Henry IV, Hotspur, Hal, and hallucinations
ID: 29822d91-5474-5389-b212-cd1943ab3887
STIX ID: report--29822d91-5474-5389-b212-cd1943ab3887
Feed Name: Cisco Talos
Threat Score
Cisco Talos reports an ongoing campaign (attributed to actor UAT-10027) using a new DoH-based backdoor called "Dohdoor" to perform stealthy C2 and payload delivery via phishing, PowerShell scripts, and DLL sideloading against U.S. education and healthcare organizations; the newsletter also highlights active exploitation of CVE-2026-20127 in Cisco Catalyst SD-WAN, recent high-profile data breaches, and provides several malware file hashes and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
