Cisco has issued critical patches for a vulnerability in its Nexus 9000 series switches, specifically those based on Silicon One architecture. This flaw, identified as CVE-2026-20212, carries a CVSS score of 9.8, indicating a severe risk. It allows remote attackers, without needing to authenticate, to execute code with root privileges on impacted systems. Alongside this vulnerability, Cisco also released a hardening update for IOS XR that includes seven additional CVEs, two of which are also rated very high at 9.8. Users of these Nexus switches should prioritize applying the patches as there are currently no workarounds available for the IOS XR versions affected.
Cisco has issued a warning about serious vulnerabilities in its Secure Email product related to S/MIME flaws that could allow attackers to access encrypted email content. Additionally, critical vulnerabilities in its IOS XR and Nexus switch software could let hackers execute remote code and bypass authentication, posing a significant risk to affected systems. Companies using these products should take immediate action to secure their environments, as the potential for exploitation could lead to unauthorized access and data breaches. The vulnerabilities have been publicly disclosed, emphasizing the need for users to stay vigilant and apply any available patches to mitigate risks. Cisco has released patches for the critical switch vulnerabilities, but users must address the S/MIME flaws as they remain unpatched at this time.
A cyber espionage group linked to China, known as Fire Ant, has broadened its operations to target Cisco IOS XR routers, TACACS servers, and Linux management hosts. This escalation follows a previous focus on VMware hypervisors. The group aims to steal credentials and disable security logs, which could severely compromise the integrity of high-value networks. Sygnia, the incident response firm that investigated the incidents, emphasizes the significance of these vulnerabilities given the critical role these systems play in network management and authentication. Organizations using these technologies should be vigilant and take immediate steps to secure their infrastructures.
Cisco's recent research raises concerns about the true origins of AI models and the risks associated with their dependencies. The study suggests that simply labeling an AI model's country of origin may not provide a complete picture of its potential vulnerabilities, as these models often inherit behaviors from upstream components. This can lead to security risks that users might not be aware of when they assume they've eliminated certain sources, such as Chinese technology. The findings highlight the need for companies and users to dig deeper into the lineage of AI models they implement to understand the associated security implications. As AI technology continues to evolve, understanding these complexities becomes increasingly vital for maintaining robust cybersecurity practices.
Cisco has released patches for several vulnerabilities found in its Crosswork and Secure Workload products. These flaws are serious, as they could allow attackers to execute remote code, bypass authentication, and perform path traversal attacks. Companies using these affected Cisco products are at risk, as these vulnerabilities could lead to unauthorized access and control over their systems. It's crucial for organizations to apply the updates provided by Cisco to protect their networks and data. Users should prioritize these patches to maintain their cybersecurity posture and prevent potential exploitation.
The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its catalog of exploited vulnerabilities. These include a heap inspection flaw in Cisco Secure Firewall (CVE-2026-20349), a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820), and a critical SQL injection vulnerability in Metabase (CVE-2026-72898). These flaws could allow attackers to exploit systems running affected software, potentially leading to unauthorized access or data breaches. Organizations using these products need to take immediate action to protect their systems. Awareness and prompt updates are essential to mitigate the risks associated with these vulnerabilities.
A significant data breach has emerged following the LiteLLM supply chain attack, with a massive 153GB archive of stolen credentials being discovered. This archive, analyzed by Hudson Rock, contains sensitive information from thousands of corporate domains, including major companies like AWS, Samsung, Cisco, and Salesforce. The data includes 433,909 files and over 118,000 CI runner dumps linked to nearly 2,500 corporate domains. Hudson Rock's co-founder stated that they are using this information to inform a global ethical disclosure initiative. The exposure of such extensive credentials poses a serious risk to the affected companies and their customers, as attackers could exploit this data for unauthorized access or other malicious activities.
Cisco has reported a high-severity vulnerability, designated as CVE-2026-20349, that attackers are using to cause temporary disruptions in the operation of Cisco firewalls. This flaw has been recognized by the Cybersecurity and Infrastructure Security Agency (CISA) and is included in their catalog of known exploited vulnerabilities. US civilian federal agencies are required to address this issue by August 14, 2026. While Cisco's Product Security Incident Response Team (PSIRT) became aware of the active exploitation in August, specific details regarding the attacks have not been disclosed. The urgency for remediation highlights the potential risks to organizations relying on Cisco’s firewall products.
