Five Eyes allies warn hackers are actively exploiting Cisco SD-WAN flaws
嗯,用户让我总结一下这篇文章的内容,控制在100字以内,而且不需要用“文章内容总结”这样的开头。首先,我得通读一下文章,了解主要信息。 文章讲的是五眼联盟的情报机构警告说,一个高级威胁行为者正在利用思科网络设备的新漏洞进行攻击。美国的CISA发布了紧急指令,指出这些漏洞对联邦网络构成重大风险。英国的NCSC也警告全球组织可能受到攻击,并建议他们调查暴露情况。思科自己的公告提到多个漏洞可能导致系统被入侵和数据泄露。澳大利亚的机构还发布了一个技术指南,帮助组织检测是否已被入侵。 我需要把这些关键点浓缩到100字以内。首先提到五眼联盟的警告,然后说明威胁行为者利用思科设备的漏洞,接着提到CISA和NCSC的具体行动,最后提到思科和澳大利亚的技术指南。 可能的结构是:五眼联盟警告高级威胁利用思科漏洞,CISA发布紧急指令指出风险,NCSC强调全球影响,建议调查暴露情况。思科公告多个漏洞可能导致入侵和数据泄露。澳大利亚发布技术指南帮助检测入侵。 这样应该能控制在100字左右。 </think> 五眼联盟情报机构警告称,一个高级威胁行为者正积极利用思科网络设备的新漏洞进行攻击。美国网络安全与基础设施安全局(CISA)发布紧急指令,指出这些漏洞对联邦网络构成重大风险。英国国家网络安全中心(NCSC)也警告全球组织可能受到攻击,并建议他们调查暴露情况。思科公告指出多个漏洞可能导致系统被入侵和数据泄露。澳大利亚信号 Directorate发布技术指南帮助组织检测潜在入侵。 2026-2-25 17:45:48 Author: therecord.media(查看原文) 阅读量:0 收藏

Cybersecurity agencies from the Five Eyes intelligence alliance urgently warned Wednesday that “an advanced threat actor” is actively exploiting new flaws in Cisco networking equipment, pressing organizations to look for signs their systems may already have been compromised.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive warning of a “cyber threat actor’s ongoing exploitation of Cisco SD-WAN systems,” describing the activity as presenting a significant risk to federal civilian executive branch networks.

The vulnerabilities cited in the alerts include CVE-2026-20127 and CVE-2022-20775, which have been linked to real-world exploitation. CISA said it has assessed that the conditions pose “an unacceptable risk to federal agencies and necessitate emergency action.”

The British National Cyber Security Centre (NCSC) also said “malicious cyber threat actors are targeting Cisco Catalyst Software Defined Wide Area Networks (SD-WAN) used by organisations globally,” underscoring that the activity is not limited to the United States.

The NCSC’s chief technology officer, Ollie Whitehouse, said organizations using the affected Cisco products “should urgently investigate their exposure to network compromise” and start to hunt for evidence that a compromise has taken place.

Cisco’s own advisory warns “multiple vulnerabilities” in its product “could allow an attacker to access an affected system, elevate privileges to root, gain access to sensitive information, and overwrite arbitrary files.”

The company stressed the vulnerabilities “are not dependent on one another” and that exploitation of one of the vulnerabilities is not required to exploit another.

As part of the joint alert, the Australian Signals Directorate, the country’s cyber and signals intelligence agency, published a technical “hunt guide” to help organizations understand whether hackers are already inside their systems.

According to the guide, at least one malicious cyber actor has been compromising Cisco SD-WAN environments since 2023 using a zero-day vulnerability that was identified late last year and has since been patched.

“The vulnerability allowed a malicious cyber actor to create a rogue peer joined to the network management plane, or control plane, of an organisation’s SD-WAN,” the document says. “The rogue device appears as a new but temporary, actor-controlled SD-WAN component that can conduct trusted actions within the management and control plane.”

The hunt guide describes how attackers who gained this level of access were able to establish long-term persistence, including by obtaining root access and taking steps to evade detection, such as interfering with logging and other monitoring.

The agencies have not publicly identified the threat groups believed to be behind the activity.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Alexander Martin

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79


文章来源: https://therecord.media/five-eyes-warn-hackers-exploit-cisco-sd-wan
如有侵权请联系:admin#unsafe.sh