Sign in

Cisco Talos Intelligence Group

@talosintelligence.com
1.2K followers 3 following 474 posts

Cisco Talos defends Cisco customers with trusted global cybersecurity intelligence. Support requests: talosintelligence.com/support

PostsRepliesMedia
Cisco Talos Intelligence Group @talosintelligence.com · 29/09/2026
Announcing Executive Threat Detection, a Talos IR service that offers protection for up to 10 principals, with monthly custom threat hunts and reports relevant to their corporate systems: cs.co/63325BGUIUb
Talos Incident Response Proactive Service: Executive Threat Detection
011
Cisco Talos Intelligence Group @talosintelligence.com · 24/09/2026
If that "quick $300 consultation" offer in your DMs feels too good to be true, your gut is likely right. Check out Martin’s latest Threat Source newsletter: cs.co/63322BGgBFr
threat source newsletter in orange on a dark blue background
011
Cisco Talos Intelligence Group @talosintelligence.com · 24/09/2026
Join Cisco’s Jessica Oppenheimer inside the Black Hat NOC to see how AI agents are investigating threats in the world’s most hostile network, and why human oversight remains essential: youtu.be/-NcisdnpTR8
011
Cisco Talos Intelligence Group @talosintelligence.com · 24/09/2026
Get up to speed on CAIRN and CLOSEDQUORUM with our latest Talos TL;DR: youtube.com/shorts/Wbtbe...
011
Cisco Talos Intelligence Group @talosintelligence.com · 24/09/2026
ICYMI: The Beers with Talos team caught up with Martin Lee to discuss why he swapped human virus research for the internet, how ultra-running keeps him sane, and exactly how many Lamborghinis it takes to sink a $245M crypto theft: cs.co/63326BG5V08
022
Cisco Talos Intelligence Group @talosintelligence.com · 23/09/2026
What is CAIRN, and how can it inform your detection, intelligence, and operational strategies around AI-integrated malware? Take a look:
100
Cisco Talos Intelligence Group @talosintelligence.com · 23/09/2026
Join us for the latest episode of Talos Takes as Vanja Svajcer breaks down a multi-stage infection chain that leverages ClickFix social engineering and EtherHiding to store malicious code on the blockchain: cs.co/63327BGjDOt
talos takes in white over a graphic of a microphone
000
Cisco Talos Intelligence Group @talosintelligence.com · 22/09/2026
Our first findings from the CAIRN project analyze CLOSEDQUORUM, the first documented autonomous AI C2 implant to demonstrate "effort displacement." Read our latest blog to understand how this architecture allows AI to execute attack phases independently: cs.co/63328BGb7JC
door with chain looped through handles and a sign reading "closed session: do not enter"
000
Cisco Talos Intelligence Group @talosintelligence.com · 22/09/2026
Take a brief video tour of CAIRN, Cisco Talos’ new open-source research toolkit for investigating AI-integrated malware. See how researchers can surface samples, uncover connections between them, and identify similarities that conventional code comparison may miss: cs.co/6043BGdufP
020
Cisco Talos Intelligence Group @talosintelligence.com · 22/09/2026
Cisco Talos is proud to introduce CAIRN, a new metadata-first research toolkit designed to scale the hunting and classification of AI-integrated malware without defenders needing to download binaries: cs.co/63323BGbAwP
CAIRN: COGNITIVE ARTIFACT INTELLIGENCE RESEARCH NETWORK
011
Cisco Talos Intelligence Group @talosintelligence.com · 17/09/2026
Does an AI slowdown really matter for cybersecurity? In the latest newsletter, David breaks down why your best defense isn't chasing the next big model, but doubling down on the security fundamentals that keep your environment safe: cs.co/63329BGTZ4v
threat source newsletter: All the security news you need to know - hitting your inbox every Thursday
000
Cisco Talos Intelligence Group @talosintelligence.com · 17/09/2026
From the rise of newer threat groups like "The Gentlemen" to Qilin’s AI usage, our latest blog post examines the shifting ransomware landscape across Japan during the first half of 2026: cs.co/63327BGTdX1
we're holding your data hostage ransom note
010
Cisco Talos Intelligence Group @talosintelligence.com · 16/09/2026
We might not be able to prevent the discovery of vulnerabilities in “unpatchable” systems, but we can ensure that attackers do not have an easy path to exploit them in the field. Read the blog: cs.co/63323BGRFM3
