What I’ve learned in my first 7-ish years in cybersecurity
ID: cd90d817-3be4-563f-a38b-ec50c2b2290b
STIX ID: report--cd90d817-3be4-563f-a38b-ec50c2b2290b
Feed Name: Cisco Talos
Cisco Talos reports a new wave of activity by a Russian-speaking actor tracked as UAT-5647 targeting Ukrainian government and Polish entities using an updated RomCom/SingeCamper (memory-resident, registry-loaded, loopback communication) and additional tooling (RustClaw, MeltingClaw, DustyHammock, ShadyHammock). The newsletter also highlights broader high-impact issues: reported Chinese state-sponsored intrusions (Salt Typhoon) accessing ISP-collected communications, and an actively exploited Qualcomm zero-day (CVE-2024-43047) affecting dozens of chipsets — Talos has published detection rules and signatures to help defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
