Avatar

Talos Group

Talos Security Intelligence & Research Group

The Talos Security Intelligence and Research Group (Talos) is made up of leading threat researchers supported by sophisticated systems to create threat intelligence for Cisco products that detects, analyzes and protects against both known and emerging threats. Talos maintains the official rule sets of Snort.org, ClamAV, SenderBase.org and SpamCop. This blog profile is managed by multiple authors with expertise that spans software development, reverse engineering, vulnerability triage, malware investigation and intelligence gathering.

Talos is the primary team that contributes threat information to the Cisco Collective Security Intelligence (CSI) ecosystem. Cisco CSI is shared across multiple security solutions and provides industry-leading security protections and efficacy. In addition to threat researchers, CSI is driven by intelligence infrastructure, product and service telemetry, public and private feeds and the open source community.

Articles

June 29, 2018

THREAT RESEARCH

Threat Roundup for June 22-29

1 min read

Today, Talos is publishing a glimpse into the most prevalent threats we've observed between June 22 and June 29. As with previous round-ups, this post isn't meant to be an...

June 29, 2018

THREAT RESEARCH

Vulnerability Spotlight: VMWare Workstation DoS Vulnerability

1 min read

Today, Talos is disclosing a vulnerability in VMWare Workstation that could result in Denial of Service.  VMWare Workstation is a widely used virtualization platform designed to run alongside a...

June 26, 2018

THREAT RESEARCH

Files Cannot Be Decrypted? Challenge Accepted. Talos Releases ThanatosDecryptor

1 min read

Talos is releasing ThanatosDecryptor, a free decryption tool that exploits weaknesses in the design of the file encryption methodology used by Thanatos. This utility can be used to regain access to data.

June 22, 2018

THREAT RESEARCH

Threat Roundup for June 16-22

1 min read

Today, Talos is publishing a glimpse into the most prevalent threats we've observed between June 1 and June 15. As with previous round-ups, this post isn't meant to be an...

June 20, 2018

THREAT RESEARCH

My Little FormBook

1 min read

Cisco Talos has been tracking a new campaign involving the FormBook malware since May 2018 that utilizes four different malicious documents in a single phishing email. FormBook is an inexpensive...

June 19, 2018

THREAT RESEARCH

Vulnerability Spotlight: Multiple Remote Vulnerabilities In Insteon Hub PubNub

1 min read

Cisco Talos is disclosing twelve new vulnerabilities in Insteon Hub, ranging from remote code execution, to denial of service. The majority of the vulnerabilities have their root cause in the...

June 15, 2018

THREAT RESEARCH

Threat Roundup for June 1-15

1 min read

Today, Talos is publishing a glimpse into the most prevalent threats we've observed between June 1 and June 15. As with previous round-ups, this post isn't meant to be an...

June 14, 2018

THREAT RESEARCH

Vulnerability Spotlight: TALOS-2018-0523-24 – Multiple Vulnerabilities in Pixars Renderman application

1 min read

Talos is disclosing two denial-of-ervice vulnerabilities in Pixar’s Renderman application. Renderman is a rendering application used in animation and film production. It is widely used for advanced rendering and shading...

June 13, 2018

THREAT RESEARCH

Vulnerability Spotlight: TALOS-2018-0545 – Microsoft wimgapi LoadIntegrityInfo Code Execution Vulnerability

1 min read

Talos is disclosing a remote code execution vulnerability in the Microsoft wimgapi library. The wimgapi DLL is used in the Microsoft Windows operating system to perform operations on Windows Imaging...