Meldingen
32 meldingen uit primaire bronnen. Filter op ernst, type of vendor, of zoek op een CVE-nummer of productnaam. Bulkpublicaties (BSI-updates, Patch Tuesday) staan als één regel.
Koppelen
Zet de feed in je RSS-lezer, of in Slack (/feed subscribe) of Teams (RSS-connector), dan komen nieuwe meldingen vanzelf in je teamkanaal.
Liever zelf bouwen? Dezelfde selectie als JSON, of de volledige API-specificatie (OpenAPI).
Give yourself room to be human
In this week’s edition, Amy reflects on the importance of prioritizing family and personal well-being over the pressure to remain constantly productive.
0laagThe Fine Art of Frustrating the Adversary
What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier. From deception and behavioral detection to breaking attack…
0laagThreat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)
Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days…
37middelChina-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a…
0laagOperTraitors: How Kubernetes Operators Betray Your Security Posture
We introduce OperTraitor, a tool to audit privileges of Kubernetes operators, identify excessive RBAC risks, and secure non-human identities. The post OperTraitors: How Kubernetes Operators Betray…
0laagSecuring the keys to the kingdom: Announcing Executive Threat Detection
This new proactive service joins the suite of retainer offerings to provide dedicated, intelligence-led hunting specifically for your organization’s most high-value IT assets.
0laag3 Consulting Myths Debunked by Unit 42 Experts
Unit 42 security experts address critical cybersecurity misconceptions, offering practical insights to help your organization reinforce its enterprise defenses. The post 3 Consulting Myths Debunked…
0laagTrust and the enticing consultancy offer
In this week’s newsletter Martin muses over a very suspicious elicitation over social media and the true value of trust within the cyber ecosystem. Hubris might be the real vulnerability that the…
0laagThe Closed Quorum: Inside the first reported autonomous AI C2 implant
CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which…
0laagIntroducing CAIRN: Frontier tracking for AI-integrated malware
Talos is releasing CAIRN, a research toolkit for hunting, classifying, and tracking emerging AI-integrated malware.
0laagFrom Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies
We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies. The post From Exposure to Lockdown: How AWS…
0laagA Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity
Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The…
0laagInside the Modern SOC: Defending the Cross-Environment Pivot
Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths. The post Inside the Modern SOC: Defending…
0laagShould you care about an “AI slowdown?”
In this week's Threat Source, David talks about why focusing on your security basics is still your best bet, even in a world with rapid AI advancements.
0laagRansomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use
Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to…
42middelSecuring the unpatchable in an age of AI-driven vulnerabilities
Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous…
0laagAtomic macOS (AMOS) Stealer Activity
Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared…
0laagUnmasking Cloud Identities: From Behavioral Clustering to Automated Detection
We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries. The post Unmasking Cloud Identities: From…
0laagWe've got one word for it, and it's usually the wrong one
In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address…
52hoogThe Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE
Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces:…
0laagActive exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.
52hoogUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind…
0laagMicrosoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
27middelClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as…
0laagClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google…
0laagThe story behind the intelligence
From engaging with cybercriminals to surviving a live Flamin’ Hot Cheetos taste test, Hazel reflects on the latest Beers with Talos with Azim, where they cover the full spectrum of what it takes to…
0laagAttackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use…
0laagAn AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack:…
0laagSpring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing…
0laagPerturbation Probing: A New Diagnostic for the Fragility of LLM Safety
New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the…
0laag