Quantcast
Channel: Talos Blog
Browsing all 353 articles
Browse latest View live
↧

Image may be NSFW.
Clik here to view.

Vulnerability Spotlight: Content Security Policy bypass in Microsoft Edge,...

The vulnerabilities were discovered by Nicolai Grødum of Cisco.Today, Talos is releasing details of vulnerabilities discovered in Microsoft Edge browser as well as older versions of Google Chrome...

View Article


Image may be NSFW.
Clik here to view.

Another Apache Struts Vulnerability Under Active Exploitation

This post authored by Nick Biasini with contributions from Alex Chiu.Earlier this week, a critical vulnerability in Apache Struts was publically disclosed in a security advisory. This new...

View Article


Image may be NSFW.
Clik here to view.

Vulnerability Spotlight: TALOS-2017-0430/0431: Multiple Vulnerabilities in...

Vulnerability discovered by Marcin Noga of Cisco TalosOverviewTalos has discovered two remote code execution vulnerabilities in the the FreeXL library. FreeXL is an open source C library to extract...

View Article

Image may be NSFW.
Clik here to view.

Microsoft Patch Tuesday - September 2017

Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 81 new...

View Article

Image may be NSFW.
Clik here to view.

Vulnerability Spotlight: LibOFX Tag Parsing Code Execution Vulnerability

This vulnerability was discovered by Cory Duplantis of TalosOverviewLibOFX is an open source implementation of OFX (Open Financial Exchange) an open format used by financial institutions to share...

View Article


Image may be NSFW.
Clik here to view.

Vulnerability Spotlight: YAML Parsing Remote Code Execution Vulnerabilities...

Vulnerabilities discovered by Cory Duplantis of Talos.Talos is disclosing the presences of remote code execution vulnerabilities in the processing of Yet Another Markup Language (YAML) content in...

View Article

Image may be NSFW.
Clik here to view.

Deep Dive in MarkLogic Exploitation Process via Argus PDF Converter

This post authored by Marcin Noga with contributions from William LargentTalos discovers and responsibly discloses software vulnerabilities on a regular basis. Occasionally we publish a deep technical...

View Article

Image may be NSFW.
Clik here to view.

Beers with Talos EP12 - IrmaGerd! The Internet Ate Our Podcast!

Beers with Talos (BWT) Podcast Episode 12 is now available.  Download this episode and subscribe to Beers with Talos:If iTunes and Google Play aren't your thing: www.talosintelligence.com/podcastBeers...

View Article


Image may be NSFW.
Clik here to view.

Threat Round Up For Sept 8 - Sept 15

Today, Talos is publishing a glimpse into the most prevalent threats we've observed between September 08 and September 15. As with previous round-ups, this post isn't meant to be an in-depth analysis....

View Article


Image may be NSFW.
Clik here to view.

CCleanup: A Vast Number of Machines at Risk

This post was authored by: Edmund Brumaghin, Ross Gibb, Warren Mercer, Matthew Molyett, and Craig WilliamsUpdate 9/18: CCleaner Cloud version 1.07.3191 is also reported to be affectedIntroduction...

View Article

Image may be NSFW.
Clik here to view.

Beers with Talos EP 13:A Vast CCleanup, Strutting Your Stuff, and the...

Beers with Talos (BWT) Podcast Episode 13 is now available.  Download this episode and subscribe to Beers with Talos:If iTunes and Google Play aren't your thing: www.talosintelligence.com/podcastBeers...

View Article

Image may be NSFW.
Clik here to view.

CCleaner Command and Control Causes Concern

This post was authored by Edmund Brumaghin, Earl Carter, Warren Mercer, Matthew Molyett, Matthew Olney, Paul Rascagneres and Craig Williams.Note: This blog post discusses active research by Talos into...

View Article

Image may be NSFW.
Clik here to view.

FIN7 Group Uses JavaScript and Stealer DLL Variant in New Attacks

This post was authored by Michael Gorelik and Josh ReynoldsExecutive SummaryThroughout this blog post we will be detailing a newly discovered RTF document family that is being leveraged by the FIN7...

View Article


Image may be NSFW.
Clik here to view.

Banking Trojan Attempts To Steal Brazillion$

This post was authored by Warren Mercer, Paul Rascagneres and Vanja SvajcerIntroductionBanking trojans are among some of the biggest threats to everyday users as they directly impact the user in terms...

View Article

Image may be NSFW.
Clik here to view.

Threat Round Up for Sept 22 - Sept 29

Today, Talos is publishing a glimpse into the most prevalent threats we've observed between September 22 and September 29. As with previous round-ups, this post isn't meant to be an in-depth analysis....

View Article


Image may be NSFW.
Clik here to view.

Beers with Talos EP14: Ranking Threats and Avoiding Bush League Breach Response

Beers with Talos (BWT) Podcast Episode 14 is now available.  Download this episode and subscribe to Beers with Talos:If iTunes and Google Play aren't your thing: www.talosintelligence.com/podcastEP14...

View Article

Image may be NSFW.
Clik here to view.

Vulnerability Spotlight: Multiple vulnerabilities in Computerinsel Photoline

These vulnerabilities are discovered by Piotr Bania of Cisco Talos.Today, Talos is releasing details of multiple vulnerabilities discovered within the Computerinsel GmbH PhotoLine image processing...

View Article


Image may be NSFW.
Clik here to view.

Vulnerability Spotlight: Arbitrary Code Execution Bugs in Simple DirectMedia...

Today, Talos is disclosing two vulnerabilities that have been identified in the Simple DirectMedia Layer library. Simple DirectMedia Layer (SDL) is a cross-platform development library designed for use...

View Article

Image may be NSFW.
Clik here to view.

Microsoft Patch Tuesday - October 2017

Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 63 new...

View Article

Image may be NSFW.
Clik here to view.

Spoofed SEC Emails Distribute Evolved DNSMessenger

This post was authored by Edmund Brumaghin, Colin Grady, with contributions from Dave Maynor and @Simpo13.Executive SummaryCisco Talos previously published research into a targeted attack that...

View Article
Browsing all 353 articles
Browse latest View live