Blog
Recent
October 26, 2017 10:26

Vulnerability Spotlight: Apache OpenOffice Vulnerabilities

Discovered by Marcin ‘Icewall’ Noga of Cisco Talos Overview Today, Talos is releasing details of three new vulnerabilities discovered within Apache OpenOffice application. The first vulnerability, TALOS-2017-0295 within OpenOffice Writer, the second TALOS-2017-0300 in the Draw

October 24, 2017 16:51

Threat Spotlight: Follow the Bad Rabbit

Note: This blog post discusses active research by Talos into a new threat. This information should be considered preliminary and will be updated as research continues. Update 2017-10-26 16:10 EDT: added additional information regarding the links between Nyetya and BadRabbit Upd

October 22, 2017 12:22

“Cyber Conflict” Decoy Document Used In Real Cyber Conflict

Update 10/23: CCDCOE released a statement today on their website Introduction Cisco Talos discovered a new malicious campaign from the well known actor Group 74 (aka Tsar Team, Sofacy, APT28, Fancy Bear…). Ironically the decoy document is a deceptive flyer relating to the Cyb

October 19, 2017 16:51

Vulnerability Spotlight: Google PDFium Tiff Code Execution

Overview Talos is disclosing a single off-by-one read/write vulnerability found in the TIFF image decoder functionality of PDFium as used in Google Chrome up to and including version 60.0.3112.101. Google Chrome is the most widely used web browser today and a specially crafted P

October 18, 2017 06:30

Beers with Talos EP 15: Landing a Job, Phishing Midstream, and Paul’s IDA Palette

Beers with Talos (BWT) Podcast Episode 15 is now available.  Download this episode and subscribe to Beers with Talos: If iTunes and Google Play aren't your thing: www.talosintelligence.com/podcast EP15 Show Notes: In this EP, we take on interviewing and finding a job wi

October 13, 2017 15:01

Threat Round Up for Oct 6 - Oct 13

Today, Talos is publishing a glimpse into the most prevalent threats we've observed between October 6 and October 13. As with previous round-ups, this post isn't meant to be an in-depth analysis. Instead, this post will summarize the threats we've observed by highligh

October 12, 2017 07:26

Disassembler and Runtime Analysis

This post was authored by Paul Rascagneres. Introduction In the CCleaner 64bit stage 2 previously described in our blog, we explained that the attacker modified a legitimate executable that is part of "Symantec Endpoint". This file is named EFACli64.dll. The modificat

October 11, 2017 12:11

Spoofed SEC Emails Distribute Evolved DNSMessenger

This post was authored by Edmund Brumaghin, Colin Grady, with contributions from Dave Maynor and @Simpo13. Executive Summary Cisco Talos previously published research into a targeted attack that leveraged an interesting infection process using DNS TXT records to create a bidir

October 10, 2017 16:25

Microsoft Patch Tuesday - October 2017

Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 63 new vulnerabilities with 28 of them rated critical and 35 rated important. These vulnerabi