If that "quick $300 consultation" offer in your DMs feels too good to be true, your gut is likely right. Check out Martin’s latest Threat Source newsletter: cs.co/6017BGgBQb
Join Cisco’s Jessica Oppenheimer inside the Black Hat NOC to see how AI agents are investigating threats in the world’s most hostile network, and why human oversight remains essential: cs.co/6010BG9WPn
ICYMI: The Beers with Talos team caught up with Martin Lee to discuss why he swapped human virus research for the internet, how ultra-running keeps him sane, and exactly how many Lamborghinis it takes to sink a $245M crypto theft: cs.co/6017BG5V0F
Join us for the latest episode of Talos Takes as Vanja Svajcer breaks down a multi-stage infection chain that leverages ClickFix social engineering and EtherHiding to store malicious code on the blockchain: cs.co/6018BGjDOQ
Our first findings from the CAIRN project analyze CLOSEDQUORUM, the first documented autonomous AI C2 implant to demonstrate "effort displacement." Read our latest blog to understand how this architecture allows AI to execute attack phases independently: cs.co/6019BGb7Jh
Take a brief video tour of CAIRN, Talos’ new open-source research toolkit for investigating AI-integrated malware. Researchers can surface samples, uncover connections between them, and identify similarities that conventional code comparison may miss: cs.co/6014BGdRlq
Cisco Talos is proud to introduce CAIRN, a new metadata-first research toolkit designed to scale the hunting and classification of AI-integrated malware without defenders needing to download binaries: cs.co/6014BGbAwu
Does an AI slowdown really matter for cybersecurity? In the latest newsletter, David breaks down why your best defense isn't chasing the next big model, but doubling down on the security fundamentals that keep your environment safe: cs.co/6016BGTZLk
From the rise of newer threat groups like "The Gentlemen" to Qilin’s AI usage, our latest blog post examines the shifting ransomware landscape across Japan during the first half of 2026: cs.co/6018BGTdXG
We might not be able to prevent the discovery of vulnerabilities in “unpatchable” systems, but we can ensure that attackers do not have an easy path to exploit them in the field. Read the blog: cs.co/6019BGRFHJ
In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address it: cs.co/6015BGznI5
Ah, the crisp fall air, brand-new books and backpacks, and the quiet irony of cybercriminals turning on each other to steal a few extra bucks. This newest Talos Takes explores a browser-based variant of ClickFix: cs.co/6015BGHdxl
Cisco Talos has uncovered an infection chain using WebDAV, BNB Smart Chain, and ClickFix tactics to deploy the Amatera stealer, ZigCryptoStealer, and unauthorized NetSupport Manager access: cs.co/6017BGHWoH
Cisco Talos is tracking a ClickFix variant that exploits the Google Visualization API for command and control, enabling attackers to hijack browser sessions and steal cryptocurrency from unsuspecting users: cs.co/6015BGHmkh