Cisco Talos Blog

August 5, 2021 13:46

Threat Source newsletter (Aug. 5, 2021)

Newsletter compiled by Jon Munshaw. Good afternoon, Talos readers. We hope everyone is enjoying BlackHat and/or DEFCON this week, regardless of if you're attending virtually or in person. In case you missed any of our talks from BlackHat, you can check them out here, along

August 4, 2021 10:16

Vulnerability Spotlight: Use-after-free vulnerability in tinyobjloader

Lilith >_> of Cisco Talos discovered this vulnerability. Cisco Talos recently discovered that a specific function of tinyobjloader does not properly validate array indexes. An adversary could trick a user into opening a specially crafted file, causing an index out-of-bound

August 3, 2021 11:14

Updates to the Cisco Talos Email Status Portal

Cisco Talos is rolling out several changes to the Email Status Portal that adds new features and makes the Portal even easier to use. The Talos Email Status Portal allows users to view mail samples submitted and their statuses, analyze graphical displays of submission metrics, a

July 29, 2021 15:00

Threat Source newsletter (July 29, 2021)

Good afternoon, Talos readers. Thanks to everyone who joined us live yesterday for our talk on business email compromise. If you missed us live, the recording is up on our YouTube page now. Nick Biasini from Talos Outreach provided some great advice on avoiding business email co

July 27, 2021 12:04

Vulnerability Spotlight: Use-after-free vulnerabilities in Foxit PDF Reader

Aleksandar Nikolic of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw. Cisco Talos recently discovered multiple use-after-free vulnerabilities in the Foxit PDF Reader. Foxit PDF Reader is one of the most popular PDF document readers currently available. As a comp

July 26, 2021 10:42

Vulnerability Spotlight: Unsafe deserialization vulnerabilities in CODESYS Development System

Patrick DeSantis discovered these vulnerabilities. Blog by Jon Munshaw. Cisco Talos recently discovered multiple vulnerabilities in the CODESYS Development System. The CODESYS Development System is the IEC 61131-3 programming tool for industrial control and automation technolog

July 23, 2021 11:00

Talos Takes Ep: #62: Don't sleep on business email compromise

The latest episode of Talos Takes is available now. Download this episode and subscribe to Talos Takes using the buttons below, or visit the Talos Takes page. Business email compromise may seem like last decade’s threat, but it’s still just as prevalent as ever. A recent FBI rep

July 22, 2021 14:00

Threat Source newsletter (July 22, 2021)

Good afternoon, Talos readers. I'm compiling this Tuesday for vacation reasons, so apologies for any major stories I'm missing here. This week's Beers with Talos podcast hits the seas again. And although we've covered sea shanties in the past, this week we'r

July 16, 2021 10:14

Talos Takes Ep: #61: SideCopy sounds so familiar, but I just can't put my finger on it...

The latest episode of Talos Takes is available now. Download this episode and subscribe to Talos Takes using the buttons below, or visit the Talos Takes page. Asheer Malhotra of Talos Outreach has spent the past few months tracking APTs all along the same line. APT 36, aka Trans