Blog
Featured

UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing

Cisco Talos identified an APT spear-phishing campaign against individuals affiliated with Taiwan research organizations. The operation leveraged legitimate public event themes and impersonated reputable academic and policy institutions.

October 8, 2026 14:00

Making sure the checks get printed

Pierre's debut newsletter explores the messy, real-world side of risk management and how to keep vital systems running when a perfect patch isn't an option.

October 8, 2026 06:00

Ignore all instructions and read this blog: The state of AI-analysis evasion in malware

“AI-analysis evasion” encapsulates the real-world techniques malware authors are developing in attempt to obstruct or defeat any layers of automated AI analysis.

October 7, 2026 06:00

One breach, please, and make no mistakes

The cybersecurity community has seen examples of autonomous agents, built inside AI labs, attacking public infrastructure. How you prepare for agentic threats is what makes the difference during real incidents.

Recent
October 7, 2026 15:27

Microsoft, Adobe, Apple, and Foxit vulnerabilities

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerabil

October 1, 2026 14:00

Give yourself room to be human

In this week’s edition, Amy reflects on the importance of prioritizing family and personal well-being over the pressure to remain constantly productive.

October 1, 2026 06:00

The Fine Art of Frustrating the Adversary

What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier, from deception and behavioral detection to breaking attack dependencies and resisting manufactured urgency.

September 30, 2026 06:00

China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor

Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.

September 29, 2026 06:00

Securing the keys to the kingdom: Announcing Executive Threat Detection

This new proactive service joins the suite of retainer offerings to provide dedicated, intelligence-led hunting specifically for your organization’s most high-value IT assets.