Cisco has issued a patch for a serious vulnerability identified as CVE-2026-20349, which affects its Secure Firewall ASA and FTD devices. This flaw can be exploited remotely without the need for authentication, allowing attackers to launch Denial of Service (DoS) attacks against the devices. The ability to target these firewalls without prior access poses a significant risk to organizations that rely on Cisco's security solutions. Users of affected devices are urged to apply the updates provided by Cisco promptly to mitigate potential exploitation. The urgency of this patch reflects the growing trend of vulnerabilities being targeted in the wild, emphasizing the need for vigilant cybersecurity practices.
The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating they are actively exploited in the wild. The vulnerabilities include a heap inspection flaw in Cisco Secure Firewall Adaptive Security Appliance (CVE-2026-20349), a use-after-free vulnerability in Microsoft Windows Ancillary Function Driver for WinSock (CVE-2026-68820), and a SQL injection vulnerability in Metabase (CVE-2026-72898). These vulnerabilities pose significant risks, especially to federal agencies, prompting CISA to emphasize the need for rapid remediation of high-risk vulnerabilities. While the Binding Operational Directive 26-04 applies specifically to federal agencies, CISA encourages all organizations to adopt similar risk-based approaches to vulnerability management. Organizations aware of other exploited vulnerabilities can submit them for potential inclusion in the KEV Catalog.
Last week, Cisco addressed a vulnerability in its Integrated Management Controller (IMC) that could allow unauthorized access to sensitive system functions. This bug potentially affects users of Cisco's servers and data center management solutions, which are critical for IT infrastructure. The flaw could lead to serious security implications if exploited, making it essential for affected users to apply patches promptly. Additionally, the article discusses an upcoming Patch Tuesday, which is expected to bring further updates and fixes, and mentions plans for Black Hat USA 2026, a major cybersecurity conference. Keeping systems updated is vital in the ongoing fight against cyber threats.
Hackread – Cybersecurity News, Data Breaches, AI and More
Actively Exploited
Researchers from Cisco Talos have discovered that hackers are exploiting simple authorization claims to circumvent security measures in artificial intelligence systems. This vulnerability allows them to create tools for Distributed Denial of Service (DDoS) attacks, steal user credentials, and gain access to live camera feeds. The implications are significant, as it poses a risk to various platforms that utilize AI to manage security protocols. Companies that rely on AI for protection need to be vigilant and assess their defenses to prevent unauthorized access and potential data breaches. This incident serves as a reminder of the evolving tactics used by cybercriminals to exploit weaknesses in technology.
Cisco's Secure Firewall Management Center (FMC) is facing a significant security issue due to a vulnerability identified as CVE-2026-20316. This flaw allows attackers to exploit static credentials associated with a low-privileged user account within the FMC's web interface. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning, indicating that this vulnerability is being actively exploited by malicious actors. Organizations using Cisco FMC should take immediate action to secure their systems, as the exploitation of these credentials could lead to unauthorized access and potential control over network security settings. The report of this vulnerability was made by Jimi Sebree from Horizon3.ai, highlighting the urgency for affected users to address this issue promptly.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a vulnerability affecting the Cisco Secure Firewall Management Center (FMC) to its Known Exploited Vulnerabilities catalog. This flaw, identified as CVE-2026-20316, has a CVSS score of 5.3, indicating a moderate level of severity. Organizations using Cisco FMC should take this seriously as the vulnerability could potentially be exploited by attackers. CISA's inclusion of this flaw in their catalog signals a heightened risk, urging companies to assess their security measures. It's crucial for users to stay updated and implement necessary patches to protect their systems from potential exploitation.
The Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability to its Known Exploited Vulnerabilities Catalog, marking it as a significant risk due to active exploitation. The vulnerability, identified as CVE-2026-20316, affects the Cisco Secure Firewall Management Center and involves the use of a hard-coded password. This type of vulnerability is a common target for attackers and poses serious risks, particularly for federal agencies. CISA's Binding Operational Directive 26-04 mandates that federal agencies prioritize rapid fixes for such vulnerabilities to protect their systems. While the directive specifically applies to federal agencies, CISA encourages all organizations to adopt similar practices to manage vulnerabilities effectively.