Mobile & Gadgets

Cisco Talos threat intelligence and BlackCat ransomware resurgence

Following the sentencing of Ryan Goldberg and Kevin Martin for BlackCat ransomware conspiracies, Cisco released critical security advisories for Identity Services Engine and Secure Firewall. The report evaluates Cisco Talos intelligence against evolving AI-driven threats.

Cisco Talos threat intelligence and BlackCat ransomware resurgence

Ryan Goldberg and Kevin Martin received four years in prison today. They conspired to use ALPHV BlackCat ransomware to attack victims in the United States between April 2023 and December 2023. These men worked in the cybersecurity industry and used their specialized skills to facilitate extortion instead of protecting victims. They agreed to pay the ALPHV BlackCat administrators a 20% share of any ransoms to obtain access to the ransomware and the extortion platform. Because Ryan Goldberg and Kevin Martin used their specialized cybersecurity knowledge to facilitate extortion instead of protecting victims, the justice system sentenced both men to four years in prison to prevent further harm to businesses and individuals. The conspiracy included Angelo Martino, who also participated in the scheme. The trio successfully extorted one victim for $1.2 million in Bitcoin and laundered the funds. While Goldberg sought to flee abroad, the FBI tracked him through 10 different countries to ensure he faced prosecution.

Cisco security advisories for September 2026

Cisco published security advisories on September 16, 2026. These advisories identify vulnerabilities in several products including Cisco Identity Services Engine, Cisco Secure Firewall, and Cisco Nexus Dashboard. The Cisco Product Security Incident Response Team assessed the risk for these releases. Customers should upgrade to the fixed software to remediate these vulnerabilities.

Product CVE ID SIR Base Score
Cisco Identity Services Engine CVE-2026-20130 Critical 10.0
Cisco Identity Services Engine CVE-2026-76423 Critical 10.0
Cisco Identity Services Engine CVE-2026-76460 Critical 10.0
Cisco Identity Services Engine CVE-2026-20211 Critical 9.9
Cisco Identity Services Engine CVE-2026-20282 Critical 9.1
Cisco Identity Services Engine CVE-2026-20307 Critical 9.9
Cisco Secure Firewall CVE-2026-20334 Critical 9.9
Cisco Secure Firewall CVE-2026-20324 Critical 9.9
Cisco Secure Firewall CVE-2026-20342 Critical 9.1
Cisco Secure Firewall CVE-2026-20344 Critical 9.1

The Cisco Identity Services Engine faces several critical issues. CVE-2026-20130 and CVE-2026-76423 both carry a 10.0 base score. The CVE-2026-76460 vulnerability also has a 10.0 score. Other ISE vulnerabilities include CVE-2026-20211 with a 9.9 score and CVE-2026-20282 with a 9.1 score. The CVE-2026-20307 vulnerability has a 9.9 score. For the Cisco Secure Firewall, CVE-2026-20334 and CVE-2026-20324 have 9.9 scores. The CVE-2026-20342 vulnerability carries a 9.1 score. Also, CVE-2026-20344 and CVE-2026-20341 carry a 9.1 score.

The ALPHV BlackCat ransomware model

The ALPHV BlackCat group operates via a Ransomware-as-a-Service model. Developers create the ransomware and maintain the internet infrastructure. Affiliates identify and attack high-value institutions. Once a victim pays, developers and affiliates split the ransom. This structure allowed the group to grow from 60 victims in March 2022 to over 1,000 victims by September 2023. The group uses the Rust language to improve attack performance. In February 2024, the group received a $22 million ransom payment from Optum, a subsidiary of UnitedHealth Group. The group also uses "triple extortion" to pressure victims. They use encryption and data theft. They also use distributed denial of service attacks. The February 2023 Sphynx update provided affiliates with better defense evasion and additional tooling. This update allows the encryption of Windows, Linux, and VMWare instances. In September 2023, the FBI reported that the group collected nearly $300 million in ransom.

AI driven threats and automated attacks

Threat actors now use frontier AI models to change the speed of attacks. Talos researchers observed threat actors using Claude to conduct reconnaissance and manage command-and-control infrastructure. In one instance, attackers used multi-agent swarms to parse developer APIs and extract data from 200 downstream customer organizations in 34 hours. These automated exploit foundries allow attackers to disassemble firmware and find zero-day vulnerabilities without human intervention. The availability of frontier models means the profile of threat actors spans every tier of global cyber adversary. State-sponsored agencies use Claude to manage command-and-control infrastructure and reverse-engineer software. Terrorist organizations in northern Yemen used AI coding instances to draft and debug guidance, navigation, and control code for rockets. Scammers use large language models to generate hyper-personalized phishing at scale.

Comparing threat intelligence platforms

I will compare Cisco Talos to Recorded Future for context. Recorded Future earned an aggregate score of 8.3/10, while Cisco Talos earned 8.2/10. Recorded Future leads in coverage depth, AI/ML analysis, and dark web monitoring. Cisco Talos leads in ease of setup and pricing value. On G2, Recorded Future has a 4.6/5 rating and Cisco Talos has a 4.4/5 rating. Recorded Future is the stronger fit for enterprise security teams needing broadest intelligence coverage. Cisco Talos is better matched to Cisco-heavy enterprises wanting best-sourced threat intelligence. Recorded Future provides analysis for malware, code, and adversary profiling. Cisco Talos provides real-time threat feeds and dark web monitoring.

Tactics used by BlackCat affiliates

Affiliates use specific tools to move through networks. They deploy AnyDesk, Mega sync, Splashtop, and other remote access tools. They create a user account named "aadmin" and use Kerberos token generation for domain access. They use Evilginx2 to obtain multifactor authentication credentials and session cookies. These attackers also use legitimate tools such as Plink and Ngrok to facilitate tunneling. Affiliates use social engineering and open source research. They pose as company IT or helpdesk staff. They use phone calls or SMS messages to get credentials. They use Cobalt Strike and Brute Ratel C4 as beacons. They also use Metasploit to bypass security. They use uniform resource locators (URLs) to live-chat with victims to convey demands. They use Mega.nz or Dropbox to move or exfiltrate victim data. How many other cybersecurity professionals currently participate in these dark web marketplaces?

Cisco AI security architecture defenses

Cisco implements a zero-trust architecture to protect against these threats. Universal Zero Trust Network Access provides identity-driven access controls. Cisco integrates Splunk’s capabilities to provide machine-speed response. Autonomous detection and hunting agents reason over full-stack telemetry in real time. These agents orchestrate containment, such as host isolation, before an attack spreads. At the Black Hat 2026 event, Cisco Secure Access blocked over 4.4 million requests to Apple’s privacy-relay hostnames. This shows the scale of intercepted traffic. Cisco’s AI security architecture also includes real-time guardrails to prevent unauthorized tool registration and data exfiltration.

The verdict on Talos intelligence

You already know the technical basics of a RaaS model, so I will skip the definitions and focus on the specific mechanics used by ALPHV. Cisco Talos provides specialized intelligence that fits the needs of Cisco-heavy environments. I recommend Cisco Talos for organizations that require tight integration with their existing Cisco stack.