Skip to main content

Threats Tagged 'cisco'

View all threats tagged with 'cisco'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cisco

Threats Tagged 'cisco'

Click on any threat for detailed analysis and mitigation recommendations

This analysis discusses the limited impact that slowing AI development would have on cybersecurity, noting that current AI models are already highly capable for both offensive and defensive purposes. It highlights the rise of ransomware activity in Japan driven by two groups, The Gentlemen and Qilin, with Qilin leveraging generative AI to accelerate attacks. The report emphasizes that foundational security practices remain critical despite AI advancements. It recommends strict management of internet-accessible devices, credential lockdown, multi-factor authentication, and robust endpoint detection to mitigate risks from AI-enhanced ransomware operations.

Join the discussion

Cisco has released patches for multiple critical vulnerabilities affecting Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard. These vulnerabilities include remote code execution, command injection, authentication bypass, SQL injection, and other flaws that could lead to root access and denial-of-service conditions. Some of the vulnerabilities have been publicly disclosed and exploited in the wild, including a zero-day authentication bypass in ISE. Cisco has issued security advisories detailing these issues and providing fixes.

Join the discussion

Ransomware incidents in Japan increased slightly by approximately 4.7% in the first half of 2026, with 90 organizations affected. The most active ransomware group was The Gentlemen, followed by Qilin, which is noted for leveraging AI to enhance its operations. Attackers primarily targeted small- and medium-sized enterprises, especially those with capital under JPY 1 billion, accounting for about 78% of victims. The manufacturing sector was the most affected industry. The Gentlemen operates via a Ransomware-as-a-Service model using a double-extortion strategy and has significantly increased its leak site activity. Investigations revealed The Gentlemen’s use of various tools for reconnaissance, exploitation, and network access, including exploits for CVE-2025-2479. The ransomware landscape in Japan is rapidly evolving with emerging groups requiring increased vigilance.

Join the discussion

Cisco has disclosed a maximum-severity zero-day vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products. This flaw allows remote attackers to bypass authentication via a crafted request to an API endpoint, regardless of configuration. The vulnerability is actively exploited in the wild, enabling unauthorized access to affected devices through the web-based management interface. Cisco has released patches for multiple ISE versions to remediate this issue. No workarounds exist, and Cisco strongly recommends immediate patching. Indicators of compromise include suspicious usernames in access logs and unusual network activity. The Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to patch this vulnerability within three days. Additional related critical vulnerabilities have also been patched but are not yet known to be exploited.

Join the discussion

A critical authentication bypass vulnerability (CVE-2026-76460) in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) allows remote unauthenticated attackers to bypass authentication via crafted API requests. This zero-day flaw has been actively exploited in the wild, enabling attackers to gain unauthorized access to the device's management interface and execute commands with root privileges. Cisco has released urgent patches for multiple versions and recommends upgrading immediately. No workarounds exist except restricting traffic via infrastructure ACLs. The US CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, urging rapid patching.

Join the discussion

Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...]

Join the discussion

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

Join the discussion

Cisco Talos disclosed a complex WebDAV infection chain linked to a Russian threat actor (UAT-10820) targeting a Ukrainian government organization. The campaign delivers the Amatera stealer along with secondary payloads such as ZigCryptoStealer and NetSupport Manager. This operation appears opportunistic and broad-based, focusing on cryptocurrency and credential theft rather than a highly targeted attack. Attackers use creative delivery and evasion techniques, including abusing legitimate infrastructure like the BNB Smart Chain for bulletproof hosting and fake CAPTCHA prompts to bypass web filters. Secondary payloads include a vulnerable driver to terminate endpoint detection and response (EDR) software and unauthorized remote access tools, enabling persistent control over infected systems. Security teams are advised to monitor for unusual WebDAV activity and suspicious DLL execution via rundll32.exe ordinal calls, educate users about fake verification prompts, and ensure endpoint solutions have robust memory scanning capabilities. No patch information is provided for this threat. The disclosure also includes a broader discussion on cybersecurity workforce mental health but is unrelated to the technical threat.

