Ghosted by a cybercriminal
ID: 82f5624a-cb9b-5a7f-b216-d475d761a890
STIX ID: report--82f5624a-cb9b-5a7f-b216-d475d761a890
Feed Name: Cisco Talos
Threat Score
Talos' weekly Threat Source newsletter discusses compartmentalized threat actor ecosystems and reports that UAT-6382 (Chinese-speaking actors) exploited Cityworks via CVE-2025-0994, deploying web shells, Rust-based malware loaders and Cobalt Strike for persistent access; it provides IOCs and malware hashes, and highlights related security headlines including VMware patches and a ransomware outage at Kettering Health.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
