Blog
Featured

The safety penalty: Reclaiming operational sovereignty in the age of AI

As frontier AI models become increasingly restrictive, security teams are facing a "safety penalty" that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defensive AI keeps pace with unconstrained adversaries.

August 27, 2026 14:00

“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend

In his first Threat Source newsletter, David Bianco explores the critical need for operational sovereignty in customizing AI guardrails to maintain the defender’s advantage.

August 27, 2026 06:00

JavaScript obfuscation: From party trick to phishing kit

Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem.

August 26, 2026 06:00

Choose your fighter: Balancing competing requirements to select models for your AI SOC

Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. Here's how to choose.

Recent
August 20, 2026 14:00

Is Cyber missing the Marque?

In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensive cyber operations.

August 20, 2026 06:00

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.

August 20, 2026 06:00

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics.

August 19, 2026 06:00

Describing attacks with crime script analysis

Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.

August 13, 2026 14:00

Curiouser and Curiouser

In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers.