惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
S
SegmentFault 最新的问题
V
Visual Studio Blog
人人都是产品经理
人人都是产品经理
阮一峰的网络日志
阮一峰的网络日志
腾讯CDC
Stack Overflow Blog
Stack Overflow Blog
博客园 - 【当耐特】
Recent Announcements
Recent Announcements
I
InfoQ
U
Unit 42
博客园_首页
GbyAI
GbyAI
Hugging Face - Blog
Hugging Face - Blog
罗磊的独立博客
博客园 - 叶小钗
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
D
DataBreaches.Net
aimingoo的专栏
aimingoo的专栏
月光博客
月光博客
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 聂微东
T
Tailwind CSS Blog
量子位

Cisco Talos Blog

Should you care about an “AI slowdown?” Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use Securing the unpatchable in an age of AI-driven vulnerabilities We've got one word for it, and it's usually the wrong one Active exploitation of Cisco Secure Firewall Management Center vulnerabilities Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 The story behind the intelligence “Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend JavaScript obfuscation: From party trick to phishing kit Choose your fighter: Balancing competing requirements to select models for your AI SOC The safety penalty: Reclaiming operational sovereignty in the age of AI Is Cyber missing the Marque? UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations Describing attacks with crime script analysis Curiouser and Curiouser Dissecting the JWR phishing framework Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities Why metaphor may dictate your security strategy “Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI [Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents You were onto something with “It’s the Climb,” Miley Black Hat special: Rewind and revisit IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains Don’t swing at everything Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel Begun, the Patch Wars have The Hunter's Paradox: Is it time to embrace automated threat hunting?
Preview: Cisco Talos at Black Hat USA 2026
Hazel Burton · 2026-07-23 · via Cisco Talos Blog

We’re looking forward to having some great conversations with those of you heading to the desert for Hacker Summer Camp 2026. We have a presence within the Cisco and Splunk booth (2633) during Black Hat where you can chat to us about our latest threat research, incident response, and how Talos powers the Cisco portfolio with our intelligence.

Or, feel free to pretend to want to talk to us about those things while grabbing a new multicolored Snorty. That’s fine, too.

Here’s some of the ways we’ll be showing up at Black Hat, alongside our friends at Cisco and Splunk: 

Meet the researchers: Booth lightning talks 

Our Talosians have spent a lot of time over the last few months putting together some truly... well, enlightening lightning talks. Throughout Wednesday and Thursday at Black Hat, you can expect to see such topics as:

  • Threat actor prompting and the emerging ways adversaries are using prompts, agents, skills, and tools to improve efficiency
  • Warlock ransomware, and why this group does not fit neatly into a simple RaaS or state-linked label.
  • Zero trust for agent identity
  • Building a "second brain" for your second brain
  • Predicting cybersecurity fraud
  • Vulnerability discovery trends
  • ... and much more

Lightning talks are 15 minutes. That’s less than 9% of The Odyssey. Don’t worry, we cut the bit where everyone gets turned into Snorty pigs.

Main Stage keynote: Security at agentic scale

Date/Time: Wednesday, August 5 | 11:30 a.m. – 12:00 p.m. (Main Stage, Business Hall)

Cisco's David Dalling and Rick Miles will be giving a Main Stage keynote all about protecting the enterprise in the age of AI agents.

As AI agents become increasingly capable (and increasingly privileged) inside enterprise environments, organizations face an entirely new set of security challenges. Drawing on research from across Cisco, the talk will explore what it takes to secure organizations as autonomous systems become part of everyday business operations.

Talos workshop: When AI finds vulnerabilities faster than humans can patch 

Date/Time: Wednesday, August 5 | 1:30 p.m. – 3:00 p.m. (Oceanside E, Level 2)

If you're looking for something hands-on and interactive, don't miss our workshop with Talos’ Nick Biasini and Cisco’s Omar Santos. In two parts, they’ll demonstrate practical ways security teams can incorporate AI into SOC workflows to identify sophisticated adversary behavior.

In Part 1, Omar will discuss the Foundry Security Spec. He’ll walk through how to deploy, build testing harnesses around its core agent roles, and integrate Project CodeGuard so that findings from autonomous testing can be converted into reusable secure-coding rules and future prevention. 

In Part 2, Nick will demonstrate how Talos leverages AI to transform threat hunting. We will explore best practices for identifying adversarial AI tactics and provide attendees with insights into how Cisco Talos is leveraging AI for defense. Participants will learn how to integrate these defensive AI strategies into their own SOC workflows.  

Splunk workshop: When agents become insider threats 

Date/Time: Wednesday, August 5 | 10:15 a.m. – 11:00 a.m. (Mandalay Bay I)

The Splunk workshop considers the fact that the next insider threat may not be a person; it may be an autonomous agent using valid credentials and delegated authority. 

Attendees will see real-world attack paths in which agents move sensitive data across tools, distribute brute-force attempts under a single delegation, and manipulate internal systems without triggering traditional SIEM or UEBA alerts. 

It was Talos all along

One of the questions we hear often is: "How do I buy Talos?"

The answer… is that you probably already did.

Throughout the Cisco booth you'll see our “It was Talos all along” campaign, highlighting the fact that Talos isn't a standalone product or a threat intelligence feed you bolt onto your security stack. Talos is already embedded across the Cisco security portfolio, which continually benefits from our threat research and intelligence.

To build your curiosity, take a look at our new video, “Where Protection Starts,” to see how Cisco Talos Intelligence Integrations help reduce uncertainty in the SOC:

See you in Las Vegas.