"on the radar" in white letters on a galaxy-like background with nodes
021
Reposted by Cisco Talos Intelligence Group
David J. Bianco @davidjbianco.bsky.social · 14/09/2026
Happy to announce the release of EvidenceForge 2.0.0 (github.com/Cisco-Talos/...). Major improvements in this release include: 🧵
github.com
GitHub - Cisco-Talos/EvidenceForge: Generate realistic synthetic security logs for cybersecurity threat hunting training and research
Generate realistic synthetic security logs for cybersecurity threat hunting training and research - Cisco-Talos/EvidenceForge
152
Cisco Talos Intelligence Group @talosintelligence.com · 10/09/2026
In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address it: cs.co/63329BGznF7
threat source newsletter banner
011
Cisco Talos Intelligence Group @talosintelligence.com · 09/09/2026
Ah, the crisp fall air, brand-new books and backpacks, and the quiet irony of cybercriminals turning on each other to steal a few extra bucks. This newest Talos Takes explores a browser-based variant of ClickFix: cs.co/63324BGHdxY
talos takes logo
011
Cisco Talos Intelligence Group @talosintelligence.com · 08/09/2026
Cisco Talos has uncovered an infection chain using WebDAV, BNB Smart Chain, and ClickFix tactics to deploy the Amatera stealer, ZigCryptoStealer, and unauthorized NetSupport Manager access: cs.co/63324BGHWCE
threat spotlight
011
Cisco Talos Intelligence Group @talosintelligence.com · 08/09/2026
Cisco Talos is tracking a ClickFix variant that exploits the Google Visualization API for command and control, enabling attackers to hijack browser sessions and steal cryptocurrency from unsuspecting users: cs.co/63329BGHmdc
threat spotlight banner with a malware shadow on the bottom
021
Cisco Talos Intelligence Group @talosintelligence.com · 03/09/2026
Recording Beers with Talos with Azim was an eye-opener, and Hazel is spilling the details on everything from dark-web persona management to her very bold snack debut in this week's newsletter: cs.co/63328B1CUhK
threat source newsletter image
011
Cisco Talos Intelligence Group @talosintelligence.com · 02/09/2026
For Azim Khodjibaev, managing eight different criminal personas at once is serious business. From being name-dropped in ransomware code to running an undercover operation from his desk, Azim joins the Beers with Talos team to discuss engaging with threat actors: cs.co/63324B1CVLG
000
Cisco Talos Intelligence Group @talosintelligence.com · 28/08/2026
We're heading to LABScon in Scottsdale, AZ. Catch up with Talosians to hear about their latest research from September 16 – 19: www.labscon.io
000
Cisco Talos Intelligence Group @talosintelligence.com · 27/08/2026
Get ready to rethink AI guardrails with David Bianco’s debut Threat Source newsletter. He’s sharing why sometimes those safety nets might just give attackers a leg up, and why your security team needs to call the shots: cs.co/63327B1aCjZ
threat source newsletter: all the security news you need to know - hitting your inbox every thursday
000
Cisco Talos Intelligence Group @talosintelligence.com · 27/08/2026
Obfuscated JavaScript might be the world’s most frustrating scavenger hunt, designed to bury the real behavior under layers of noise. Here’s a crash course on how to strip away the chaos and make sense of those cryptic scripts: cs.co/63329B1Q7dc
tool talk banner
011
Cisco Talos Intelligence Group @talosintelligence.com · 26/08/2026
More reasoning power doesn't always equal better SOC results. Talos tested 66 AI model combinations to show you how to find the balance between cost, speed, and reliability for your security operations: cs.co/63324B1Q7ME
tool talk banner
021
Cisco Talos Intelligence Group @talosintelligence.com · 26/08/2026
Year after year, Talos sees cyber threats spike during the back-to-school rush. On the newest Talos Takes, Amy and Pierre are breaking down the practical, high-priority steps to keep school networks protected: cs.co/63321B1Q3e7
021
Cisco Talos Intelligence Group @talosintelligence.com · 25/08/2026
Have a listener question for this week’s Beers with Talos recording? Ask us about the latest threats, something happening in cybersecurity that you’d like our take on, or anything else you think might provoke a useful (or entertaining) argument. Drop your questions below!
beers with talos logo. full beer glass with talos shield logomark on it.
