{"total":32,"items":[{"id":577,"title":"Give yourself room to be human","original_title":"Give yourself room to be human","source_rating":null,"summary":"In this week’s edition, Amy reflects on the importance of prioritizing family and personal well-being over the pressure to remain constantly productive.","ai":false,"actions":[],"url":"https://blog.talosintelligence.com/give-yourself-room-to-be-human/","type":"research","language":"en","published_at":"2026-10-01T18:00:52+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"talos","name":"Cisco Talos Intelligence","category":"onderzoek","country":null,"license":"© Cisco Talos","reuse":"excerpt"},"bundle":null},{"id":374,"title":"The Fine Art of Frustrating the Adversary","original_title":"The Fine Art of Frustrating the Adversary","source_rating":null,"summary":"What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier. From deception and behavioral detection to breaking attack…","ai":false,"actions":[],"url":"https://blog.talosintelligence.com/the-fine-art-of-frustrating-the-adversary/","type":"research","language":"en","published_at":"2026-10-01T10:00:05+00:00","severity":"laag","priority":0,"vendors":["Cisco"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"talos","name":"Cisco Talos Intelligence","category":"onderzoek","country":null,"license":"© Cisco Talos","reuse":"excerpt"},"bundle":null},{"id":359,"title":"Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)","original_title":"Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)","source_rating":null,"summary":"Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/","type":"research","language":"en","published_at":"2026-09-30T20:00:04+00:00","severity":"middel","priority":37,"vendors":["Citrix"],"cves":[{"id":"CVE-2026-88772","cvss":9.5,"epss":0.01301,"epss_percentile":0.69413,"in_kev":true,"kev_ransomware":false},{"id":"CVE-2026-88771","cvss":9.5,"epss":0.01063,"epss_percentile":0.63393,"in_kev":true,"kev_ransomware":false}],"cve_count":2,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.5,"epss_max":0.01301,"source_count":3,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":344,"title":"China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor","original_title":"China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor","source_rating":null,"summary":"Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a…","ai":false,"actions":[],"url":"https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/","type":"research","language":"en","published_at":"2026-09-30T10:00:01+00:00","severity":"laag","priority":0,"vendors":["Cisco"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"talos","name":"Cisco Talos Intelligence","category":"onderzoek","country":null,"license":"© Cisco Talos","reuse":"excerpt"},"bundle":null},{"id":360,"title":"OperTraitors: How Kubernetes Operators Betray Your Security Posture","original_title":"OperTraitors: How Kubernetes Operators Betray Your Security Posture","source_rating":null,"summary":"We introduce OperTraitor, a tool to audit privileges of Kubernetes operators, identify excessive RBAC risks, and secure non-human identities. The post OperTraitors: How Kubernetes Operators Betray…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/agentic-ai-kubernetes-operator-risks/","type":"research","language":"en","published_at":"2026-09-29T10:00:48+00:00","severity":"laag","priority":0,"vendors":["Kubernetes"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":345,"title":"Securing the keys to the kingdom: Announcing Executive Threat Detection","original_title":"Securing the keys to the kingdom: Announcing Executive Threat Detection","source_rating":null,"summary":"This new proactive service joins the suite of retainer offerings to provide dedicated, intelligence-led hunting specifically for your organization’s most high-value IT assets.","ai":false,"actions":[],"url":"https://blog.talosintelligence.com/securing-the-keys-to-the-kingdom-announcing-executive-threat-detection/","type":"research","language":"en","published_at":"2026-09-29T10:00:36+00:00","severity":"laag","priority":0,"vendors":["Cisco"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"talos","name":"Cisco Talos Intelligence","category":"onderzoek","country":null,"license":"© Cisco Talos","reuse":"excerpt"},"bundle":null},{"id":361,"title":"3 Consulting Myths Debunked by Unit 42 Experts","original_title":"3 Consulting Myths Debunked by Unit 42 Experts","source_rating":null,"summary":"Unit 42 security experts address critical cybersecurity misconceptions, offering practical insights to help your organization reinforce its enterprise defenses. The post 3 Consulting Myths Debunked…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/3-consulting-myths-debunked-by-unit-42-experts/","type":"research","language":"en","published_at":"2026-09-25T23:00:28+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":346,"title":"Trust and the enticing