Blog
Featured

IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains

Talos IR's Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses.

July 30, 2026 06:00

Black Hat special: Rewind and revisit

Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence.

July 23, 2026 06:00

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.

July 23, 2026 06:00

Preview: Cisco Talos at Black Hat USA 2026

Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk.

Recent
July 30, 2026 14:00

You were onto something with “It’s the Climb,” Miley

Amy hikes Virginia’s most difficult trail and muses on the persistent challenges of cybersecurity. The two aren't dissimilar.

July 23, 2026 14:00

Don’t swing at everything

Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.

July 16, 2026 14:00

Begun, the Patch Wars have

Long foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story.

July 16, 2026 06:00

The Hunter's Paradox: Is it time to embrace automated threat hunting?

Humans can no longer keep up with the volume and velocity of security data on their own, but AI can't be fully trusted. David discusses the merits of both and muses on what the future might look like.

July 16, 2026 06:00

UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.