A public announcement exists for the Cisco Secure Email vulnerability pair in S/MIME decryption, plus a Cisco phone SIP denial-of-service flaw.
Related Posts:
CVE-2026-75754 (CVSS 10): ASUS Control Center Root RCE
Apache Allura Security Vulnerabilities Patched in v1.21.0
CVE-2026-52924 PoC Exploit Disclosed: 9.8 CVSS Linux Root Privilege Escalation
The post Cisco Secure Email S/MIME Flaws Publicly Disclosed appeared first on Daily CyberSecurity.
Cisco patched a critical Nexus 9000 vulnerability, CVE-2026-20212, allowing unauthenticated remote root code execution.
Cisco has released patches for a critical flaw, tracked as tracked as CVE-2026-20212 (CVSS score of 9.8) in 10 Silicon One-based Nexus 9000 switches. The vulnerability could let an unauthenticated remote attacker execute code with root privileges.
Cisco’s Technical Assistance Center (TAC) discovered the flaw while investigating a customer support case.
The flaw exists
Cisco has released patches for a critical flaw, tracked as tracked as CVE-2026-20212 (CVSS score of 9.8) in 10 Silicon One-based Nexus 9000 switches. The vulnerability could let an unauthenticated remote attacker execute code with root privileges.
Cisco’s Technical Assistance Center (TAC) discovered the flaw while investigating a customer support case.
The flaw exists because TCP ports 43210 and 43211 are exposed through the default Layer 3 VRF. An attacker could connect remotely and send specially crafted data that gets executed with root privileges. The attack could also crash the S1HAL process, potentially forcing the affected device to reload.
“A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges.” reads the advisory. “This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.”
The vulnerability affects Cisco Nexus 9000 Series switches equipped with a Silicon One ASIC.
At the time of disclosure, the following models were known to include the affected Silicon One hardware:
N9324C-SE1U
N9348Y2C6D-SE1U
N9364E-SG2-O
N9364E-SG2-Q
N9396T12C-SE1
N9348Y12C-SE1
N9396Y12C-SE1
N9336C-SE1
N9K-C9804
N9K-C9808
Administrators can check the Product ID (PID) of a switch by running the show module command. For example, the output below shows N9336C-SE1, which is one of the affected models.
Other Nexus 9000 models are not affected. The same applies to Nexus 9000 switches running in ACI mode, as well as the Nexus 3000 and Nexus 7000 series.
Cisco provides a workaround to reduce the risk of remote exploitation. Administrators can use infrastructure access control lists (iACLs) to allow only the management and control traffic that the affected switch actually needs. Another option is to block TCP traffic to locally configured IP addresses on ports 43210 and 43211.
Cisco has also released a Live Protect shield for CVE-2026-20212. The shield provides temporary protection while organizations prepare to install the proper software update.
However, Cisco recommends upgrading to a fixed NX-OS release as the permanent solution. Before deploying any workaround or mitigation, administrators should test it in their own environment, as it could affect network functionality or performance.
Cisco says its Product Security Incident Response Team (PSIRT) is not aware of any public disclosure or active exploitation of this vulnerability.
“The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.” concludes the advisory.
Cisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited.
Cisco released another batch of security fixes for its Crosswork platforms and Secure Workload software, part of what it’s calling an ongoing internal security review, and the CVSS scores in this round are unusually severe.
“As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a compr
Cisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited.
Cisco released another batch of security fixes for its Crosswork platforms and Secure Workload software, part of what it’s calling an ongoing internal security review, and the CVSS scores in this round are unusually severe.
“As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.” reads the advisory. “These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class – Common Weakness Enumeration (CWE) – and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping.”
Four vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, all impacting these products regardless of how they’re configured:
CVE-2026-20030 (CVSS score: 10.0) – an SQL injection vulnerability that lets an attacker manipulate database queries directly.
CVE-2026-20357 (CVSS score: 10.0) – a missing authentication for critical function vulnerability, meaning a sensitive operation can be triggered without ever proving who you are.
CVE-2026-20358 (CVSS score: 10.0) – an external control of file system vulnerability, letting an outside actor influence which files the system reads or writes.
CVE-2026-20359 (CVSS score: 9.9) – an insufficiently protected credentials vulnerability, where stored login material isn’t locked down the way it should be.
Seeing three CVSS 10.0 vulnerabilities in a single Cisco advisory is unusual. The four flaws affect Crosswork 7.2.1 and earlier, and Cisco fixed them in version 7.2.1-SP.
Five more vulnerabilities got patched in Cisco Secure Workload, spanning both its cloud SaaS and on-premises deployments:
CVE-2026-20231 (CVSS score: 9.9) – a set of improper neutralization of special elements vulnerabilities covering command, operating system, and argument injection, essentially several different ways to smuggle unintended commands into the system.
CVE-2026-20315 (CVSS score: 10.0) – a set of improper access control vulnerabilities spanning authorization, authentication, privileges, and bypasses, a broad category that generally means the system doesn’t reliably enforce who’s allowed to do what.
CVE-2026-20317 (CVSS score: 10.0) – a set of improper authentication vulnerabilities covering missing authentication, authentication bypass, and reliance on untrusted inputs, another maximum-severity cluster centered on identity verification failing outright.
CVE-2026-20318 (CVSS score: 9.6) – a set of improper input validation vulnerabilities spanning input validation, path traversal, and external path control, the kind of flaw that lets crafted input reach files or directories it was never meant to touch.
CVE-2026-20319 (CVSS score: 7.5) – a set of improper restriction of operations within the bounds of a memory buffer vulnerabilities spanning buffer overflows and out-of-bounds writes, lower severity than the rest but still a genuine memory-safety problem.
The networking giant addressed five vulnerabilities in Secure Workload Release 3.10.9.1 for the 3.10 branch and earlier, and 4.0.4.16 for the 4.0 branch.
The company found these vulnerabilities during internal testing; it is not aware of attacks in the wild exploiting this issue.
“The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.” conctinues the advisory. “Cisco says it found the vulnerabilities through internal security testing that also used advanced AI models.”
