INTEL_REPORT
Cisco Talos Blog · published 5/28/2026, 10:00:52 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
DICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heap This white paper presents a concrete case study demonstrating the creation of a heap overflow vulnerability through the exploitation of the DICOM file format. Over the last decade, DICOM parsing has become an active research topic. The reason is simple: DICOM is both critical and complicated. Hospitals rely on DICOM-based PACS systems, and those systems often automatically ingest files re…
https://blog.talosintelligence.com/dicom-pydicom-gdcm-and-orthanc-a-technical-tour-of-what-really-happens-in-the-heap
sha256:e7369100b6dab5f8a3f585fd1c41c75a1a898aa82e3dad85fa9b6a5a8a9cb13a
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
No indicators linked for this report.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.