William Largent
banner
securitywill.bsky.social
William Largent
@securitywill.bsky.social
70 followers 74 following 18 posts
Cisco Talos Threat Research
Posts Media Videos Starter Packs
Reposted by William Largent
From a wave of ToolShell incidents, to a rise in post-exploitation phishing and the creative misuse of legitimate tools like Velociraptor, this episode of the TTP is packed with insights from Q3: www.youtube.com/watch?v=q7yV...
they won't even open betting lines for DNS as the RFO on these things.
Reposted by William Largent
Save the date: Cisco Talos is hosting a live Reddit AMA on r/cybersecurity on October 30! Our team members will be on standby to answer your questions about our latest Incident Response Quarterly Trends Report, today’s threat landscape, and more.
Reposted by William Largent
Talos is serving up a special episode of Beers with Talos! VP Christopher Marshall (the “real Marshall,” much to Joe’s displeasure) joins Hazel, Bill, and Joe for a very real conversation about leading a large team when the world won’t stop moving: cs.co/63325AFR3x
Reposted by William Largent
Reposted by William Largent
If anyone needs me I will be in the museum, lying down next to the bog bodies.
Trying to imagine the level of derangement in thinking Bob Dylan is cooler than Johnny Cash - and I just can't get there. Holy fucking dumbfuck. Even as clickbait garbage this is painfully stupid and Fasman is way too old to be cut any slack for this. Jettisoned to the sun.
Reposted by William Largent
Support your public library. Defend your public library. Slay the enemies of your public library.
Reposted by William Largent
Ozzy Osbourne visited my magic shop. He said he'd like to buy some stink bombs. How many? All of them. I had to go through drawers finding every last one. He bought 900 of them. To sign the credit card slip I handed him a shock pen, which he thought was hilarious and bought that too. RIP
This. Read this and repeat it over and over to yourself if you need to do so.
Never tell a bug reporter that their vulnerability can not be exploited. That only serves to guarantee that there will be an exploit built for your vulnerability.

Try "Thank you, we'll patch that" and see how that works out for you.
Look, I'm not going to say that this is a personal attack ...

... it is. This is a personal attack.
Nerds reaction if someone does ransomware: "whoa whoa whoa based"

Nerds reaction if someone cheats in multiplayer video games: "fuck you, you're a piece of shit"
Reposted by William Largent
We’re halfway through 2025, and vulnerability reporting is evolving fast. Check out the latest Threat Source newsletter as Thorsten breaks down record CVE volumes and new reporting challenges: blog.talosintelligence.com/patch-track-...
Reposted by William Largent
Join us for a deep dive into how Cisco Talos uncovered two critical vulnerabilities in the AsIO3.sys driver powering ASUS Armory Crate: blog.talosintelligence.com/decrement-by...
Reposted by William Largent
Cisco Talos uncovered zero-day vulnerabilities in catdoc, plus vulnerabilities in Parallel, NVIDIA, and High-Logic FontCreator 15—all now patched:
blog.talosintelligence.com/catdoc-zero-...
Reposted by William Largent
Cisco Talos’ 2024 Year in Review is available now! With visibility into more than 886 billion security events per day, the report features our key insights. Read the full report here: http://cs.co/63320FzuMG
I really hate this archaic nonsense is still a part of the community - but this is a really good post from a couple of Splunk/SURGe folks.

I am so lucky to work on a team that is very diverse across the board but I am very aware that we are flying in the face of the norm.
Why We Need More Women and Intersectional Diversity in Cyber (And How to Get There)
Representation matters in cybersecurity. Here’s why—and what we can do about it.
dispatch.thorcollective.com
Reposted by William Largent
From threat hunting, detection building, vulnerability discoveries and incident response, Cisco Talos shows up every day to try and make the internet a safer place. Watch our full overview here: http://cs.co/633280m3rs
"The PureCrypter malware found in this intrusion is a Windows dynamic-link library obfuscated with Eziriz’s .NET Reactor obfuscator. It has resources of encrypted binaries of legitimate DLLs, including Protobuf-net and Microsoft task scheduler DLL along with the TorNet backdoor. "
Cisco Talos discovered an ongoing malicious campaign operated by a financially motivated threat actor targeting users, predominantly in Poland and Germany. Read the blog on the new TorNet backdoor here: blog.talosintelligence.com/new-tornet-b...