Nobody’s reported active attacks against any of these nine flaws yet, and Cisco’s own review process caught them before an outside researcher or attacker did.
If your organization runs Crosswork or Secure Workload in any configuration, this isn’t a patch to schedule for next month’s maintenance window. Perfect CVSS scores tend to attract attention fast once a vulnerability’s technical details start circulating, and Cisco’s internal discovery only buys you a head start if you actually use it.
Cisco has released security updates for a high-severity XML External Entity injection vulnerability in Cisco BroadWorks that could allow unauthenticated remote attackers to read sensitive configuration data and files from affected systems.
Tracked as CVE-2026-20320, the issue carries a CVSS score of 7.5 and affects several components of the BroadWorks platform. The vulnerability, identified in the Open Client Interface XML Parser, is classified as CWE-611, or improper restriction of XML exter
Cisco has released security updates for a high-severity XML External Entity injection vulnerability in Cisco BroadWorks that could allow unauthenticated remote attackers to read sensitive configuration data and files from affected systems.
Tracked as CVE-2026-20320, the issue carries a CVSS score of 7.5 and affects several components of the BroadWorks platform. The vulnerability, identified in the Open Client Interface XML Parser, is classified as CWE-611, or improper restriction of XML external entity reference.
Cisco published the advisory, cisco-sa-bworks-xxe-uwUd7CEt, on August 19, 2026. Cisco said the flaw exists because the affected XML parser allows external entity resolution by default.
When XML input is processed, external entities can instruct the parser to retrieve local resources or access other available locations. This behavior can expose information that should not be reachable through the XML interface.
Successful exploitation does not require authentication or user interaction, increasing the risk for exposed or reachable BroadWorks deployments.
Cisco External Entity Injection Vulnerability
Cisco warned that a successful attack could allow the threat actor to view sensitive files from the filesystem using the permissions assigned to the Cisco BroadWorks user. The advisory specifically describes the issue as an out-of-band blind XML External Entity injection vulnerability.
In a blind XXE attack, the attacker may not receive the target file contents directly in the application response. Instead, the vulnerable server can be induced to send data or interaction results to an attacker-controlled external system.
The affected products include Cisco BroadWorks Application Delivery Platform, BroadWorks Application Server, BroadWorks Profile Server, and BroadWorks Xtended Services Platform.
Systems running releases earlier than RI.2026.07 are affected across these product families, according to Cisco. Cisco has addressed the vulnerability in BroadWorks RI.2026.07. For the BroadWorks Application Delivery Platform, the fix applies to Open Client Server and OCIOverSoap components.
Organizations using impacted releases should identify systems that expose or use OCI-P and upgrade to the appropriate fixed software release as soon as possible.
No workaround is available. Cisco recommends upgrading rather than relying on temporary mitigations, as a fixed release is required to remediate the issue fully. Administrators should also review network exposure for BroadWorks management and provisioning interfaces.
OCI-P should not be broadly accessible from untrusted networks, and organizations should limit access through network segmentation, firewall policies, and tightly controlled administrative paths.
Security teams can monitor for unusual XML requests, unexpected outbound connections from BroadWorks infrastructure, and suspicious attempts to access local files or internal network services.
Cisco PSIRT said it was not aware of public announcements or malicious exploitation of CVE-2026-20320 at the time of publication. Security researcher Sandesh M Gawai reported the vulnerability.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
Cisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks.
Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux. ClamAV is an open-source antivirus engine widely used to scan files and emails for malware.
The company states that two flaws have public PoCs and could let unauthenticated attackers cause DoS conditions.
“Multiple vulnerabilities
Cisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks.
Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux. ClamAV is an open-source antivirus engine widely used to scan files and emails for malware.
The company states that two flaws have public PoCs and could let unauthenticated attackers cause DoS conditions.
“Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations.” reads the advisory.
The flaws, tracked as CVE-2026-20337 to CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348, affect ClamAV parsers for several file formats. ClamAV fixed them in version 1.5.4, Cisco later warned that public PoCs are available for the vulnerabilities CVE-2026-20337 and CVE-2026-20338. Company’s PSIRT said it has no evidence that attackers have exploited these vulnerabilities in the wild.
“”The Cisco PSIRT is aware that proof-of-concept exploit code is available for the vulnerabilities that are described in CVE-2026-20337 and CVE-2026-20338.The Cisco PSIRT is not aware of proof-of-concept exploit code for any of the other vulnerabilities that are described in this advisory.” continues the advisory. “The Cisco PSIRT is not aware of any malicious use of the vulnerabilities that are described in this advisory.”
Below are the descriptions of CVE-2026-20337 and CVE-2026-20338:
CVE-2026-20337 (CVSS score of 7.5) – CVE-2026-20337: ClamAV Zip File Format Processing Out-of-Bounds Write Vulnerability – A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
CVE-2026-20337 (CVSS score of 7.5) – ClamAV Zip File Format Processing Memory Corruption Vulnerability – A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate as a result of a memory double-free, resulting in a DoS condition on the affected software.
Cisco identified the affected products in its advisory and recommends customers check the related bug IDs for details on each vulnerability.
Secure Endpoint Private Cloud is not affected, but must distribute the fixes to endpoints.
Cisco said no workaround is available. Patches will be released in August. The flaws are high risk on Windows because ClamAV runs with elevated privileges, while macOS and Linux face medium risk.
Cisco disclosed seven ClamAV vulnerabilities that let a remote attacker crash scanning via crafted files. Details are public. Patch now.
Related Posts:
CVE-2026-27912: PoC Released for SYSTEM Privilege Flaw
CVE-2026-58231 (CVSS 10.0) and Code Injection RCE Flaws Top SAP August 2026 Patch Day
Windows PnP Attack Chain Turns a USB Plug Into SYSTEM: Details and PoC Now Public
The post Multiple ClamAV Flaws Let Remote Attackers Cause DoS appeared first on Daily CyberSecurity.
PoC exploit code is public for CVE-2026-20200, a Cisco IMC argument injection flaw enabling root RCE. CVSS 8.8. Patch details inside.
