vulnerabilities
"Publishing security advisories for such critical issues with such limited information only serves to hurt defenders and threat hunters"
Attacks appear to be "linked to legacy credential use during migrations from Gen 6 to Gen 7 firewalls"
"Once on the network, the attackers don't waste time. Their actions are a mix of automated scripts for speed and hands-on-keyboard activity"
Cisco
|
Jul 28, 2025
All exploitation takes is a “crafted API request”. The bug affects Cisco ISE and ISE-PIC releases 3.3 and 3.4, “regardless of device configuration.”
Security
|
Jul 20, 2025
"A modern zero-day chain with automatic shell drop, full persistence, and zero authentication"