Cisco Talos Intelligence Group
@talosintelligence
Cisco Talos defends Cisco customers with trusted global cybersecurity intelligence. Support requests:
Protect your development environment from rising Python supply-chain threats by understanding the package installation lifecycle and implementing these essential defensive strategies: cs.co/63323BEnJc1
NEW VIDEO: In an era of AI-powered threats, having the right intelligence is more critical than ever. See how Cisco Talos Intelligence Integrations identify and block malicious activity across Cisco's security and enterprise technologies: cs.co/63328BEnKPw
🎙️ Podcast listener question time! In our last episode of Beers with Talos, we tackled a listener question about the potential security challenges of data centers in space. We're recording again this week, and we'd love another question to discuss. What would you like to ask the team?
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, 14 in GeoVision, and one vulnerability in VTK-DICOM: cs.co/63322BEMdja
Hazel is here to remind you that in cybersecurity — just like at Wimbledon — you don’t need to be perfect to win the match: cs.co/63326BEHeHp
What does it take to turn threat intelligence into proactive protection? We're taking you behind the scenes with the Talos team. Coming soon.
From space data centers to the great U.S.A. vs. U.K. snack war, join the Beers with Talos team for a deep dive into Living Off Trusted Services: cs.co/63325BEEDGF
Windows COM is a playground for threat actors, but it doesn't have to be a mystery. Join us on the latest Talos Takes to learn how to spot malicious activity and sharpen your analysis skills: cs.co/63320BDm4is
Talos has identified "ARToken," a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoint exfiltration. cs.co/63323BDLHQN
Want a long career in cybersecurity? In this episode, Martin Lee shares why you should “flavor your life with many spices” both in the office… and possibly the Arctic? cs.co/63323BDm2EP
Malware authors often hide their tracks using COM, but our latest guide provides the roadmap you need to decode those cryptic vtable calls and finally see exactly what’s happening under the hood: cs.co/63323BDgbFS
We’re tackling the AI-driven vulnerability arms race, the deluge of junk bug reports, and the high-stakes debate over whether we can resist Rickrolling the entire planet on this week’s Beers with Talos: cs.co/63324BDdTDe
5. Balance your investment across people, processes, and tech.
3. Implement strict change control governance.
2. Treat patching as a process, not just a click.
Missed the latest Talos Takes? Catch Pierre’s top asset management and patching tips below, and tune in for more information on how to sharpen your response strategy and stay ahead of unknown threats: www.buzzsprout.com/2018149/epis...
Talos' latest blog demonstrates how exposing internal object models allows you to turn static analysis tools into queryable data servers, empowering AI agents to automate complex reverse-engineering tasks locally and securely: cs.co/63325BDMmcR
Don't let the unknown catch you off guard. In the latest Talos Takes episode, Pierre explains why patching is a critical, process-driven journey rather than just a one-click fix: cs.co/63326BDMKs0
Time sensitive request! We’re recording a new Beers with Talos later today, and we’d like to open the show with a listener question. Comment below! It could be about cybersecurity, threat research, the industry, life at Talos, movies, terrible decisions…. Sky's the limit!
In a post-Mythos era where AI discovers zero-days in minutes, your strongest defense isn't a new tool. Instead, master the security fundamentals you’ve been overlooking: cs.co/63322B8NJ5C
🚨 We’ve expanded the Cisco Talos Threat Hunting service to proactively uncover the sophisticated threats hiding in your telemetry, combining AI-driven scale with human expertise: cs.co/63325B8WrQZ
DICOM is a critical, complicated, and surprisingly vulnerable file format. See how Talos created a heap overflow vulnerability through exploiting DICOM in our latest white paper: cs.co/63329B8Xp6z
People told William to stay in his lane, so he built a new road that led to Talos. Now, he discusses why being kind but "ungovernable" is the secret to a successful career in cybersecurity: cs.co/63322B869oG
Responding to a state-sponsored attack is much different than responding to ransomware. These are the things your organization needs to have in place before, during, and after an intrusion: cs.co/63322BBsnUg
There’s still time to register for Tales from the Frontlines on Wednesday, May 13. This exclusive briefing goes behind-the-scenes of the most critical incidents we responded to last quarter: cs.co/IRTales-2026...
Attackers are recycling phone numbers used in scam emails like they’re going out of style. Learn how Talos is turning those digits into a roadmap to expose the hidden infrastructure: cs.co/63329BBdoJU
Cisco Talos discovered an intrusion where an unknown attacker implanted a CloudZ RAT and a plugin called Pheno to steal victims’ credentials and potentially one-time passwords: cs.co/63324BBw4Ns
Join Talos IR next week for an exclusive look at last quarter's cyber attacks. Our incident responders are skipping the standard report walkthrough to share the behind-the-scenes details you won't find anywhere else: cs.co/IRTales-2026...
CVE 2026-000-25 (aka William Largent) has had 25 years of uninterrupted persistence with Cisco! Hazel, Dave, and Joe celebrate Bill’s years of service with a good, old-fashioned roast: cs.co/63320BBuhgw