<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Cisco Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Cisco.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel</title><link>https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel</link><guid isPermaLink="false">cst-3081</guid><description>Cisco Talos discovered msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that establishes command-and-control communications exclusively through Chrome DevTools Protocol rather than direct network connections. The malware is delivered via a malicious MSI installer disguised as a Windows update and leverages the browser, Cloudflare Workers, and Twilio TURN relays to create a covert WebRTC DataChannel for C2 communications. Chaos is a ransomware-as-a-service group active since February 2025 that uses phishing, vishing, and legitimate tools for post-compromise activities before deploying encryption.</description><pubDate>Thu, 23 Jul 2026 10:00:38 GMT</pubDate></item><item><title>Preview: Cisco Talos at Black Hat USA 2026</title><link>https://blog.talosintelligence.com/preview-cisco-talos-at-black-hat-usa-2026</link><guid isPermaLink="false">cst-3082</guid><description>Cisco Talos will present research and demonstrations at Black Hat USA 2026, including lightning talks on threat actor use of AI prompts, the Warlock ransomware group, zero trust agent identity, and vulnerability discovery trends. The group will deliver a main stage keynote on securing enterprises with AI agents, plus two workshops focused on integrating AI into security operations and monitoring autonomous systems as potential insider threats. Talos threat intelligence is embedded across the Cisco security portfolio and will be showcased at booth 2633.</description><pubDate>Thu, 23 Jul 2026 10:00:14 GMT</pubDate></item><item><title>New msaRAT malware uses Chrome, Edge browsers to route C2 traffic</title><link>https://bleepingcomputer.com/news/security/new-msarat-malware-uses-chrome-edge-browsers-to-route-c2-traffic</link><guid isPermaLink="false">cst-3068</guid><description>Chaos ransomware operators deployed a new backdoor called msaRAT that conceals command-and-control traffic by routing it through Chrome or Edge browsers. This technique allows attackers to blend malicious communications with legitimate browser traffic, making detection more difficult.</description><pubDate>Thu, 23 Jul 2026 10:00:00 GMT</pubDate></item><item><title>Cisco Launches Low-Cost AI Models for Source Code Security</title><link>https://securityweek.com/cisco-launches-low-cost-ai-models-for-source-code-security</link><guid isPermaLink="false">cst-2955</guid><description>Cisco has released open-weight Antares artificial intelligence (AI) models designed to detect known vulnerabilities in source code with improved speed and reduced cost compared to larger AI models.</description><pubDate>Tue, 21 Jul 2026 17:44:33 GMT</pubDate></item><item><title>Cisco’s open-weight Antares models make vulnerability localization cheaper</title><link>https://helpnetsecurity.com/2026/07/21/cisco-antares-vulnerability-localization-released</link><guid isPermaLink="false">cst-2910</guid><description>Cisco released Antares, a family of open-weight small language models designed to accelerate the initial triage phase of vulnerability management by automating the task of locating vulnerabilities within unfamiliar codebases. The models address the time-intensive process of pinpointing vulnerable files across large repositories with inconsistent naming conventions. This approach reduces the manual expertise and hours previously required for this foundational security analysis step.</description><pubDate>Tue, 21 Jul 2026 13:01:57 GMT</pubDate></item><item><title>Russian hackers trojanize WebEx, Zoom apps to push Starland malware</title><link>https://bleepingcomputer.com/news/security/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware</link><guid isPermaLink="false">cst-2650</guid><description>A Russian financially motivated threat actor identified as UAT-11795 is distributing trojanized versions of WebEx and Zoom applications to deliver Starland RAT, a new backdoor designed to steal credentials and cryptocurrency.</description><pubDate>Thu, 16 Jul 2026 10:19:34 GMT</pubDate></item><item><title>UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign</title><link>https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign</link><guid isPermaLink="false">cst-2666</guid><description>Cisco Talos identified UAT-11795, a Russian-speaking financially motivated threat actor conducting campaigns since at least June 2025 against victims in the U.S. and Europe. The group deploys Starland RAT, a Python-based remote access tool, alongside WLDR, a sophisticated PowerShell-based command-and-control implant featuring encrypted beaconing and task queuing capabilities. The actor distributes trojanized installers of legitimate software such as MobaXterm, WebEx, Zoom, and DBeaver to establish persistence and steal credentials and cryptocurrency assets.