Related Posts:
Metabase SQL Injection Zero-Day (CVSS 10) Exploited
Multiple ClamAV Flaws Let Remote Attackers Cause DoS
CryptoJS Randomness Vulnerability Drains Crypto Wallets
The post Cisco IMC Argument Injection Flaw CVE-2026-20200 Enables Root RCE, PoC Exploit Code Publicly Available appeared first on Daily CyberSecurity.
Cisco has released a critical security hardening update for Cisco IOS XE Software, fixing several serious vulnerabilities that could expose enterprise network devices to remote attacks.
The advisory covers vulnerabilities identified during Cisco’s internal security testing, including testing supported by frontier AI models.
Cisco said it is not aware of public exploitation or malicious activity linked to these flaws. However, the severity of the issues, combined with the lack of available
Cisco has released a critical security hardening update for Cisco IOS XE Software, fixing several serious vulnerabilities that could expose enterprise network devices to remote attacks.
The advisory covers vulnerabilities identified during Cisco’s internal security testing, including testing supported by frontier AI models.
Cisco said it is not aware of public exploitation or malicious activity linked to these flaws. However, the severity of the issues, combined with the lack of available workarounds, makes prompt patching essential.
The vulnerabilities affect Cisco IOS XE Software running in autonomous mode or controller mode, regardless of device configuration. Cisco assessed releases 17.9, 17.12, 17.15, 17.18, and 26.1 as part of this review. Cisco Catalyst 3650 and 3850 Series Switches were not evaluated because they do not run the reviewed releases.
The most severe issue is CVE-2026-20272, which carries a maximum CVSS score of 9.8 out of 10. The flaw is linked to CWE-74, or improper neutralization of special elements. This weakness can include command injection, operating system injection, and argument injection risks.
Cisco Patches Critical IOS XE Flaws
If successfully exploited, such weaknesses may allow an attacker to execute unintended commands or alter how a system processes input. Cisco also addressed CVE-2026-20267, an improper access control issue rated 9.0.
This vulnerability falls under CWE-284 and includes risks involving authentication bypasses, authorization failures, privilege issues, and other access-control weaknesses. Attackers could potentially abuse these conditions to gain access beyond their intended permissions.
Several other vulnerabilities received a maximum CVSS score of 8.6. CVE-2026-20268 involves memory buffer restrictions, including possible buffer overflows and out-of-bounds writes.
CVE-2026-20269 relates to improper resource lifetime management, such as invalid memory handling, null pointer dereferences, and file handler issues.
Cisco also patched CVE-2026-20270, which covers incorrect calculations and numeric conversion problems, including integer overflow and truncation.
CVE-2026-20271 addresses insufficient control-flow management, including race conditions, uncontrolled recursion, and infinite loops. CVE-2026-20273 concerns improper input validation, with potential impacts including path traversal and unsafe external path handling.
CVE ID
Vulnerability Class
CWE
Maximum CVSS Score
CVE-2026-20267
Improper access control
CWE-284
9.0
CVE-2026-20268
Improper restriction of operations within a memory buffer
CWE-119
8.6
CVE-2026-20269
Improper control of a resource through its lifetime
CWE-664
8.6
CVE-2026-20270
Incorrect calculation
CWE-682
8.6
CVE-2026-20271
Insufficient control-flow management
CWE-691
8.6
CVE-2026-20272
Improper neutralization of special elements, including command injection
CWE-74
9.8
CVE-2026-20273
Improper input validation
CWE-20
8.6
Cisco has confirmed that there are no workarounds for these flaws. Organizations using affected IOS XE releases must install the fixed software versions to remediate the exposure fully.
Cisco strongly recommends affected organizations immediately upgrade to fixed software releases, as outlined in advisory cisco-sa-hardening-iosxe-V8NMuMZJ published on August 5, 2026. The first patched versions are IOS XE 17.9.10, 17.12.8, 17.15.6, 17.18.4/17.18.4a, and 26.1.2.
Network administrators should first identify all Cisco IOS XE devices in their environment and confirm their currently installed release. They should then review hardware capacity, configuration compatibility, and maintenance windows before upgrading.
Because IOS XE devices often support core routing, switching, wireless, and controller functions, patching should be carefully planned and treated as a high-priority security task.
Cisco PSIRT validates only the affected and fixed release information listed in the advisory. Organizations should also monitor Cisco security advisories for additional fixes and upgrade guidance.
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Firewall Management Center (FMC) flaw, tracked as CVE-2026-20316 (CVSS score of 5.3), to its Known Exploited Vulnerabilities (KEV) catalog.
CVE-2026-20316 is a static credential vulnerability in the web interface of Cisco Secure Firewall Ma
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog.
CVE-2026-20316 is a static credential vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software that could allow an unauthenticated, remote attacker to authenticate using a built-in low-privileged account and access sensitive information stored on the affected system.
“A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.” reads the advisory. “A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.”
The flaw stems from the presence of hardcoded credentials for a low-privileged user account. Although the account provides limited access, it could be combined with other Cisco Secure FMC Software vulnerabilities to achieve privilege escalation. The attack surface is reduced if the FMC management interface is not exposed to the public internet.
Cisco released the following hot fixes to address this issue:
Cisco confirmed active exploitation of the vulnerability in July 2026 and strongly urges customers to upgrade to a fixed software release immediately.
“In July 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.” states the advisory.
Administrators can check for exploitation by running cat /var/log/messages | grep license in expert mode. If the logs contain references to /var/tmp/license.tmp, the device may have been compromised. Cisco advises organizations that suspect exploitation to contact TAC for recovery assistance and immediately rotate all user credentials, cryptographic keys, and certificates, as the vulnerability has been actively exploited.
Phishing played a part in more than half of all incident response engagements undertaken by Talos, Cisco's threat research organization, during the second quarter of 2026, with healthcare organizations and manufacturing firms among the top targets.
The post Talos: Attackers Refine Phishing Playbook To Target Critical Infrastructure appeared first on The Security Ledger with Paul F. Roberts.
Phishing played a part in more than half of all incident response engagements undertaken by Talos, Cisco's threat research organization, during the second quarter of 2026, with healthcare organizations and manufacturing firms among the top targets.
