Category: Research
Cisco Talos Releases EvidenceForge for Realistic Synthetic Security Logs
EvidenceForge is a new open-source tool from Cisco Talos that generates correlated, realistic security log datasets across 20-plus formats to support threat…
Encryption Optional: How Cyber Extortion Is Evolving Beyond Ransomware
Unit 42 research shows ransomware encryption dropped to 78% of extortion cases in 2025, as threat actors pivot to pure data theft…
Operation FlutterBridge: New macOS Backdoor Spreads via Google Ads
Unit 42 researchers have identified a macOS malvertising campaign delivering a Flutter-based backdoor called FlutterShell, capable of browser hijacking, shell command execution,…
Inside Cisco Talos Threat Hunting: Hypotheses, Telemetry, and Human Judgment
Cisco Talos has published a detailed look at its hypothesis-driven threat hunting methodology, including a real-world case study showing how correlated firewall…
Microsoft Teams Becomes Prime Vector for IT Impersonation Phishing
Threat actors including APT29 are exploiting overly permissive Teams federation settings to impersonate IT staff and trick employees into approving MFA prompts.…
How Attackers Abuse Cloud Logging Services to Evade Detection
Unit 42 researchers outline five techniques adversaries use to manipulate AWS CloudTrail and Google Cloud Logging, turning essential security infrastructure into a…
Researchers Link Ransomware Group ‘The Gentlemen’ to Izhevsk Man
Intelligence trails connecting forum handles, leaked databases, and open-source lookups point to a named Russian individual as the administrator behind one of…
New macOS Tahoe 26 Biome Stream Logs Every Menu Selection Users Make
Unit 42 researchers have identified a previously undocumented macOS artifact, App.MenuItem, that records granular user menu interactions and can help forensic examiners…
Cisco Talos Shows How AI Agents Can Drive a Disassembler via COM
A new technique from Cisco Talos demonstrates that reverse engineering tools do not need built-in AI features to support agentic workflows. By…
Popa Android Botnet Tied to Publicly Traded Israeli Proxy Firm
Researchers from multiple security firms have linked the Popa botnet, which routes traffic through millions of compromised TV boxes, to NetNut, a…
Cisco Talos Pairs Local AI Agents with Disassemblers to Automate Reverse Engineering
Cisco Talos has detailed a privacy-preserving approach to agentic reverse engineering that connects local AI agents to traditional analysis tools via COM…
Cloud Bucket Hijacking Technique Threatens Data Streams Across AWS, GCP, and Azure
Unit 42 researchers have disclosed a bucket hijacking method that exploits globally unique bucket names across major cloud providers, allowing attackers to…