Tag: cisco
-
Chinese Fire Ant hackers turn Cisco routers into spying platforms
The researchers discovered Fire Ant’s new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms/
-
China-linked Fire Ant Hides Inside Trusted Infrastructure
Fire Ant hijacked Cisco routers, stole credentials and altered logs to hide its tracks, using trusted infrastructure to reach high-value networks. Chinese-linked cyber espionage group Fire Ant has spent the past year quietly graduating from hacking individual computers to hacking the infrastructure that connects them. Sygnia’s new report traces how the group expanded from compromising…
-
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks.Sygnia, the incident response firm that investigated the intrusion, said the actor First seen…
-
OpenAI Warns AI-Enabled Cyberattacks Will Surge, Calls for Global Cyber Defense
Tags: ai, cisco, crowdstrike, cyber, cyberattack, defense, google, government, infrastructure, microsoft, openai, technologyOpenAI has issued a warning that AI-enabled cyberattacks could become significantly more widespread and sophisticated within months. The organization urges industries, governments, technology providers, and critical infrastructure operators to work together in a coordinated global response to cyber defense. In an open letter signed by over 100 organizations, including Microsoft, Google, AWS, Cisco, Cloudflare, CrowdStrike,…
-
Cisco Report Shows How AI Agents Are Changing Cybersecurity Jobs
Cisco research shows how AI agents are reshaping cybersecurity roles and skills. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/artificial-intelligence/cisco-report-shows-how-ai-agents-are-changing-cybersecurity-jobs/
-
Top 10 Cybersecurity Companies in 2026
Compare the top cybersecurity companies in 2026, including Cisco, CrowdStrike, Bitdefender, Semperis, and more, to find the right security vendor. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/top-cybersecurity-companies/
-
Cybersecurity job ads demanding AI skills double in a year
Job postings asking for AI skills in cybersecurity have doubled in a single year in G7 countries according to new research from the Cisco-founded AI Workforce Consortium. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/24/cybersecurity-job-ads-ai-skills-research/
-
Six Maximum-Severity Flaws Found in Cisco Products
Cisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited. Cisco released another batch of security fixes for its Crosswork platforms and Secure Workload software, part of what it’s calling an ongoing internal security review, and the CVSS scores in this round are unusually severe.…
-
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review.Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below – First…
-
Cisco BroadWorks Vulnerability Allows Remote Attackers to Access Sensitive Files
Cisco has issued security updates for a high-severity vulnerability in Cisco BroadWorks that could allow unauthenticated remote attackers to access sensitive configuration files on affected systems. This vulnerability is tracked as CVE-2026-20320 and is characterized as an out-of-band blind XML External Entity (XXE) injection vulnerability in the Open Client Interface (OCI) XML Parser. Cisco assigned…
-
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/
-
Cisco Firewall Alert: Hackers Exploit ASA, FTD Flaw to Force Remote Restarts
Cisco patches an actively exploited ASA and FTD flaw that can remotely crash vulnerable firewalls, prompting security teams to prioritize updates now. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-cisco-asa-ftd-dos-flaw/
-
Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs
Cisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks. Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux. ClamAV is an open-source antivirus engine widely used to scan files and emails for malware. The company…
-
Cisco warns of high-severity ClamAV flaws with public exploits
Cisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisco-warns-of-high-severity-clamav-flaws-with-public-exploits/
-
CiscoClamAV Vulnerabilities Let Remote Attackers Crash Antivirus Scanning With Crafted Files
Cisco has disclosed seven high-severity vulnerabilities in ClamAV that could allow unauthenticated remote attackers to disrupt antivirus scanning by submitting specially crafted files. These vulnerabilities are tracked as CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, and CVE-2026-20348, and have been assigned a maximum CVSS score of 7.5. ClamAV Vulnerabilities The issues are detailed in the Cisco…
-
Absicherung der digitalen Belegschaft
“‹Vor kurzem hat Nvidia gemeinsam mit Microsoft, Cisco, Crowdstrike, Palo Alto Networks und vielen weiteren Unternehmen die <> gegründet. Hinter dieses Bündnis stellt sich auch KnowBe4. Ziel der Allianz ist, offene Werkzeuge zu entwickeln und bereitzustellen, mit denen sich KI im Zeitalter autonomer Agenten absichern lässt. Warum KnowBe4 die Open-Secure-AI-Alliance unterstützt, erläutert […] First seen…
-
Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Mapping the malware blast radius a single alert won’t show you In this … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/09/week-in-review-cisco-fixes-imc-bug-patch-tuesday-forecast-black-hat-usa-2026/
-
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review.The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode.”These vulnerabilities were found First…
-
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review.The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode.”These vulnerabilities were found First…
-
Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)
Cisco has fixed a critical vulnerability (CVE-2026-20200) in its Integrated Management Controller (IMC), which allows an attacker to run commands as root through the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/cisco-imc-cve-2026-20200-public-poc-exploit/
-
Cisco Patches 7 IOS XE Vulnerability Classes, Including Critical Command Injection Flaws
Cisco has released security-hardening updates for IOS XE Software that address seven classes of vulnerabilities, including a critical command, operating system, and argument injection category identified as CVE-2026-20272. The advisory, released on August 5, has an overall CVSS score of 3.1 and 9.8 and provides no workarounds, meaning that upgrading is the only recommended solution.…
-
Statische Zugangsdaten – Cisco warnt vor aktiv ausgenutzter FMC-Schwachstelle
First seen on security-insider.de Jump to article: www.security-insider.de/cisco-fmc-cve-2026-20316-statische-zugangsdaten-hotfixes-a-2100ea013718c4c70cce681fe6e105c9/
-
“I’m Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails
Cisco Talos found hackers using simple authorization claims to bypass AI guardrails, build DDoS attack tools, steal credentials and access live camera services. First seen on hackread.com Jump to article: hackread.com/im-allowed-hackers-use-claims-bypass-ai-guardrails/
-
Stolen Greatness Tokens Provide Microsoft 365 Access More Than Two Weeks After Phishing
Stolen Greatness authentication tokens are providing sustained, MFA”‘approved access to victim Microsoft 365 tenants for more than two weeks after the initial phish, underscoring that token replay not password theft is driving the persistence in this AiTM PhaaS ecosystem. Originally documented by Cisco Talos in May 2023 and further covered by Hornet Security, […] The…
-
Small Language Models ‘Antares” – Cisco bietet KI-Schwachstellen-Analyse für weniger als einen Dollar
First seen on security-insider.de Jump to article: www.security-insider.de/cisco-antares-slms-schwachstellen-quellcode-a-77d83f36c434daaa67b19b1e04c5e76b/
-
North Korea Rebuilt Its Antivirus Using ClamAV and Gave It Four Different Names
North Korea’s national antivirus appears to have quietly pivoted to ClamAV’s open”‘source engine, recompiled it, and shipped it under four different domestic product names underscoring Pyongyang’s reliance on foreign code to secure tightly controlled networks while obscuring the software’s true origin. ClamAV is a widely used open”‘source antivirus engine maintained by the Cisco Talos team,…
-
CVE-2026-20316 Zero-Day Actively Exploited, Cisco Releases Fix
Cisco has released security updates for an actively exploited zero-day vulnerability, CVE-2026-20316, affecting Cisco Secure FMC (Secure Firewall Management Center) software. The flaw, disclosed on July 29, 2026, allows a remote, unauthenticated attacker to log in to vulnerable systems using a built-in low-privilege account and access sensitive data. First seen on thecyberexpress.com Jump to article:…
-
Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/phishing-dominates-initial-entry/
-
Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/phishing-dominates-initial-entry/