IntroductionThe modern cyber threat landscape has seen a fundamental shift in how threat actors manage and deploy their infrastructure. Advanced persistent threats (APTs) have almost completely moved away from static command-and-control (C2) servers, opting instead to build complex, multi-layered botnets known as Operational Relay Box (ORB) networks. Project ORBITAL (which stands for Operational Relay Box Intelligence, Tracking, & Analysis Lexicon) was established as a centralised intelligen
The modern cyber threat landscape has seen a fundamental shift in how threat actors manage and deploy their infrastructure. Advanced persistent threats (APTs) have almost completely moved away from static command-and-control (C2) servers, opting instead to build complex, multi-layered botnets known as Operational Relay Box (ORB) networks.
Project ORBITAL (which stands for Operational Relay Box Intelligence, Tracking, & Analysis Lexicon) was established as a centralised intelligence matrix to track, analyse, and ultimately help defenders disrupt this highly evasive infrastructure.
To construct these networks, adversaries systematically compromise unpatched, end-of-life devices. By targeting legacy, unpatched Small Office/Home Office (SOHO) router and Internet-of-Things (IoT) devices attackers can create a sprawling, decentralised mesh of proxy nodes. By routing their operations through layers of compromised devices, adversaries mask their true origins, making malicious activity blend seamlessly with legitimate regional traffic.
Blogs by my colleagues at Team Cymru as well as Google offer detailed explanations as to why and how these ORBs have grown over many years and continue to expand.
Project Background
Project ORBITAL represents a centralised Open Source Intelligence (OSINT) collection driven by public reporting from advanced research teams across the cybersecurity and technology sectors. This initiative aggregates telemetry and findings from top-tier vendors including Cisco Talos, CrowdStrike, Google, GreyNoise Labs, Lumen Black Lotus Labs, Microsoft, SecurityScorecard, Sekoia, SentinelLabs, Sygnia, and Team Cymru. Furthermore, it incorporates critical alerts and intelligence shared publicly by United States government agencies, specifically the Federal Bureau of Investigation (FBI), the Cyber National Mission Force (CNMF), and the National Security Agency (NSA).
This repository builds on the methodology of my previous OSINT tracking initiatives. It is heavily inspired by the structure and community success of my earlier matrix projects, specifically the Ransomware Tool Matrix (RTM) (here), the Ransomware Vulnerability Matrix (RVM) (here), and the Russian APT Tool Matrix (RUTM) (here). By applying a similar, structured approach to mapping Operational Relay Box (ORB) networks, this project aims to provide defenders with a clear, actionable lexicon for hunting and tracking evasive edge-device botnets.
Graph Visualisation
Once Project ORBITAL was initially assembled, it was then possible to use a GitHub Action automation with NetworkX and PyVis to create a Graph Visualisation using the data collected. Once in this view, some interesting patterns could be observed.
Analysis of the extracted data uncovered that ASUS devices were the most targeted out of all of the targeted devices by ORBs from the public reports.
Another interesting point the graph highlighted is that the LapDogs ORB network had the highest number of reported targeted devices.
In most reported scenarios, a singular threat group used a dedicated ORB network. However, from extracting the details from the Google and SentinelLabs reports, an adversary like APT15, reportedly leverages both SPACEHOP and PurpleHaze ORB networks, alongside two other separate adversaries UNC2630 and UNC5174.
The overlap in ORB usage suggests these APTs aren't all building their own botnets from scratch. These overlaps likely indicate there are provisioning teams, such as specialised contractors, like Beijing Integrity Tech, who build and maintain these ORB networks and then lease access to the broader Chinese intelligence community in the Ministry of State Security (MSS) and People’s Liberation Army (PLA).
Panda-monium
Below is the list of well-known China-nexus APTs listed using CrowdStrike’s naming scheme and their Google or Microsoft aliases that are all mentioned in Project ORBITAL.
CAULDRON PANDA (aka UNC3886)
ETHEREAL PANDA (aka Flax Typhoon)
JUDGMENT PANDA (APT31, Violet Typhoon)
KEYHOLE PANDA (aka UNC2630, APT5)
MURKY PANDA (aka Silk Typhoon)
VANGUARD PANDA (aka Volt Typhoon)
VIXEN PANDA (aka APT15, Nylon Typhoon)
The most notable aspect about this list is that it contains APTs with wildly different mandates. VANGUARD PANDA (Volt Typhoon) is famous for pre-positioning within critical infrastructure with the potential disruptive attacks, while KEYHOLE PANDA (APT5) and JUDGMENT PANDA (APT31) are long-running cyber-espionage and IP theft operators. The fact that both the saboteurs and the spies have all adopted ORB networks goes to show that this tactic is not niche but instead is the baseline standard for Chinese APT operational security (OPSEC).
How to Access
You can find Project ORBITAL on my GitHub repository below:
Hackers exploited Cisco Catalyst SD-WAN flaw CVE-2026-20245 as a zero-day months before disclosure, enabling privileged command execution.
Google-owned Mandiant reported that an unknown threat actor exploited Cisco Catalyst SD-WAN vulnerability CVE-2026-20245 (CVSS base score of 7.8) as a zero-day at least two months before it was publicly disclosed.
The flaw allows an authenticated attacker with netadmin privileges to execute arbitrary commands with elevated rights by using a crafted fi
Hackers exploited Cisco Catalyst SD-WAN flaw CVE-2026-20245 as a zero-day months before disclosure, enabling privileged command execution.
Google-owned Mandiant reported that an unknown threat actor exploited Cisco Catalyst SD-WAN vulnerability CVE-2026-20245 (CVSS base score of 7.8) as a zero-day at least two months before it was publicly disclosed.
The flaw allows an authenticated attacker with netadmin privileges to execute arbitrary commands with elevated rights by using a crafted file. Cisco has confirmed awareness of active exploitation and released fixes.
An authenticated local attacker can trigger the vulnerability to run arbitrary commands as root. The mechanics are straightforward: bad input validation. Although the flaw requires netadmin privileges, attackers can obtain them using stolen credentials or by exploiting previously disclosed vulnerabilities such as CVE-2026-20182 and CVE-2026-20127.
