CVE Tools
Back to feed
Advisory ai-ml patch-tuesday

Don’t swing at everything

Cisco Talos·By Thorsten Rosendahl··6 min read
CVE Tools coverage

Cisco Talos researchers have uncovered a new remote access trojan (RAT) named msaRAT, developed by the Chaos ransomware group. This Rust-based malware leverages the Chrome DevTools Protocol to create a stealthy command-and-control (C2) channel without direct network interaction. It begins with a deceptive MSI file posing as a Windows update, loading the payload into memory to facilitate ransomware deployment. The technique allows attackers to evade detection by routing traffic through legitimate browser processes. Organizations are advised to monitor for unusual curl commands, unauthorized MSI downloads, and signs of Chrome or Edge manipulation.

Thursday, July 23, 2026 14:00

Welcome to this week’s edition of the Threat Source newsletter. 

Lately I've found myself thinking a lot about the Australian TV series Mr. Inbetween (IMDb 8.7/10) — not because I'm a hitman for hire, but because I literally feel in-between. Specifically, in-between what I'd call the "pre-Mythos" and “post-Mythos” eras. We've crossed a capability threshold, and it's not just one model family driving that — Codex 5.3 and GPT-5.5 deliver comparable or better performance, and Tulongfeng or GLM-5.2 (an incredibly powerful open-weight model, MIT-licensed) show the frontier isn't limited to closed models anymore.…

Continue reading on Cisco Talos