Welcome to this week’s edition of the Threat Source newsletter. 

My name is Pierre Cadieux, and I’ll be helping contribute to these newsletters. A little about me: I’ve been working in the cybersecurity industry in many roles over the past 20+ years, first focusing on endpoint security, policies, and firewalls, then moving to risk management and compliance, disaster recovery, and investigations. I spent about 15 years as a consultant working across many well-known consultancy firms and eventually moved to Cisco where I spent time doing security operations center (SOC) design and assessments as well as segmentation before moving to the Talos IR team. I spent many years there, first as an Incident Commander and then a manager of our excellent team of global IR consultants and investigators. My current role is with the Talos Threat Intelligence and Interdiction team, where I’m focused on intelligence efficacy — how we can do better with the data we have, how we can get more data, and what our customers want from our intelligence products. 

Since it’s Cybersecurity Awareness Month, I wanted to take a few minutes to collectively thank all of the defenders out there for the hard work you do each day. The work you do may not always be visible, but it matters.  

I remember one job I had many years ago when I was in charge of security for a financial institution. I spent time learning each of the business processes that we had so I could understand each of the moving parts, what was essential, and what was on the horizon for change. I even spent a couple days meeting with the folks who handled printing. Yeah, printing — but not reports or internal documents. These were the people that created the checks that our institution used to pay other institutions, and more importantly (to me) our customers. 

I recall there being many out-of-patch compliance boxes in this area of the company, so I, being the diligent Director, decided to find out why. It turns out the software being used to print these business essential checks would not run on the current operating systems, and the physical printer cards used to connect to these non-network printers also required older hardware ports. As one of the people I interviewed said, “We don’t want to be the reason someone’s grandma doesn’t get her check and can’t go to the grocery store.” 

There were (at the time) no other alternatives that we could deploy, and the environment had zero tolerance for downtime. The solution I proposed was to isolate these devices into their own network, which blocked access to and from the internet for these devices, and also reduced the likelihood that these devices would be identified during an adversary’s internal reconnaissance or mapping. It didn’t patch the vulnerable devices, but it went a long way to reducing the likelihood of a bad thing happening to these devices due to their out-of-date OS and software. 

This story is especially appropriate today, as we face ever-increasing numbers of vulnerabilities announced by software vendors, and can only expect this volume to continue to increase. Do what you can to make sure the checks still get printed, while managing your risks intentionally. 

The one big thing  

Cisco Talos is disclosing new findings from our CAIRN research that show malware authors are embedding natural-language instructions into their code to evade AI-assisted analysis. We classify this growing trend as "A3: AI-Analysis Evasion." Over the past 18 months, we've tracked techniques ranging from simple comments telling an AI to ignore a file, to advanced "template spraying" designed to trick specific large language models (LLMs).  

Why do I care? 

Attackers expect AI to be in your analysis pipeline, and they’re developing cheap methods to manipulate those systems. While we found these prompt-injection techniques only steer the AI's verdict in the attacker's favor about 35 percent of the time, they are being adopted across all levels of malware sophistication. A3 families like MANTLEMAZE also pair these AI deceptions with serious underlying threats, such as abusing vulnerable drivers to disable EDR from kernel space. 

So now what? 

Because these evasion instructions must be written in plaintext, defenders have a highly stable detection surface to monitor. Security teams should flag imperative language addressed to analysis systems within binaries as a suspicious signal. Most importantly, anyone building or using AI-assisted pipelines must ensure that text extracted from a sample is strictly treated as evidence, never as a system directive. Read the full blog for more information on these techniques and a list of sample hashes. 

Top security headlines of the week 

Citrix NetScaler security snafus get even worse amid more zero-day reports 
This latest vulnerability, tracked as CVE-2026-88779, is a memory overflow bug that leads to denial of service attacks. (The Register) 

Hackers steal 8 million citizens’ records from Danish government database 
The Danish government would not say who is behind the breach, which happened in September but was discovered on October 2. However, it said the unauthorized access was obtained by “abusing a Danish company’s lawful access to search for information in the CPR system.” (TechCrunch) 

Google narrows open-source bug bounty amid wave of invalid automated reports 
Google has temporarily closed its Open Source Software Vulnerability Reward Program (OSS VRP) to product vulnerability submissions. According to Google, it has no impact on the program’s supply chain reports or on any pending reports. (SecurityWeek) 

Warlock ransomware hits large Spanish, Portuguese orgs 
In the last two months, researchers observed Warlock attacks against four victims: a water utility, a telecommunications provider, a regional government body, and a university. (Dark Reading) 

U.S. Senate passes health care cybersecurity bill after 190 million impacted by Change Healthcare breach 
The Health Care Cybersecurity and Resiliency Act of 2026 was passed by unanimous consent last week, potentially expanding federal cyber requirements for health care organizations. (The Record) 

Can’t get enough Talos? 

One breach, please, and make no mistakes 
The cybersecurity community has seen examples of autonomous agents, built inside AI labs, attacking public infrastructure. How you prepare for agentic threats is what makes the difference during real incidents. 

Talos Takes: Honey, I Trapped the Adversary 
It’s time to start having fun and messing with your attackers. For Cybersecurity Awareness Month, Martin Lee joins Amy to discuss the fine art of making life on your network a complete nightmare for adversaries. 

The Fine Art of Frustrating the Adversary 
What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier, from deception and behavioral detection to breaking attack dependencies. 

Upcoming events where you can find Talos 

Most prevalent malware files from Talos telemetry over the past week  

SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 
MD5: 2915b3f8b703eb744fc54c81f4a9c67f 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 
Example Filename: sample.exe 
Detection Name: W32.9F1F11A708-100.SBX.TG 

SHA256: fed979f93bcaf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f 
MD5: 207d9d891ac756b2bfad88aba5682c65 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=fed979f93bcaf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f 
Example Filename: sample.exe 
Detection Name: W32.FED979F93B-95.SBX.TG 

SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
MD5: 38de5b216c33833af710e88f7f64fc98 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
Example Filename: SECOH-QAD.exe 
Detection Name: W32.9896A6FCB9-95.SBX.TG 

SHA256: 73ac1bbfaee6c76c34f655ac0477a4cd930f2aa55e658c8e312ff81aac9a741f 
MD5: 63f3351cfdf618bec6045f60203e7978 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=73ac1bbfaee6c76c34f655ac0477a4cd930f2aa55e658c8e312ff81aac9a741f 
Example Filename: f_003914.exe 
Detection Name: W32.PUP:PulseBrowser.29kh.in12.Talos 

SHA256: 58d6fec4ba24c32d38c9a0c7c39df3cb0e91f500b323e841121d703c7b718681 
MD5: f1fe671bcefd4630e5ed8b87c9283534 
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=58d6fec4ba24c32d38c9a0c7c39df3cb0e91f500b323e841121d703c7b718681 
Example Filename: KMSAuto Net.exe 
Detection Name: W32.58D6FEC4BA-95.SBX.TG