“This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user.” reads the advisory. “To exploit this vulnerability, the attacker must have netadmin privileges on the affected system. This would require valid credentials or exploitation of CVE-2026-20182 or CVE-2026-20127. Cisco is not aware of successful exploitation by other methods. Cisco has observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices.”
The vulnerability affects Cisco Catalyst SD-WAN Manager across all deployment models, including on-premises installations, Cisco SD-WAN Cloud-Pro, Cisco-managed cloud deployments, and FedRAMP environments.
“In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access.” reads the report published by Mandiant. “Throughout the intrusion, to maintain operational security and avoid detection, the threat actor consistently employed anti-forensic techniques, selectively deleting and restoring system configuration files that were modified during their activities.”
Mandiant observed attackers targeting a communications service provider in two separate campaigns between late 2025 and March 2026, ultimately escalating a compromised administrator account to full root access.
The first activity likely exploited two then-unknown Cisco SD-WAN authentication bypass flaws, tracked as CVE-2026-20127 and CVE-2026-20182, to establish unauthorized connections. A later intrusion targeted a patched device and may have relied on certificates stolen during an earlier compromise, though investigators have not confirmed whether the same threat actor was responsible for both incidents.
“After establishing an SSH session with the admin account, the threat actor exploited CVE-2026-20245 by executing the following command to upload a file named evil_tenant.csv:
“The evil_tenant.csv file contains the exploit payload.”
The exploit enabled attackers to gain elevated privileges and create a rogue “troot” account with full root-level access to the system. The threat actor then accessed this new troot account from the admin account via the su (substitute user) command.
The attackers systematically erased evidence by deleting files, undoing configuration changes, and running cleanup scripts to hinder forensic investigations.
“Mandiant identified that the threat actor deleted all files they created, including evil_tenant.csv, and restored any system configurations they modified. These deletion and modifications were done to minimize their forensic footprint.” continues the report.
According to Google, the case highlights a growing trend of threat actors exploiting zero-day vulnerabilities in edge devices such as SD-WAN systems, which often lack sufficient logging and monitoring capabilities. Compromising these devices can provide long-term access and visibility into an organization’s internal network traffic.
“This campaign underscores the living off the edge paradigm, where threat actors prioritize the compromise of network appliances to bypass traditional security perimeters.” Mandiant concludes. “As organizations increasingly adopt software-defined networking, the orchestrators managing these environments become primary targets.”
Attackers exploit Cisco Unified CM flaw (CVE-2026-20230) allowing unauth HTTP requests to trigger SSRF, write files, and gain root access
Cisco Unified Communications Manager has a serious vulnerability, tracked as CVE-2026-20230 (CVSS score of 8.6), that attackers are already exploiting. The flaw, caused by improper validation of certain HTTP requests, allows a remote attacker without authentication to perform server-side request forgery (SSRF) attacks. Early June, Cisco warned that public
Attackers exploit Cisco Unified CM flaw (CVE-2026-20230) allowing unauth HTTP requests to trigger SSRF, write files, and gain root access
Cisco Unified Communications Manager has a serious vulnerability, tracked as CVE-2026-20230 (CVSS score of 8.6), that attackers are already exploiting. The flaw, caused by improper validation of certain HTTP requests, allows a remote attacker without authentication to perform server-side request forgery (SSRF) attacks. Early June, Cisco warned that public PoC code is available and that successful exploitation could allow attackers to write files that may later be used to gain root privileges.
This makes affected systems high risk if exposed. Be careful.
“This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device.” reads the advisory. “A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root.”
Cisco rated this advisory as Critical instead of High because successful exploitation could allow an attacker to escalate privileges to root. However, the risk depends on configuration: the vulnerability can only be exploited if the WebDialer service is enabled, which is disabled by default on affected systems.
There is no full workaround for this vulnerability. The networking giant recommends mitigating risk by disabling the WebDialer service until a patch is applied. Administrators can do this through the Unified CM Administration interface by going to Unified Serviceability, opening Service Activation under Tools, and unchecking the WebDialer Web Service option in the CTI Services section before saving the changes.
Below are the fixed releases:
Cisco Unified CM and Unified CM SME Release
First Fixed Release
14
14SU6
15
15SU5 (Sep 2026) or COP1
The company confirms that PoC exploit code for the vulnerability is publicly available. However, the PSIRT is not aware of attacks in the wild exploiting this issue.
This week, Defused Cyber researchers confirmed it observed active exploitation of the issue in attacks in the wild.
Over the weekend we observed exploitation of CVE-2026-20230 – Cisco Unified CM (CUCM) WebDialer SSRF → root file-write (CVSS 8.6)
No previously recorded exploitation, and not yet listed in CISA KEV.
“Over the weekend we observed exploitation of CVE-2026-20230 – Cisco Unified CM (CUCM) WebDialer SSRF → root file-write (CVSS 8.6)” the researchers wrote on X. “No previously recorded exploitation, and not yet listed in CISA KEV.
This is currently being exploited from a single source using an unvetted PoC, with genuinely-formatted file:// file-write payloads landing on our decoys. Track Cisco CUCM exploitation”
At this time, Cisco PSIRT has yet to confirm active exploitation of the flaw.
Cisco has released security updates to fix a critical vulnerability, tracked as CVE-2026-20223, affecting its Cisco Secure Workload platform. The flaw, which received the maximum CVSS score of 10.0, could allow an unauthenticated remote attacker to access sensitive information and make unauthorized configuration changes through vulnerable REST API endpoints.
The company said the issue originates from insufficient validation and authentication checks in internal REST API functions used by Secu
Cisco has released security updates to fix a critical vulnerability, tracked as CVE-2026-20223, affecting its Cisco Secure Workload platform. The flaw, which received the maximum CVSS score of 10.0, could allow an unauthenticated remote attacker to access sensitive information and make unauthorized configuration changes through vulnerable REST API endpoints.The company said the issue originates from insufficient validation and authentication checks in internal REST API functions used by Secure Workload. The vulnerability has also been classified under CWE-306, a category associated with missing authentication protections for critical operations.According to Cisco, “an attacker could exploit this vulnerability if they can send a crafted API request to an affected endpoint.” The company added that a successful exploitation of CVE-2026-20223 could allow attackers to “read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user.”
