vulnerability Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities Cisco Talos has identified ongoing exploitation of vulnerabilities within Cisco Catalyst SD-WAN Controller and Manager, specifically CVE-2026-20182 and a set of related vulnerabilities (CVE-2026-20133, CVE-2026-20128, an… Cisco Talos · May 14, 2026 High CVE-2026-20182CVE-2026-20133CVE-2026-20128sd-wanciscoauthentication
vulnerability Breaking things to keep them safe with Philippe Laulheret This article details the work of Philippe Laulheret, a Senior Vulnerability Researcher at Cisco Talos, focusing on his unique career path and approach to identifying security flaws. Laulheret’s background includes a stro… Cisco Talos · May 13, 2026 Medium vulnerability researchreverse engineeringctf
vulnerability Microsoft Patch Tuesday for May 2026 — Snort rules and prominent vulnerabilities Microsoft released its May 2026 Patch Tuesday update, addressing 137 vulnerabilities across its product suite. The update includes a significant number of critical vulnerabilities, primarily remote code execution (RCE) f… Cisco Talos · May 12, 2026 High CVE-2026-32161CVE-2026-33109CVE-2026-33844rcebuffer overflowuse after free
threat-intel State-sponsored actors, better known as the friends you don’t want This Cisco Talos report highlights the significant differences in responding to state-sponsored cyber threats compared to conventional attacks like ransomware. It emphasizes that these actors operate within an organizati… Cisco Talos · May 12, 2026 High USUKstate-sponsoredzero trustosint
threat-intel Unplug your way to better code This article from Cisco Talos discusses a shift in threat intelligence strategy, focusing on tracking phone numbers used in sophisticated scam campaigns. Attackers are increasingly utilizing API-driven VoIP numbers for T… Cisco Talos · May 7, 2026 Medium voipscamphone numbers
threat-intel Insights into the clustering and reuse of phone numbers in scam emails This article details Cisco Talos’s intelligence gathering on the increasing use of phone numbers in scam email campaigns. Attackers are leveraging API-driven VoIP providers like Sinch and Twilio to operate high-volume, d… Cisco Talos · May 6, 2026 High USUKvoipscamphishing
apt UAT-8302 and its box full of malware Cisco Talos has identified UAT-8302, a China-nexus advanced persistent threat (APT) group, targeting government entities in South America and southeastern Europe. The group utilizes a range of custom malware families, in… Cisco Talos · May 5, 2026 High CVE-2025-0994BRCOCUchinaaptgovernment
threat-intel Great responsibility, without great power This article from Cisco Talos discusses the importance of empathy and understanding in cybersecurity, particularly in recognizing and responding to attacker behavior. It highlights five critical priorities for defenders… Cisco Talos · Apr 30, 2026 High CVE-2026-42208identityanomalythreat-hunting
threat-intel AI-powered honeypots: Turning the tables on malicious AI agents This article details a new approach to cybersecurity utilizing generative AI to create dynamic honeypots. By leveraging AI to simulate vulnerable systems and respond to attacker actions, defenders can actively manipulate… Cisco Talos · Apr 29, 2026 Medium CVE-2014-6271aihoneypotgenerative-ai
threat-intel Five defender priorities from the Talos Year in Review This Cisco Talos report, part of their Year in Review, highlights five key priorities for cybersecurity defenders in the current threat landscape. The report emphasizes the increasing ease of attack due to readily availa… Cisco Talos · Apr 28, 2026 High USidentityvulnerabilityanomaly detection
threat-intel It pays to be a forever student This article from Cisco Talos highlights the importance of broad knowledge beyond traditional cybersecurity for threat intelligence professionals. It emphasizes the need to understand diverse fields like economics and in… Cisco Talos · Apr 23, 2026 High CVE-2025-20333CVE-2025-20362aiphishingindustrial espionage