Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Should we let AI run our threat hunts?
The debate over whether AI should be used in threat hunting centers on the Hunter’s Paradox: while humans can no longer handle the volume and velocity of security data alone, AI—though necessary—cannot be fully trusted. The author, who originally defined threat hunting in 2015 as a human-driven process, now acknowledges that automation is essential due to the overwhelming scale of modern cybersecurity challenges.
This Talos article explores the debate over using AI for threat hunting, weighing the overwhelming scale of security telemetry against the trustworthiness of AI systems. The author reevaluates his previous stance that hunting must be human-driven, introducing the Hunter's Paradox.
This Talos article explores the debate over using AI for threat hunting, weighing the overwhelming scale of security telemetry against the trustworthiness of AI systems. The author reevaluates his previous stance that hunting must be human-driven, introducing the Hunter's Paradox.
Disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025. Talos has discovered that the actor in this...
A financially motivated Russian-speaking threat actor, tracked as UAT-11795, has been conducting a campaign targeting users in the U.S. and Europe since at least June 2025. The group deploys a Python-based remote access trojan (RAT) called "Starland RAT" and a sophisticated PowerShell-based C2 memory implant known as "WLDR agent," which features encrypted beaconing, task queuing, and a Runspace execution engine for additional payloads.