Search
Find merged stories by title or summary.
Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Mapping the malware blast radius a single alert won’t show you In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works outward to map how far a malware campaign spread. He walks through the research behind the claim that each published sample hides an … More → The post Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026 appeared first on Help Net Security .
[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents
Have you ever read the Talos IR Quarterly Trends report and wondered, “How did that phishing or ransomware campaign actually play out? When was Talos IR contacted, how did they contain it, and how did they remediate the environment?" You’re in luck. Next Tuesday, August 11, Cisco Talos Incident Responders will be hosting an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents our customers faced in Q2 2026. This isn’t a rehashing of the report itself, but a candid discussion of what happened, how we handled it, and what it means for your organization. The session is designed for security professionals of all levels, from analysts and incident responders to managers and senior leaders. We'll focus on strategic takeaways and business impact, with just enough technical depth to provide context and spark meaningful conversations.
Black Hat special: Rewind and revisit
Cybersecurity is rarely a straight line. In this special Black Hat edition of Humans of Talos, Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence. From forensic labs and newsrooms to the kitchen line, we’re revisiting the stories and lessons that define the people behind the threat intelligence. Heading to Black Hat? We have a presence within the Cisco and Splunk booth (2633) during Black Hat where you can chat to us about our latest threat research and incident response, and grab the newest Snorty. Check out our schedule here . Want more episodes? Watch the full episode , and don’t forget to subscribe to our YouTube channel for the next Humans of Talos.
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.
CVE-2026-20316 - Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
Phishing was the primary means of gaining initial access this quarter, appearing in over half of all Cisco Talos Incident Response (Talos IR) engagements – an increase from approximately a third of engagements last quarter. Attackers continued to innovate their delivery methods to evade defenses, deploying QR code-embedded PDFs to bypass traditional email gateways and hosting links on trusted cloud platforms. We also saw a spike in authentication abuse this quarter — observed in 65 percent of engagements compared to 35 percent last quarter — with attackers frequently bypassing or defeating multi-factor authentication (MFA) using adversary-in-the-middle (AitM) proxies, session-token theft, MFA fatigue attacks, and self-enrolled devices, amongst other methods. Ransomware incidents made up over 20 percent of engagements this quarter, similar to just under 20 percent last quarter.
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
• Cisco Talos has discovered a new Rust-based remote access trojan (RAT) we call “msaRAT” attributed to the Chaos ransomware group. The name is derived from the binding names found in the binary: “msaOpen,” “msaClose,” “msaError,” and “msaMessage”. • msaRAT is implemented using the Tokio asynchronous runtime, with primary capabilities of browser-leveraged remote code execution and covert tunneling to establish command-and-control (C2) communications. • This RAT never touches the network directly — it controls its C2 communication channel exclusively through Chrome DevTools Protocol (CDP), a browser debugging API. The binary contains a Cloudflare Workers endpoint, but it never makes HTTP connections to that domain itself; it offloads that work entirely to the browser.
Preview: Cisco Talos at Black Hat USA 2026
We’re looking forward to having some great conversations with those of you heading to the desert for Hacker Summer Camp 2026. We have a presence within the Cisco and Splunk booth (2633) during Black Hat where you can chat to us about our latest threat research, incident response, and how Talos powers the Cisco portfolio with our intelligence. Or, feel free to pretend to want to talk to us about those things while grabbing a new multicolored Snorty. That’s fine, too. Here’s some of the ways we’ll be showing up at Black Hat, alongside our friends at Cisco and Splunk: Meet the researchers: Booth lightning talks Our Talosians have spent a lot of time over the last few months putting together some truly... well, enlightening lightning talks.
[tl;dr sec] #337 - Harnessing Harnesses, Generate Decoy Environments, Bug Bounty Singularity
Hey there, I hope you’ve been doing well! 🍬 Grandma Seems Chill In the San Francisco Bay Area, basically every billboard is about AI or tech. But when I was traveling recently, I saw a “Gummies for Granny” billboard that brightened my day: I imagined the meeting where the marketing leads were reviewing different framings for their products, and the right target demographic, and this is what they came up with 😂 I wonder if they have other brands or stores. Mushrooms for Mommy? Doobies for Daddies? A Little Ket for the Family Pet? Working in marketing must be delightful sometimes.
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
• Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025. • Talos has discovered that the actor in this campaign delivers a Python-based remote access tool (RAT) that we track as “Starland RAT” and a command-and-control (C2) memory implant known as the “WLDR agent.” • The WLDR agent is a sophisticated PowerShell-based C2 memory implant that features encrypted beaconing, task queuing, and a Runspace execution engine for executing additional payloads. • UAT-11795 also has CastleStealer and Remcos RAT as alternative payload implants in their arsenal.
