We've got one word for it, and it's usually the wrong one
In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address it.
GuardBreaker: Derailing AI-assisted malware analysis with a code comment
LLM-based code scanners won’t help attackers build a nuclear weapon, but that refusal could work in their favor
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.
ESET WeLiveSecurity MalwareSafe word: What is it and why do you need one?
AI scams are now hyper-realistic. But there’s one simple way to see through them.
Talos Intelligence VulnMicrosoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
Talos Intelligence MalwareClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.
Talos Intelligence BreachClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session.
Talos Intelligence MalwareThe story behind the intelligence
From engaging with cybercriminals to surviving a live Flamin’ Hot Cheetos taste test, Hazel reflects on the latest Beers with Talos with Azim, where they cover the full spectrum of what it takes to gather threat intel.
ESET WeLiveSecurity MalwareI’ve been deepfaked: What do I do?
Don’t panic if you spot an illegally created image or video of you online – there are ways to request its removal
ESET WeLiveSecurity MalwareThis month in security with Tony Anscombe – August 2026 edition
Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity news
Talos Intelligence Malware“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend
In his first Threat Source newsletter, David Bianco explores the critical need for operational sovereignty in customizing AI guardrails to maintain the defender’s advantage.
Talos Intelligence MalwareJavaScript obfuscation: From party trick to phishing kit
Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem.
ESET WeLiveSecurity MalwareAI-assisted reconnaissance: Why everyone could be a viable target for fraud
It’s getting cheaper and easier for cybercriminals to research potential victims. Here’s what’s still in your control.
Talos Intelligence MalwareChoose your fighter: Balancing competing requirements to select models for your AI SOC
Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. Here's how to choose.
Talos Intelligence MalwareThe safety penalty: Reclaiming operational sovereignty in the age of AI
As frontier AI models become increasingly restrictive, security teams are facing a "safety penalty" that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defensive AI keeps pace with unconstrained adversaries.
Objective-See MalwareDetecting (Evil) Dylibs
Attackers are increasingly turning to dylibs to host malicious code, gain stealth, and inherit the trust of legitimate processes. In this blog post, we explore how to statically enumerate dylib dependencies, inspect libraries loaded into running processes, and leverage Endpoint Security to detect, and even block, malicious dylibs at load time.
Talos Intelligence MalwareIs Cyber missing the Marque?
In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensive cyber operations.
Talos Intelligence BreachUAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.
Talos Intelligence MalwareUAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics.
Talos Intelligence MalwareDescribing attacks with crime script analysis
Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.
ESET WeLiveSecurity MalwareHow QR-code phishing can slip past corporate security measures
Quishing has become a popular alternative to traditional phishing. Here’s how businesses can close the gap.
Talos Intelligence MalwareCuriouser and Curiouser
In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers.
- ESET WeLiveSecurity Vuln
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?
And will today’s surge in AI-driven vulnerability discovery eventually make tomorrow’s software safer?
SentinelOne Labs MalwareThe Model Is the Malware | What Four Agentic Intrusions Tell Defenders
OpenAI, Anthropic and Meta disclosed agents reaching external systems. The tools didn't matter, and that changes the playbook for investigating intrusions.
Talos Intelligence MalwareDissecting the JWR phishing framework
Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.
- ESET WeLiveSecurity Malware
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility
The incident involving OpenAI models shows that autonomous hacks make human oversight more important, not less
ESET WeLiveSecurity MalwareBlack Hat USA 2026: AI is racing ahead of cybersecurity controls
AI took center stage, but the clearest lesson was less about what AI can do than about who is accountable when something goes wrong
Talos Intelligence VulnMicrosoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical."
ESET WeLiveSecurity MalwareAre AI tutors safe for your kids?
AI tutors can offer useful support, but their quality and safeguards vary widely. Here’s what parents should check before handing one to a child.
Talos Intelligence MalwareWhy metaphor may dictate your security strategy
In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely change how we react to the threat.
- Talos Intelligence Malware
“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI
Talos has collected prompt logs from threat actor endpoints running various applications, such as Claude Code, CodeX, Cursor, or Gemini. This blog is an analysis of the ways we've seen bad actors leveraging cloud-based AI.
- Talos Intelligence Malware
[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents
Register for an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents Talos IR faced in Q2.
- Objective-See Malware
The Dacls RAT ...now on macOS!
A sophisticated Lazarus Group implant has arrived on macOS. In this post, we deconstruct the Mac variant of a OSX.Dacls, detailing its install logic, persistence, and capabilities.
- Objective-See Vuln
The 'S' in Zoom, Stands for Security
Today we uncover two (local) security flaws in Zoom's latest macOS client. First, a privilege escalation vulnerability, and second, a method to surreptitiously access a user's webcam and microphone (via Zoom).
- Objective-See Vuln
Sniffing Authentication References on macOS
CVE-2017-7170 was a local priv-esc vulnerability that affected OSX/macOS for over a decade! Here (for the first time!), we dive into the technical details of finding the bug, the core flaw, and exploitation.
- Objective-See Malware
Weaponizing a Lazarus Group Implant
The Lazarus group's latest implant/loader supports in-memory loading of 2nd-stage payloads. In this post we describe exactly how to repurposing this 1st-stage loader to execute *our* custom 'fileless' payloads!