CVE-2026-20223 Impacts Internal Secure Workload REST API Functions
Cisco stated in its advisory that the vulnerability affects internal REST API endpoints within Cisco Secure Workload Cluster Software. The issue impacts both SaaS and on-premises deployments regardless of device configuration.However, the company clarified that the flaw does not affect the web-based management interface. Instead, the exposure is limited to internal API functions associated with Secure Workload infrastructure.The advisory, identified as “cisco-sa-csw-pnbsa-g8WEnuy,” was first published on May 20, 2026, at 16:00 GMT. Cisco assigned the flaw a base CVSS score of 10.0 due to the severity of the potential impact and the lack of authentication requirements needed for exploitation. The issue is internally tracked under Cisco Bug ID CSCwt99942.Cisco explained that the root cause behind CVE-2026-20223 is “insufficient validation and authentication when accessing REST API endpoints.” Because of these missing protections, attackers may be able to bypass authorization boundaries and gain access to site resources with Site Admin-level privileges.
Cisco Warns of Cross-Tenant Data Exposure Risks
The company warned that exploitation of CVE-2026-20223 could allow unauthorized access to sensitive information across tenant environments. Attackers could also modify configurations across tenant boundaries while operating with elevated Site Admin permissions.The nature of the vulnerability makes it particularly severe in multi-tenant Secure Workload environments where administrative controls and segmentation are critical for protecting customer data.Cisco also confirmed that there are currently no workarounds available to mitigate the REST API vulnerability. As a result, organizations using affected Secure Workload releases are being advised to install fixed software versions as quickly as possible.The company stated that temporary mitigations are not enough to fully remediate the issue and strongly recommended upgrading to patched releases to avoid future exposure related to CVE-2026-20223.
Fixed Secure Workload Versions for CVE-2026-20223
Cisco released patches for affected Secure Workload versions and outlined the following fixed releases:
Cisco Secure Workload Release 3.10 — fixed in version 3.10.8.3
Cisco Secure Workload Release 4.0 — fixed in version 4.0.3.17
Cisco Secure Workload Release 3.9 and earlier — customers are advised to migrate to a fixed release
The company also noted that the cloud-based Cisco Secure Workload SaaS deployment has already been secured against CVE-2026-20223. Cisco said no user action is required for SaaS customers because the fixes have already been applied to the hosted environment.Customers requiring additional support were advised to contact the Cisco Technical Assistance Center (TAC) or their contracted maintenance providers for guidance regarding patch deployment and remediation.
Cisco Says No Active Exploitation Has Been Detected
Despite the maximum severity rating assigned to CVE-2026-20223, Cisco stated that its Product Security Incident Response Team (PSIRT) is “not aware of any public announcements or malicious use of the vulnerability” at the time of disclosure.The company added that the vulnerability was identified during internal security testing rather than through reports of active attacks in the wild.The disclosure highlights the increasing risks associated with insecure REST API implementations in enterprise infrastructure products. Vulnerabilities tied to CWE-306 can become especially dangerous when authentication checks are absent from critical administrative functions.As more organizations rely on APIs to manage workloads, automate infrastructure, and support cloud-native environments, flaws like CVE-2026-20223 demonstrate how authentication weaknesses in Secure Workload platforms can expose sensitive systems and tenant data to unauthorized access.Cisco published version 1.0 of the advisory as a final release on May 20, 2026, and has not indicated whether additional revisions related to the Secure Workload REST API vulnerability are expected.
Notes the April 2026 Dark Web Breach Incident Trend Report is compiled from data breach cases posted on the deep web and dark web forums. some information is included in cases where it is difficult to fully verify the factuality of the information due to the nature of the source. Major Issues data breaches and […]
Notes the April 2026 Dark Web Breach Incident Trend Report is compiled from data breach cases posted on the deep web and dark web forums. some information is included in cases where it is difficult to fully verify the factuality of the information due to the nature of the source. Major Issues data breaches and […]
CISA and NCSC warn that FIRESTARTER, a Linux-based backdoor, targets Cisco Firepower devices, evades patches, and enables persistent access even after firmware updates.
CISA and NCSC warn that FIRESTARTER, a Linux-based backdoor, targets Cisco Firepower devices, evades patches, and enables persistent access even after firmware updates.
Cisco has released security updates to fix multiple vulnerabilities in its Identity Services Engine and Webex Services, warning that successful exploitation could lead to remote code execution, root-level access, and user impersonation. The Cisco ISE vulnerabilities affect widely used enterprise authentication and collaboration systems, making patching a priority for organizations.
The Cisco ISE vulnerabilities and the Webex Services flaw have not been observed in active exploitation so far.
Cisco has released security updates to fix multiple vulnerabilities in its Identity Services Engine and Webex Services, warning that successful exploitation could lead to remote code execution, root-level access, and user impersonation. The Cisco ISE vulnerabilities affect widely used enterprise authentication and collaboration systems, making patching a priority for organizations.
The Cisco ISE vulnerabilities and the Webex Services flaw have not been observed in active exploitation so far. However, the company has urged customers to update affected systems immediately to reduce risk exposure.
Critical Cisco ISE Vulnerabilities Enable Remote Code Execution
The most severe issues impact Cisco Identity Services Engine (ISE) and its Passive Identity Connector (ISE-PIC). These Cisco ISE vulnerabilities stem from insufficient validation of user-supplied input, a flaw that allows attackers to send specially crafted HTTP requests to targeted systems.
Among them, CVE-2026-20147 carries a CVSS score of 9.9 and allows an authenticated attacker with administrative credentials to execute arbitrary commands on the underlying operating system. According to Cisco, this could enable attackers to gain user-level access and then escalate privileges to root.
Two additional vulnerabilities, CVE-2026-20180 and CVE-2026-20186, also rated 9.9, allow attackers with read-only administrative access to execute arbitrary commands. These Cisco ISE vulnerabilities highlight how even limited privileges can be leveraged for deeper system compromise.
