Articles
Adwind Dodges AV via DDE
1 min read
his blog post is authored by Paul Rascagneres, Vitor Ventura and with the contribution of Tomislav Pericin from ReversingLabs. Introduction Cisco Talos, along with fellow cybersecurity firm ReversingLabs, recently discovered...
Cyber Threat Alliance Releases Cryptomining Whitepaper
1 min read
Despite the recent devaluation of some cryptocurrencies, illicit cryptocurrency miners remain a lucrative and widespread attack vector in the threat landscape. These miners are easy to deploy, and attackers see...
GPlayed trojan – .Net playing with Google Market
1 min read
Cisco Talos has identified the latest attempt to penetrate mobile devices — a new Android trojan that we have dubbed "GPlayed."
Threat Roundup for September 7 to September 14
1 min read
Today, Talos is publishing a glimpse into the most prevalent threats we've observed between September 7 and September 14. As with previous round-ups, this post isn't meant to be an...
SigAnalyzer: Signature analysis with CASC
1 min read
ClamAV Signature Creator (CASC) is an IDA Pro plugin that assists in the creation of ClamAV pattern signatures. We have enhanced this plugin to also analyze these signatures. The plugin highlights matching parts in a binary when its given a particular signature.
Microsoft Patch Tuesday – September 2018
1 min read
Microsoft released its monthly set of security updates today for a variety of its products that address a variety of bugs. The latest Patch Tuesday covers 61 vulnerabilities, 17 of...
Threat Roundup for August 31 to September 7
1 min read
Today, Talos is publishing a glimpse into the most prevalent threats we've observed between August 31 and September 7. As with previous round-ups, this post isn't meant to be an...
Vulnerability Spotlight: CVE-2018-3952 / CVE-2018-4010 – Multi-provider VPN Client Privilege Escalation Vulnerabil …
1 min read
Cisco Talos has discovered two similar vulnerabilities in the ProtonVPN and NordVPN VPN clients that make it possible to execute code as an administrator on the system.
Vulnerability Spotlight: TALOS-2018-0560 – ERPNext SQL Injection Vulnerabilities
1 min read
Overview Talos is disclosing multiple SQL injection vulnerabilities in the Frappe ERPNext Version 10.1.6 application. Frappe ERPNext is an open-source enterprise resource planning (ERP) cloud application. These vulnerabilities enable an...