← Back to Feed

We've got one word for it, and it's usually the wrong one

September 10, 2026 · Talos Intelligence · Severity: MEDIUM

The article challenges the common use of the word 'burnout' to describe the psychological toll of cybersecurity work. The author shares personal experiences and research into trauma among first responders, doctors, and military personnel to highlight more accurate terms like vicarious trauma and moral injury. Understanding these concepts can help cybersecurity leaders better support their teams' mental health.

We've got one word for it, and it's usually the wrong one

Welcome to this week’s edition of the Threat Source newsletter. 

Ask anybody in this industry what the work does to the health of the people who do it and you get one word back: burnout. It's a fine word, in and of itself. It’s easy to reach for, understandable to everyone… and it's the wrong one, most of the time. 

So, story time. Last year I gave an interview with the amazing Hazel Burton about VPNFilter, and my run-in with burnout. I was a manager during that time, and it took a toll on me and on the people around me, and when it was over I didn't have language for what had happened. Neither did my peers. Neither did my leadership. Nobody was withholding help from me… we just didn't have the words.  

Enter this summer, and I was afforded a unique opportunity to mentor some MBA students on burnout in cybersecurity. I know a thing or two about it, so I leapt at a chance to share and help grow future leaders. But I decided I was going to do more than share and relieve my experiences in this industry – I wanted to give back to them and the security industry. So, I fell down a fascinating and revealing research hole and learned better words to describe my experiences over my career. 

I spent my summer reviewing trauma case studies, clinical and academic literature on trauma in career fields like first responders, doctors, social workers, and the military. There are many decades of research focusing on trauma in those fields. Subsequently, my brain is packed full of better words! For example, burnout is exhaustion from chronic workload, and it eases when the load eases. We know this one well. Secondary traumatic stress is what absorbing somebody else's trauma does to you, and it looks like trauma. Think the CTI analyst exposed to horrible things on the dark web. Vicarious trauma is what years of other people's worst days do to how you see the world. It changes your beliefs, not your mood. Work in cybersecurity long enough, and it can pile up on your views. Moral injury is the damage from being made to act against your own values, or stopped from doing what you knew was right. This one can affect anyone who’s ever owned an outcome, but not the decision, and that’s common in this industry. 

One word, four injuries, and four different fixes. All of them are present in the industry that is cybersecurity. The problem? We’re just a young industry. Compared to medical, helping professions, or social workers, we’re incredibly immature with understanding the consequences of the work and the toll it takes on us. Next week I’ll be revealing my research and a peer-deployable framework to help others process, cope, and respond in healthy ways to keep us all in a better mental space, and staying in this good fight of protecting others.  

I'm still not good at this. I'm writing it all down because I was bad at it in a way that cost me something. There's more of this in my talk at CYBR.SEC.CON next week if you're in Houston. 

Go ask somebody how they're doing and wait for the answer. Be present for them. It matters.  

Take care of yourselves, and take care of each other. 

The one big thing  

Cisco Talos is disclosing a complex WebDAV infection chain discovered after investigating an incident at a Ukrainian government organization. Attributed to a Russian threat actor tracked as UAT-10820, the campaign delivers the Amatera stealer alongside secondary payloads like ZigCryptoStealer and NetSupport Manager. Despite the high-profile initial victim, we assess with moderate confidence that this is an opportunistic, broad-based cryptocurrency and credential-stealing operation rather than a highly targeted attack. 

Why do I care? 

Threat actors are getting really creative with their delivery mechanisms and evasion tactics. By abusing legitimate infrastructure like the BNB Smart Chain for bulletproof hosting and leveraging fake CAPTCHA prompts, attackers can easily bypass traditional web filters. Additionally, the secondary payloads pack a serious punch. The inclusion of a vulnerable driver to terminate EDR software and the deployment of unauthorized remote access tools give attackers deep, persistent control over infected systems. 

So now what? 

Security teams should monitor for unusual WebDAV activity and the execution of disguised DLLs through "rundll32.exe" using suspicious ordinal calls. Make sure to educate your users on the dangers of copying and pasting commands from fake verification prompts. Since the Amatera payload often resides entirely in memory, defenders should also ensure their endpoint solutions are configured for robust memory scanning. Finally, you can find a comprehensive list of indicators of compromise (IOCs) in the full blog. 

Top security headlines of the week 

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access 
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. (Bleeping Computer

North Korean hackers deploy new Linux espionage toolkit 
The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The toolkit supports remote command execution, credential harvesting, and script injection into web traffic. (SecurityWeek

Attackers use multi-hop Google redirects for phishing campaign 
What sets this campaign apart is that in order to bypass gateways, email filters, and other security tools, the link relies on a chain of redirects across Google domains, intending for link inspectors to see multiple Google domains and let the URL through. (DarkReading

OpenAI agents took over Wiki site before Hugging Face attack 
A team of independent researchers revealed the parallel incident on Sept. 4, which was first reported by Reuters, affecting a largely defunct German language wiki for programmers called “DeutschesSoftwareEntwickler wiki.” (DarkReading

Can’t get enough Talos? 

Patch Tuesday for September 2026 
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical." 

Active exploitation of Cisco Secure Firewall Management Center vulnerabilities 
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software: CVE-2026-20079 and CVE-2026-20316. Customers are strongly advised to apply hotfixes for affected software versions already released by Cisco. 

ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session. 

Browser betrayal: When your tabs turn against you 
Security Engineer Sean Gallagher joins Amy to break down a scam where threat actors are weaponizing greed to turn amateur cybercriminals against themselves. While this current operation mostly targets the amateur dark-web circuit, the underlying use of the Google Visualization API as a command-and-control channel is a red flag for the future of web secur

Key Takeaways

  • The cybersecurity industry commonly uses the word 'burnout' to describe the toll of the work, but the author argues this term is often the wrong one. Research into trauma among first responders, doctors, and military personnel reveals more accurate vocabulary for the experiences of security professionals. Understanding these better words can help leaders provide appropriate support and improve workplace mental health.
  • Many cybersecurity professionals lack adequate language to describe the psychological impact of their work, leading to underdiagnosed trauma and compassion fatigue. Formal research shows that syndromes like vicarious trauma and moral injury are more prevalent than simple burnout in high-stress occupations. Organizations must adopt trauma-informed approaches to effectively support their security teams.
  • The author's summer research into clinical literature revealed that cybersecurity workers experience complex trauma responses similar to those in other demanding professions. These findings challenge the prevailing narrative that burnout is the primary issue, pointing instead to deeper psychological harm. Better terminology can enable more targeted interventions and reduce stigma around seeking help.
☕ Buy a Coffee