010
Cisco Talos Intelligence Group @talosintelligence.com · 25/08/2026
Is your SOC paying the "safety penalty?” When AI guardrails block legitimate forensic requests during a live incident, you hand the advantage to the attacker. It's time to regain control over your security operations: cs.co/63323B1t2Zt
on the radar banner
020
Cisco Talos Intelligence Group @talosintelligence.com · 21/08/2026
Adversaries are evolving, and so are their tactics. If you missed Talos’ recent research on how they’re weaponizing AI, catch up with this interview with Nick Biasini and ISMG Studio at Black Hat: cs.co/63327B1lEEN
A white man with short brown hair and a beard sits in front of a purple backdrop. He's wearing a blue polo with Cisco Talos embroidered on the breast and is looking off to the side, presumably at an interviewer.
000
Cisco Talos Intelligence Group @talosintelligence.com · 20/08/2026
In his debut Threat Source newsletter, Mick Baccio asks the big questions about the new White House memorandum on private sector involvement in offensive cyber operations. Let’s dig in: cs.co/63328B1cB18
threat source newsletter: All the security news you need to know - hitting your inbox every Thursday
000
Cisco Talos Intelligence Group @talosintelligence.com · 20/08/2026
Decoding complex threat intelligence, securing AI-enabled smart toilets, and Derry Girls — what more could you want? Tune into the latest Beers with Talos episode to see how Kaitlin Acharya handles everything from cyber defense to run-ins with an evil genie: cs.co/63327B1iWid
000
Cisco Talos Intelligence Group @talosintelligence.com · 19/08/2026
What if we treated cyber attacks more like crime scenes? Learn how crime script analysis helps simplify complex threats for multi-level audiences and reveals new ways to stop attackers in their tracks: cs.co/63323B1j0JB
on the radar banner
011
Cisco Talos Intelligence Group @talosintelligence.com · 17/08/2026
Are your security tools missing threats hiding under the radar? Watch our latest video to learn how Cisco Talos Threat Hunting combines AI and expert human analysis to uncover sophisticated adversary activity that traditional detection methods often miss: youtu.be/8yUXRIS97Wc?...
011
Cisco Talos Intelligence Group @talosintelligence.com · 13/08/2026
Cybersecurity is a team sport, and the best solutions often come from a mix of perspectives. Check out the latest Threat Source newsletter to hear William reflect on making Hazel a hacker: cs.co/63321B1Osgv
threat source newsletter: all the security news you need- hitting your inbox every Thursday
000
Cisco Talos Intelligence Group @talosintelligence.com · 12/08/2026
What does it take to defend against a cloud-native attack? After walking us through a real Talos IR case involving QR code phishing, Terryn shared his go-to strategies for staying ahead of the game. Take a look and a listen: www.buzzsprout.com/2018149/epis...
111
Cisco Talos Intelligence Group @talosintelligence.com · 12/08/2026
Amy and Terryn are pulling back the curtain on a real Talos Incident Response case where a simple QR code led to a security scramble for a medical center. Tune into the new Talos Takes to learn how we handled this cloud-native breach: cs.co/63324B13LM6
talos takes logo
011
Cisco Talos Intelligence Group @talosintelligence.com · 06/08/2026
Is AI a brilliant escape artist or a hazardous containment failure? Martin explains how the metaphors we use to frame AI incidents can completely change how we react to security threats: cs.co/63326B1DKYA
threat source newsletter banner
010
Cisco Talos Intelligence Group @talosintelligence.com · 06/08/2026
There’s still time to register for the next Tales from the Frontlines. Join the Talos Incident Response team to get behind-the-scenes insights on the incidents we responded to in Q2: cs.co/IRTales-2026...