</description><pubDate>Thu, 16 Jul 2026 10:00:01 GMT</pubDate></item><item><title>Microsoft releases Windows 10 KB5099539 extended security update</title><link>https://bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5099539-extended-security-update</link><guid isPermaLink="false">cst-2513</guid><description>Microsoft released Windows 10 KB5099539, an extended security update containing July 2026 Patch Tuesday fixes for 570 vulnerabilities and additional security patches. This update addresses a substantial volume of identified flaws across the Windows 10 platform.</description><pubDate>Tue, 14 Jul 2026 18:49:28 GMT</pubDate></item><item><title>[Video] Where protection starts: Cisco Talos Intelligence Integrations</title><link>https://blog.talosintelligence.com/video-where-protection-starts-cisco-talos-intelligence-integrations</link><guid isPermaLink="false">cst-2489</guid><description>Cisco Talos Intelligence Integrations apply threat intelligence across Cisco's security and enterprise technologies to identify and block malicious activity. The integrations help security teams answer critical questions about newly registered domains, outbound connections, and unusual user behavior in their environments. A new video introduces the team and explains how these integrations work.</description><pubDate>Tue, 14 Jul 2026 10:47:18 GMT</pubDate></item><item><title>Officials once again warn defenders that Russian hackers are targeting network devices</title><link>https://cyberscoop.com/russian-fsb-cisco-joint-cybersecurity-advisory</link><guid isPermaLink="false">cst-2419</guid><description>Russian FSB Center 16 (tracked under multiple names including Berserk Bear and Dragonfly) has conducted sustained targeting of critical infrastructure globally by exploiting poorly configured and outdated networking devices, particularly Cisco routers with default credentials and unpatched vulnerabilities. A joint cybersecurity advisory from the United States and 12 allied nations on Monday detailed the group's tactics and recommended defenses including disabling Cisco Smart Install, enforcing strong authentication, and monitoring local account activity. The warning follows a December 2025 attack attributed to FSB Center 16 on Poland's energy grid and comes nearly a year after similar alerts.</description><pubDate>Mon, 13 Jul 2026 15:23:46 GMT</pubDate></item><item><title>Cybersecurity M&amp;A Roundup: 37 Deals Announced in June 2026</title><link>https://securityweek.com/cybersecurity-ma-roundup-37-deals-announced-in-june-2026</link><guid isPermaLink="false">cst-2402</guid><description>A total of 37 cybersecurity mergers and acquisitions were announced during June 2026, involving major companies including 1Password, Accenture, Cisco, F5, Rubrik, and SailPoint. The article provides a roundup of these transaction announcements in the cybersecurity sector.</description><pubDate>Mon, 13 Jul 2026 12:20:14 GMT</pubDate></item><item><title>WolfSSL, GeoVision, VTK vulnerabilities</title><link>https://blog.talosintelligence.com/wolfssl-vulnerabilities</link><guid isPermaLink="false">cst-2273</guid><description>Cisco Talos disclosed three vulnerabilities in WolfSSL (two improper input validation issues and one integer underflow), fourteen advisories covering 37 CVEs in GeoVision's camera and monitoring solutions (spanning memory corruption, command injection, buffer overflow, privilege escalation, and authentication issues), and one heap-based buffer overflow in VTK-DICOM. All vulnerabilities have been patched by their respective vendors, and Snort rules are available for detection.</description><pubDate>Thu, 09 Jul 2026 18:52:29 GMT</pubDate></item><item><title>UAT-7810 continues building ORB networks using new malware</title><link>https://blog.talosintelligence.com/uat-7810</link><guid isPermaLink="false">cst-516</guid><description>Cisco Talos is tracking UAT-7810, a China-nexus APT actor that builds and maintains Operational Relay Box (ORB) networks for use by secondary threat actors. UAT-7810 has developed and deployed new malware variants including LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST, targeting Linux and embedded devices across multiple architectures. The group exploits known vulnerabilities in Ruckus wireless routers and ASUS AiCloud routers from infrastructure in Eastern Europe and Hong Kong.</description><pubDate>Tue, 07 Jul 2026 10:00:05 GMT</pubDate></item><item><title>ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit</title><link>https://bleepingcomputer.com/news/security/artoken-phaas-exposes-eviltokens-microsoft-365-phishing-toolkit</link><guid isPermaLink="false">cst-6</guid><description>Researchers discovered ARToken, a phishing-as-a-service (PhaaS) platform operating as an affiliate of the EvilTokens phishing platform, which provides an extensive toolkit for targeting Microsoft 365 accounts. The discovery reveals the organized infrastructure and business model behind credential theft attacks against enterprise email systems.