< ciso
brief />
Tag Banner

All news with #cisco tag

257 articles

Cisco issues patches for Crosswork and Secure Workload

🔒 Cisco released security updates for its Crosswork platforms and Secure Workload software following an internal review. Four critical flaws affecting Crosswork (including SQL injection and missing authentication) were fixed in Crosswork 7.2.1-SP. Five vulnerabilities impacting Secure Workload (SaaS and on-premises) were remediated in releases 3.10.9.1 and 4.0.4.16. Customers are urged to apply updates despite no known active exploitation.
read more →

Talos Threat Source: Phishing Frameworks and Trends

📰 Cisco Talos highlights a newly discovered real-time phishing framework named JWR, likely related to The Outsider phishing-as-a-service. JWR uses WebSockets to capture live keystrokes and steer victims through fraudulent checkout and login flows, often delivered via SMS lures impersonating toll or postal authorities. Operators can harvest payment data, 2FA codes, identity documents, and device fingerprints, enabling MFA bypass and extensive follow-on fraud. Talos recommends user education on smishing, monitoring for unusual authentications, and adopting phishing-resistant MFA like FIDO2.
read more →

Cisco ASA and FTD HTTP DoS Flaw Exploited

🛡️ Cisco has disclosed a high-severity vulnerability (CVE-2026-20349, CVSS 8.6) in Secure Firewall ASA and Secure Firewall FTD that allows unauthenticated remote attackers to trigger a denial-of-service by sending crafted HTTP requests to the Remote Access SSL VPN service. The flaw affects multiple ASA and FTD versions and configurations (IKEv2 Remote Access VPN, SSL-VPN, Zero Trust Network Access). Cisco released fixes across affected ASA and FTD releases and said it found active exploitation earlier this month; no viable workarounds exist.
read more →

Cisco warns of ASA and FTD VPN flaw causing DoS

🔒 Cisco warns of a high-severity DoS vulnerability, CVE-2026-20349, affecting Secure Firewall ASA and Threat Defense (FTD) devices when certain remote access services are enabled. The flaw stems from insufficient error checking in HTTP request processing and can be exploited remotely without authentication to crash affected devices. Cisco has released hotfixes for multiple ASA and FTD releases and urges customers to upgrade, noting no available workarounds. The company reports active exploitation since August 2026 but has not shared exploit details or indicators of compromise.
read more →

Cisco warns of high-severity ClamAV flaws with PoC exploits

🔒 Cisco alerted customers to two high-severity vulnerabilities in the ClamAV ZIP archive parser used by its Secure Endpoint Connector, tracked as CVE-2026-20337 and CVE-2026-20338. The flaws, caused by improper boundary checks and memory handling, allow unauthenticated remote attackers to crash the ClamAV scanning process, resulting in denial-of-service (DoS). Proof-of-concept exploit code is publicly available, and Cisco plans updates later this month to address the issues across Windows, Linux, and macOS.
read more →

Cisco releases critical SD‑WAN and IOS XE fixes

🔒 Cisco issued patches for multiple critical vulnerabilities in Catalyst SD‑WAN and IOS XE Software discovered during an internal security review. The flaws—ranging from improper input validation and access control to command injection—affect many releases and have been fixed across several patched versions. Cisco noted these were found during testing, including use of frontier AI models, and are not known to be actively exploited, urging customers to update promptly.
read more →

Talos webinar: Q2 incident briefing for security teams

📢 Next Tuesday, August 11, Cisco Talos Incident Responders will host a 30-minute, unrecorded webinar reviewing high-impact incidents from Q2 2026. The session will candidly cover timelines, containment, and remediation efforts rather than repeating the published trends report. Designed for security professionals at all levels, it emphasizes strategic takeaways, business impact, and enough technical detail to inform discussions. Registration is required to attend this exclusive briefing.
read more →

Humans of Talos: Black Hat special rewind

🎙️ Amy revisits past guests in a special Black Hat edition of Humans of Talos, exploring the varied career paths that led them to threat intelligence. From forensic labs and newsrooms to kitchen lines, the episode highlights personal stories and lessons that shape the field. Attendees can meet the team at Cisco and Splunk booth 2633 during Black Hat to discuss research and incident response and pick up the latest Snorty.
read more →

Cisco FMC Zero‑Day Added to CISA KEV Catalog

🔒 CISA has added a newly disclosed zero‑day affecting Cisco Secure Firewall Management Center (FMC) Software, tracked as CVE-2026-20316, to its Known Exploited Vulnerabilities list after reports of active exploitation. The flaw allows an unauthenticated remote actor to log in using a static low‑privilege account and access sensitive data; Cisco warns the risk increases if the management interface is internet‑exposed. Hotfixes are available for multiple FMC versions and Cisco published an IoC check for "/var/tmp/license.tmp" to help detect compromise.
read more →

Cisco warns of FMC static credential zero-day exploit

🔒 Cisco warns that a high-severity static credential flaw in Secure Firewall Management Center (FMC)—tracked as CVE-2026-20316—has been actively exploited in zero-day attacks to gain unauthorized access. The flaw stems from built-in static credentials for a low-privilege account, enabling unauthenticated remote login and access to account data. Cisco released hot fixes for multiple FMC releases and advises installing them immediately, noting no effective workarounds and recommending credential rotation if compromise is detected.
read more →

