Should you care about an “AI slowdown?”
Welcome to this week’s edition of the Threat Source newsletter. There’s been a lot of talk recently about slowing down the pace of AI development. And yes, there are legitimate moral, ethical,...
View ArticleRansomware incidents in Japan in the first half of 2026: Investigation of The...
Compared with the same period last year, ransomware incidents in Japan increased slightly by approximately 4.7%, indicating that ransomware continues to pose a significant threat.In Japan, The...
View ArticleSecuring the unpatchable in an age of AI-driven vulnerabilities
AI is accelerating vulnerability discovery, leaving unpatchable operational technology (OT) systems at risk. Hoping for the best is not a viable anti-exploitation strategy. Deploying next-generation...
View ArticleWe've got one word for it, and it's usually the wrong one
Welcome to this week’s edition of the Threat Source newsletter. Ask anybody in this industry what the work does to the health of the people who do it and you get one word back: burnout. It's a fine...
View ArticleActive exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in...
View ArticleMicrosoft Patch Tuesday for September 2026 — Snort rules and prominent...
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."Microsoft...
View ArticleClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer,...
Cisco Talos began an investigation after observing a DLL named "verification.google" executing from WebDAV at a Ukrainian government organization. We assess with moderate confidence that the attacks...
View ArticleClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google...
View ArticleThe story behind the intelligence
Welcome to this week’s edition of the Threat Source newsletter. Our goal is to get accurate threat intelligence to our audience as quickly as possible, with all the context you need to ask the right...
View Article“Sorry, I can’t help with that”: How your guardrails might become the...
Welcome to this week’s edition of the Threat Source newsletter. Hello, everyone. Long time reader, first time writer here at the Threat Source newsletter! I wanted to start out by introducing myself....
View ArticleJavaScript obfuscation: From party trick to phishing kit
We open a JavaScript artifact hoping for code, and instead get string arrays, strangely named functions, encoded URLs, runtime decoders, and eval statements. That is the point where “reading the...
View ArticleChoose your fighter: Balancing competing requirements to select models for...
Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. SOC...
View ArticleThe safety penalty: Reclaiming operational sovereignty in the age of AI
As frontier models advance in cyber capability, their guardrails also become more restrictive. Defenders relying on these models to power core SOC processes cannot afford to pay the “safety penalty” of...
View ArticleIs Cyber missing the Marque?
Welcome to this week’s edition of the Threat Source newsletter. Hello friend. I’m Mick. This is my first Threat Source newsletter, so I should probably introduce myself before I start telling you...
View ArticleUAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and...
UAT-10147 is a highly capable Chinese-speaking intrusion actor operating a multi-platform post-exploitation ecosystem targeting IIS and Linux servers, combining search engine optimization (SEO) fraud...
View ArticleUAT-10147: Chinese-speaking adversary integrates agentic AI into...
Cisco Talos identified UAT-10147 targeting Windows and Linux web servers globally, impacting organizations in government, education, media, technology, and gaming sectors. The actor leveraged publicly...
View ArticleDescribing attacks with crime script analysis
Crime script analysis is a narrative-driven technique that can be used alongside, or as an alternative to, tactics, techniques, and procedures (TTPs) — creating human-readable stories that describe...
View ArticleCuriouser and Curiouser
Welcome to this week’s edition of the Threat Source newsletter. “Experiment is the mother of knowledge.” ― Madeleine L'Engle, A Wrinkle in Time“Don't slide down the rabbit hole. The way down is a...
View ArticleDissecting the JWR phishing framework
Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and...
View ArticleMicrosoft Patch Tuesday for August 2026 — Snort rules and prominent...
Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical." Microsoft notes...
View Article