Tag Cisco

Cisco Confirms Active Exploits Targeting Vulnerabilities in ISE, Leading to Unauthenticated Root Access

On July 22, 2025, Cisco updated its advisory regarding several recently disclosed security vulnerabilities in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), confirming that they are being actively exploited. Cisco’s Product Security Incident Response Team (PSIRT) reported awareness of attempts to exploit these vulnerabilities in real-world scenarios. However, the company did not specify which vulnerabilities are being targeted, the identity of the attacking entities, or the scale of these activities. Cisco ISE is crucial for network access control, determining which users and devices can access corporate networks and under what conditions. A breach at this level could allow attackers unrestricted access to internal systems, effectively bypassing authentication and logging controls and transforming a key policy engine into an unguarded entry point. The alert emphasizes that the identified vulnerabilities are classified as critical.

Cisco Confirms Ongoing Exploitation of ISE Vulnerabilities Leading to Unauthenticated Root Access On July 22, 2025, Cisco updated its advisory regarding recently unveiled vulnerabilities in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), admitting that active exploitation is occurring in live environments. The Cisco Product Security Incident…

Read More

Cisco Confirms Active Exploits Targeting Vulnerabilities in ISE, Leading to Unauthenticated Root Access

On July 22, 2025, Cisco updated its advisory regarding several recently disclosed security vulnerabilities in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), confirming that they are being actively exploited. Cisco’s Product Security Incident Response Team (PSIRT) reported awareness of attempts to exploit these vulnerabilities in real-world scenarios. However, the company did not specify which vulnerabilities are being targeted, the identity of the attacking entities, or the scale of these activities. Cisco ISE is crucial for network access control, determining which users and devices can access corporate networks and under what conditions. A breach at this level could allow attackers unrestricted access to internal systems, effectively bypassing authentication and logging controls and transforming a key policy engine into an unguarded entry point. The alert emphasizes that the identified vulnerabilities are classified as critical.

IBM: Shadow AI Breaches Lead to $670K Increase in Costs; 97% of Companies Unprepared

The Rising Threat of Shadow AI: A Growing Challenge for Organizations Organizations are increasingly facing a hidden risk known as Shadow AI, a phenomenon that has been tagged as a staggering $670,000 issue that many aren’t even aware exists. Recent findings from IBM’s 2025 Cost of a Data Breach Report,…

Read MoreIBM: Shadow AI Breaches Lead to $670K Increase in Costs; 97% of Companies Unprepared

GitHub Exploited for Distributing Malware-as-a-Service Payloads

Researchers from Cisco’s Talos security team have identified a sophisticated malware-as-a-service (MaaS) operation that exploited public GitHub accounts to distribute various types of malicious software to targeted entities. This innovative distribution method capitalized on GitHub’s widespread acceptance in enterprise environments, where many organizations rely on the platform for software development.…

Read MoreGitHub Exploited for Distributing Malware-as-a-Service Payloads

Aviatrix Shifts Focus from Networking to Cloud Security Investments

Cloud Security, Governance & Risk Management, Network Firewalls, Network Access Control CEO Doug Merritt: GenAI, Workload Sprawl Heighten Zero Trust Imperatives for Aviatrix Michael Novinson (MichaelNovinson) • July 14, 2025 Doug Merritt, chairman, president, and CEO, Aviatrix (Image: Aviatrix) Initially, Aviatrix focused on creating a networking abstraction layer that unified…

Read MoreAviatrix Shifts Focus from Networking to Cloud Security Investments

Patch Released for Static Credentials Vulnerability in Cisco Systems

Network Firewalls, Network Access Control, Security Operations Critical Vulnerability Uncovered, Exposing Remote Privilege Escalation Threat Prajeet Nair (@prajeetspeaks) • July 3, 2025 Image: Anucha Cheechang/Shutterstock Cisco has issued urgent security updates to address a significant vulnerability in its Unified Communications Manager (UCM), which enables unauthorized attackers to gain root access…

Read MorePatch Released for Static Credentials Vulnerability in Cisco Systems

‘IntelBroker’ Hacker Nabbed for Series of High-Profile Data Breaches

U.S. and international law enforcement have detained a British national, believed to be the infamous hacker known as “IntelBroker,” alongside four individuals presumed to be associated with the BreachForums online marketplace for illicitly obtained data. The primary suspect, identified in an indictment as 25-year-old Kai Logan West, was apprehended in…

Read More‘IntelBroker’ Hacker Nabbed for Series of High-Profile Data Breaches