Blog
Recent
July 31, 2015 07:01

Your Files Are Encrypted with a "Windows 10 Upgrade"

This post was authored by Nick Biasini with contributions from Craig Williams & Alex Chiu Update 8/1: To see a video of this threat in action click here Adversaries are always trying to take advantage of current events to lure users into executing their malicious payload. T

July 17, 2015 06:13

Vulnerability Spotlight: Total Commander FileInfo Plugin Denial of Service

Talos is releasing an advisory for multiple vulnerabilities that have been found within the Total Commander FileInfo Plugin. These vulnerabilities are local denial of service flaws and have been assigned CVE-2015-2869. In accordance with our Vendor Vulnerability Reporting and Dis

July 14, 2015 07:40

Microsoft Patch Tuesday – July 2015

Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release sees a total of 14 bulletins being released which address 57 CVEs. Four of the bulletins are listed as Critical and addre

July 8, 2015 06:49

Ding! Your RAT has been delivered

This post was authored by Nick Biasini Talos is constantly observing malicious spam campaigns delivering various different types of payloads. Common payloads include things like Dridex, Upatre, and various versions of Ransomware. One less common payload that Talos analyzes perio

June 30, 2015 06:32

Vulnerability Spotlight: Apple Quicktime Corrupt stbl Atom Remote CodeExecution

This post was authored by Rich Johnson, William Largent, and Ryan Pentney. Earl Carter contributed to this post. Cisco Talos, in conjunction with Apple’s security advisory issued on June 30th,  is disclosing the discovery of a remote code execution vulnerability within Apple Qui

June 24, 2015 07:46

Hook, Line & Sinker: Catching Unsuspecting Users Off Guard

This post was authored by Earl Carter. Attackers are constantly looking for ways to monetize their malicious activity. In many instances this involves targeting user data and accounts. Talos continues to see phishing attacks targeting customers of multiple high profile financial

June 16, 2015 05:57

Domain Shadowing Goes Nuclear: A Story in Failed Sophistication

This post was authored by Nick Biasini Exploit Kits are constantly altering their techniques to compromise additional users while also evading detection. Talos sees various campaigns start and stop for different exploit kits all the time. Lately a lot of focus has been put on An

June 9, 2015 06:49

Microsoft Patch Tuesday - June 2015

Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release sees a total of 8 bulletins being released which address 45 CVE. Two of the bulletins are listed as Critical and address

June 5, 2015 06:00

My Resume Protects All Your Files

This post was authored by Nick Biasini Talos has found a new spam campaign that is using multiple layers of obfuscation to attempt to evade detection.  spammers are always evolving to get their messages to the end users by bypassing spam filters while still appearing convincing