Visualização de leitura

US, South Korea Warn of Growing Gunra Ransomware Threat

U.S. and South Korean authorities warn about the growing Gunra ransomware threat as the operation expands its capabilities and affiliate network.

The post US, South Korea Warn of Growing Gunra Ransomware Threat appeared first on TechRepublic.

Cisco Warns of Active Exploitation of Catalyst SD-WAN Flaw With No Patch Available

CVE-2026-20245

Cisco has issued an urgent warning that a high-severity vulnerability in its Catalyst SD-WAN Manager platform is being actively exploited in the wild—and no patch exists yet. CVE-2026-20245 allows authenticated attackers with netadmin privileges to execute arbitrary commands as root, placing wide-area network infrastructure at severe risk.
The disclosure is particularly alarming because Catalyst SD-WAN Manager controls and orchestrates SD-WAN deployments across enterprise and carrier networks. A successful exploit could allow attackers to push malicious configurations to thousands of edge devices simultaneously.

Understanding CVE-2026-20245

CVE-2026-20245 exists in the command-line interface (CLI) of Cisco Catalyst SD-WAN Manager, resulting from insufficient validation of user-supplied input when processing file arguments. The vulnerability carries a CVSS base score of 7.8 (High), with a vector of CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
To exploit the flaw, an attacker must have netadmin-level credentials on the affected system. While this limits the immediate attack surface, Cisco noted in its advisory that attackers are chaining CVE-2026-20245 with two related vulnerabilities—CVE-2026-20182 and CVE-2026-20127—to achieve initial access before escalating to root execution. This chaining technique effectively reduces the privilege prerequisite in practice.
An attacker supplies a specially crafted file to the Catalyst SD-WAN Manager CLI. Insufficient input validation allows the crafted file to execute arbitrary OS-level commands with root privileges. Cisco confirmed "limited cases" in which exploitation resulted in configuration changes being pushed to downstream edge devices—a significant escalation of potential impact.

No Patch Available — Cisco Plans Future Release

Unlike most critical vulnerability advisories, Cisco has disclosed CVE-2026-20245 without an accompanying patch. The company stated it plans to address the vulnerability in a future software release but did not provide a specific timeline.
This leaves organisations with only partial mitigations at their disposal. Cisco advises restricting CLI access to only trusted users and applying strict controls on file upload functionality within SD-WAN Manager administrative interfaces.
A vulnerability without a patch and with confirmed in-the-wild exploitation is a worst-case scenario for network defenders," noted a network security practitioner familiar with SD-WAN infrastructure. Every day without a patch is another day of active risk.

Why It Matters

SD-WAN infrastructure occupies a privileged position in modern enterprise networks, providing policy control over traffic routing across branches, data centres, and cloud environments. Compromising the management plane—which CVE-2026-20245 enables—gives attackers visibility into traffic flows, the ability to redirect connectivity, and the power to inject backdoor configurations across all managed edges.
The impact extends beyond a single organisation. Managed service providers (MSPs) and telecommunications carriers that use Cisco Catalyst SD-WAN to manage multiple customer environments face the prospect of cross-tenant compromise if their management platform is breached.

Mitigation Steps

  • Immediately audit who holds netadmin credentials on Catalyst SD-WAN Manager deployments and revoke unnecessary access.
  • Enable multi-factor authentication (MFA) for all SD-WAN Manager administrative accounts to reduce credential-theft risk.
  • Restrict file upload functionality within the SD-WAN Manager interface to the absolute minimum required for operations.
  • Monitor SD-WAN Manager CLI logs for unusual file upload activity or unexpected root-level command executions.
  • Apply network segmentation to isolate the SD-WAN management plane from general enterprise networks.
  • Subscribe to Cisco Security Advisories (tools.cisco.com/security/center) and apply the patch immediately upon release.
  • Conduct a configuration audit of all managed edge devices to identify any unauthorized configuration pushes already applied.

[un]prompted 2026 – Injecting Security Context During Vibe Coding

Author, Creator & Presenter: Srajan Gupta, Senior Security Engineer At Dave


Our thanks to [un]prompted for publishing their Creators, Authors and Presenter’s outstanding [un]prompted 2026 AI Security Practitioner content on the Organizations' YouTube Channel.

Permalink

The post [un]prompted 2026 – Injecting Security Context During Vibe Coding appeared first on Security Boulevard.

U.S. Consumers Lost $2.1 Billion in Social Media Scams in 2025, FTC Says

An FTC report says that Americans last year lost $2.1 billion in social media scams, such as shopping and investment schemes. Social media site have become the place where most of these scams start, and more than half of that money was stolen in scams began on Facebook, WhatsApp, and Instagram.

The post U.S. Consumers Lost $2.1 Billion in Social Media Scams in 2025, FTC Says appeared first on Security Boulevard.

