A joint advisory from the UK NCSC and 18 international agencies warns that Russian FSB Centre 16 cyber actors are globally exploiting poorly configured routers and network devices to target critical national infrastructure. The group uses SNMP scanning to find devices with default or weak credentials and exploits known vulnerabilities in Cisco devices and web portals to gain control. The advisory coincides with UK sanctions and formal attribution of a December 2025 attack on Poland's energy grid to the same actor.
Cisco
12 posts
UK and Allies urge critical sectors to improve defences against Russian intelligence targeting - 6 minWeekly Recap — 2026-06-22 -> 2026-06-29
Legitimate Tools Hijacked as AI Becomes the New Battleground The most damaging intrusions this week didn't rely on custom malware — they hijacked the legitimate tools and protocols organizations already trust. FortiBleed harvested real credentials from FortiGate firewall configurations worldwide, EvilTokens bypassed multi-factor authentication by abusing Microsoft's own device login flow, and a WhatsApp campaign installed legitimate ManageEngine remote management software to maintain persistent access. Simultaneously, attackers are learning to manipulate the AI systems defenders increasingly depend on. The macOS.Gaslight malware feeds fake error messages to AI analysis tools to blind security analysts, malicious skills on the OpenClaw marketplace trick AI assistants into executing harmful commands, and researchers demonstrated that chatbot reconnaissance can map an organization's defenses through casual conversation. Reset all FortiGate and VPN credentials immediately, scrutinize AI marketplace add-ons before installation, and assume that any legitimate-looking login prompt or remote management tool could be an attacker wearing a trusted disguise.
Cyber Centre Daily Advisory Digest — 2026-06-16 (3 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting critical vulnerabilities across Cisco, Fortinet, and Zyxel products. Notably, CVE-2026-20262 in Cisco Catalyst SD-WAN Manager and multiple Fortinet CVEs (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are actively being exploited in the wild, prompting immediate patching requirements.
Cyber Centre Daily Advisory Digest — 2026-06-05 (1 advisories) The Canadian Centre for Cyber Security released an advisory highlighting an authenticated privilege escalation vulnerability (CVE-2026-20245) affecting Cisco Catalyst SD-WAN Manager. Administrators are advised to review Cisco's security advisories and apply the necessary updates to prevent unauthorized privilege elevation within the management infrastructure.
18th May – Threat Intelligence Report This threat intelligence report highlights a surge in ransomware activity, critical zero-day vulnerabilities in Windows, and the active exploitation of Cisco Catalyst SD-WAN controllers. Additionally, it details emerging AI-driven threats, including malicious Hugging Face repositories and the abuse of AI website generators for phishing, alongside an APT intrusion by FamousSparrow targeting the energy sector.
Thus Spoke…The Gentlemen A recent leak of internal communications and backend data from 'The Gentlemen' RaaS operation has revealed the group's highly structured operational model and mature toolset. The threat actors actively exploit edge appliances and NTLM relay vulnerabilities for initial access, followed by extensive use of red-team tools and custom EDR evasion techniques to deploy their cross-platform ransomware.
Riding the Rails: Threat Actors Abuse Railway.com PaaS as Microsoft 365 Token Attack Infrastructure Threat actors are leveraging the EvilTokens Phishing-as-a-Service platform hosted on Railway.com to conduct large-scale device code phishing campaigns against Microsoft 365 users. By abusing legitimate cloud infrastructure and multi-hop redirect chains, attackers successfully bypass email filtering and MFA to harvest persistent OAuth tokens.
Security Advisory 2026-002 Cisco has disclosed multiple critical and high-severity vulnerabilities affecting Catalyst SD-WAN Controller and Manager, including CVE-2026-20127, a CVSS 10 authentication bypass exploited in the wild since 2023. Successful exploitation allows unauthenticated remote attackers to gain administrative privileges, manipulate network configurations, and establish persistent access, sometimes by downgrading software to exploit older vulnerabilities.
Security Advisory 2025-042 Cisco has disclosed a critical, unpatched vulnerability (CVE-2025-20393) affecting its Secure Email Gateway and Secure Email and Web Manager appliances. The flaw allows attackers to execute arbitrary commands with root privileges if the Spam Quarantine feature is enabled and exposed to the internet. Organizations are urged to immediately restrict internet access to this feature and contact Cisco TAC to check for indicators of compromise.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-20131, a deserialization of untrusted data vulnerability affecting Cisco Secure Firewall Management Center (FMC) and Cisco Security Cloud Control (SCC), to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation.
Exploitation of Cisco Catalyst SD-WAN Malicious cyber threat actors are actively exploiting Cisco Catalyst SD-WANs globally, primarily targeting systems with internet-exposed management interfaces. Upon compromise, attackers add malicious rogue peers to the network, enabling them to escalate privileges to root and maintain persistent access. A coalition of international cybersecurity agencies has released a joint Hunt Guide, and Cisco has issued software updates to mitigate the threat.
AL26-004 - Critical vulnerability affecting Cisco Catalyst SD-WAN - CVE-2026-20127 The Canadian Centre for Cyber Security has issued an alert regarding the active exploitation of CVE-2026-20127, a critical improper authentication vulnerability affecting Cisco Catalyst SD-WAN Controller and Manager systems. Unauthenticated remote attackers can exploit this flaw to bypass peering authentication, gain administrative privileges, and add malicious rogue peers to the network configuration for long-term persistence.