Avatar

Talos Group

Talos Security Intelligence & Research Group

The Talos Security Intelligence and Research Group (Talos) is made up of leading threat researchers supported by sophisticated systems to create threat intelligence for Cisco products that detects, analyzes and protects against both known and emerging threats. Talos maintains the official rule sets of Snort.org, ClamAV, SenderBase.org and SpamCop. This blog profile is managed by multiple authors with expertise that spans software development, reverse engineering, vulnerability triage, malware investigation and intelligence gathering.

Talos is the primary team that contributes threat information to the Cisco Collective Security Intelligence (CSI) ecosystem. Cisco CSI is shared across multiple security solutions and provides industry-leading security protections and efficacy. In addition to threat researchers, CSI is driven by intelligence infrastructure, product and service telemetry, public and private feeds and the open source community.

Articles

June 14, 2019

THREAT RESEARCH

Threat Roundup for June 7 to June 14

1 min read

Talos publishes a glimpse into the most prevalent threats observed between May 31 and June 7.

June 10, 2019

THREAT RESEARCH

The sights and sounds from the Talos Threat Research Summit

1 min read

More than 250 threat hunters, network defenders and analysts gathered ahead of Cisco Live for the second annual Talos Threat Research Summit on Sunday. The conference by defenders, for defenders,...

June 7, 2019

THREAT RESEARCH

Threat Roundup for May 31 to June 7

1 min read

Today, Talos is publishing a glimpse into the most prevalent threats we've observed between May 31 and June 7. As...

June 4, 2019

THREAT RESEARCH

It’s alive: Threat actors cobble together open-source pieces into monstrous Frankenstein campaign

1 min read

This blog was authored by Danny Adamitis, David Maynor and Kendall McKay. Executive summary Cisco Talos recently identified...

May 31, 2019

THREAT RESEARCH

Using Firepower to defend against encrypted RDP attacks like BlueKeep

1 min read

This blog authored by Brandon Stultz Microsoft recently released fixes for a critical pre-authentication remote code execution vulnerability...

May 31, 2019

THREAT RESEARCH

Threat Roundup for May 24 to May 31

1 min read

Today, Talos is publishing a glimpse into the most prevalent threats we've observed between May 17 and May 24. As...

May 30, 2019

THREAT RESEARCH

10 years of virtual dynamite: A high-level retrospective of ATM malware

1 min read

It has been 10 years since the discovery of Skimer, first malware specifically designed to attack automated teller machines (ATMs). At the time, the learning curve for understanding its functionality...

May 24, 2019

THREAT RESEARCH

Threat Roundup for May 17 to May 24

1 min read

Today, Talos is publishing a glimpse into the most prevalent threats we've observed between May 17 and May 24. As...

May 23, 2019

THREAT RESEARCH

One year later: The VPNFilter catastrophe that wasn’t

1 min read

One year ago, Cisco Talos first disclosed the existence of VPNFilter on May 23, 2018. The malware made headlines across the globe, as it was a sophisticated piece of malware...