Cisco says hackers have been exploiting a critical bug to break into big customer networks since 2023

Cisco says hackers have been exploiting a critical bug to break into big customer networks since 2023

Cisco has issued a stern warning about a significant vulnerability in one of its widely-used networking products that has been under exploitation for at least three years. This flaw, rated at the highest severity score of 10.0, poses a serious risk to large enterprises and government agencies utilizing its Catalyst SD-WAN products. The flaw allows cybercriminals to remotely access networks, providing them with elevated permissions to these crucial devices. Once infiltrated, hackers can maintain covert access to the victim's network, enabling them to monitor activities or siphon off sensitive data over extended periods. Cisco's researchers have traced exploitation activities back to 2023, with concerns particularly surrounding organizations classified as critical infrastructure, which could encompass essential services like power and water supply, as well as transportation systems. Following this discovery, several governments, including those of Australia, Canada, New Zealand, the United Kingdom, and the United States, have issued alerts about the global targeting of organizations by malicious actors. In a decisive move, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) mandated that all civilian federal agencies must update their systems by the end of the week, flagging the situation as an imminent threat. This directive comes amid a partial government shutdown that has left the federal cybersecurity agency operating at a limited capacity, yet they are still aware of ongoing exploits. While neither Cisco nor governmental agencies have pinpointed a specific threat group or nation responsible for these attacks, they have categorized a related cluster of activity under the identifier UAT-8616. In a prior warning issued in December, Cisco had highlighted a similar 10.0 vulnerability found in its Async software, which supports numerous products and was also being exploited to infiltrate customer networks.

Sources : TechCrunch

Published On : Feb 26, 2026, 16:20

Cybersecurity
Legal Battle Erupts Over 'Duress' Password in Groundbreaking Data Wiping Case

The U.S. Justice Department has initiated legal proceedings against a Georgia resident, Samuel Tunick, who is accused of...

TechCrunch | Jul 24, 2026, 18:25
Legal Battle Erupts Over 'Duress' Password in Groundbreaking Data Wiping Case
AI
Alphabet Takes the Lead in AI Investment Amid Industry Competition

In a bold move that underscores its commitment to artificial intelligence, Alphabet has significantly ramped up its spen...

CNBC | Jul 24, 2026, 19:45
Alphabet Takes the Lead in AI Investment Amid Industry Competition
AI
Anthropic Unveils Claude Opus 5: A Game-Changer in Cost-Effective AI

Anthropic has officially launched its latest AI model, Claude Opus 5, which the company claims is its most efficient and...

CNBC | Jul 24, 2026, 17:20
Anthropic Unveils Claude Opus 5: A Game-Changer in Cost-Effective AI
Startups
Sam Altman's World Secures $52.5 Million in Crypto Funding for Online Verification

World, an innovative online verification platform co-founded by Sam Altman of OpenAI fame, has successfully raised $52.5...

TechCrunch | Jul 24, 2026, 16:40
Sam Altman's World Secures $52.5 Million in Crypto Funding for Online Verification
AI
Cognition Acquires Poke: Redefining AI Interaction for Enhanced Productivity

Poke, the friendly AI assistant that users interact with as if chatting with a friend, is set to embark on a new journey...

TechCrunch | Jul 24, 2026, 18:25
Cognition Acquires Poke: Redefining AI Interaction for Enhanced Productivity
View All News