logo

The art of being ungovernable

ID: 7157efee-bab8-5a85-abae-d20f04334dcc

STIX ID: report--7157efee-bab8-5a85-abae-d20f04334dcc

Feed Name: Cisco Talos

Threat Score
75/100

Date Published: 2026-05-21

Date Updated: 2026-05-22

Author: William Largent

...
...

Cisco Talos warns of an active Chinese-language BadIIS commodity malware ecosystem (identifiable by embedded "demo.pdb" strings) used for SEO fraud, content hijacking, and traffic redirection, advises defenders to monitor IIS for unauthorized redirection/reverse proxying and to hunt for the demo.pdb strings and Chinese-language paths; the newsletter also highlights a public CISA repo leak of secrets, a large NYC Health + Hospitals breach exposing biometric data, several recent high-impact vulnerabilities (NGINX njs, OpenClaw chain, and vendor disclosures), and lists prevalent malware file hashes and detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.