- Objective-See Malware
The Mac Malware of 2019
Our annual report on all the Mac malware of the year - including samples for download, infection vectors, persistence mechanisms, payloads and more!
- Objective-See Malware
Mass Surveillance, is an (un)Complicated Business
A massively popular iOS application turns out to be a government spy tool! Here, we analyze the app; decrypting its binary and studying its network traffic.
- Objective-See Malware
Lazarus Group Goes 'Fileless'
The rather infamous APT group, "Lazarus", continues to evolve their macOS capabilities. Today, we tear apart their latest 1st-stage implant that supports remote download & in-memory execution of secondary payloads!
- Objective-See Vuln
[0day] Abusing XLM Macros in SYLK Files
A 0day logic flaw in Microsoft Excel leads to 'remote' code execution on macOS, via malicious macros.
- Objective-See Malware
Pass the AppleJeus
A new macOS backdoor written by the infamous Lazarus APT group needs analyzing. Here, we examine it's infection vector, method of persistence, capabilities, and more!
- Objective-See Malware
Writing a File Monitor with Apple's Endpoint Security Framework
Learn how to leverage Apple's new Endpoint Security Framework to create a comprehensive (user-mode) File Monitor for macOS 10.15!
- Objective-See Malware
Writing a Process Monitor with Apple's Endpoint Security Framework
Learn how to leverage Apple's new Endpoint Security Framework to create a comprehensive (user-mode) Process Monitor for macOS 10.15!
- Objective-See Malware
Getting Root with Benign AppStore Apps
In this guest blog post, "Objective by the Sea" speaker, Csaba Fitzl writes about an interesting way to get root via Apps from the official Mac App Store!
- Objective-See Malware
Burned by Fire(fox) (Part III)
Recently, an attacker targeted (Mac) users via a Firefox 0day. In this third post, we analyze a second backdoor used in the attack, detailing its persistence, capabilities, and ultimate identify it a new variant of the cross-platform Mokes malware!
- Objective-See Malware
Burned by Fire(fox) (Part II)
Recently, an attacker targeted (Mac) users via a Firefox 0day. In this second post, we fully reverse OSX.NetWire.A, revealing (for the first time!), its inner workings and complex capabilities.
- Objective-See Malware
Burned by Fire(fox) (Part I)
Recently, an attacker targeted (Mac) users via a Firefox 0day. In this first post, we triage and identify the malware (OSX.NetWire.A) utilized in this attack, identifying its methods of persistence, and more!
- Objective-See Malware
"Objective by the Sea" v2.0
After the success of #OBTS v1.0, we decided to go international and plan #OBTS v2.0 in Europe! In this blog post, we re-live the highlights (from Monaco!) of "Objective by the Sea" v2.0.
- Objective-See Malware
Rootpipe Reborn (Part II)
@CodeColorist continues writing about bugs, such as CVE-2019-8521 and CVE-2019-8565 that provide a mechanism to elevate privileges to root on macOS.
- Objective-See Vuln
Rootpipe Reborn (Part I)
In part one of a guest blog post, @CodeColorist writes about several neat macOS vulnerabilities.
- Objective-See Malware
Mac Adware, à la Python
Let's tear apart a persistent piece of adware, decompiling, decoding, and decompressing it's code to uncover its methods and capabilities.
- Objective-See Malware
Death by vmmap
A core Mojave utility is rather disastrously broken - causing a full-system lockup. Let's find out why!
- Objective-See Breach
Middle East Cyber-Espionage (part two)
The APT group WindShift has been targeting Middle Eastern governments with Mac implants. Let's (continue to) analyze their 1st-stage macOS implant: OSX.WindTail!
- Objective-See Malware
The Mac Malware of 2018
Our annual report on all the Mac malware of the year - including samples for download, infection vectors, persistence mechanisms, payloads and more!
- Objective-See Breach
Middle East Cyber-Espionage
The APT group WindShift has been targeting Middle Eastern governments with Mac implants. Let's analyze their 1st-stage macOS implant: OSX.WindTail!
- Objective-See Malware
Word to Your Mac
A malicious Word document targeting macOS users, was recently uncovered. Let's extract the embedded macros, decode an embedded downloader, and retrieve the 2nd-stage payload!
- Objective-See Malware
[0day] Mojave's Sandbox is Leaky
The macOS sandbox is seeks to prevent malicious applications from surreptitiously spy on unsuspecting users. Turns out, it's trivial to sidestep some of these protections, resulting in significant privacy implications!
- Objective-See Malware
A Deceitful 'Doctor' in the Mac App Store
A massively popular app from the official Mac App Store, surreptitiously steals your browsing history! By fully reversing the application, we can fully expose its functionality and rather shady capabilities.
- Objective-See Breach
Remote Mac Exploitation Via Custom URL Schemes
The WINDSHIFT APT group is successfully infecting Macs with a novel infection mechanism. By abusing custom URL scheme handlers and minimal user interaction, Macs can be remotely compromised!
- Objective-See Malware
[0day] Synthetic Reality
If you can programmatically generate synthetic mouse clicks, you can break macOS! Approving kernel extensions, dismissing privacy alerts, and much more more...