</description><pubDate>Fri, 03 Jul 2026 14:12:22 GMT</pubDate></item><item><title>Catan and Mouse</title><link>https://blog.talosintelligence.com/catan-and-mouse</link><guid isPermaLink="false">cst-348</guid><description>Cisco Talos published research on ARToken, a phishing-as-a-service (PhaaS) operator panel that shares infrastructure and patterns with the previously documented EvilTokens platform. The panel provides 80+ API endpoints for device code phishing, Primary Refresh Token (PRT) persistence, email access, business email compromise (BEC) operations, and SharePoint exfiltration through a React-based dashboard, indicating a mature BEC operations environment rather than a basic phishing kit.</description><pubDate>Thu, 02 Jul 2026 18:00:34 GMT</pubDate></item><item><title>Cisco finally confirms attackers exploiting Unified CM flaw</title><link>https://bleepingcomputer.com/news/security/cisco-finally-confirms-attackers-exploiting-unified-cm-flaw</link><guid isPermaLink="false">cst-12</guid><description>Cisco confirmed that attackers are actively exploiting a vulnerability in Unified Communications Manager that the company patched in early June. The exploitation indicates the flaw has moved from theoretical to real-world attacks following the patch release.</description><pubDate>Thu, 02 Jul 2026 11:35:25 GMT</pubDate></item><item><title>This phishing kit looks more like BEC-as-a-service</title><link>https://cyberscoop.com/artoken-bec-platform-cisco-talos</link><guid isPermaLink="false">cst-143</guid><description>Cisco Talos discovered ARToken, an operator panel that functions as a business email compromise-as-a-service platform affiliated with the EvilTokens phishing-as-a-service operation. ARToken includes advanced capabilities beyond typical phishing kits, such as inbox rule manipulation and shared access links, along with a seven-layer anti-analysis system for evasion. The platform targets specific organizations with customized lures that impersonate legitimate vendors, such as spoofed accounts-payable communications designed to trigger fraudulent payment requests.</description><pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate></item><item><title>Cisco Adds NHI to Security Stack With Astrix, WideField Acquisitions</title><link>https://darkreading.com/identity-access-management-security/cisco-adds-nhi-security-stack-with-astrix-widefield</link><guid isPermaLink="false">cst-100</guid><description>Cisco has acquired Astrix and WideField to expand its security platform with capabilities for managing identity in agentic environments, reflecting industry momentum toward identity-centric security controls.</description><pubDate>Fri, 26 Jun 2026 17:31:04 GMT</pubDate></item><item><title>Beyond IOCs: AI-enabled threat intelligence</title><link>https://blog.talosintelligence.com/beyond-iocs-ai-enabled-threat-intelligence</link><guid isPermaLink="false">cst-351</guid><description>Large language models can improve threat intelligence operations by indexing and cross-referencing unstructured strategic and operational reports that traditional indicator-based systems struggle to handle. The approach could enable faster retrieval of relevant threat intelligence and generation of tailored advice, while defenders must address data veracity and query confidentiality concerns. Additionally, malware families increasingly abuse Windows COM (Component Object Model) for lateral movement and evasion, making detection labor-intensive without specialized analysis techniques.</description><pubDate>Thu, 25 Jun 2026 18:00:26 GMT</pubDate></item><item><title>Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure</title><link>https://darkreading.com/cyberattacks-data-breaches/attackers-hit-cisco-sd-wan-flaw-2-months-before-disclosure</link><guid isPermaLink="false">cst-111</guid><description>Attackers exploited a Cisco SD-WAN vulnerability to gain administrative and root-level access to victim devices using rogue peering techniques, beginning approximately two months before the flaw was publicly disclosed. The attackers leveraged this early window to establish unauthorized access before patches were available. This incident highlights the risk posed by zero-day-like vulnerabilities when disclosure lags behind active exploitation.</description><pubDate>Wed, 24 Jun 2026 21:16:41 GMT</pubDate></item><item><title>Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager</title><link>https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager</link><guid isPermaLink="false">cst-306</guid><description>Mandiant identified threat actors exploiting a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager to escalate from compromised administrative accounts to root-level access via malicious file uploads. The attackers established initial access through unauthorized peering connections, manipulated credentials, and employed extensive anti-forensic techniques to cover their tracks. The vulnerability stems from inadequate filtering in the device's file upload feature, affecting SD-WAN infrastructure used by distributed organizations like banks, retail, and healthcare providers.