Recent
- Field reportTI-2026-0437
Malware that does not wait for an operator
Talos reports CLOSEDQUORUM, the first documented implant with fully autonomous command and control — a shift from speed and scale to effort displacement.
3 minSource: Cisco Talos
- Field reportTI-2026-0436
Reading JavaScript written not to be read
String arrays, renamed functions, encoded URLs and runtime decoders — a Talos walkthrough of getting obfuscated samples to explain themselves.
3 minSource: Cisco Talos
- Field reportTI-2026-0435
405 samples, twelve on endpoints
Unit 42 gathered every AI-enabled malware sample it could find. Three percent reached a real machine, and none needed new detection.
SeverityLow
3 minSource: Unit 42
- Field reportTI-2026-0434
Seven families, sixty-five machines
Bitdefender's SilkParasite report describes about a year of quiet work across Central Asia and the Caucasus, five of the seven toolsets previously undocumented.
SeverityMedium
3 minSource: The Record
- Field reportTI-2026-0433
An adversary that writes its own playbooks
Talos documents UAT-10147 using agentic AI after the breach, not before it — for exploit refinement, validation and documenting its own intrusions.
SeverityHigh
3 minSource: Cisco Talos
- News briefTI-2026-0432
Medusa passes five hundred organisations
A joint advisory puts the count above 500 as of April, against 300 in March last year — and names what the affiliates are paid.
SeverityHigh
2 minSource: BleepingComputer
- News briefTI-2026-0431
A nine-month-old patch meets a ransomware crew
CISA has flagged CVE-2025-60710 as used in ransomware attacks. Microsoft fixed it in November 2025.
SeverityHigh
2 minSource: BleepingComputer
- News briefTI-2026-0430
ShieldBreak turns Defender into a way up
A privilege escalation flaw disclosed without notice, with a working exploit and no patch yet.
SeverityHigh
2 minSource: BleepingComputer
- Field reportTI-2026-0429
JWR phishing kit streams keystrokes live
Talos documents a framework whose operators watch partial card numbers appear before the victim submits anything.
SeverityHigh
2 minSource: Cisco Talos
- Field reportTI-2026-0428
Ransomware crews are skipping the encryption
Extortion without a payload is faster, quieter, and defeats the control most organisations invested in.
SeverityCritical
9 min
- AnalysisTI-2026-0421
Initial access brokers are specialising by sector
Listings now advertise vertical, revenue band and security stack.
SeverityHigh
6 min
- Research noteTI-2026-0414
Infostealer logs feed almost every other campaign
Commodity credential theft on personal devices is the input to targeted intrusion.
SeverityHigh
5 min
- Field reportTI-2026-0407
Build systems are the current supply chain target
Not the package registry — the pipeline that consumes it.
SeverityCritical
8 min