Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Filtered by source: talos Clear filter
Martin Lee: Running through the Arctic (and the threat landscape)

2mo ago · talos

Martin Lee, EMEA Lead at Talos, shares his journey from academic research in human virology to leading cybersecurity initiatives. He reflects on the early days of the internet, the evolution of cyber threats, and the accidental discovery of advanced persistent threats (APT) while developing early spam filters. His current role focuses on analyzing the threat landscape and communicating insights to customers and partners. The discussion highlights the importance of curiosity and adaptability in cybersecurity careers.

Catan and Mouse

2mo ago · talos

Cisco Talos has identified ARToken, a sophisticated phishing-as-a-service (PhaaS) platform, which provides a wide range of capabilities including device code phishing, Primary Refresh Token (PRT) persistence, email access, business email compromise (BEC), and SharePoint exfiltration. The platform shares infrastructure and operational patterns with the previously documented EvilTokens platform. ARToken features a React-based dashboard and exposes over 80 API endpoints, indicating it is a mature BEC operations environment rather than a simple phishing kit.

15 IoCs
← Previous