</description><pubDate>Wed, 24 Jun 2026 11:00:00 GMT</pubDate></item><item><title>Close Encounters of the Human Kind</title><link>https://blog.talosintelligence.com/close-encounters-of-the-human-kind</link><guid isPermaLink="false">cst-353</guid><description>The article is primarily a philosophical commentary on human decision-making and information processing in cybersecurity contexts, using a Spielberg film as a framing device. It argues that knowing what security controls to implement (patching, MFA, segmentation, backups) is easier than actually executing them due to competing priorities and resource constraints. The piece includes a brief technical note about Cisco Talos presenting a new reverse engineering approach that integrates AI agents with traditional disassembly tools through a COM interface to automate analysis workflows locally.</description><pubDate>Thu, 18 Jun 2026 18:00:24 GMT</pubDate></item><item><title>May 2026 CVE Landscape</title><link>https://recordedfuture.com/blog/may-2026-cve-landscape</link><guid isPermaLink="false">cst-1953</guid><description>In May 2026, Insikt Group identified 41 high-impact vulnerabilities requiring prioritized remediation, representing an 11% increase from April. These vulnerabilities affected 20 vendors, with 21 included in CISA's Known Exploited Vulnerabilities catalog, 19 detected via honeypot data, and one reported by a vendor. Notably, 12 vulnerabilities enabled remote code execution, public proof-of-concept exploits were available for 32 of them, and five were first disclosed between 2008 and 2010, demonstrating continued exploitation of long-standing weaknesses.</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Reporting from Vegas: Networking, AI, and good boys</title><link>https://blog.talosintelligence.com/reporting-from-vegas-networking-ai-and-good-boys</link><guid isPermaLink="false">cst-356</guid><description>This article is a first-person account from Cisco Live U.S. in Las Vegas covering conference observations, including the prevalence of AI infrastructure and security discussions among attendees. The author also highlights Cisco Talos' expansion of its Threat Hunting program, which uses AI-driven analysis combined with human expertise to identify advanced threats that evade traditional detection methods.</description><pubDate>Thu, 04 Jun 2026 18:00:59 GMT</pubDate></item><item><title>Winning the cyber marathon with Tony Giandomenico</title><link>https://blog.talosintelligence.com/winning-the-cyber-marathon-with-tony-giandomenico</link><guid isPermaLink="false">cst-357</guid><description>Tony Giandomenico, Senior Director of Product Management at Cisco Talos, discusses how frontier AI models are reshaping cybersecurity and describes the newly launched Cisco Talos Threat Hunting service, which combines AI and human analysis to detect threats bypassing existing security controls. The conversation also explores Giandomenico's leadership philosophy and how he balances intense product work with personal endurance pursuits.</description><pubDate>Thu, 04 Jun 2026 12:05:31 GMT</pubDate></item><item><title>Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting</title><link>https://blog.talosintelligence.com/hypotheses-telemetry-and-human-judgment-inside-cisco-talos-threat-hunting</link><guid isPermaLink="false">cst-358</guid><description>Cisco Talos Threat Hunting uses hypothesis-driven investigation combined with AI and human expertise to identify threats that evade traditional detection rules. Rather than waiting for known-bad patterns to trigger alerts, analysts form theories about adversary behavior based on threat intelligence and telemetry from 50 million sensors, then search proactively for those indicators. The approach enables detection of novel techniques before formal signatures exist and has successfully identified threats like KongTuke C2 by correlating data across multiple security domains.</description><pubDate>Thu, 04 Jun 2026 12:05:05 GMT</pubDate></item><item><title>Less panic patching, more precision</title><link>https://blog.talosintelligence.com/less-panic-patching-more-precision</link><guid isPermaLink="false">cst-359</guid><description>The article discusses optimizing patch prioritization by combining CVSS (severity) scores with EPSS (Exploit Prediction Scoring System), which estimates the probability of exploitation within 30 days based on real-world signals. It recommends supplementing the centralized KEV catalog with GCVE (Global CVE), a decentralized approach that provides faster enrichment and broader exploitation signals from multiple sources. The piece emphasizes that proper triage logic can reduce patch backlogs without weakening security posture as a surge in patching demand approaches.