Vulnerability Spotlight: Content Security Policy bypass in Microsoft Edge,...
The vulnerabilities were discovered by Nicolai Grødum of Cisco.Today, Talos is releasing details of vulnerabilities discovered in Microsoft Edge browser as well as older versions of Google Chrome...
View ArticleAnother Apache Struts Vulnerability Under Active Exploitation
This post authored by Nick Biasini with contributions from Alex Chiu.Earlier this week, a critical vulnerability in Apache Struts was publically disclosed in a security advisory. This new...
View ArticleVulnerability Spotlight: TALOS-2017-0430/0431: Multiple Vulnerabilities in...
Vulnerability discovered by Marcin Noga of Cisco TalosOverviewTalos has discovered two remote code execution vulnerabilities in the the FreeXL library. FreeXL is an open source C library to extract...
View ArticleMicrosoft Patch Tuesday - September 2017
Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 81 new...
View ArticleVulnerability Spotlight: LibOFX Tag Parsing Code Execution Vulnerability
This vulnerability was discovered by Cory Duplantis of TalosOverviewLibOFX is an open source implementation of OFX (Open Financial Exchange) an open format used by financial institutions to share...
View ArticleVulnerability Spotlight: YAML Parsing Remote Code Execution Vulnerabilities...
Vulnerabilities discovered by Cory Duplantis of Talos.Talos is disclosing the presences of remote code execution vulnerabilities in the processing of Yet Another Markup Language (YAML) content in...
View ArticleDeep Dive in MarkLogic Exploitation Process via Argus PDF Converter
This post authored by Marcin Noga with contributions from William LargentTalos discovers and responsibly discloses software vulnerabilities on a regular basis. Occasionally we publish a deep technical...
View ArticleBeers with Talos EP12 - IrmaGerd! The Internet Ate Our Podcast!
Beers with Talos (BWT) Podcast Episode 12 is now available. Â Download this episode and subscribe to Beers with Talos:If iTunes and Google Play aren't your thing:Â www.talosintelligence.com/podcastBeers...
View ArticleThreat Round Up For Sept 8 - Sept 15
Today, Talos is publishing a glimpse into the most prevalent threats we've observed between September 08 and September 15. As with previous round-ups, this post isn't meant to be an in-depth analysis....
View ArticleCCleanup: A Vast Number of Machines at Risk
This post was authored by: Edmund Brumaghin, Ross Gibb, Warren Mercer, Matthew Molyett, and Craig WilliamsUpdate 9/18:Â CCleaner Cloud version 1.07.3191 is also reported to be affectedIntroduction...
View ArticleBeers with Talos EP 13:A Vast CCleanup, Strutting Your Stuff, and the...
Beers with Talos (BWT) Podcast Episode 13 is now available. Â Download this episode and subscribe to Beers with Talos:If iTunes and Google Play aren't your thing:Â www.talosintelligence.com/podcastBeers...
View ArticleCCleaner Command and Control Causes Concern
This post was authored by Edmund Brumaghin, Earl Carter, Warren Mercer, Matthew Molyett, Matthew Olney, Paul Rascagneres and Craig Williams.Note: This blog post discusses active research by Talos into...
View ArticleFIN7 Group Uses JavaScript and Stealer DLL Variant in New Attacks
This post was authored by Michael Gorelik and Josh ReynoldsExecutive SummaryThroughout this blog post we will be detailing a newly discovered RTF document family that is being leveraged by the FIN7...
View ArticleBanking Trojan Attempts To Steal Brazillion$
This post was authored by Warren Mercer, Paul Rascagneres and Vanja SvajcerIntroductionBanking trojans are among some of the biggest threats to everyday users as they directly impact the user in terms...
View ArticleThreat Round Up for Sept 22 - Sept 29
Today, Talos is publishing a glimpse into the most prevalent threats we've observed between September 22 and September 29. As with previous round-ups, this post isn't meant to be an in-depth analysis....
View ArticleBeers with Talos EP14: Ranking Threats and Avoiding Bush League Breach Response
Beers with Talos (BWT) Podcast Episode 14 is now available. Â Download this episode and subscribe to Beers with Talos:If iTunes and Google Play aren't your thing:Â www.talosintelligence.com/podcastEP14...
View ArticleVulnerability Spotlight: Multiple vulnerabilities in Computerinsel Photoline
These vulnerabilities are discovered by Piotr Bania of Cisco Talos.Today, Talos is releasing details of multiple vulnerabilities discovered within the Computerinsel GmbH PhotoLine image processing...
View ArticleVulnerability Spotlight: Arbitrary Code Execution Bugs in Simple DirectMedia...
Today, Talos is disclosing two vulnerabilities that have been identified in the Simple DirectMedia Layer library. Simple DirectMedia Layer (SDL) is a cross-platform development library designed for use...
View ArticleMicrosoft Patch Tuesday - October 2017
Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 63 new...
View ArticleSpoofed SEC Emails Distribute Evolved DNSMessenger
This post was authored by Edmund Brumaghin, Colin Grady, with contributions from Dave Maynor and @Simpo13.Executive SummaryCisco Talos previously published research into a targeted attack that...
View Article