Threat Intelligence
Community feed · Vendors

Vendor Threat Advisories

The latest threat research aggregated from Vendor Threat Advisories — browse the feed inside NivX, click through to read the full article on the source site.

Article previews are curated from Vendor Threat Advisories. We show the title, cover image and a short snippet here; clicking any card opens the full article on the source site so the original authors get proper credit.
Threat Research

We've got one word for it, and it's usually the wrong one

In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address it…

Sep 10, 2026
Read on Vendors
Threat Research

Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software…

Sep 9, 2026
Read on Vendors
Threat Research

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."…

Sep 8, 2026
Read on Vendors
Threat Research

ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as th…

Sep 8, 2026
Read on Vendors
Threat Research

ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Shee…

Sep 8, 2026
Read on Vendors
Threat Research

The story behind the intelligence

From engaging with cybercriminals to surviving a live Flamin’ Hot Cheetos taste test, Hazel reflects on the latest Beers with Talos with Azim, where they cover the full spectrum of what it takes to ga…

Sep 3, 2026
Read on Vendors
Threat Research

“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend

In his first Threat Source newsletter, David Bianco explores the critical need for operational sovereignty in customizing AI guardrails to maintain the defender’s advantage…

Aug 27, 2026
Read on Vendors
Threat Research

JavaScript obfuscation: From party trick to phishing kit

Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem…

Aug 27, 2026
Read on Vendors
Threat Research

Choose your fighter: Balancing competing requirements to select models for your AI SOC

Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. Her…

Aug 26, 2026
Read on Vendors
Threat Research

The safety penalty: Reclaiming operational sovereignty in the age of AI

As frontier AI models become increasingly restrictive, security teams are facing a "safety penalty" that hampers real-time incident response. Discover how organizations can move toward operational sov…

Aug 25, 2026
Read on Vendors
Threat Research

Is Cyber missing the Marque?

In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in…

Aug 20, 2026
Read on Vendors
Threat Research

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, a…

Aug 20, 2026
Read on Vendors
Threat Research

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affe…

Aug 20, 2026
Read on Vendors
Threat Research

Describing attacks with crime script analysis

Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrup…

Aug 19, 2026
Read on Vendors
Threat Research

Curiouser and Curiouser

In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correc…

Aug 13, 2026
Read on Vendors