threat-intel New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework A new threat cluster, OP-512, is targeting Microsoft IIS servers with a custom web shell framework, exhibiting sophisticated evasion techniques and centralized management capabilities. ReliaQuest has linked the activity… The Hacker News · Jun 5, 2026 High CNiisweb shellespionage
vulnerability Cisco warns of unpatched SD-WAN zero-day exploited in attacks Cisco has issued a warning about a previously unknown zero-day vulnerability (CVE-2026-20245) in its Cisco Catalyst SD-WAN Manager software, which is being actively exploited to gain root privileges. The flaw, stemming f… BleepingComputer · Jun 5, 2026 High CVE-2026-20245CVE-2026-20182CVE-2026-20127zero-daysd-wanroot privilege
vulnerability Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026 Cisco has issued a security advisory regarding a newly discovered zero-day vulnerability (CVE-2026-20245) within its SD-WAN Manager product. This vulnerability, exploitable via command injection, has been actively used b… SecurityWeek · Jun 5, 2026 High CVE-2026-20245CVE-2026-20182CVE-2026-20127zero-daycommand injectionsd-wan
threat-intel Reporting from Vegas: Networking, AI, and good boys This Cisco Talos Threat Source newsletter highlights the ongoing challenges of managing data at scale in an AI-driven world, particularly during large technology conferences like Cisco Live. It details Talos’ expansion o… Cisco Talos · Jun 4, 2026 High USRUaithreat huntingc2
threat-intel ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories This bulletin highlights several ongoing cyber threats, including a high-severity SSRF vulnerability in Cisco Unified Communications Manager, a large-scale spyware operation targeting Russian officials by foreign intelli… The Hacker News · Jun 4, 2026 High CVE-2026-20230CVE-2022-0492CVE-2019-5736RUIRUSssrfspywarekeylogger
threat-intel Winning the cyber marathon with Tony Giandomenico This article discusses Cisco Talos Senior Director of Product Management, Tony Giandomenico’s perspective on the evolving cybersecurity landscape, particularly the increasing capabilities of AI and frontier models. He hi… Cisco Talos · Jun 4, 2026 Medium aithreat huntingcybersecurity
threat-intel Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting This article details Cisco Talos' approach to threat hunting, which differs from traditional alert-based detection. Instead of waiting for alerts, Talos analysts formulate hypotheses about adversary behavior based on tel… Cisco Talos · Jun 4, 2026 High USthreat huntingaicorrelation
vulnerability Cisco warns of critical Unified CM flaw with PoC exploit code Cisco has issued a critical security update addressing a vulnerability (CVE-2026-20230) in its Unified Communications Manager (Unified CM) software. This flaw allows attackers to gain root privileges through SSRF attacks… BleepingComputer · Jun 4, 2026 Critical CVE-2026-20230CVE-2026-20045CVE-2024-20253ssrfprivilege escalationroot access
threat-intel Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels North Korean state-sponsored threat actor Kimsuky has expanded its arsenal and tactics, utilizing HTTPSpy, HelloDoor, and VS Code tunnels to target South Korean military and corporate entities between March and April 202… The Hacker News · May 29, 2026 High KRnorth koreanremote access trojansocial engineering
threat-intel Less panic patching, more precision This article from Cisco Talos discusses a shift in cybersecurity threat intelligence prioritization, moving away from solely relying on CVSS scores to incorporate exploit prediction and broader data enrichment. The core… Cisco Talos · May 28, 2026 Medium USDEvulnerability_managementepssgcve
threat-intel Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake Cisco Talos has released EvidenceForge, an open-source synthetic security log generator designed to address the limitations of existing synthetic data solutions. The tool utilizes a canonical event model, causal ordering… Cisco Talos · May 27, 2026 Medium synthetic datalog generationthreat hunting
threat-intel MFA Prompt Bombing: Why Your Second Factor Isn't Saving You This article details a new attack technique called ‘MFA prompt bombing,’ where attackers repeatedly trigger multi-factor authentication prompts to trick users into approving access. The attack leverages push-based MFA sy… The Hacker News · May 26, 2026 High USmfapush-mfaprompt bombing
data-breach 7-Eleven data breach exposes personal information of 185,000 people 7-Eleven experienced a data breach following a cyberattack by the ShinyHunters extortion gang, exposing the personal information of over 185,000 individuals. The attackers gained access to 7-Eleven’s systems, primarily a… BleepingComputer · May 26, 2026 High DEdata breachsalesforceextortion
malware The art of being ungovernable This analysis focuses on a Cisco Talos report detailing the emergence of a sophisticated, multi-year-old BadIIS malware variant being utilized by Chinese-speaking cybercrime groups as part of a malware-as-a-service (MaaS… Cisco Talos · May 21, 2026 High CHmalware-as-a-serviceseo fraudtraffic hijacking
threat-intel Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks Microsoft disrupted a malware-signing-as-a-service (MSaaS) operation, dubbed OpFauxSign, led by the threat actor Fox Tempest, which was using its Artifact Signing system to distribute malware and ransomware. The operatio… The Hacker News · May 20, 2026 High USFRINmsaascode-signingmalware
threat-intel Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API A China-aligned threat actor known as Webworm has expanded its arsenal with two new backdoors, EchoCreep and GraphWorm, utilizing Discord and the Microsoft Graph API for command-and-control communications. The group, act… The Hacker News · May 20, 2026 High CHRUGEdiscordmicrosoft graphrat
malware From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat This report details the discovery of a commodity BadIIS malware variant, identified by its "demo.pdb" strings, being utilized by multiple Chinese-speaking cybercrime groups operating under a MaaS model. Developed by an a… Cisco Talos · May 19, 2026 Medium CNUSGBseomalware-as-a-serviceiis
threat-intel ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More This week’s security news highlights several active exploits and attacks, including a widespread vulnerability in on-prem Exchange Servers, a Cisco SD-WAN controller compromise attributed to UAT-8616, and a significant s… The Hacker News · May 18, 2026 High CVE-2026-42897CVE-2026-20182CVE-2026-20127USexchangesupply chainnpm
ransomware IT threat evolution in Q1 2026. Non-mobile statistics In Q1 2026, Kaspersky products blocked over 343 million attacks, with significant ransomware activity including 2938 new ransomware variants and 77,000 ransomware attacks. Law enforcement actions disrupted the RAMP cyber… Securelist · May 18, 2026 High CVE-2026-20131POUNransomwarezero-dayraas
threat-intel The time of much patching is coming This article from Cisco Talos anticipates a significant increase in software patching due to advancements in AI-powered vulnerability detection and the uncovering of long-standing technical debt. The surge in discovered… Cisco Talos · May 14, 2026 High USvulnerabilitypatchingai