Phishing Now Leading Initial Access in Incidents

📈 Analysis of incidents from March to June 2026 shows phishing was the initial entry vector in just over half of cases requiring remediation, up markedly from the prior quarter. Cisco Talos researchers highlight increasingly sophisticated campaigns, including QR code-based credential harvesting and use of trusted cloud hosting to evade detection. The report also warns that advanced Phishing-as-a-Service kits and post-compromise toolsets are expanding capabilities and recommends phishing-resistant MFA, logging, patching, and stricter email controls.
read more →

NVIDIA Leads New Open Secure AI Alliance Initiative

🛡️ NVIDIA has convened nearly 40 technology firms to form the Open Secure AI Alliance, a coalition aimed at building open source security tools for AI, announced on July 27. Members include Adobe, Cisco, Microsoft, CloudStrike, SpaceX, SAP and the Linux Foundation, while notable frontier model developers such as Google, Anthropic and OpenAI are absent. The alliance will focus on finding, fixing and disclosing vulnerabilities, and aims to create an open defense stack for agents, covering identity, isolation, secure model formats and secure coding workflows.
read more →

NVIDIA leads 37-member Open Secure AI Alliance

🔒 NVIDIA and 36 organizations have launched the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and AI agents. The group spans cloud, security, enterprise software, and AI companies including Microsoft, Cisco, CrowdStrike, Hugging Face, IBM, and the Linux Foundation. The alliance’s scope covers identity, permissions, isolation, guardrails, logs, model formats, scanning, and secure coding workflows. Its first technical contribution is NVIDIA-labs OO Agents (NOOA), an Apache 2.0 research framework to test, trace, audit, and govern agent behavior.
read more →

Threat Source newsletter: Q2 2026 vulnerability trends

📈 This edition of the Threat Source newsletter reviews Q2 2026 vulnerability trends, noting a 49% YoY increase in tracked CVEs and roughly 200 CVEs per day by June. The author contrasts a shifting AI model landscape with slower real-world impact, highlights concerns about keyword-sensitive AI-CVE counts, and advocates prioritizing patches using EPSS rather than raw CVSS scores. Additional coverage includes Cisco Talos' discovery of the Rust-based msaRAT, new Antares SLMs for vulnerability localization, major incidents impacting land registries and WordPress sites, and tactical detection recommendations.
read more →

Cisco Talos preview at Black Hat USA 2026

🎤 Talos will be present at Black Hat USA 2026 across the Cisco and Splunk booths to discuss threat research, incident response, and how Talos powers the Cisco security portfolio. The team will deliver lightning talks, a Main Stage keynote on securing enterprises in the age of AI agents, and hands-on workshops demonstrating AI-driven SOC workflows and the Foundry Security Spec. Attendees can also learn how Talos is embedded across Cisco products and view the new “Where Protection Starts” video.
read more →

Cisco’s Antares AI targets repository vulnerability hotspots

🔎 Cisco introduced the Antares family of open-weight AI models to help security teams quickly locate files likely to contain specific classes of vulnerabilities using CWE descriptions. Rather than detecting CVEs or producing patches, Antares ranks source files and provides an exploration trace to guide human reviewers. Available in 350M, 1B, and 3B parameter sizes, the models are optimized for local deployment and aimed at reducing triage workload without replacing analysts.
read more →

Cisco Talos intelligence integrations overview

🎯 Cisco Talos Intelligence Integrations apply continuous, up-to-date threat intelligence across Cisco security and enterprise products to help identify and block malicious activity. The integrations aim to reduce uncertainty for defenders facing advanced, adaptive threats such as AI-assisted attacks and polymorphic malware. A short video introduces Talos team members and demonstrates how reputation and detection feeds inform security decisions. A more detailed technical overview is available on the Cisco Security site.
read more →

Governments urge enterprises to improve router security

🔒 A multinational cybersecurity advisory warns that Russian government-sponsored actors are exploiting poorly configured routers and legacy protocols to steal device configurations and credentials. Attackers scan for devices using SNMPv1/v2, default community strings, and vulnerable Cisco features like Smart Install, then exfiltrate config files to attacker-controlled servers. Agencies recommend migrating to SNMPv3, disabling legacy protocols and Cisco Smart Install, enforcing strong passwords and MFA, blocking SNMP at firewalls, updating software, and retiring EOL devices.
read more →

FSB Centre 16 Targets Routers Using Weak SNMP

🔒 Cyber agencies from 12 countries warn that Russian FSB Centre 16 (aka Berserk Bear/Static Tundra) is scanning the internet for routers using default or weak SNMP credentials and occasionally exploiting known CVEs in Cisco devices. Sectors such as communications, defence, energy, finance, government and healthcare are urged to adopt SNMPv3, patch affected systems and disable vulnerable features like Smart Install when patching is not possible. The advisory links Centre 16’s tactics to broader disruptive campaigns and coincides with UK/EU attribution of late 2025 attacks on Poland’s energy grid to the group.
read more →

US and Allies Share Guidance on Russian Router Attacks

🔒 Cybersecurity agencies from the US and eight partner nations issued a joint advisory warning that Russian state-linked hackers (FSB Centre 16) are exploiting poorly configured routers and default SNMP credentials to breach critical infrastructure networks. The advisory attributes scanning and exfiltration activity to groups tracked as Berserk Bear and others, and highlights exploitation of Cisco Smart Install (CVE-2018-0171). Agencies urged mitigation steps including upgrading to SNMPv3, disabling Cisco Smart Install, enforcing strong passwords, blocking TFTP/SNMP at the perimeter, and updating firmware to protect energy, communications, healthcare, finance, and government sectors.
read more →