Skip to content

lab

Cisco Talos

Cisco Talos is Cisco's threat intelligence unit, researching malware, vulnerabilities, and nation-state and criminal cyber activity.

Known aliases

  • blog.talosintelligence.com
  • Cisco Talos Intelligence Group
  • Cisco Talos Threat Intelligence
  • Talos
  • Talos Intelligence
  • Talos Threat Intelligence

Relationships

No evidence-backed relationships are recorded.

Current stories

security3 publishers

China-nexus UAT-11587 runs its Antino backdoor through Outlook and OneDrive

Cisco Talos links China-nexus UAT-11587 to 16 affected or targeted institutions in eight Asian countries, via a backdoor run through Microsoft 365. Its commands move through Outlook and OneDrive via Microsoft Graph, so defenders have no command server to block.

Perspective Coverage

3 publishers
Builder
Builder 32%
Operator
Operator 63%
Investor
Investor 5%

Reality

Evidence62
Adoption30
Hype gap+8
Incentives
Insufficient
Confidence65
build1 publisher

Qilin ransomware affiliate logged into Cisco firewall management with a credential scored 5.3

Cisco Talos says three threat clusters are exploiting a CVSS 10.0 pre-auth root bypass and a 5.3 hard-coded credential in Secure Firewall Management Center. A patch policy with a severity cutoff above 5.3 would have skipped the credential fix on the console that pushes policy to every managed firewall.

Publishers:dev.to

Reality

Evidence58
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence55
security7 publishers

CLOSEDQUORUM puts its next action to a vote of four commercial LLM providers

Cisco Talos found a 16.4MB Go implant that asks DeepSeek, Qwen, Mistral and Gemini what to do next and acts on the winning vote, treating the providers themselves as its C2 infrastructure. Talos has no confirmation it was ever deployed.

Perspective Coverage

7 publishers
Builder
Builder 28%
Operator
Operator 66%
Investor
Investor 6%

Reality

Evidence58
Adoption
Insufficient
Hype gap+30
Incentives45
Confidence62
security6 publishers

Cisco's own July 23 log indicator predates its August date for FMC exploitation

CVE-2026-20079 hands unauthenticated attackers root on Secure Firewall Management Center. CISA wants federal boxes fixed by September 12. The hot fix closes the path but does not evict anyone who already walked it.

Perspective Coverage

6 publishers
Builder
Builder 23%
Operator
Operator 65%
Investor
Investor 12%

Reality

Evidence80
Adoption
Insufficient
Hype gap+15
Incentives60
Confidence74
security1 publisher

Salt Typhoon logged into telecom network gear with stolen credentials in all but one case Talos examined

Salt Typhoon used legitimate stolen credentials to reach Cisco devices in every telecom intrusion Cisco Talos investigated but one. It then pulled more logins from weakly encrypted router configs and captured TACACS and RADIUS keys, so credentials stored on network gear are the first exposure for defenders to close.

Reality

Evidence62
Adoption
Insufficient
Hype gap−5
Incentives55
Confidence60

Earlier coverage

  1. Talos argues defenders are already behind the models they have

    Security · September 17, 2026 · 1 publisher

  2. Talos puts 78% of Japan's ransomware victims under JPY 1 billion in capital

    Security · September 17, 2026 · 1 publisher

  3. Talos wants exploit filtering upstream of OT that certification has frozen

    Security · September 16, 2026 · 1 publisher

  4. A process created at boot lets one HTTP request take root on Cisco's firewall console

    Build · September 14, 2026 · 1 publisher

  5. Talos splits security burnout into four injuries with four different fixes

    Security · September 10, 2026 · 1 publisher

  6. Talos ties a fake Google CAPTCHA to a DLL executing from a remote WebDAV share

    Security · September 8, 2026 · 1 publisher

  7. Talos found ClickFix operators moving their skimmer into a Tampermonkey userscript

    Product · September 8, 2026 · 1 publisher

  8. ClickFix crews shift paste target to Chrome address bar or Tampermonkey

    Security · September 8, 2026 · 1 publisher

  9. Higher reasoning settings produced blocked responses in Talos's 66-combination model test

    Security · August 27, 2026 · 1 publisher

  10. Seven RAT families, one actor: what SilkParasite does to behavioural clustering

    Security · August 27, 2026 · 2 publishers

  11. Talos: obfuscated JavaScript is phishing kit plumbing, and beautifiers will not read it for you

    Security · August 27, 2026 · 1 publisher

  12. Talos ran 66 model settings at one log-review task and refused to name a winner

    Security · August 26, 2026 · 1 publisher

  13. Count the refusals: Talos turns model guardrails into a procurement number

    Security · August 25, 2026 · 1 publisher

  14. Talos puts a name to the AI retry loop: UAT-10147 fixes its own failed exploits

    Build · August 20, 2026 · 1 publisher

  15. Talos finds a commodity crew running agentic AI, and a target list of 170,000 URLs

    Security · August 20, 2026 · 1 publisher

  16. An SEO fraud crew is now shipping kernel rootkits and BYOVD, and that is the story

    Security · August 20, 2026 · 1 publisher

  17. Talos tells the story instead of the matrix, and BEC's new economics fall out

    Security · August 20, 2026 · 1 publisher