Cisco

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) 2026-09-15 at 14:09 By Zeljka Zorz Attackers have leveraged a zero-day SQL injection vulnerability (CVE-2026-76461) to compromise Cisco Secure Email Gateway appliances, Cisco confirmed on Monday. The vendor’s Product Security Incident Response Team became aware of active exploitation of this vulnerability in September 2025, and has shared […]

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) Read More »

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation 2026-09-15 at 08:18 By Eduard Kovacs An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges. The post Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation appeared first on SecurityWeek. This article is an […]

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation Read More »

Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)

Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316) 2026-09-10 at 14:22 By Zeljka Zorz State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC), which is used for centrally managing multiple Cisco Secure Firewall devices across a network. Two FMC vulnerabilities under […]

Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316) Read More »

Organizations Warned of Cisco Secure FMC Exploitation

Organizations Warned of Cisco Secure FMC Exploitation 2026-09-10 at 13:06 By Eduard Kovacs Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026. The post Organizations Warned of Cisco Secure FMC Exploitation appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Organizations Warned of Cisco Secure FMC Exploitation Read More »

Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities

Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities 2026-09-03 at 13:30 By Ionut Arghire Publicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution and authentication bypass. The post Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities appeared […]

Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities Read More »

Cybersecurity job ads demanding AI skills double in a year

Cybersecurity job ads demanding AI skills double in a year 2026-08-24 at 14:53 By Sinisa Markovic Job postings asking for AI skills in cybersecurity have doubled in a single year in G7 countries according to new research from the Cisco-founded AI Workforce Consortium. Analysis from recruitment firms Cornerstone and Indeed covering 24 months, from April […]

Cybersecurity job ads demanding AI skills double in a year Read More »

Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

Cisco Patches Firewall Zero-Day Exploited for DoS Attacks 2026-08-12 at 08:10 By Eduard Kovacs CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. The post Cisco Patches Firewall Zero-Day Exploited for DoS Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cisco Patches Firewall Zero-Day Exploited for DoS Attacks Read More »

Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC

Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC 2026-08-10 at 17:07 By Ionut Arghire Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition. The post Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC Read More »

Cisco FMC static credentials exploited by attackers (CVE-2026-20316)

Cisco FMC static credentials exploited by attackers (CVE-2026-20316) 2026-07-30 at 13:44 By Zeljka Zorz A static credentials vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC), a platform for centrally managing multiple Cisco Secure Firewall devices across a network, is being leveraged by attackers, CISA warned. Two FMC flaws, one indicator of compromise CVE-2026-20316, reported […]

Cisco FMC static credentials exploited by attackers (CVE-2026-20316) Read More »

Cisco Secure FMC Zero-Day Exploited in the Wild

Cisco Secure FMC Zero-Day Exploited in the Wild 2026-07-30 at 09:31 By Eduard Kovacs The vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices.  The post Cisco Secure FMC Zero-Day Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Cisco Secure FMC Zero-Day Exploited in the Wild Read More »

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process 2026-07-23 at 13:38 By Mirko Zorz Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or […]

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process Read More »

Cisco Launches Low-Cost AI Models for Source Code Security

Cisco Launches Low-Cost AI Models for Source Code Security 2026-07-21 at 20:44 By Kevin Townsend The open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models. The post Cisco Launches Low-Cost AI Models for Source Code Security appeared first on SecurityWeek. This […]

Cisco Launches Low-Cost AI Models for Source Code Security Read More »

Cisco’s open-weight Antares models make vulnerability localization cheaper

Cisco’s open-weight Antares models make vulnerability localization cheaper 2026-07-21 at 16:01 By Mirko Zorz A security analyst opens an unfamiliar repository, pulls up a vulnerability advisory, and starts hunting for the file where the weakness lives. The naming conventions belong to someone else. Evidence sits in scattered corners of a codebase that runs to thousands […]

Cisco’s open-weight Antares models make vulnerability localization cheaper Read More »

New ClamAV security patch closes seven scanner bugs dating back two decades

New ClamAV security patch closes seven scanner bugs dating back two decades 2026-07-06 at 01:30 By Sinisa Markovic Open source antivirus scanning sits inside mail gateways, file upload checks, and endpoint tooling at organizations of every size. Much of that work runs through ClamAV, the scanning engine maintained by Cisco’s Talos group. The project released […]

New ClamAV security patch closes seven scanner bugs dating back two decades Read More »

The ARToken phishing panel targets Microsoft 365 accounts

The ARToken phishing panel targets Microsoft 365 accounts 2026-07-01 at 13:00 By Sinisa Markovic Accounts-payable staff at U.S. companies keep receiving invoice emails that look like they come from vendors they already work with. One landed at a life-sciences company in April 2026, addressed to the person who handles payments and written in the voice […]

The ARToken phishing panel targets Microsoft 365 accounts Read More »

Cisco SD-WAN Zero-Day Exploited Months Before Patching

Cisco SD-WAN Zero-Day Exploited Months Before Patching 2026-06-25 at 09:08 By Eduard Kovacs CVE-2026-20245, the 7th Cisco SD-WAN vulnerability exploited in 2026, was used for months prior to its disclosure and patching. The post Cisco SD-WAN Zero-Day Exploited Months Before Patching appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cisco SD-WAN Zero-Day Exploited Months Before Patching Read More »

Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230)

Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230) 2026-06-24 at 14:36 By Zeljka Zorz CVE-2026-20230, a server-side request forgery (SSRF) vulnerability affecting Cisco’s Unified Communications Manager (Unified CM), is being exploited to drop webshells and achieve remote code execution capability on the underlying server. “Our honeypots are seeing automated sweeps dropping webshells, all […]

Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230) Read More »

Hackers Exploiting Cisco Unified CM Vulnerability

Hackers Exploiting Cisco Unified CM Vulnerability 2026-06-24 at 08:44 By Eduard Kovacs Cisco noted that a PoC had been available for CVE-2026-20230 when it announced patches in early June. The post Hackers Exploiting Cisco Unified CM Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hackers Exploiting Cisco Unified CM Vulnerability Read More »

Cisco to Acquire WideField Security to Boost Splunk’s Agentic SOC

Cisco to Acquire WideField Security to Boost Splunk’s Agentic SOC 2026-06-19 at 10:22 By Eduard Kovacs WideField will accelerate Agentic SOC capabilities by expanding the lens on threat investigation to include identity, credentials, sessions, and blast radius. The post Cisco to Acquire WideField Security to Boost Splunk’s Agentic SOC appeared first on SecurityWeek. This article […]

Cisco to Acquire WideField Security to Boost Splunk’s Agentic SOC Read More »

Critical Command Execution Vulnerability Patched in Cisco ISE

Critical Command Execution Vulnerability Patched in Cisco ISE 2026-06-18 at 13:27 By Ionut Arghire Insufficient validation of user input allows an attacker to gain access to the underlying OS and elevate their privileges to root. The post Critical Command Execution Vulnerability Patched in Cisco ISE appeared first on SecurityWeek. This article is an excerpt from […]

Critical Command Execution Vulnerability Patched in Cisco ISE Read More »

Scroll to Top