news.mlab.sh
Back to the feed
threat-intel

Reporting from Vegas: Networking, AI, and good boys

High
Summary

This Cisco Talos Threat Source newsletter highlights the ongoing challenges of managing data at scale in an AI-driven world, particularly during large technology conferences like Cisco Live. It details Talos’ expansion of its Threat Hunting program, focusing on proactive detection of advanced adversaries using AI and human expertise, exemplified by a recent KongTuke command-and-control (C2) discovery. The newsletter also reports on several recent security incidents, including a prolonged email campaign targeting a global stock exchange, a GitHub vulnerability allowing token theft, and a phishing kit expansion.

Cisco Talos is expanding its Threat Hunting program to proactively track down advanced adversaries who deliberately slip past traditional detection thresholds. This initiative combines AI-driven telemetry analysis with human expert validation to continuously hunt for hidden threats across endpoint, network, and identity data. The focus is on hypothesis-driven approaches, allowing defenders to identify complex intrusions before formal detection signatures exist. A recent example cited was the discovery of a KongTuke command-and-control (C2) network, demonstrating the program's ability to uncover sophisticated threats. This expansion addresses the growing challenge of managing massive data volumes, particularly in an environment where AI is accelerating threat actor capabilities.

The newsletter also reports on several recent security incidents. A threat actor gained near-continuous access to an influential finance executive's email inbox through a prolonged email campaign, leveraging legitimate Windows tools. Simultaneously, a vulnerability in GitHub allowed attackers to steal full GitHub OAuth tokens via malicious VS Code extensions. Furthermore, the FBI-flagged phishing kit “Kali365” has expanded its targeting to include AWS, Okta, and Russian platforms, showcasing the evolving tactics of phishing-as-a-service operations. Finally, dozens of Red Hat packages were backdoored through its official NPM channel, highlighting supply chain vulnerabilities.

These incidents underscore the importance of proactive threat hunting and vigilance against sophisticated attacks. The newsletter emphasizes the need for organizations to adapt their security strategies to address the evolving threat landscape, particularly in the context of AI-driven attacks and large-scale data management.

Read the full article at Cisco Talos