logo

Tomorrow, and tomorrow, and tomorrow: Information security and the Baseball Hall of Fame

ID: 64c10a8f-24a1-5484-a5e2-e2af8e63cd74

STIX ID: report--64c10a8f-24a1-5484-a5e2-e2af8e63cd74

Feed Name: Cisco Talos

Threat Score
78/100

Date Published: 2025-03-20

Date Updated: 2026-04-27

Author: William Largent

...
...

Cisco Talos weekly newsletter highlights research into UAT-5918, an active post-compromise intrusion campaign targeting critical infrastructure in Taiwan with overlaps to known APT activity (Volt Typhoon and others); it details credential harvesting (registry hives, NTDS, Mimikatz, browser credential extraction), lateral movement (RDP, WMIC/PowerShell, Impacket), common tooling (FRPC, FScan, In-Swor, Earthworm, Neo-reGeorg), provides associated IOCs and several prevalent malware SHA-256 hashes from Talos telemetry, and notes other trending security headlines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.