Severity: HighAction: Be aware

UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing

Cisco Talos identified an APT spear-phishing campaign against individuals affiliated with Taiwan research organizations. The operation leveraged legitimate public event themes and impersonated reputable academic and policy institutions.

Excerpt from the primary source: Cisco Talos Intelligence

Who is affected

Home users · Enterprises · Security professionals

Affected technology: Cisco networking & security

What you should do · Be aware

No immediate action is indicated. Share this with the relevant teams and watch for updates.

Automated guidance based on this story's classification. Check the linked advisories for specifics.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Security research

UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing Cisco Talos Intelligence · blog.talosintelligence.com · Oct 8, 2026 · Primary source
Severity: ElevatedAction: Patch

Microsoft, Adobe, Apple, and Foxit vulnerabilities

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy . For Snort coverage that can detect…

Severity: ElevatedAction: Be aware

The Fine Art of Frustrating the Adversary

What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier. From deception and behavioral detection to breaking attack dependencies and resisting manufactured urgency.

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Cisco warns of new SD-WAN zero-day exploited in attacks

CISA added CVE-2026-76504 (Cisco Catalyst SD-WAN Manager) to its Known Exploited Vulnerabilities catalog on September 30, 2026, which means there is reliable evidence of exploitation in the wild. Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI…

Why it matters

CISA lists this as exploited in the wild. Unpatched Cisco networking & security and Catalyst SD-WAN Manager systems are exposed to active attacks now.

Act now

Treat this as an emergency.