Blog
Recent
October 6, 2020 12:07

90 days, 16 bugs, and an Azure Sphere Challenge

Cisco Talos reports 16 vulnerabilities in Microsoft Azure Sphere's sponsored research challenge. By Claudio Bozzato, Lilith [-_-]; and Dave McDaniel. On May 15, 2020, Microsoft kicked off the Azure Sphere Security Research Challenge, a three-month initiative aimed at fi

October 6, 2020 10:52

PoetRAT: Malware targeting public and private sector in Azerbaijan evolves

By Warren Mercer, Paul Rascagneres and Vitor Ventura. * The Azerbaijan public sector and other important organizations are still targeted by new versions of PoetRAT. * This actor leverages malicious Microsoft Word documents alleged to be from the Azerbaijan government. * The

October 2, 2020 19:13

Threat Roundup for September 25 to October 2

Today, Talos is publishing a glimpse into the most prevalent threats we've observed between Sept. 25 and Oct. 2. As with previous roundups, this post isn't meant to be an in-depth analysis. Instead, this post will summarize the threats we've observed by highlighting k

October 1, 2020 17:04

Beers with Talos Ep. #93: “More Secure” myths and misconceptions

Beers with Talos (BWT) Podcast episode No. 93 is now available. Download this episode and subscribe to Beers with Talos: If iTunes and Google Play aren't your thing, click here. By Mitch Neff. Recorded Sept. 11, 2020 On today’s show, we take several of the larger security

October 1, 2020 14:00

Threat Source newsletter for Oct. 1, 2020

Newsletter compiled by Jon Munshaw. Good afternoon, Talos readers. In the past, we’ve covered what disinformation (otherwise known as “fake news”) is and who spreads it. Now, we’re diving into why it works, and why it’s so easy for people to spread. Check out our full paper her

October 1, 2020 09:00

What to expect when you're electing: Information hygiene and the human levers of disinformation

Editor's note: Related reading on Talos election security research: /what-to-expect-when-youre-electing /election-roundtable-video /what-to-expect-electing-disinformation-building-blocks By Azim Khodjibaev and Ryan Pentney. As Cisco Talos researchers outlined in a paper

September 30, 2020 15:37

Vulnerability Spotlight: Remote code execution bugs in NVIDIA D3D10 driver

Piotr Bania of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw. Cisco Talos recently discovered multiple remote code execution vulnerabilities in the NVIDIA D3D10 driver. This driver supports multiple GPUs that NVIDIA produces. An adversary could exploit these vul

September 29, 2020 12:41

LodaRAT Update: Alive and Well

* During our continuous monitoring of LodaRAT, Cisco Talos observed changes in the threat that add new functionality. * Multiple new versions of LodaRAT have been spotted being used in the wild. * These new versions of LodaRAT abandoned their previous obfuscation techniques.

September 28, 2020 19:19

Microsoft Netlogon exploitation continues to rise

Cisco Talos is tracking a spike in exploitation attempts against the Microsoft vulnerability CVE-2020-1472, an elevation of privilege bug in Netlogon, outlined in the August Microsoft Patch Tuesday report. The vulnerability stems from a flaw in a cryptographic authentication sche