logo

Henry IV, Hotspur, Hal, and hallucinations

ID: 29822d91-5474-5389-b212-cd1943ab3887

STIX ID: report--29822d91-5474-5389-b212-cd1943ab3887

Feed Name: Cisco Talos

Threat Score
70/100

Date Published: 2026-02-26

Date Updated: 2026-04-27

Author: William Largent

...
...

Cisco Talos reports an ongoing campaign (attributed to actor UAT-10027) using a new DoH-based backdoor called "Dohdoor" to perform stealthy C2 and payload delivery via phishing, PowerShell scripts, and DLL sideloading against U.S. education and healthcare organizations; the newsletter also highlights active exploitation of CVE-2026-20127 in Cisco Catalyst SD-WAN, recent high-profile data breaches, and provides several malware file hashes and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.