China-Backed Groups are Using Massive Botnets in Espionage, Intrusion Campaigns

Chinese, A PRC flag flies atop a metal flagpole

China-sponsored threat groups like Salt Typhoon and Flax Typhoon are increasingly relying on multiple massive botnets comprising edge and IoT devices to run their cyber espionage and network intrusion campaigns, CISA and other security agencies say. The use of such "covert networks" makes it more difficult to detect and mitigate their campaigns.

The post China-Backed Groups are Using Massive Botnets in Espionage, Intrusion Campaigns appeared first on Security Boulevard.

[un]prompted 2026 – Securing Workspace GenAl At Google Speed

Author, Creator & Presenter: Nicolas Lidzborski, Principal Engineer At Google Workspace Security


Our thanks to [un]prompted for publishing their Creators, Authors and Presenter’s outstanding [un]prompted 2026 AI Security Practitioner content on the Organizations' YouTube Channel.

Permalink

The post [un]prompted 2026 – Securing Workspace GenAl At Google Speed appeared first on Security Boulevard.

[un]prompted 2026 – Rethinking How We Evaluate Security Agents For Real-World Use

Author, Creator & Presenter: Mudita Khurana, Staff Security Engineer At Airbnb


Our thanks to [un]prompted for publishing their Creators, Authors and Presenter’s outstanding [un]prompted 2026 AI Security Practitioner content on the Organizations' YouTube Channel.

Permalink

The post [un]prompted 2026 – Rethinking How We Evaluate Security Agents For Real-World Use appeared first on Security Boulevard.

[un]prompted 2026 – Trajectory-Aware Post-Training Security Agents

Author, Creator & Presenter: Aaron Brown, Agentic AI Builder, AWS


Our thanks to [un]prompted for publishing their Creators, Authors and Presenter’s outstanding [un]prompted 2026 AI Security Practitioner content on the Organizations' YouTube Channel.

Permalink

The post [un]prompted 2026 – Trajectory-Aware Post-Training Security Agents appeared first on Security Boulevard.

[un]prompted 2026 – Kinetic Risk: Securing And Governing Physical Al In The Wild

Author, Creator & Presenter: Padma Apparao, Architecting Al Solutions, Govt Agencies


Our thanks to [un]prompted for publishing their Creators, Authors and Presenter’s outstanding [un]prompted 2026 AI Security Practitioner content on the Organizations' YouTube Channel.

Permalink

The post [un]prompted 2026 – Kinetic Risk: Securing And Governing Physical Al In The Wild appeared first on Security Boulevard.

NIST, Overrun by Massive Numbers of Submitted CVEs, Limits Analysis Work

NIST CSF vulnerabilities ransomware backlog

NIST said it overwhelmed by the surge in the number of CVEs submissions in recent years, so it is paring back the analysis work it does on the dangerous security flaws. Security experts say the number of new vulnerabilities detected will only grow during the AI era and that the private sector will need to pick up the slack left by NIST's decision.

The post NIST, Overrun by Massive Numbers of Submitted CVEs, Limits Analysis Work appeared first on Security Boulevard.

[un]prompted 2026 – Vibe Check: Security Failures In Al-Assisted IDEs

Author, Creator & Presenter: Piotr Ryciak, Al Red Teamer At Mindgard


Our thanks to [un]prompted for publishing their Creators, Authors and Presenter’s outstanding [un]prompted 2026 AI Security Practitioner content on the Organizations' YouTube Channel.

Permalink

The post [un]prompted 2026 – Vibe Check: Security Failures In Al-Assisted IDEs appeared first on Security Boulevard.

Banning Routers Won’t Secure the Internet

Washington’s push to ban foreign-made Wi-Fi routers may sound tough on cybersecurity, but like earlier bans on foreign drones and telecom gear it risks becoming security theater that ignores the real problem: Millions of unpatched devices already sitting on American networks.

The post Banning Routers Won’t Secure the Internet appeared first on Security Boulevard.

[un]prompted 2026 – Security Guidance as a Service

Author, Creator & Presenter: Shruti Datta Gupta, Product Security Engineer, Adobe & Chandrani Mukherjee, Product Security Engineer, Adobe


Our thanks to [un]prompted for publishing their Creators, Authors and Presenter’s outstanding [un]prompted 2026 AI Security Practitioner content on the Organizations') YouTube Channel.

Permalink

The post [un]prompted 2026 – Security Guidance as a Service appeared first on Security Boulevard.

[un]prompted 2026 – The Hard Part Isn’t Building The Agent: Measuring Effectiveness

Author, Creator & Presenter: Joshua Saxe, Al Security Technical Lead, Meta


Our thanks to [un]prompted for publishing their Creators, Authors and Presenter’s outstanding [un]prompted 2026 AI Security Practitioner content on the Organizations') YouTube Channel.

Permalink

The post [un]prompted 2026 – The Hard Part Isn’t Building The Agent: Measuring Effectiveness appeared first on Security Boulevard.

❌