Security News
![Cisco discloses new IOS XE zero-day exploited to deploy malware implant](/static/build/img/news/cisco-discloses-new-ios-xe-zero-day-exploited-to-deploy-malware-implant-small.jpg)
Cisco disclosed a new high-severity zero-day today, actively exploited to deploy malicious implants on IOS XE devices compromised using the CVE-2023-20198 zero-day unveiled earlier this week. On Monday, Cisco disclosed that unauthenticated attackers have been exploiting the CVE-2023-20198 authentication bypass zero-day since at least September 18 to hack into IOS XE devices and create "Cisco tac admin" and "Cisco support."
![Over 40,000 Cisco IOS XE devices infected with backdoor using zero-day](/static/build/img/news/over-40000-cisco-ios-xe-devices-infected-with-backdoor-using-zero-day-small.jpg)
More than 40,000 Cisco devices running the IOS XE operating system have been compromised after hackers exploited a recently disclosed maximum severity vulnerability tracked as CVE-2023-20198. Initial estimates of breached Cisco IOS XE devices were around 10,000 and the number started growing as security researchers scanned the internet for a more accurate figure.
![New Critical Zero-Day Vulnerability Affects Web UI of Cisco IOS XE Software & Allows Attackers to Compromise Routers](/static/build/img/news/new-critical-zero-day-vulnerability-affects-web-ui-of-cisco-ios-xe-software-allows-attackers-to-compromise-routers-small.jpg)
Cisco Talos discovered a new critical zero-day vulnerability in the Web User Interface feature of Cisco IOS XE software that's currently being used in the wild. The vulnerability used to access the system and create those accounts is CVE-2023-20198; it received the highest Common Vulnerability Scoring System score of 10.
![Over 10,000 Cisco devices hacked in IOS XE zero-day attacks](/static/build/img/news/over-10000-cisco-devices-hacked-in-ios-xe-zero-day-attacks-small.jpg)
Attackers have exploited a recently disclosed critical zero-day bug to compromise and infect more than 10,000 Cisco IOS XE devices with malicious implants. According to threat intelligence company VulnCheck, the maximum severity vulnerability has been extensively exploited in attacks targeting Cisco IOS XE systems with the Web User Interface feature enabled, that also have the HTTP or HTTPS Server feature toggled on.
![Thousands of Cisco IOS XE devices hacked in widespread attacks](/static/build/img/news/thousands-of-cisco-ios-xe-devices-hacked-in-widespread-attacks-small.jpg)
Attackers have exploited a recently disclosed critical zero-day bug to compromise and infect thousands of Cisco IOS XE devices with malicious implants. According to threat intelligence company VulnCheck, the maximum severity vulnerability has been extensively exploited in attacks targeting Cisco IOS XE routers and switches with the Web User Interface feature enabled, that also have the HTTP or HTTPS Server feature toggled on.
![Warning: Unpatched Cisco Zero-Day Vulnerability Actively Targeted in the Wild](/static/build/img/news/warning-unpatched-cisco-zero-day-vulnerability-actively-targeted-in-the-wild-small.jpg)
Cisco has warned of a critical, unpatched security flaw impacting IOS XE software that’s under active exploitation in the wild. Rooted in the web UI feature, the zero-day vulnerability is assigned...
![Cisco IOS XE zero-day exploited by attackers to deliver implant (CVE-2023-20198)](/static/build/img/news/cisco-ios-xe-zero-day-exploited-by-attackers-to-deliver-implant-cve-2023-20198-small.jpg)
A previously unknown vulnerability affecting networking devices running Cisco IOS XE software is being exploited by a threat actor to take control of the devices and install an implant, Cisco Talos researchers have warned today. CVE-2023-20198 is a privilege escalation vulnerability in the web UI feature of Cisco IOS XE software, which is installed on various Cisco controllers, switches, edge, branch and virtual routers.
![Cisco warns of new IOS XE zero-day actively exploited in attacks](/static/build/img/news/cisco-warns-of-new-ios-xe-zero-day-actively-exploited-in-attacks-small.jpg)
Cisco warned admins today of a new and maximum severity zero-day vulnerability in its IOS XE Software that can let attackers gain full administrator privileges and take complete control of affected routers. "Cisco has identified active exploitation of a previously unknown vulnerability in the Web User Interface feature of Cisco IOS XE software when exposed to the internet or untrusted networks," the company revealed today.
![Cisco Can’t Stop Using Hard-Coded Passwords](/static/build/img/news/alt/managed-security-small.jpg)
About Bruce Schneier I am a public-interest technologist, working at the intersection of security, technology, and people. I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.
![Cisco warns of critical flaw in Emergency Responder code](/static/build/img/news/cisco-warns-of-critical-flaw-in-emergency-responder-code.jpg)
Cisco has issued a security advisory about a vulnerability in its Emergency Responder software that would allow an unauthenticated remote attacker to log in to an affected device using the root account. Cisco Emergency Responder is designed to work with Cisco Unified Communications Manager to ensure that emergency calls get routed to a location-appropriate Public Safety Answering Point.