Vulnerabilities

2 Likes

On Monday, Cisco reported that a critical zero-day vulnerability in devices running IOS XE software was being exploited by an unknown threat actor who was using it to backdoor vulnerable networks. Company researchers described the infections as a “cluster of activity.”

On Tuesday, researchers from security firm VulnCheck said that at last count, that cluster comprised more than 10,000 switches, routers, and other Cisco devices. All of them, VulnCheck said, have been infected by an implant that allows the threat actor to remotely execute commands that run at the deepest regions of hacked devices, specifically the system or iOS levels.

“Cisco buried the lede by not mentioning thousands of Internet-facing IOS XE systems have been implanted,” VulnCheck CTO Jacob Baines wrote. “VulnCheck scanned internet-facing Cisco IOS XE web interfaces and found thousands of implanted hosts. This is a bad situation, as privileged access on the IOS XE likely allows attackers to monitor network traffic, pivot into protected networks, and perform any number of man-in-the-middle attacks.”

3 Likes
6 Likes
4 Likes

Another reminder to always use a strong adblocker, everywhere. Including sites you like and trust, because they get their ads from Google, and there’s no telling what bullshit is hidden there.

The age of ad-funded internet is over.

8 Likes
2 Likes
3 Likes
5 Likes
4 Likes

More info here.

3 Likes
2 Likes
2 Likes
1 Like
2 Likes

Not to take away from the seriousness of GPS jamming but I don’t see how spoofing would corrupt the INS (not IRS as the article says). They’re passive systems and so Pilots can use them as reliable backup to GPS. Because every INS will drift over time it isn’t that unusual for pilots to get a reference from the ground to update the INS data and keep it accurate. Some military aircraft also support navigation via terrain matching.

4 Likes

Nick Fury : Is the sun coming up? Carrier Bridge Tech : Yes, sir. Nick Fury : Then put it on the left . Get us over water.

Or break out the sextant?

4 Likes

In truth, the C-130 still carries a sextant for navigation.

3 Likes

That’s exactly what the :us: navy does. We are one Carrington Event-level coronal mass ejection from being back to sextants, sunstones and lighthouses.

4 Likes

Don’t break the sextant!

The chances of making it through a Carrington event without a total technology collapse actually aren’t that bad.

3 Likes

Get Ready Prep GIF by CBS

1 Like