consultancy offer","original_title":"Trust and the enticing consultancy offer","source_rating":null,"summary":"In this week’s newsletter Martin muses over a very suspicious elicitation over social media and the true value of trust within the cyber ecosystem. Hubris might be the real vulnerability that the…","ai":false,"actions":[],"url":"https://blog.talosintelligence.com/trust-and-the-enticing-consultancy-offer/","type":"research","language":"en","published_at":"2026-09-24T18:00:37+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"talos","name":"Cisco Talos Intelligence","category":"onderzoek","country":null,"license":"© Cisco Talos","reuse":"excerpt"},"bundle":null},{"id":347,"title":"The Closed Quorum: Inside the first reported autonomous AI C2 implant","original_title":"The Closed Quorum: Inside the first reported autonomous AI C2 implant","source_rating":null,"summary":"CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which…","ai":false,"actions":[],"url":"https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/","type":"research","language":"en","published_at":"2026-09-22T10:00:58+00:00","severity":"laag","priority":0,"vendors":["Cisco"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"talos","name":"Cisco Talos Intelligence","category":"onderzoek","country":null,"license":"© Cisco Talos","reuse":"excerpt"},"bundle":null},{"id":348,"title":"Introducing CAIRN: Frontier tracking for AI-integrated malware","original_title":"Introducing CAIRN: Frontier tracking for AI-integrated malware","source_rating":null,"summary":"Talos is releasing CAIRN, a research toolkit for hunting, classifying, and tracking emerging AI-integrated malware.","ai":false,"actions":[],"url":"https://blog.talosintelligence.com/introducing-cairn-frontier-tracking-for-ai-integrated-malware/","type":"research","language":"en","published_at":"2026-09-22T10:00:25+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"talos","name":"Cisco Talos Intelligence","category":"onderzoek","country":null,"license":"© Cisco Talos","reuse":"excerpt"},"bundle":null},{"id":362,"title":"From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies","original_title":"From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies","source_rating":null,"summary":"We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies. The post From Exposure to Lockdown: How AWS…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/detecting-exposed-aws-iam-credentials/","type":"research","language":"en","published_at":"2026-09-21T10:00:13+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":363,"title":"A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity","original_title":"A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity","source_rating":null,"summary":"Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials/","type":"research","language":"en","published_at":"2026-09-18T10:00:36+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":364,"title":"Inside the Modern SOC: Defending the Cross-Environment Pivot","original_title":"Inside the Modern SOC: Defending the Cross-Environment Pivot","source_rating":null,"summary":"Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths. The post Inside the Modern SOC: Defending…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/soc-cross-environment-pivot/","type":"research","language":"en","published_at":"2026-09-17T22:00:33+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":349,"title":"Should you care about an “AI slowdown?”","original_title":"Should you care about an “AI slowdown?”","source_rating":null,"summary":"In this week's Threat Source, David talks about why focusing on your security basics is still your best bet, even in a world with rapid AI advancements.","ai":false,"actions":[],"url":"https://blog.talosintelligence.com/should-you-care-about-an-ai-slowdown/","type":"research","language":"en","published_at":"2026-09-17T18:00:23+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"talos","name":"Cisco Talos Intelligence","category":"onderzoek","country":null,"license":"© Cisco Talos","reuse":"excerpt"},"bundle":null},{"id":350,"title":"Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use","original_title":"Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use","source_rating":null,"summary":"Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to…","ai":false,"actions":[],"url":"https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/","type":"research","language":"en","published_at":"2026-09-17T10:00:43+00:00","severity":"middel","priority":42,"vendors":["Cisco"],"cves":[{"id":"CVE-2020-1472","cvss":5.5,"epss":0.99389,"epss_percentile":0.9994,"in_kev":true,"kev_ransomware":true},{"id":"CVE-2025-24799","cvss":9.8,"epss":0.86692,"epss_percentile":0.99738,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2025-2479","cvss":6.1,"epss":0.00335,"epss_percentile":0.24502,"in_kev":false,"kev_ransomware":false}],"cve_count":3,"in_kev":true,"exploited_by":["CISA