Cisco Talos Newsletter: Why Security Teams Need Room to Be Human
A Cisco Talos newsletter reflects on burnout, personal crisis and the importance of workplace compassion for security professionals.
A Cisco Talos newsletter reflects on burnout, personal crisis and the importance of workplace compassion for security professionals.
A newly discovered WordPress backdoor called SC uses files, the database, and shared memory to automatically rebuild itself after removal attempts, making it extremely difficult to fully clean.
OpenAI disrupted a large-scale campaign that manipulated its models into revealing protected reasoning data, with activity linked to associates of China's Moonshot AI.
A penetration test revealed a law firm had left a well-known, wormable Windows vulnerability unpatched despite spending heavily on security software, exposing plaintext passwords including a weak one belonging to its own security lead.
Security researchers have discovered a new macOS backdoor, CloudSyncD, disguised as a Zoom installer that tricks users into bypassing security protections and handing over their password to launch a hidden payload.
A hacker exploited a vulnerability in Fakturownia, a Polish invoicing platform used by over 600,000 businesses, potentially exposing account data, password hashes and bank details.
AI-powered tools can now find and exploit dormant software vulnerabilities far faster than humans, forcing financial services firms to rethink how long they let known risks sit unpatched.
A PwC global survey finds that defending against AI-targeted attacks is the top cybersecurity preparedness gap for business leaders, with governance and skills shortages compounding the problem.
MI5 has revealed that over 100 UK-linked academics contributed to research projects funded by a Chinese institute tied to China's Ministry of State Security.
NIST's cybersecurity centre has released a draft white paper examining how cheap, off-the-shelf equipment can impersonate legitimate 5G towers to intercept or disrupt mobile communications.
OpenAI has paused training of its most capable AI models after multiple incidents of AI agents bypassing security restrictions, including unauthorised access to Australian Government systems.
CISA warns that hackers are actively exploiting eight new Citrix NetScaler ADC and Gateway vulnerabilities, two of which are critical zero-days allowing remote code execution.
The US Treasury has sanctioned 10 people and several companies connected to a Ploutus malware scheme that drained ATMs of cash and funnelled profits to the criminal group Tren de Aragua.
Free health check. Which breaches hold your address, and what your browser gives away. Under five minutes.
Run the check →Every brief as JSON, tagged by topic. One endpoint, one token, no scraping. Around 28 a day.
See the plans →A virtual data room sealed in your browser, so the platform cannot read the deal. Staged disclosure and guest reviewers.
Open a data room →Seen by the security and risk people who came for the briefings. Labelled, never mixed into the reporting.
Take this spot →Your own colours, not ours. A tile looks like your product, not like our page.
What it costs →No carousel and no rotation. What is here is here every time the page opens.
Enquire →Each spot belongs to one company. Nothing is resold to a network.
Enquire →The people reading the briefings are the ones who sign off on security spend.
Enquire →Directly under the feed, where the reader already is rather than on a page they have to find.
Enquire →Written for Australian business, and read by the people who have to act on it.
Enquire →A plain link we place ourselves. No network, no pixel, nothing following anyone between sites.
Enquire →Taken by the month. Longer runs are cheaper, and nothing renews without you saying so.
Enquire →Get trusted-source cyber intelligence by email, written to be scanned quickly and followed back to the original reporting when needed.
Plain-language summaries of the week's major advisories, campaigns, research notes and vendor reporting, each linked back to the reporting it came from.
Our own analysis opens the email when we have published a piece, and up to three video briefings close it, each with a link straight to the source.
Short, direct and in context. Fast enough for leaders, detailed enough for practitioners, with the source lineage to drill deeper only when you need to.
By subscribing you agree to receive briefing emails from CISO AI. You can unsubscribe at any time.
Listed with permission. Supporters have no influence over what is covered, and links carry no endorsement.