Avatar

Talos Group

Talos Security Intelligence & Research Group

The Talos Security Intelligence and Research Group (Talos) is made up of leading threat researchers supported by sophisticated systems to create threat intelligence for Cisco products that detects, analyzes and protects against both known and emerging threats. Talos maintains the official rule sets of Snort.org, ClamAV, SenderBase.org and SpamCop. This blog profile is managed by multiple authors with expertise that spans software development, reverse engineering, vulnerability triage, malware investigation and intelligence gathering.

Talos is the primary team that contributes threat information to the Cisco Collective Security Intelligence (CSI) ecosystem. Cisco CSI is shared across multiple security solutions and provides industry-leading security protections and efficacy. In addition to threat researchers, CSI is driven by intelligence infrastructure, product and service telemetry, public and private feeds and the open source community.

Articles

July 12, 2019

THREAT RESEARCH

Threat Roundup for July 5 to July 12

1 min read

Today, Talos is publishing a glimpse into the most prevalent threats we've observed between July 5 and July 12. As...

July 11, 2019

THREAT RESEARCH

Should governments pay extortion payments after a ransomware attack?

1 min read

When it comes to ransomware attacks this year, it’s been a tale of three cities. In May, the city of Baltimore suffered a massive ransomware attack that took many of its...

July 9, 2019

THREAT RESEARCH

Sea Turtle Keeps on Swimming

1 min read

By Danny Adamitis with contributions from Paul Rascagneres. Executive summary After several months of activity, the actors behind the "Sea Turtle" DNS hijacking campaign are not slowing down. Cisco Talos recently discovered...

July 5, 2019

THREAT RESEARCH

Threat Roundup for June 28 to July 5

1 min read

Today, Talos is publishing a glimpse into the most prevalent threats we've observed between June 28 and July 5. As...

July 1, 2019

THREAT RESEARCH

RATs and stealers rush through “Heaven’s Gate” with new loader

1 min read

Malware is constantly finding new ways to avoid detection. This doesn't mean that some will never be detected, but it does allow adversaries to increase the period of time between...

July 2, 2019

THREAT RESEARCH

Vulnerability Spotlight: Remote code execution vulnerabilities in Simple DirectMedia Layer

1 min read

Simple DirectMedia Layer contains two vulnerabilities that could an attacker to remotely execute code on the victim’s machine. Both bugs are present in the SDL2_image library, which is used for...

June 28, 2019

THREAT RESEARCH

Threat Roundup for June 21 to June 28

1 min read

Today, Talos is publishing a glimpse into the most prevalent threats we've observed between June 21 and June 28. As...

June 27, 2019

THREAT RESEARCH

Welcome Spelevo: New exploit kit full of old tricks

1 min read

Nick Biasini authored this post with contributions from Caitlyn Hammond....

June 21, 2019

THREAT RESEARCH

Threat Roundup for June 14 to June 21

1 min read

Today, Talos is publishing a glimpse into the most prevalent threats we've observed between June 14 and June 21. As with previous roundups, this post isn't meant to be an...