Cisco noted that exploitation in single-node deployments could disrupt services entirely, potentially leading to a denial-of-service condition where new endpoints cannot authenticate to the network.
Webex Services Flaw Risks User Impersonation
Alongside the Cisco ISE vulnerabilities, a critical issue has been identified in Cisco Webex Services. Tracked as CVE-2026-20184 with a CVSS score of 9.8, the flaw affects single sign-on integration with Control Hub.
This vulnerability is caused by improper certificate validation and could allow an unauthenticated remote attacker to impersonate any user within the service. Successful exploitation could result in unauthorized access to legitimate Webex accounts, raising concerns for enterprises relying on the platform for communication and collaboration.
Affected Versions and Exposure
The Cisco ISE vulnerabilities impact multiple versions of the platform. All Cisco ISE versions 3.5 and earlier are affected by CVE-2026-20147, while versions 3.4 and earlier are vulnerable to CVE-2026-20180 and CVE-2026-20186. Cisco ISE-PIC systems are also impacted regardless of configuration.
For Webex Services, the vulnerability affects deployments using SSO integration with Control Hub.
Cisco emphasized that the vulnerabilities are independent of each other, meaning exploitation of one does not require another. Some versions may be affected by specific flaws while not impacted by others.
No Workarounds Available, Patching is Essential
Cisco has confirmed that there are no workarounds to mitigate these vulnerabilities. Organizations must apply the available software updates to fully address the risks.
Fixed releases have been issued across supported versions. For example, patches include ISE 3.1 Patch 11, 3.2 Patch 10, 3.3 Patch 11, 3.4 Patch 6, and 3.5 Patch 3. Systems running versions earlier than 3.1 are advised to migrate to a supported release.
Security teams are also advised to review system configurations and ensure that upgrade prerequisites such as hardware compatibility and memory requirements are met before deployment.
No Active Exploitation Reported But Risk Remains High
The Cisco Product Security Incident Response Team has stated that it is not aware of any public exploitation or malicious use of these vulnerabilities at the time of disclosure. The issues were reported by Jonathan Lein of TrendAI Research.
Despite the lack of active attacks, the severity of the Cisco ISE vulnerabilities and the Webex flaw places them in a high-risk category. Vulnerabilities that allow remote code execution or user impersonation are often targeted quickly once technical details become public.
Security Implications for Enterprises
The Cisco ISE vulnerabilities are particularly significant because ISE plays a central role in network access control, authentication, and policy enforcement. A compromise could provide attackers with deep visibility and control over enterprise networks.
Similarly, the Webex vulnerability introduces risks to identity and access management, especially in environments that rely on SSO for centralized authentication.
Organizations using affected products are advised to prioritize patching, restrict administrative access where possible, and monitor systems for suspicious activity.
Cisco has made detailed advisories and upgrade guidance available through its security portal, and customers are encouraged to follow official recommendations to secure their environments.
Cisco today at the RSA Conference (RSAC) extended its cybersecurity portfolio to secure artificial intelligence (AI) agents while at the same time employing AI to automate security operations. At the core of that effort are extensions to the Cisco Duo identity and access management (IAM) platform that make it possible to discover them and apply..
The post Cisco Extends Security Reach to AI Agents appeared first on Security Boulevard.
Cisco today at the RSA Conference (RSAC) extended its cybersecurity portfolio to secure artificial intelligence (AI) agents while at the same time employing AI to automate security operations. At the core of that effort are extensions to the Cisco Duo identity and access management (IAM) platform that make it possible to discover them and apply..
Executive Summary
Salt Typhoon, first reported in September 2024, compromised over 80 telecommunications companies globally, facilitating an expansive intelligence collection effort that included intercepting unencrypted calls and texts, and breaching lawful intercept (CALEA) systems.
The operation is tied to Yuyang (余洋) and Qiu Daibing (邱代兵), co-owners of companies named in the cybersecurity advisory and who worked closely to file patents and orchestrate the attacks.
The hackers’ history trace
Salt Typhoon, first reported in September 2024, compromised over 80 telecommunications companies globally, facilitating an expansive intelligence collection effort that included intercepting unencrypted calls and texts, and breaching lawful intercept (CALEA) systems.
The operation is tied to Yuyang (余洋) and Qiu Daibing (邱代兵), co-owners of companies named in the cybersecurity advisory and who worked closely to file patents and orchestrate the attacks.
The hackers’ history traces back to the 2012 Cisco Network Academy Cup, where they excelled as students from a poorly-regarded university.
The episode suggests that offensive capabilities against foreign IT products likely emerge when companies begin supplying local training and that there is a potential risk of such education initiatives inadvertently boosting foreign offensive research.
In markets where foreign firms are given a fair shake at competition these initiatives still make sense. As China seeks to delete American-made IT from its tech stacks, these initiatives may present more risk than reward.
First publicly reported in September 2024, Salt Typhoon’s campaign is now known to have penetrated more than 80 telecommunications companies globally. The group’s campaign collected unencrypted calls and texts between US presidential candidates, key staffers, and many China-experts in Washington, DC.
However, Salt Typhoon’s collection activity went beyond those intercepts. Systems embedded in telecommunications companies for CALEA, which facilitates lawful intercept of criminals’ communications, were also breached by Salt Typhoon. A recent Joint Cybersecurity Advisory published by the U.S. and more than 30 allies sheds light on how Salt Typhoon came to penetrate global telecommunications infrastructure.
All of that high-tech novelty disguises a tale as old as time: skilled master trains apprentice, apprentice masters skills with tutelage, apprentice usurps the master owing to some core ideological difference between the two that festers over time. Gordon Ramsay’s feud with Marco Pierre White, Anakin’s rise under Obi-wan Kenobi, and Mao Zedong’s study of communism under Chen Duxiu all fit the mold.
This report adds Yuyang (余洋) and Qiu Daibing’s (邱代兵) and their history with the Cisco Networking Academy to the list of master-apprentice turned rivals narrative arc.
