talosintelligence

What happened in Vegas (that you actually want to know about)

Cisco Talos unveiled several critical cybersecurity developments at Black Hat USA 2025, including a new multi-stage malware campaign named PS1Bot and groundbreaking research on AI guardrail bypasses and embedded chip vulnerabilities.

Malvertising campaign leads to PS1Bot, a multi-stage malware framework

A persistent malvertising campaign active throughout 2025 is delivering PS1Bot, a modular multi-stage malware framework written in PowerShell and C#. PS1Bot is designed for stealth and flexibility.

ReVault! When your SoC turns against you… deep dive edition

Researchers uncovered multiple critical vulnerabilities in Dell ControlVault3 and ControlVault3 Plus firmware, including CVE-2025-25215, CVE-2025-24922, and CVE-2025-24919.

WWBN, MedDream, Eclipse vulnerabilities

Researchers have disclosed multiple vulnerabilities across WWBN AVideo, MedDream PACS Premium, and Eclipse ThreadX FileX. These include cross-site scripting (XSS), race conditions, privilege escalation, and buffer overflow issues.

Bloomberg Comdb2 null pointer dereference and denial-of-service vulnerabilities

Researchers identified five critical vulnerabilities in Bloomberg’s Comdb2 version 8.1, an open-source clustered database system. These flaws can be exploited remotely to cause denial-of-service (DoS) conditions via specially crafted TCP packets.

MaaS operation using Emmenhtal and Amadey linked to threats against Ukrainian entities

A sophisticated Malware-as-a-Service (MaaS) operation has been identified leveraging the Emmenhtal loader and Amadey malware to distribute a variety of payloads. The campaign targets Ukrainian entities and utilizes public GitHub repositories.

Asus and Adobe vulnerabilities

Researchers have discovered four critical vulnerabilities—two in Asus Armoury Crate and two in Adobe Acrobat Reader. These vulnerabilities have been patched by their respective vendors.

Microsoft Patch Tuesday for July 2025 — Snort rules and prominent vulnerabilities

Microsoft’s July 2025 Patch Tuesday addresses 132 vulnerabilities, including 14 marked as critical. These span across Windows services, Microsoft Office, SharePoint, Hyper-V, and SQL Server.

Decrement by one to rule them all: AsIO3.sys driver exploitation

Two critical vulnerabilities in the ASUS AsIO3.sys driver (CVE-2025-1533 and CVE-2025-3464) allow local privilege escalation to SYSTEM level. These flaws affect ASUS Armory Crate and AI Suite applications.

Famous Chollima deploying Python version of GolangGhost RAT

PylangGhost is tailored for Windows, while the Golang version targets MacOS. The threat actors target professionals in cryptocurrency and blockchain industries, mostly in India, using fake job interviews.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags