< ciso
brief />
Tag Banner

All news with #cisco tag

281 articles

Multiple Vendor Vulnerabilities and Vendor Patches

🔒 Cisco Talos disclosed multiple vulnerabilities affecting Adobe, Apple, Foxit Reader, and Microsoft. The vendors have issued patches in accordance with Cisco’s disclosure policy. Snort rule updates are available to detect exploitation, and Talos posts ongoing vulnerability advisories on its site. Affected components include Photoshop installer, macOS CoreWLAN, Foxit PDF JavaScript features, and several Windows kernel drivers.
read more →

New Antino Backdoor Targets Asian Government Entities

🛡️ Cisco Talos attributes a recent espionage campaign to a China-nexus actor tracked as UAT-11587 that has targeted government and policy organizations across Asia using a previously undocumented Rust-compiled Windows backdoor called Antino. The actor employs tailored spear-phishing lures, sender spoofing, and a multi-stage chain that culminates in DLL sideloading to deploy the implant, which uses Microsoft 365 (Outlook and OneDrive) as its native C2 channel. Talos sees overlaps with known China-aligned clusters but treats UAT-11587 as a distinct activity set.
read more →

Critical Zero-Day in Cisco Catalyst SD‑WAN Manager

🔒 Cisco has released an urgent advisory for CVE-2026-76504, a critical (CVSS 9.8) authentication bypass in Cisco Catalyst SD-WAN Manager that is being actively exploited. The flaw stems from improper URI encoding handling in API session authentication, allowing unauthenticated remote attackers to gain admin-level access. Cisco and CISA urge immediate upgrades to fixed releases; no practical workaround exists, and cloud-hosted mitigations have been deployed but require customer validation.
read more →

Cisco SD‑WAN Manager zero‑day allows admin access

🔒 Cisco fixed a critical flaw in Cisco Catalyst SD‑WAN Manager that let attackers bypass authentication via improperly handled URI encoding in HTTP requests. The vulnerability, tracked as CVE-2026-76504 with a 9.8 CVSS score, could grant administrative API privileges without credentials. Cisco has patched cloud-managed systems and released fixes for affected on‑prem releases; there is no workaround, so restricting access until upgrades are applied is advised.
read more →

CISA Adds Critical Cisco SD‑WAN Manager Flaw to KEV

🔒 CISA has added a critical authentication bypass vulnerability in Cisco Catalyst SD‑WAN Manager (CVE-2026-76504, CVSS 9.8) to its Known Exploited Vulnerabilities list after reports of active exploitation. The flaw allows an unauthenticated, remote attacker to gain admin privileges by abusing improper URI handling in HTTP requests. Cisco provided IoCs and log entries to audit, and FCEB agencies must apply fixes by October 3, 2026. Organizations are urged to upgrade to fixed releases and hunt for POST requests to URL-encoded variants of "/j_security_check".
read more →

Frustrating Adversaries Through Defensive Tradecraft

🛡️ Cisco Talos outlines practical ways defenders can increase friction for attackers across the attack chain. The piece highlights techniques such as unique configurations, deception (honeypots and tarpits), behavior-based detections, RMM inventorying and allowlisting, social-engineering preparedness, and controls for AI agents. Each recommendation aims to force adversaries into slower, noisier, or less reliable methods while providing defenders more chances to detect and stop activity.
read more →

Critical Cisco SD‑WAN Manager Zero‑Day Alert

🛡️ Cisco warned on September 30 that attackers are actively exploiting a critical zero‑day, CVE‑2026‑76504, in Catalyst SD‑WAN Manager that allows unauthenticated API access as the admin user. The flaw, tied to mishandled URI encoding in session login requests, scored 9.8/10 and has fixed releases available across affected release trains. Cisco confirmed active exploitation and advised upgrades; no workaround exists and internet‑exposed Managers are at highest risk.
read more →

Cisco warns of SD‑WAN authentication bypass zero‑day

🔒 Cisco released updates to address a critical zero-day in the Catalyst SD-WAN Manager (CVE-2026-76504) that is being actively exploited to gain admin privileges. The flaw affects API session-based authentication and allows unauthenticated remote access by bypassing an authentication rule via improper URI encoding. Cisco published IOCs and log locations for detection and urged customers to upgrade to fixed releases or open TAC cases for investigation. Multiple fixed releases are listed for affected versions.
read more →

InfraTrust report: Management systems under attack

🛡️ The September InfraTrust Pulse warns attackers are increasingly targeting infrastructure management systems across vendors, with many critical flaws exploited before or soon after disclosure. Between Aug 25 and Sep 17, InfraTrust tracked 158 advisories covering 1,699 vulnerabilities, including 42 critical and several with CVSS 10.0. The report highlights chained exploits against Cisco FMC and ISE, active exploitation of SonicWall and Check Point flaws, and supply-chain and firmware weaknesses.
read more →

Windows Malware Uses AI Vote for Command Decisions

🛡️ Cisco Talos disclosed a Windows implant named CLOSEDQUORUM that delegates command decisions to up to four commercial AI models instead of relying on a traditional C2 server. The malware collects basic system facts and asks the models to vote among actions such as steal, inject, and persist, then executes the majority choice. Talos found the code in mid-June 2026 and released tooling, CAIRN, to hunt for AI-driven malware, noting the public build contains placeholder API keys and webhooks so it is not operational.
read more →

AI-driven malware removes humans from attack loop

🛡️ Cisco Talos reports a new malware family called CLOSEDQUORUM that uses a panel of large language models (LLMs) to fully automate command-and-control decisions and credential theft. The binary compiles tactical knowledge into model-readable prompts and constrains responses to JSON-formatted executable choices, enabling unattended execution against LSASS memory, browser-saved passwords, and crypto wallets. Researchers found the sample via the CAIRN toolkit and note the approach trades human limits for model and API weaknesses, and has not yet been confirmed in the wild.
read more →

ClosedQuorum: AI-driven Windows malware emerges

🛡️ Cisco Talos details a new Go-based Windows implant named ClosedQuorum that uses multiple AI models — including Google Gemini, DeepSeek, Qwen, and Mistral — to autonomously decide post-compromise actions. The malware uses reconnaissance data and a voting system to select among restricted options such as steal, inject, persist, and move (the latter currently unimplemented). Stolen credentials and wallet data are exfiltrated via Discord webhooks, enabling fully automated attack chains.
read more →

Cisco issues emergency patches for critical ISE zero-day

🔒 Cisco released emergency patches for an actively exploited authentication bypass in Cisco Identity Services Engine (ISE) and ISE-PIC, tracked as CVE-2026-76460 with a CVSS score of 10.0. The flaw allows unauthenticated, root-level access via a management API endpoint; fixes are included in specific 3.1–3.5 patch releases. CISA has added the flaw to its Known Exploited Vulnerabilities list and Cisco urges log checks, iACLs, and re-imaging if compromise is suspected.
read more →

Cisco warns of active exploit for ISE API flaw

🔒 Cisco has warned of active exploitation of a critical vulnerability, CVE-2026-76460, in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector. The flaw, rated 10.0 CVSS, stems from insufficient control on an API endpoint and can allow attackers to bypass the web-based management interface. Cisco released software updates and recommends using iACLs and log reviews while urging customers to upgrade immediately.
read more →

Cisco alerts on exploited ISE authentication bypass zero-day

🔒 Cisco has issued urgent updates for a maximum-severity Identity Services Engine vulnerability being actively exploited in the wild. The flaw (CVE-2026-76460) allows remote attackers to bypass authentication via a vulnerable API in Cisco ISE and ISE-PIC, enabling unauthorized access to the web-based management interface. Cisco PSIRT recommends immediate upgrades to fixed releases, and no workarounds are available.
read more →

Cisco warns of critical ISE authentication zero-day

🛡️ Cisco has disclosed a maximum-severity zero-day, CVE-2026-76460 (CVSS 10.0), in Identity Services Engine (ISE) and ISE-PIC that allows unauthenticated remote attackers to bypass authentication by exploiting an API endpoint. Cisco reports active exploitation and urges customers to upgrade to fixed patches for supported versions. There are no workarounds; recommended mitigations include iACLs and log review for suspicious usernames using the provided detection command.
read more →

Critical Cisco Secure Email Gateway zero-day patch

🔒 Cisco issued emergency fixes for a critical Secure Email Gateway vulnerability, CVE-2026-76461, that was being actively exploited. The flaw is an SQL injection in the product’s email parsing code and can lead to arbitrary SQL execution and root command execution. Patches are included in AsyncOS 15.5.5-0141, 16.0.4-3021, and 16.5.0-780, and CISA has added the issue to its KEV catalog.
read more →

Critical Cisco Secure Email Gateway zero-day exploited

📣 Cisco warned customers of an actively exploited zero-day in Secure Email Gateway that allows unauthenticated remote attackers to execute arbitrary commands as root. The flaw stems from insufficient validation in email parsing and malicious SQL in crafted messages. Cisco released patches and IOC guidance, while CISA added CVE-2026-76461 to its KEV Catalog, ordering federal fixes within three days.
read more →

CISA Adds Cisco, Citrix, Fortinet Flaws to KEV List

🔒 CISA has added three critical vulnerabilities affecting Cisco, Citrix, and Fortinet to its Known Exploited Vulnerabilities (KEV) catalog, mandating Federal Civilian Executive Branch (FCEB) agencies to patch by September 12, 2026. The issues include a Cisco FMC authentication bypass (CVE-2026-20079, CVSS 10.0) with active exploitation, a Citrix NetScaler ADC/Gateway bypass (CVE-2026-19490, CVSS 9.3), and a Fortinet FortiOS heap overflow (CVE-2025-25249, CVSS 7.3) linked to a Node.js RAT called PivotC2. Vendors and researchers reported observed post-compromise activity, honeypot hits, and large-scale scanning campaigns, prompting guidance to patch, limit internet exposure, and hunt for indicators of compromise.
read more →

Critical Cisco Nexus 9000 Flaw and IOS XR Hardening

🔒 Cisco released patches for a critical Nexus 9000 vulnerability (CVE-2026-20212) that allows unauthenticated remote root code execution via TCP ports 43210 and 43211. The advisory affects 10 Silicon One-based Nexus 9000 PIDs and lists mitigations including iACLs and a Live Protect shield while customers use the Software Checker to pick fixed releases. Cisco also published an IOS XR hardening release bundling seven umbrella CVEs, two rated 9.8, and provided SMUs and upgrade guidance for affected XR trains.
read more →