Latest Briefings
Inside Cisco Talos Threat Hunting: Hypotheses, Telemetry, and Human Judgment
Cisco Talos has published a detailed look at its hypothesis-driven threat hunting methodology, including a real-world case study showing how correlated firewall…
Microsoft Teams Becomes Prime Vector for IT Impersonation Phishing
Threat actors including APT29 are exploiting overly permissive Teams federation settings to impersonate IT staff and trick employees into approving MFA prompts.…
Active Exploitation of PAN-OS GlobalProtect Auth Bypass CVE-2026-0257
Unit 42 has confirmed active in-the-wild exploitation of a PAN-OS authentication bypass affecting GlobalProtect portals and gateways, with the flaw added to…
Horner Automation Cscape Flaw Enables Code Execution via Malicious Files
An out-of-bounds read vulnerability in Horner Automation Cscape prior to version 10.2 SP3 allows a local attacker to disclose information and execute…
How Attackers Abuse Cloud Logging Services to Evade Detection
Unit 42 researchers outline five techniques adversaries use to manipulate AWS CloudTrail and Google Cloud Logging, turning essential security infrastructure into a…
CISA Warns of Two High-Severity Flaws in AzeoTech DAQFactory
CISA has published an updated advisory detailing two memory-corruption vulnerabilities in AzeoTech DAQFactory that allow arbitrary code execution via malicious control files.
Critical Path Traversal Flaw in pynetdicom Threatens Healthcare Systems
A critical path traversal vulnerability in the pynetdicom library allows unauthenticated attackers to write files to arbitrary locations, affecting all versions from…
Researchers Link Ransomware Group ‘The Gentlemen’ to Izhevsk Man
Intelligence trails connecting forum handles, leaked databases, and open-source lookups point to a named Russian individual as the administrator behind one of…
Mitsubishi MELSEC iQ-F EtherNet/IP Module Vulnerable to Remote DoS
An integer overflow flaw in the FX5-EIP module allows unauthenticated remote attackers to crash the device by flooding it with TCP connections.…
CISA Flags Two High-Severity Flaws in H.VIEW HV-500S6 IP Camera
A pair of vulnerabilities in H.VIEW's HV-500S6 IP camera allow authenticated attackers to execute arbitrary commands and upload malicious files. The vendor…
AI Agent Skills Need Supply-Chain Audits, Unit 42 Research Finds
A new audit primitive called Behavioral Integrity Verification scanned nearly 50,000 agent skills and found that 80 percent deviate from their declared…
AI-Driven Vuln Discovery Has Outpaced Human Patching, Talos Warns
Cisco Talos researcher Yuri Kramarz argues that frontier AI models can autonomously find and exploit zero-days in minutes, collapsing the traditional vulnerability…