Avatar

Talos Group

Talos Security Intelligence & Research Group

The Talos Security Intelligence and Research Group (Talos) is made up of leading threat researchers supported by sophisticated systems to create threat intelligence for Cisco products that detects, analyzes and protects against both known and emerging threats. Talos maintains the official rule sets of Snort.org, ClamAV, SenderBase.org and SpamCop. This blog profile is managed by multiple authors with expertise that spans software development, reverse engineering, vulnerability triage, malware investigation and intelligence gathering.

Talos is the primary team that contributes threat information to the Cisco Collective Security Intelligence (CSI) ecosystem. Cisco CSI is shared across multiple security solutions and provides industry-leading security protections and efficacy. In addition to threat researchers, CSI is driven by intelligence infrastructure, product and service telemetry, public and private feeds and the open source community.

Articles

September 24, 2018

THREAT RESEARCH

Adwind Dodges AV via DDE

1 min read

his blog post is authored by Paul Rascagneres, Vitor Ventura and with the contribution of Tomislav Pericin from ReversingLabs. Introduction Cisco Talos, along with fellow cybersecurity firm ReversingLabs, recently discovered...

September 19, 2018

THREAT RESEARCH

Cyber Threat Alliance Releases Cryptomining Whitepaper

1 min read

Despite the recent devaluation of some cryptocurrencies, illicit cryptocurrency miners remain a lucrative and widespread attack vector in the threat landscape. These miners are easy to deploy, and attackers see...

October 11, 2018

THREAT RESEARCH

GPlayed trojan – .Net playing with Google Market

1 min read

Cisco Talos has identified the latest attempt to penetrate mobile devices — a new Android trojan that we have dubbed "GPlayed."

September 14, 2018

THREAT RESEARCH

Threat Roundup for September 7 to September 14

1 min read

Today, Talos is publishing a glimpse into the most prevalent threats we've observed between September 7 and September 14. As with previous round-ups, this post isn't meant to be an...

September 13, 2018

THREAT RESEARCH

SigAnalyzer: Signature analysis with CASC

1 min read

ClamAV Signature Creator (CASC) is an IDA Pro plugin that assists in the creation of ClamAV pattern signatures. We have enhanced this plugin to also analyze these signatures. The plugin highlights matching parts in a binary when its given a particular signature.

September 11, 2018

THREAT RESEARCH

Microsoft Patch Tuesday – September 2018

1 min read

Microsoft released its monthly set of security updates today for a variety of its products that address a variety of bugs. The latest Patch Tuesday covers 61 vulnerabilities, 17 of...

September 7, 2018

THREAT RESEARCH

Threat Roundup for August 31 to September 7

1 min read

Today, Talos is publishing a glimpse into the most prevalent threats we've observed between August 31 and September 7. As with previous round-ups, this post isn't meant to be an...

September 7, 2018

THREAT RESEARCH

Vulnerability Spotlight: CVE-2018-3952 / CVE-2018-4010 – Multi-provider VPN Client Privilege Escalation Vulnerabil …

1 min read

Cisco Talos has discovered two similar vulnerabilities in the ProtonVPN and NordVPN VPN clients that make it possible to execute code as an administrator on the system.

September 6, 2018

THREAT RESEARCH

Vulnerability Spotlight: TALOS-2018-0560 – ERPNext SQL Injection Vulnerabilities

1 min read

Overview Talos is disclosing multiple SQL injection vulnerabilities in the Frappe ERPNext Version 10.1.6 application. Frappe ERPNext is an open-source enterprise resource planning (ERP) cloud application. These vulnerabilities enable an...