KEV"],"kev_ransomware":true,"cvss_max":9.8,"epss_max":0.99389,"source_count":1,"ncsc":null,"source":{"slug":"talos","name":"Cisco Talos Intelligence","category":"onderzoek","country":null,"license":"© Cisco Talos","reuse":"excerpt"},"bundle":null},{"id":351,"title":"Securing the unpatchable in an age of AI-driven vulnerabilities","original_title":"Securing the unpatchable in an age of AI-driven vulnerabilities","source_rating":null,"summary":"Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous…","ai":false,"actions":[],"url":"https://blog.talosintelligence.com/securing-the-unpatchable-in-an-age-of-ai-driven-vulnerabilities/","type":"research","language":"en","published_at":"2026-09-16T10:00:36+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"talos","name":"Cisco Talos Intelligence","category":"onderzoek","country":null,"license":"© Cisco Talos","reuse":"excerpt"},"bundle":null},{"id":365,"title":"Atomic macOS (AMOS) Stealer Activity","original_title":"Atomic macOS (AMOS) Stealer Activity","source_rating":null,"summary":"Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/","type":"research","language":"en","published_at":"2026-09-16T10:00:06+00:00","severity":"laag","priority":0,"vendors":["Apple"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":366,"title":"Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection","original_title":"Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection","source_rating":null,"summary":"We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries. The post Unmasking Cloud Identities: From…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/behavioral-clustering-map-to-cloud-identities/","type":"research","language":"en","published_at":"2026-09-14T10:00:01+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":352,"title":"We've got one word for it, and it's usually the wrong one","original_title":"We've got one word for it, and it's usually the wrong one","source_rating":null,"summary":"In this week's Threat Source newsletter, Joe explores why the word \"burnout\" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address…","ai":false,"actions":[],"url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/","type":"research","language":"en","published_at":"2026-09-10T18:00:15+00:00","severity":"hoog","priority":52,"vendors":[],"cves":[{"id":"CVE-2026-20079","cvss":10.0,"epss":0.8818,"epss_percentile":0.99765,"in_kev":true,"kev_ransomware":false},{"id":"CVE-2026-20316","cvss":5.3,"epss":0.35096,"epss_percentile":0.98395,"in_kev":true,"kev_ransomware":true}],"cve_count":2,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":true,"cvss_max":10.0,"epss_max":0.8818,"source_count":3,"ncsc":null,"source":{"slug":"talos","name":"Cisco Talos Intelligence","category":"onderzoek","country":null,"license":"© Cisco Talos","reuse":"excerpt"},"bundle":null},{"id":367,"title":"The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE","original_title":"The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE","source_rating":null,"summary":"Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces:…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/","type":"research","language":"en","published_at":"2026-09-10T10:00:43+00:00","severity":"laag","priority":0,"vendors":["Kubernetes"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":353,"title":"Active exploitation of Cisco Secure Firewall Management Center vulnerabilities","original_title":"Active exploitation of Cisco Secure Firewall Management Center vulnerabilities","source_rating":null,"summary":"Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.","ai":false,"actions":[],"url":"https://blog.talosintelligence.com/fmc-ongoing-exploitation/","type":"research","language":"en","published_at":"2026-09-09T16:08:59+00:00","severity":"hoog","priority":52,"vendors":["Cisco"],"cves":[{"id":"CVE-2026-20079","cvss":10.0,"epss":0.8818,"epss_percentile":0.99765,"in_kev":true,"kev_ransomware":false},{"id":"CVE-2026-20316","cvss":5.3,"epss":0.35096,"epss_percentile":0.98395,"in_kev":true,"kev_ransomware":true}],"cve_count":2,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":true,"cvss_max":10.0,"epss_max":0.8818,"source_count":3,"ncsc":null,"source":{"slug":"talos","name":"Cisco Talos Intelligence","category":"onderzoek","country":null,"license":"© Cisco Talos","reuse":"excerpt"},"bundle":null},{"id":368,"title":"Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure","original_title":"Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure","source_rating":null,"summary":"An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/","type":"research","language":"en","published_at":"2026-09-09T10:00:55+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":354,"title":"Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities","original_title":"Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities","source_rating":null,"summary":"Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as \"critical.