From Students to Operators
Qiu Daibing and Yuyangappear in variousreports on companies named in the Salt Typhoon cybersecurity advisory. Both Qiu and Yu are co-owners of Beijing Huanyu Tianqiong, and Yu is also tied to another Salt Typhoon connected company, Sichuan Zhixin Ruijie. Qiu and Yu worked closely, filing patents together for work done at Beijing Huanyu Tianqiong.
Through their work at these firms, they hacked more than 80 telecommunications companies, facilitating one of the most expansive intelligence collection efforts of the last decade.
Person
Company (Role)
Qiu Daibing
Beijing Huanyu Tianqiong (Shareholder 45% – Held through Sichuan Kala Benba Network Security Technology Company)
Qiu and Yu’s personal history extends back at least 13 years before their companies would be named in the Cybersecurity Advisory.
In 2012, the same names–Qiu Daibing and Yu Yang–appeared on different teams in the Cisco Network Academy Cup both representing their school, Southwest Petroleum University. Yu Yang’s team would win second place in Sichuan. Qiu Daibing’s team took first prize and eventually won third place nationally.
List of Cisco Network Academy Cup winners from Southwest Petroleum University
The data suggests this is not just some weird name collision and a case of mistaken identity. A database of 1.2 billion Chinese last names from 1930 to 2008 compiled by Bruce H.W.S.Bao at East China Normal University finds the last name “Qiu” (邱) is used by 0.27% of China’s population.
A second database of 30,282,623 first names from 1920-2019 shows a frequency of the first name “Daibing” (代兵) at a rate of 0.000845%. In other words, there are approximately 3,194 “Qiu Daibings” in China, or 0.000228% of the population. Yu Yang is a much more common name, so is less useful for trying to de-duplicate these characters.
Qiu Daibing’s LinkedIn profile
Qiu Daibing helpfully created a LinkedIn account. His education confirms that this person is the same Qiu Daibing who won the Cisco Network Cup competition as a SWPU student in 2012. But his employer is listed as Ruijie Network Company, not Sichuan Zhixin Ruijie. Why?
Qiu likely selected this much larger, well-known networking company in China with a partial name match simply because Sichuan Zhixin Ruijie is not a verified employer on LinkedIn. Although Qiu Daibing is not listed in corporate records as a shareholder of Sichuan Zhixin Ruijie, that absence of evidence does not preclude him from having been an employee at his friend Yu Yang’s company.
Alternatively, it is far less likely that two people with the same name, in the same province, in the same line of work, work at companies which have a partial name match. The odds of that happening? Even less than 0.000228%.
This, combined with other circumstantial evidence, like their alma mater being located in the same province as the companies registered to individuals of the same names, their career trajectories being related to the same field of study, and the apparent enduring relationship between the two across patent and corporate registration data, suggests that the Qiu Daibing and Yu Yang associated with the companies in the Salt Typhoon CSA are almost certainly the same Cisco Cup winners from 2012.
Of course, a product training academy educating students on the company’s wares is hardly surprising. More notable is the fact that two students from a regional university, with limited recognition in IT and cybersecurity education participated in the Cisco Network Academy and went on to run one of the most expansive collection operations against global telecommunications firms ever detected and disclosed publicly.
Southwest Petroleum University is not a beneficiary of China’s efforts to professionalize and harmonize the country’s offensive cyber talent pipeline. SWPU is a Double First-Class institution, meaning the university is in the top 150 schools in the country, but it has relatively few accolades for its cybersecurity and information security programs.
Qiu Daibing and Yu Yang are all the more remarkable given SWPU’s apparently unremarkable cybersecurity education.
The duo’s participation in Cisco Network Academy and excellence in the Cisco Academy Cup, given the lack of excellent education at their alma mater, underlines what the author considers one of the best parts of the cybersecurity community–as the line from Ratatouille goes, “Anyone can cook.”
Cisco Network Academy has trained more than 200,000 students in China since the roll out of its program in the late 90s. No doubt that other graduates have gone on to participate in offensive operations against its products, but the vast majority do not. The program itself is not cause for concern, nor should participation in it be construed as such.
Lessons from the Kitchen
Instead, the episode of Qiu and Yu should highlight to defenders, policymakers, and the offensive hacking community a few key findings. First, offensive cyber capabilities against foreign-made IT products likely extends to whenever those companies entered the market and began supplying training to locals. As a result, China likely had some offensive capabilities against Cisco products by the early 2000s. This dynamic exists for most countries where such training takes place, not just the PRC.
Second, hiring processes for cybersecurity roles should emphasize demonstration of technical competencies, similar to coding interviews for software engineers, as the university degree may itself be a modest indicator of potential success in the workplace. China does an excellent job emphasizing hands-on learning for cybersecurity students. Other countries should follow suit.
Finally, some offensive teams may benefit from putting employees through similar product academies offered by firms manufacturing targeted products–like Huawei’s ICT academy.
Conclusion
Like other master-apprentice rivalries, the betrayal of Qiu and Yu was based on ideology and, ultimately, nationality. Qiu and Yu are not an oddity; they are evidence of a world in which today’s students can become tomorrow’s rivals with little more than time, opportunity, and a different notion of whose security they serve.
Their path to attacking Cisco products also raises the spectre of more widespread capability against western ICT products than previously acknowledged. Throughout the 1990s and 2000s, the PRC pushed the line of “China’s peaceful rise” with the help of influence operations of the Ministry of State Security. With money on their mind and a rapidly growing market, most western technology companies set up shop in China and moved to train new talent on their products and systems. The result was a boon to sales and growth over the following 20 years.
Only in hindsight, and with the story of Qiu and Yu, can security researchers now see how those efforts may have incidentally boosted offensive researchers. Microsoft’s sharing of source code with the MSS has long been touted as a Faustian bargain by the security community. Education initiatives fall short of such acclaim, but may come to present more risk than return as the Chinese Communist Party remakes the country’s computer networks with home-grown technology–as the Delete America document makes clear is their goal.
All third-party product names, logos, and brands mentioned in this publication are the property of their respective owners and are for identification purposes only. Use of these names, logos, and brands does not imply affiliation, endorsement, sponsorship, or association with the third-party.