tales from the frontlines
010
Cisco Talos Intelligence Group @talosintelligence.com · 05/08/2026
When threat actors start arguing with AI, the results are as revealing as they are ridiculous. Catch the full breakdown of how adversaries are weaponizing (and struggling with) AI in the latest Beers with Talos: cs.co/63328B16eIY
041
Cisco Talos Intelligence Group @talosintelligence.com · 05/08/2026
TODAY: Looking for a practical Black Hat workshop? Join Talos experts Nick Biasini and Omar Santos to learn how you can incorporate AI into SOC workflows to identify sophisticated adversary behavior. cs.co/63326BEa030
event flyer
031
Cisco Talos Intelligence Group @talosintelligence.com · 04/08/2026
Tomorrow at Black Hat: Don't miss this interactive workshop to learn practical ways you can incorporate AI into SOC workflows to identify sophisticated adversary behavior. cs.co/63323BEaLaD
event flyer
011
Cisco Talos Intelligence Group @talosintelligence.com · 04/08/2026
Some threat actors really need to learn how to prompt. Talos recovered attacker prompts logs and another AI artifacts to learn how they bypass guardrails, build and scale capabilities, and automate workflows. While amusing, some made sophisticated outputs: cs.co/63329BEAg9c
an AI prompt reading "dont give me this type of finding give me some real finding which is making some real ipmct analys be crative"
032
Cisco Talos Intelligence Group @talosintelligence.com · 03/08/2026
Join the Cisco Talos Incident Response team for a unique, informal, and unrecorded session where we go beyond the blog to share real stories from Q2's most critical and high-impact incidents: cs.co/IRTales-2026...
tales from the frontlines
021
Cisco Talos Intelligence Group @talosintelligence.com · 03/08/2026
Want to hear Talosians' lightning talks, talk about threat research, or grab a new multicolored Snorty? Here's where you can find us during Black Hat: cs.co/63323BEaIQh
JOIN TALOS AT BLACK HAT
Booth 2633
August 1 - 6, Las Vegas, NV
011
Cisco Talos Intelligence Group @talosintelligence.com · 31/07/2026
Register now to hear Talos IR share real stories from Q2's most critical and high-impact incidents. We'll share what really happened, how we handled it, and what it means for your organization: cs.co/IRTales-2026...
Tales from the Frontlines
000
Cisco Talos Intelligence Group @talosintelligence.com · 31/07/2026
In the latest episode of the TTP, Hazel, Craig, and Joe explore the tactics behind recent trends in the Q2 Incident Response report. Learn how to stay one step ahead: cs.co/63325BE0f0U
000
Cisco Talos Intelligence Group @talosintelligence.com · 30/07/2026
If you think your cybersecurity workload is a mountain, the latest newsletter is here to remind you that even the toughest climbs are worth the effort — or at least the post-hike iced coffee: cs.co/63324BELiN2
threat source newsletter banner
021
Cisco Talos Intelligence Group @talosintelligence.com · 30/07/2026
We’re hitting the rewind button for a special Black Hat edition of Humans of Talos, featuring a look back at the diverse paths and career-defining moments that make our team who they are today: cs.co/63327BEaUUU
humans of talos banner
011
Cisco Talos Intelligence Group @talosintelligence.com · 30/07/2026
It was Talos all along. Learn how our automated, real-time threat detection is already working to secure your Cisco environment: cs.co/63324BEaxr0
011
Cisco Talos Intelligence Group @talosintelligence.com · 29/07/2026
Black Hat is just around the corner! Swing by to discuss our latest research and snag this year’s exclusive Snorty. See where to find us here: cs.co/63324BEatTG
JOIN TALOS AT BLACK HAT!
Booth 2633
August 1-6, Las Vegas, NV
011
Cisco Talos Intelligence Group @talosintelligence.com · 29/07/2026
Cisco Talos Incident Response’s Q2 trends report is out. Author Lexi DiScola joins Amy to show you exactly how attackers are evolving and the practical steps you can take to stop them: cs.co/63325BEatZZ
011