[Video] Where protection starts: Cisco Talos Intelligence Integrations
Cybersecurity has always involved elements of uncertainty. Every day, security teams are asked to make decisions with incomplete information, while attackers rely on defenders not being able to see the full picture. What defenders haven't always had to deal with is attackers using AI to rewrite malicious commands on the fly, malware that adapts its code upon every installation, and models that can search through decades of vulnerable code and exposed interfaces to uncover new opportunities for exploitation. While none of that changes the fundamental purpose of cybersecurity — to understand and act on what's happening in your environment — it does make that picture harder and harder to build. Is a newly registered domain part of an attack? Is that outbound connection normal? Is that user behavior unusual? Cisco Talos Intelligence Integrations helps answer those questions.
[tl;dr sec] #336 - Autonomous Vulnerability Hunting, GuardDog 3.0, Are Bug Bounties Cooked?
Hey there, I hope you’ve been doing well! 🎆 Amurrica Day I love how peak America the 4th of July is, with tons of outdoor grilling, people wearing red, white, and blue, and of course fireworks. In some circles, it’s not cool to be patriotic right now. While we have and will continue to make mistakes as a country, I think we can still be proud of the good parts, while striving to do better. I think everyone should be proud of where they came from, and what makes that place unique. This year I watched the Pier 39 fireworks from a nearby rooftop while a DJ blasted Katy Perry’s song Firework (not the Moulin Rouge musical version). Watching fireworks in San Francisco is often a futile endeavor, given the high likelihood that what you actually get to see is some slight glimmers in the ever present fog. Still, it was fun.
Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager
Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability ( CVE-2026-20245 ) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access. The vulnerability stems from the device’s file upload feature lacking the ability to properly filter malicious data. Throughout the intrusion, to maintain operational security and avoid detection, the threat actor consistently employed anti-forensic techniques, selectively deleting and restoring system configuration files that were modified during their activities.
CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild
CVE-2026-20127 is an improper authentication vulnerability impacting Cisco Catalyst SD-WAN Controller, formerly vSmart, and SD-WAN Manager, formerly vManage, components.
Issue 276: API discovery hype, BOLA at McDonalds, Cisco APIs exploited, input validation best practices
This week, we’re sharing two articles focused on input validation best practices, exploring how weak validation can leave APIs exposed. We also take a closer look at some recent claims about API discovery that risk distracting from real security issues, plus a review of recent API security incidents reported at McDonald’s and Cisco. Article: How Discovery Hype Is Undermining API Security An article on API sprawl highlights real risks that emerge when API governance policies aren’t enforced. But a misleading claim about “discovery” really stands out: “API security is never the problem, it is always the discovery. Once you’ve discovered it, you’ll fix it.” If only that were true. Unfortunately, decades of experience prove the opposite. In reality, most API breaches involve known APIs that were simply not properly secured.
Issue 272: Volkswagen API hacked, API flaws in Instagram & Tiktok, ELi attacks, Radware & Cisco API vulnerabilities
This week, we’re sharing five API vulnerability incidents that provide valuable insights into how APIs are commonly hacked and how to prevent these same vulnerabilities in your APIs. These incidents include the exposure of vehicle owner data from Volkswagen’s mobile app, enumeration vulnerabilities in Instagram and Tiktok APIs, an in-depth look at expression language injection attacks, and cases of API vulnerabilities in Radware and Cisco platforms. Vulnerability: Volkswagen Authentication API Exposes OTP A security researcher successfully hacked Volkswagen’s mobile app by launching a brute-force attack on an API used to validate a one-time password (OTP).
Issue 256: Privilege escalation bugs in Kia vehicles, Cisco and Gov APIs, NIST’s new rules for password security
This week, we review three different cases of API authorization and privilege escalation vulnerabilities, each of which is a wake-up call for API teams. We examine NIST updates on password security guidelines and share findings from an industry survey on API security and an upcoming OWASP API Top 10 webinar. Also this week we celebrate APISecurity. io’s 6th anniversary! Since publishing Issue #1 on October 11, 2018, the newsletter has become a trusted resource for staying up-to-date on the latest threats, best practices, innovations, and solutions in the API security space. Thank you to all subscribers for your continued feedback and support as we work to provide timely and valuable content to drive the conversation around API security. Industry News: NIST updates the rules for password security In the latest revision of Special Publication 800-63 Digital Identity Guidelines , the U.
Issue 253: Breached companies face litigation, SQL injection in Cisco APIs, API Security for Automotive & Finance
This week, we look at the growing number of penalties that companies can now face in the event of a data breach. We also learn about critical API vulnerabilities discovered in Cisco and Traccar products. VicOne recently published a white paper on automotive API security, and we also want to highlight a LinkedIn post on the crucial role of APIs in the financial sector. Article: Costly Breaches at National Public Data and T-Mobile National Public Data (NPD) in the US has been in the news recently due to a massive data breach. A report by BiometricUpdate. com indicates a breach that includes 272 million Social Security numbers. While the cause of the breach remains unclear, a recent update from KrebsOnSecurity suggests that a sister site to NPD may have accidentally published its own site passwords in a publicly accessible file.