\"","ai":false,"actions":[],"url":"https://blog.talosintelligence.com/microsoft-patch-tuesday-for-september-2026/","type":"research","language":"en","published_at":"2026-09-08T22:16:35+00:00","severity":"middel","priority":27,"vendors":["Microsoft"],"cves":[{"id":"CVE-2026-85880","cvss":7.8,"epss":0.03616,"epss_percentile":0.89136,"in_kev":true,"kev_ransomware":false},{"id":"CVE-2026-65772","cvss":8.8,"epss":0.01693,"epss_percentile":0.76272,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-69845","cvss":9.8,"epss":0.01022,"epss_percentile":0.62164,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-66302","cvss":9.8,"epss":0.00974,"epss_percentile":0.60687,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-78509","cvss":9.8,"epss":0.00974,"epss_percentile":0.60691,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-72982","cvss":9.8,"epss":0.00974,"epss_percentile":0.60685,"in_kev":false,"kev_ransomware":false}],"cve_count":165,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":10.0,"epss_max":0.03616,"source_count":2,"ncsc":null,"source":{"slug":"talos","name":"Cisco Talos Intelligence","category":"onderzoek","country":null,"license":"© Cisco Talos","reuse":"excerpt"},"bundle":null},{"id":355,"title":"ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager","original_title":"ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager","source_rating":null,"summary":"We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as…","ai":false,"actions":[],"url":"https://blog.talosintelligence.com/clearfake-webdav-infection-chain/","type":"research","language":"en","published_at":"2026-09-08T10:01:07+00:00","severity":"laag","priority":0,"vendors":["Cisco"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"talos","name":"Cisco Talos Intelligence","category":"onderzoek","country":null,"license":"© Cisco Talos","reuse":"excerpt"},"bundle":null},{"id":356,"title":"ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2","original_title":"ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2","source_rating":null,"summary":"Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google…","ai":false,"actions":[],"url":"https://blog.talosintelligence.com/clickfix-moves-into-the-browser/","type":"research","language":"en","published_at":"2026-09-08T10:00:38+00:00","severity":"laag","priority":0,"vendors":["Cisco"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"talos","name":"Cisco Talos Intelligence","category":"onderzoek","country":null,"license":"© Cisco Talos","reuse":"excerpt"},"bundle":null},{"id":357,"title":"The story behind the intelligence","original_title":"The story behind the intelligence","source_rating":null,"summary":"From engaging with cybercriminals to surviving a live Flamin’ Hot Cheetos taste test, Hazel reflects on the latest Beers with Talos with Azim, where they cover the full spectrum of what it takes to…","ai":false,"actions":[],"url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/","type":"research","language":"en","published_at":"2026-09-03T18:00:13+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"talos","name":"Cisco Talos Intelligence","category":"onderzoek","country":null,"license":"© Cisco Talos","reuse":"excerpt"},"bundle":null},{"id":369,"title":"Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America","original_title":"Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America","source_rating":null,"summary":"Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/","type":"research","language":"en","published_at":"2026-09-03T10:00:58+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":370,"title":"An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation","original_title":"An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation","source_rating":null,"summary":"Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack:…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/","type":"research","language":"en","published_at":"2026-09-02T10:00:46+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":371,"title":"Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams","original_title":"Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams","source_rating":null,"summary":"Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/","type":"research","language":"en","published_at":"2026-08-31T10:00:36+00:00","severity":"laag","priority":0,"vendors":["Microsoft"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":372,"title":"Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety","original_title":"Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety","source_rating":null,"summary":"New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/perturbation-probing-llm-safety/","type":"research","language":"en","published_at":"2026-08-28T22:00:07+00:00","severity":"laag","priority":0,"vendors":[],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null}]}