Advertisement
The AI Safety Penalty: How LLM Guardrails Hinder Defenders
Cisco Talos warns about the 'AI safety penalty,' where large language model guardrails impede legitimate defensive operations, giving attackers an advantage.
Critical Cisco Nexus 9000 RCE (CVE-2026-20212) & IOS XR Hardening
Cisco addresses a critical RCE flaw (CVE-2026-20212) in Nexus 9000 switches, alongside significant IOS XR hardening updates.
Evaluating LLMs for SOC Operations and Log Analysis
Discover how Cisco Talos evaluated 66 model and reasoning combinations for SOC workflows, focusing on cost, speed, and consistency.
Cisco Patches Nine Crosswork and Secure Workload Flaws
Cisco patches nine vulnerabilities in Crosswork and Secure Workload platforms, with five flaws scoring the maximum CVSS 10.0 severity rating.
CVE-2026-20349: Cisco ASA/FTD DoS Vulnerability Under Active Exploit
CISA warns of active exploitation of CVE-2026-20349, a heap inspection vulnerability causing DoS in Cisco ASA and FTD devices.
Cisco Talos: AI, Adaptive Malware, and Threat Intelligence
Cisco Talos Intelligence Integrations help defend against advanced threats like AI-driven attacks and adaptive malware by applying real-time threat intelligence.
AI-Driven Vulnerability Surges and UAT-11795 Starland RAT Campaign
Analysis of a record Patch Tuesday driven by AI vulnerability research, alongside Cisco Talos findings on UAT-11795 deploying Starland RAT.
Cisco Talos Previews AI Threats and Warlock Ransomware at Black Hat
Cisco Talos outlines research on AI threat actor tactics, Warlock ransomware, and agent identity security ahead of Black Hat USA 2026.
msaRAT: Chaos Ransomware's Covert Browser-Based C2
Cisco Talos uncovers msaRAT, a new Rust-based RAT used by Chaos ransomware for covert C2 via Chrome DevTools Protocol, evading detection.
Talos Q2 2026 Report: Phishing and Living-off-the-Land Trends
Cisco Talos Q2 2026 report reveals spikes in MFA-bypassing phishing and malicious use of remote management tools.
CVE-2026-20316: Cisco Secure FMC Hard-coded Password Vulnerability
CISA confirms active exploitation of CVE-2026-20316, a hard-coded password vulnerability in Cisco Secure Firewall Management Center.
Cisco FMC CVE-2026-20316: Static Credentials Actively Exploited
CISA adds CVE-2026-20316 to its Known Exploited Vulnerabilities catalog following active exploitation of static credentials in Cisco Firewall Management Center.
Cisco Antares AI Models: Enhancing Source Code Vulnerability Detection
Cisco introduces low-cost, open-weight Antares AI models for rapid, efficient source code vulnerability detection, empowering developers and security teams.
Cisco Secures Non-Human Identity with Astrix and WideField
Cisco's acquisition of Astrix and WideField signals a strategic shift toward Non-Human Identity (NHI) as a critical control plane for securing cloud access.
Cisco Unified Communications Manager: Urgent Patch for Active Exploitation
CISA mandates urgent patching for an actively exploited vulnerability in Cisco Unified Communications Manager, posing immediate risk to federal agencies and beyond.
Cisco CUCM SSRF Flaw: Rapid Exploitation & Root Privilege Escalation
Attackers are rapidly weaponizing a Cisco Unified CM server-side request forgery (SSRF) flaw, escalating privileges to root. Immediate patching is critical.
CVE-2026-20245: Zero-Day Root Privilege Escalation in Cisco SD-WAN
Attackers are exploiting a zero-day vulnerability in Cisco Catalyst SD-WAN Manager to gain root access. Learn how to detect and remediate CVE-2026-20245.
Cisco Catalyst SD-WAN CVE-2026-20245 Root Access Exploit Analysis
Exploitation of Cisco Catalyst SD-WAN zero-day CVE-2026-20245 allows root access. Mandiant reveals active abuse months prior to the June 2026 disclosure.
Cisco SD-WAN CVE-2023-20252 Exploited via Rogue Peering - Patch Now
Attackers exploited Cisco SD-WAN Manager flaws like CVE-2023-20252 for two months before disclosure. Learn how to secure your vManage infrastructure today.
CVE-2024-20230: Critical RCE in Cisco Unified CM Actively Exploited
Cisco confirms active exploitation of CVE-2024-20230, a critical 9.9 CVSS vulnerability in Unified Communications Manager. Urgent patching is required.
Cisco Unified CM CVE-2026-20230: File-Write Path to Root Exploited
Exploitation of CVE-2026-20230 in Cisco Unified CM allows unauthenticated root access via file-write. Critical security updates are required to prevent compromise.
CVE-2026-20230: Cisco Unified CM SSRF Actively Exploited
Cisco Unified CM Server is vulnerable to CVE-2026-20230, a high-severity SSRF flaw now under active exploitation. Patch immediately to prevent attacks.
Cisco Acquires WideField Security to Advance Splunk Agentic SOC
Cisco expands its security portfolio by acquiring WideField Security to integrate identity and session context into Splunk’s AI-driven Agentic SOC platform.
Cisco Catalyst SD-WAN Manager CVE-2026-20262 Exploited in the Wild
Cisco patches an actively exploited medium-severity vulnerability in Catalyst SD-WAN Manager (CVE-2026-20262) that allows authenticated file creation.