Latest Briefings
AI Agent Skills Need Supply-Chain Audits, Unit 42 Research Finds
A new audit primitive called Behavioral Integrity Verification scanned nearly 50,000 agent skills and found that 80 percent deviate from their declared…
AI-Driven Vuln Discovery Has Outpaced Human Patching, Talos Warns
Cisco Talos researcher Yuri Kramarz argues that frontier AI models can autonomously find and exploit zero-days in minutes, collapsing the traditional vulnerability…
New macOS Tahoe 26 Biome Stream Logs Every Menu Selection Users Make
Unit 42 researchers have identified a previously undocumented macOS artifact, App.MenuItem, that records granular user menu interactions and can help forensic examiners…
Bucket Squatting Flaw in Vertex AI Python SDK Enabled Cross-Tenant RCE
A now-patched vulnerability in Google Cloud's Vertex AI Python SDK allowed an attacker with no access to a victim's project to hijack…
Cisco Talos Shows How AI Agents Can Drive a Disassembler via COM
A new technique from Cisco Talos demonstrates that reverse engineering tools do not need built-in AI features to support agentic workflows. By…
Popa Android Botnet Tied to Publicly Traded Israeli Proxy Firm
Researchers from multiple security firms have linked the Popa botnet, which routes traffic through millions of compromised TV boxes, to NetNut, a…
Cisco Talos Pairs Local AI Agents with Disassemblers to Automate Reverse Engineering
Cisco Talos has detailed a privacy-preserving approach to agentic reverse engineering that connects local AI agents to traditional analysis tools via COM…
Cloud Bucket Hijacking Technique Threatens Data Streams Across AWS, GCP, and Azure
Unit 42 researchers have disclosed a bucket hijacking method that exploits globally unique bucket names across major cloud providers, allowing attackers to…
Scattered Spider Members Plead Guilty on Day One of UK Trial
Two key members of the Scattered Spider cybercrime group admitted to hacking Transport for London and conspiring in a series of ransomware…
Malicious Skills Persist on ClawHub Despite AI Agent Marketplace Scanning
Unit 42 researchers found five undetected malicious skills in OpenClaw's ClawHub marketplace between February and May 2026, including macOS infostealers and novel…
How Windows COM Becomes a Weapon: A Technical Primer from Cisco Talos
Cisco Talos breaks down how threat actors exploit the Component Object Model for lateral movement, persistence, evasion, and more, offering reverse-engineering guidance…
Poland Arrests Four in SIM-Swapping Gang Behind Millions in Crypto Theft
Polish authorities, working with the FBI and HSI, have detained four members of a cybercrime group that breached telecom infrastructure and hijacked…