THREAT FIELD NOTESINTELLIGENCE FOR DEFENDERS
Back to home

Intel feed

Selected reporting from trusted security teams, translated into why it matters and what defenders can do next.

Live source reporting, refreshed at most once per hour.

SANS ISC · VulnerabilitySep 6, 2026

Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)

Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is…

SANS ISCVulnerability
Brief overview

This item was published by SANS ISC. Read the source report for its complete evidence, indicators, scope, and caveats.

Defender next steps

  • Confirm whether the affected product is present and internet-facing.
  • Review vendor guidance, patch status, and signs of exploitation before closing the item.
Read the original report at SANS ISC
SANS ISC · VulnerabilitySep 5, 2026

numbat - AI agent observability, (Fri, Sep 4th)

Enterprises face an unmanaged crisis of AI agent and MCP server sprawl, characterized by rapid, decentralized proliferation of autonomous agents, protocol connections operating with excessive privilege, opaque execution paths, and identity blind spots. Absent agent-aware governance, modern…

SANS ISCVulnerability
Brief overview

This item was published by SANS ISC. Read the source report for its complete evidence, indicators, scope, and caveats.

Defender next steps

  • Confirm whether the affected product is present and internet-facing.
  • Review vendor guidance, patch status, and signs of exploitation before closing the item.
Read the original report at SANS ISC
SANS ISC · ResearchSep 4, 2026

ISC Stormcast For Friday, September 4th, 2026 https://isc.sans.edu/podcastdetail/10082, (Fri, Sep 4th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

SANS ISCResearch
Brief overview

This item was published by SANS ISC. Read the source report for its complete evidence, indicators, scope, and caveats.

Defender next steps

  • Compare the reported behavior with your environment and current detection coverage.
  • Validate important findings in the original research before taking disruptive action.
Read the original report at SANS ISC
Cisco Talos · VulnerabilitySep 3, 2026

The story behind the intelligence

Welcome to this week’s edition of the Threat Source newsletter. Our goal is to get accurate threat intelligence to our audience as quickly as possible, with all the context you need to ask the right questions of your own environment: How at risk are we from this threat? Are we prepared for it? And…

Cisco TalosVulnerability
Brief overview

This item was published by Cisco Talos. Read the source report for its complete evidence, indicators, scope, and caveats.

Defender next steps

  • Confirm whether the affected product is present and internet-facing.
  • Review vendor guidance, patch status, and signs of exploitation before closing the item.
Read the original report at Cisco Talos
Unit 42 · ResearchSep 3, 2026

Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations.

Unit 42Research
Brief overview

This item was published by Unit 42. Read the source report for its complete evidence, indicators, scope, and caveats.

Defender next steps

  • Compare the reported behavior with your environment and current detection coverage.
  • Validate important findings in the original research before taking disruptive action.
Read the original report at Unit 42
SANS ISC · VulnerabilitySep 3, 2026

Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)

[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program] Honeypot-Omaha is a DShied Sensor located at the Internet Storm Center (ISC) that is set up as a decoy for the original target and deployed over the internet. It is a flawed and very vulnerable system that…

SANS ISCVulnerability
Brief overview

This item was published by SANS ISC. Read the source report for its complete evidence, indicators, scope, and caveats.

Defender next steps

  • Confirm whether the affected product is present and internet-facing.
  • Review vendor guidance, patch status, and signs of exploitation before closing the item.
Read the original report at SANS ISC
SANS ISC · ResearchSep 3, 2026

ISC Stormcast For Thursday, September 3rd, 2026 https://isc.sans.edu/podcastdetail/10080, (Thu, Sep 3rd)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

SANS ISCResearch
Brief overview

This item was published by SANS ISC. Read the source report for its complete evidence, indicators, scope, and caveats.

Defender next steps

  • Compare the reported behavior with your environment and current detection coverage.
  • Validate important findings in the original research before taking disruptive action.
Read the original report at SANS ISC
Unit 42 · ResearchSep 2, 2026

An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation

Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks.

Unit 42Research
Brief overview

This item was published by Unit 42. Read the source report for its complete evidence, indicators, scope, and caveats.

Defender next steps

  • Compare the reported behavior with your environment and current detection coverage.
  • Validate important findings in the original research before taking disruptive action.
Read the original report at Unit 42
Unit 42 · MalwareAug 31, 2026

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers.

Unit 42Malware
Brief overview

This item was published by Unit 42. Read the source report for its complete evidence, indicators, scope, and caveats.

Defender next steps

  • Review unusual sign-ins, recovery events, consent grants, and privilege changes.
  • Strengthen verification for helpdesk and other high-risk identity workflows.
Read the original report at Unit 42
Unit 42 · ResearchAug 28, 2026

Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety

New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security.

Unit 42Research
Brief overview

This item was published by Unit 42. Read the source report for its complete evidence, indicators, scope, and caveats.

Defender next steps

  • Compare the reported behavior with your environment and current detection coverage.
  • Validate important findings in the original research before taking disruptive action.
Read the original report at Unit 42
Cisco Talos · VulnerabilityAug 27, 2026

“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend

Welcome to this week’s edition of the Threat Source newsletter. Hello, everyone. Long time reader, first time writer here at the Threat Source newsletter! I wanted to start out by introducing myself. My colleague and friend Mick Baccio set the bar pretty high last week , so I was planning to tell…

Cisco TalosVulnerability
Brief overview

This item was published by Cisco Talos. Read the source report for its complete evidence, indicators, scope, and caveats.

Defender next steps

  • Confirm whether the affected product is present and internet-facing.
  • Review vendor guidance, patch status, and signs of exploitation before closing the item.
Read the original report at Cisco Talos
Cisco Talos · VulnerabilityAug 27, 2026

JavaScript obfuscation: From party trick to phishing kit

We open a JavaScript artifact hoping for code, and instead get string arrays, strangely named functions, encoded URLs, runtime decoders, and eval statements. That is the point where “reading the script” stops being enough. Obfuscated JavaScript is still code, but it is code with the useful context…

Cisco TalosVulnerability
Brief overview

This item was published by Cisco Talos. Read the source report for its complete evidence, indicators, scope, and caveats.

Defender next steps

  • Confirm whether the affected product is present and internet-facing.
  • Review vendor guidance, patch status, and signs of exploitation before closing the item.
Read the original report at Cisco Talos