HighAnalysis#cisco
Join the discussion

A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a nation-state problem, despite two years of headlines about China-nexus actors targeting Ivanti, Fortinet, and Palo Alto Networks. The data here tells a different and much broader story. One focused on vendors vs CVEs. Key Takeaways Two independent observation systems, Tenable exposure telemetry across thousands of customer containers and SentinelOne DFIR casework across 66 CVEs, converge 79% on the same vendor attack surfaces despite minimal CVE-level overlap. Twelve CVEs in the combined dataset have confirmed multi-nexus attribution: state-sponsored and criminal actors independently exploiting the same vulnerability, across five nexus categories (China, Russia, DPRK, Iran, ransomware). The exposure picture is flatter than the headlines suggest: Fortinet, the vendor most associated with edge-device attacks in the press, sits mid-pack on container-grain exposure (25%) — well behind F5 (54%) and in a tight 10-point band with Check Point, Ivanti, and Citrix. 54% of customer environments running F5 products have at least one exposed, actively-exploited CVE; Citrix customers show the slowest remediation patterns at 461 days median time to patch. Remediation complexity, particularly of high priority CVEs, leads to a statistically significant 24-day remediation gap, leaving large windows of opportunity for attackers. The same product lines get hit again and again: Ivanti EPMM and Ivanti Connect Secure each show a newly exploited CVE roughly every 8.5 to 13 months. Leverage multiple defense-in-depth strategies: patch as quickly as possible, but also minimize the attack surface (feature-set minimization) and run endpoints in protect mode to better stop lateral movement from attacks that gain initial access. The convergence is the story Twelve CVEs in the combined dataset have confirmed multi-nexus attribution: state-sponsored and criminal actors independently exploiting the same vulnerability, across five nexus categories. Four examples illustrate the pattern: CVE Product Actors (Nexus) Significance CVE-2026-15409 SonicWall SMA1000 UTA0533 (unattributed) + INC Ransomware Espionage-to-ransomware succession on an active zero-day CVE-2023-42793 JetBrains TeamCity APT29 (Russia) + Lazarus (DPRK) Two state-sponsored actors from different nations on the same CVE CVE-2024-3400 PAN-OS GlobalProtect UTA0218 (China) + INC Ransomware China-nexus zero-day reused by ransomware operators CVE-2024-24919 Check Point Quantum PurpleHaze (China) + Fox Kitten (Iran) China and Iran independently exploiting the same gateway vulnerability The remaining eight confirmed multi-nexus CVEs span Fortinet, Citrix, Cisco, and Ivanti product lines. State-sponsored actors and ransomware operators are not operating in separate vulnerability ecosystems. They share the same entry points into the same products. The breadth of the convergence, not any single actor's activity, is the finding. That pattern holds across the full combined analysis. Three conclusions emerge: Vendor attack surfaces are the persistent exploitation target. The same eleven vendors (i.e., Fortinet, Citrix, Ivanti, Palo Alto Networks, Cisco, Juniper, VMware, Microsoft, Oracle, CrushFTP, and Meta's React framework ) appear in both observation systems at 79% convergence, and all seven edge-product vendors converge. Serial exploitation timing on Ivanti products shows the vulnerability-to-exploitation pipeline refreshing at 8.5 to 13-month intervals on the same product lines. This is structural, not episodic. Patch…

Join the discussion

Two recently patched vulnerabilities in Cisco Secure Firewall Management Center (FMC) have been exploited by multiple threat clusters linked to ransomware and state-sponsored attacks. CVE-2026-20079 is a critical authentication bypass vulnerability with a CVSS score of 10.0, allowing unauthenticated remote root access. CVE-2026-20316 involves static credentials for a low-privileged account and has a CVSS score of 5.3 but can be combined with other flaws for privilege escalation. Exploitation has led to deployment of web shells, credential theft, reverse shells, proxies, and malware including Qilin ransomware and Cyclops Blink backdoor. Cisco has released hotfixes for both vulnerabilities and plans further hardening patches. The attacks highlight significant post-compromise activity by ransomware affiliates and a Russian state-sponsored group known as Sandworm.

Join the discussion

Showing 1 to 10 of 47 results

Filters:Tag: cisco
Page 1 of 5
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses