTC · Sep 19, 2023Malware55
Cybercriminals target graphic designers with GPU minersCisco Talos·Sep 7, 12:00 UTC · Sep 7, 2023Malware42
SapphireStealer: Open-source information stealer enables credential and data theftCisco Talos·Aug 31, 12:00 UTC · Aug 31, 2023Malware142
Lazarus Group's infrastructure reuse leads to discovery of new malwareCisco Talos·Aug 24, 12:04 UTC · Aug 24, 2023MalwareCVE-2022-4796660
Lazarus Group exploits ManageEngine vulnerability to deploy QuiteRATCisco Talos·Aug 24, 12:02 UTC · Aug 24, 2023VulnerabilityCVE-2022-47966135
What Cisco Talos knows about the Rhysida ransomwareCisco Talos·Aug 8, 19:36 UTC · Aug 8, 2023Ransomware57
New threat actor targets Bulgaria, China, Vietnam and other countries with customized Yashma ransomwareCisco Talos·Aug 7, 12:00 UTC · Aug 7, 2023Ransomware57
Malicious campaigns target government, military and civilian entities in Ukraine, PolandCisco Talos·Jul 13, 10:45 UTC · Jul 13, 2023Threat actor145
Undocumented driver-based browser hijacker RedDriver targets Chinese speakers and internet cafesCisco Talos·Jul 11, 17:04 UTC · Jul 11, 2023Malware55
Old certificate, new signature: Open-source tools forge signature timestamps on Windows driversCisco Talos·Jul 11, 17:04 UTC · Jul 11, 2023Malware55
Active exploitation of the MOVEit Transfer vulnerability — CVE-2023Cisco Talos·Jun 16, 18:17 UTC · Jun 16, 2023Vulnerability in the wildCVE-2023-34362CVE-2023-35036CVE-2023-3570860
Newly identified RA Group compromises companies in U.S. and South Korea with leaked Babuk source codeCisco Talos·May 15, 12:00 UTC · May 15, 2023Ransomware57
New phishing-as-a-service tool “Greatness” already seen in the wildCisco Talos·May 10, 12:00 UTC · May 10, 2023Phishing & fraud30
Typhon Reborn V2: Updated stealer features enhanced antiCisco Talos·Apr 4, 12:00 UTC · Apr 4, 2023Malware30
Threat Advisory: 3CX Softphone Supply Chain CompromiseCisco Talos·Mar 30, 22:29 UTC · Mar 30, 2023Advisory42
Emotet resumes spam operations, switches to OneNoteCisco Talos·Mar 22, 19:41 UTC · Mar 22, 2023Malware30
Threat Advisory: Microsoft Outlook privilege escalation vulnerability being exploited in the wildCisco Talos·Mar 15, 23:46 UTC · Mar 15, 2023Exploit / PoC in the wildCVE-2023-2339760
Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agencyCisco Talos·Mar 14, 11:00 UTC · Mar 14, 2023Threat actor60
Following the LNK metadata trailCisco Talos·Jan 19, 13:00 UTC · Jan 19, 2023VulnerabilityCVE-2015-009635
Threat Spotlight: Cyber Criminal Adoption of IPFS for Phishing, Malware CampaignsCisco Talos·Nov 9, 13:00 UTC · Nov 9, 2022Malware30
Threat Advisory: High Severity OpenSSL VulnerabilitiesCisco Talos·Nov 1, 19:03 UTC · Nov 1, 2022Vulnerability in the wildCVE-2022-3602CVE-2022-378660
Alchimist: A new attack framework in Chinese for Mac, Linux and WindowsCisco Talos·Oct 13, 12:00 UTC · Oct 13, 2022Exploit / PoC in the wildCVE-2021-4034160
Threat Advisory: Microsoft warns of actively exploited vulnerabilities in Exchange ServerCisco Talos·Sep 30, 21:16 UTC · Sep 30, 2022Vulnerability in the wildCVE-2022-41040CVE-2022-4108260
New campaign uses government, union-themed lures to deliver Cobalt Strike beaconsCisco Talos·Sep 28, 12:12 UTC · Sep 28, 2022Threat actorCVE-2017-019960
Gamaredon APT targets Ukrainian government agencies in new campaignCisco Talos·Sep 15, 13:00 UTC · Sep 15, 2022Threat actor157
MagicRAT: Lazarus’ latest gateway into victim networksCisco Talos·Sep 7, 12:01 UTC · Sep 7, 2022Malware42
Small-time cybercrime is about to explode — We aren’t readyCisco Talos·Aug 29, 18:45 UTC · Aug 29, 2022Ransomware57
Attackers leveraging Dark Utilities "C2aaS" platform in malware campaignsCisco Talos·Aug 4, 12:00 UTC · Aug 4, 2022Malware30