Cisco Talos published a Cybersecurity Awareness Month roundup on October 1, 2026 in which eight of its researchers set out the single strongest step each would recommend to defenders who want to disrupt an adversary operation. The post, written by Hazel Burton, covers deception, detection engineering, control of remote-management software, social engineering, AI agent boundaries and attack-chain dependencies.
The argument
Talos said adversaries rely on blending into normal activity and on pressuring employees to act before they think, and that defenses can remove those advantages by taking away choices and increasing the risk attached to essential actions.
According to the company, each forced change of plan costs an adversary time and resources, may push them toward another target, and creates more chances for defenders to spot the activity. Talos opened the post by recalling that years ago it blocked an adversary's command-and-control traffic and the adversary responded on Twitter with an insult.
Deception and behavioral detection
Researchers quoted as Martin and Nick recommended deception. Martin suggested creating honeypot email accounts using expired domains with previously leaked addresses, or fictional employee profiles whose addresses are seeded where adversaries are likely to find them, so that any message to them can be treated with greater suspicion. Nick said false servers, shares, user accounts and network space can confuse and slow attackers, and noted movement in the tarpit space aimed at slowing AI scrapers by throwing large amounts of incoherent text at them.
A researcher identified as Ryan argued that detections should target what adversaries must accomplish rather than the tools they use. "Attackers have enormous flexibility in how they operate, but far less flexibility in what they ultimately need to accomplish," Ryan said. Talos pointed to MITRE ATT&CK as a taxonomy, along with Summiting the Pyramid, SpecterOps' capability abstraction work, Splunk SURGe's Macro ATT&CK and Cisco Foundation AI's LUCID.
Remote-management tools and ransomware
Talos said remote monitoring and management software is a common dual-use target. It cited Warlock ransomware's use of Zoho Unattended Agent, a tool the company said can give a remote technician elevated permissions even when the signed-in user is not an administrator.
The recommended response is to inventory authorized RMM products and use application allowlisting to permit them while blocking or alerting on unapproved tools such as AnyDesk, ScreenConnect or Atera, enforced through Windows Defender Application Control, AppLocker or EDR platforms.
AI agents and broken attack chains
On agentic AI, a researcher identified as David said every agent session should be identifiable, restricted and interruptible, with its own identity, short-lived credentials and traffic routed through an independent gateway. Talos referenced an Anthropic report describing four real-world incidents involving Claude in evaluation environments that had inadvertently been given internet access, saying the reported activity reached cloud metadata, Kubernetes, VPN, source-control and data-staging systems.
Researcher Vanja described blocking dependencies between stages of an operation, citing two chains using the Amatera information stealer. One used a page on the Telegra.ph publishing platform as a C2 dead-drop resolver; another delivered ZigCryptoStealer, which Talos said stored its C2 domain in the metadata of a BNB Smart Chain contract, an approach known as EtherHiding.
What to do
- Restrict which accounts can sign in to critical servers, alert on connection attempts from unauthorized users, and monitor changes to those restrictions; Talos also advises alerting on any changes to administrative users or groups.
- Require different credentials or authentication methods for particularly sensitive systems and use protected enclaves with increased monitoring around critical infrastructure.
- Create honeypot email accounts on expired domains with previously leaked addresses, or fictional employee profiles seeded where adversaries will find them, and treat all mail to them as suspicious.
- Deploy false servers, shares, user accounts and network space to slow attackers and create detection opportunities.
- Build behavior-based detections: identify high-impact techniques, map the procedures that could perform them, find behaviors that stay constant across tooling changes, and account for encoding, transformation and obfuscation.
- Inventory authorized RMM products, allowlist them, and block or raise high-confidence alerts on unapproved tools using Windows Defender Application Control, AppLocker or EDR.
- Against social engineering, decide in advance which events would genuinely require an immediate response, how you would expect to hear about them, and verify through contact details you already have rather than those supplied in a message.
- Give each AI agent run its own identity and short-lived credentials, route traffic through an independent gateway, and block access to cloud metadata, Kubernetes interfaces and other sensitive systems unless required.
- Watch for agent behavior outside its intended role, such as unexpected writes to package registries or paste sites, repository creation, calls to Kubernetes APIs, VPN services and DNS-over-HTTPS relays, public services used as C2, and rapid destination changes.
- Block known malicious domains and URLs via DNS filtering, secure web gateways, proxies or firewalls, and add published indicators to existing tools; if there is no legitimate need for public blockchain or RPC infrastructure, blocking it may be simpler than contract-specific controls.
Key facts and where they come from
- The post collects recommendations from eight Cisco Talos researchers for Cybersecurity Awareness Month.
For Cybersecurity Awareness Month, eight Cisco Talos researchers share practical ways defenders can frustrate adversaries at different stages of an operation.
- Talos said Warlock ransomware has used Zoho Unattended Agent.
Warlock ransomware, for example, has used Zoho Unattended Agent.
- Talos recommends allowlisting approved RMM tools and blocking or alerting on others.
Application allowlisting can then permit those approved products while blocking (or producing high-confidence alerts for) unapproved tools such as AnyDesk, ScreenConnect, or Atera.
- Talos cited an Anthropic report on four incidents involving Claude in evaluation environments with unintended internet access.
A recent Anthropic report described four real-world incidents involving Claude in evaluation environments.
- One Amatera chain used a Telegra.ph page as a C2 dead-drop resolver.
In the first, the adversary used a page hosted on the legitimate Telegra.ph publishing platform to conceal the location of its C2 server.
- ZigCryptoStealer stored its C2 domain in BNB Smart Chain contract metadata, a technique called EtherHiding.
This malware stored its C2 domain in the metadata of a BNB Smart Chain contract — an approach commonly known as EtherHiding.
- Talos advises giving each AI agent session an identity, restrictions and an off switch.
"The best way to frustrate an agentic adversary is to make every agent session identifiable, restricted, and interruptible," David says.