</description><pubDate>Thu, 28 May 2026 18:00:27 GMT</pubDate></item><item><title>MediaArea heap-based buffer overflow vulnerabilities</title><link>https://blog.talosintelligence.com/mediaarea-heap-based-buffer-overflow-vulnerabilities</link><guid isPermaLink="false">cst-361</guid><description>Cisco Talos disclosed four heap-based buffer overflow vulnerabilities in MediaArea's MediaInfoLib library version 26.01, all of which can lead to arbitrary code execution. The vulnerabilities are triggered by providing malicious media files and have been patched by the vendor. Talos has published Snort detection rules and vulnerability advisories for these issues.</description><pubDate>Wed, 27 May 2026 14:00:14 GMT</pubDate></item><item><title>The Internet Changes Before the Advisory Drops</title><link>https://greynoise.io/blog/the-internet-changes-before-the-advisory-drops</link><guid isPermaLink="false">cst-1850</guid><description>A GreyNoise study found that malicious targeting activity on the internet typically begins 11 days before vendors publicly disclose vulnerabilities, with the pattern observed across 33 CVEs from 16 vendors. The research showed eight distinct attack surges against a Cisco CVSS 10.0 zero-day compressed from 39 days to just 2 days before disclosure, suggesting attackers gain knowledge of flaws before official advisories.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC Zero-Day</title><link>https://recordedfuture.com/blog/march-2026-cve-landscape</link><guid isPermaLink="false">cst-1981</guid><description>Insikt Group identified 31 high-impact vulnerabilities actively exploited in March 2026, with 29 rated as very critical. The affected products span major vendors including Cisco, Microsoft, Google, ConnectWise, Citrix, and others, with Microsoft and Apple accounting for approximately 32% of the total. Notable findings include the Interlock ransomware group exploiting a Cisco Firewall Management Center zero-day, the continued exploitation of a nine-year-old Hikvision vulnerability, and public proof-of-concept exploits available for 10 of the 31 vulnerabilities.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Coordinated Credential-Based Campaign Targets Cisco and Palo Alto Networks VPN Gateways</title><link>https://greynoise.io/blog/credential-based-campaign-cisco-palo-alto-networks-vpn-gateways</link><guid isPermaLink="false">cst-1868</guid><description>GreyNoise has identified a coordinated, automated campaign attempting to compromise enterprise VPN gateways through credential-based attacks targeting Cisco SSL VPN and Palo Alto Networks GlobalProtect services. The campaign appears to be systematically probing authentication infrastructure across multiple organizations.</description><pubDate>Wed, 17 Dec 2025 00:00:00 GMT</pubDate></item><item><title>25,000 IPs Scanned Cisco ASA Devices — New Vulnerability Potentially Incoming</title><link>https://greynoise.io/blog/scanning-surge-cisco-asa-devices</link><guid isPermaLink="false">cst-1888</guid><description>GreyNoise detected two spikes in scanning activity targeting Cisco Adaptive Security Appliance (ASA) devices in late August, with one surge involving over 25,000 unique IP addresses. This represents a dramatic increase from the typical baseline of fewer than 500 daily scans, suggesting potential reconnaissance before a vulnerability disclosure.</description><pubDate>Thu, 04 Sep 2025 00:00:00 GMT</pubDate></item><item><title>GreyNoise Observes Active Exploitation of Cisco Vulnerabilities Tied to Salt Typhoon Attacks</title><link>https://greynoise.io/blog/greynoise-observes-active-exploitation-of-cisco-vulnerabilities-tied-to-salt-typhoon-attacks</link><guid isPermaLink="false">cst-1919</guid><description>GreyNoise detected active exploitation attempts against two Cisco vulnerabilities, CVE-2023-20198 and CVE-2018-0171, with over 110 malicious IP addresses targeting the former vulnerability from multiple countries. The vulnerabilities were mentioned in recent Salt Typhoon reporting but GreyNoise has not attributed the observed exploitation to the Chinese state-sponsored group.</description><pubDate>Mon, 24 Feb 2025 00:00:00 GMT</pubDate></item><item><title>Cisco and Wiz Help Customers Modernize Cybersecurity</title><link>https://wiz.io/blog/cisco-and-wiz-help-customers-modernize-cybersecurity</link><guid isPermaLink="false">cst-1496</guid><description>Cisco and Wiz have announced an enhanced collaboration to strengthen cloud security capabilities for their joint customers. The partnership aims to make security solutions more accessible across cloud-based businesses and improve overall cybersecurity posture.</description><pubDate>Wed, 12 Feb 2025 11:29:11 GMT</pubDate></item></channel></rss>