Tech News
← Home  ·  All topics

Cisco

17 GoKawiil briefs on this topic

Cisco Talos finds malware querying four AI chatbots to self-direct attacks

Cisco Talos researchers identified Windows malware named CLOSEDQUORUM that consults DeepSeek, Qwen, Mistral and Google Gemini to decide its next actions on infected machines, continuing to function if one service goes down. The tool, designed to steal credentials and cryptocurrency, has no built-in mechanism for human operators to issue commands directly, and Talos linked it to 2025 credit-card fraud forum activity, though the creator and any real-world targets remain unidentified.

Piper Sandler cuts Cisco price target to $125, shares fall 5%

Piper Sandler lowered its price target on Cisco Systems to $125 from $132, citing a lower price-to-earnings multiple assumption amid worries that networking-industry growth is peaking. Cisco shares fell about 5% on the news. The stock had hit a record high in June and remains up roughly 56% over the past year, helped by revenue growth tied to AI demand, including a fourth-quarter earnings beat last month with $17.25 billion in revenue versus a $16.8 billion estimate.

Cisco Talos finds ClosedQuorum, a Windows malware that uses AI models to run attacks

Cisco Talos researchers identified a Go-based Windows malware called ClosedQuorum that queries Google Gemini, DeepSeek, Qwen, and Mistral to decide post-compromise actions without human input. The models vote on options such as credential theft, code injection, and persistence, with DeepSeek breaking ties, and stolen data is sent to attackers via a Discord webhook.

Cisco Talos unveils CAIRN framework, uncovers AI-driven malware CLOSEDQUORUM

Cisco Talos researchers released an open-source system called CAIRN designed to detect and classify malware that relies on artificial intelligence for decision-making. Using the tool, they identified a new strain, CLOSEDQUORUM, which queries up to four large language models to determine its next actions inside a compromised system rather than following pre-programmed commands.

Cisco's Chuck Robbins says AI-driven workplace change will unsettle employees

In a Modern CEO newsletter interview, Cisco CEO Chuck Robbins reflected on his time as chair of the Business Roundtable and discussed how artificial intelligence is reshaping the workplace. He warned that employees resistant to organizational change driven by AI adoption should expect ongoing discomfort rather than relief.

Cisco expands Duo to manage identity risks from autonomous AI agents

Cisco says many organizations already have AI agents operating without proper identities, owners, or access controls, often connected directly to production systems by developers without IT's knowledge. The company's identity product lead, Matt Caulfield, is developing Duo Agentic Identity to address this gap as traditional identity and access management tools were never designed for autonomous, machine-speed actors.

Cisco patches actively exploited zero-day in Identity Services Engine

Cisco disclosed and fixed several critical vulnerabilities in its Identity Services Engine and ISE-PIC products, including CVE-2026-76460, a maximum-severity authentication bypass that attackers are already exploiting in the wild. The flaw lets an attacker send a crafted request to an unguarded API endpoint and slip past ISE's web management interface entirely. CISA added the bug to its Known Exploited Vulnerabilities catalog the same day the patch shipped.

Cisco patches actively exploited zero-day in Identity Services Engine (CVE-2026-76460)

Cisco has issued patches for a maximum-severity flaw in its Identity Services Engine and ISE-PIC products that allows attackers to bypass authentication on an API endpoint and gain unauthorized administrative access, regardless of configuration. Cisco's security team confirmed the vulnerability, tracked as CVE-2026-76460, is being actively exploited and there are no workarounds available, making immediate patching the only defense.

Cisco patches actively exploited zero-day in Secure Email Gateway software

Cisco released fixes for CVE-2026-76461, a critical flaw in AsyncOS Software for Secure Email Gateway that lets unauthenticated attackers run root-level commands by sending crafted emails with malicious SQL statements. The company confirmed it detected active exploitation of the bug in September 2026 and issued indicators of compromise for defenders to check mail logs and network traffic. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 17 to patch.

Sandworm exploits two Cisco FMC bugs to deploy new Cyclops Blink malware

Security researchers at Sophos and Cisco report that a suspected Russian state actor, previously tied to the Sandworm group linked to Russia's GRU, is exploiting two vulnerabilities in Cisco's Secure Firewall Management Center software. The attackers chain a maximum-severity authentication bypass flaw with a lower-severity privilege escalation bug to install a reverse shell and then deploy an updated version of the Cyclops Blink implant, which can steal credentials, map internal networks, and intercept live traffic.

Cisco Talos: Ransomware and state hackers exploit FMC firewall flaws

Cisco Talos reported that three distinct threat groups—including Qilin ransomware affiliates and state-sponsored actors—have been exploiting two vulnerabilities in Cisco Secure Firewall Management Center. The flaws, a maximum-severity authentication bypass (CVE-2026-20079) and a static credential issue (CVE-2026-20316), let attackers gain root access, deploy web shells, steal credentials, and in some cases install Qilin ransomware or Cyclops Blink malware. Cisco has issued hot fixes and urges immediate patching, with broader hardening updates planned next week.

Cisco confirms active exploitation of critical Secure FMC bug CVE-2026-20079

Cisco has verified that attackers are actively exploiting CVE-2026-20079, a maximum-severity (CVSS 10.0) flaw in its Secure Firewall Management Center software that lets unauthenticated remote attackers bypass login and run commands as root. The company first disclosed the bug in March without evidence of exploitation, but updated its advisory this week to acknowledge PSIRT detected active attacks in August, though it hasn't shared attacker identity or attack timeline details. CISA has since added the flaw to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 12 to patch.