Nation
Full article620 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Hackers, some of them backed by a nation-state, have attacked Cisco switches in multiple countries, the tech giant’s cyber-threat intelligence division has revealed. Some of these attacks “are believed to be associated with nation-state actors, such as those described” in a recent Department of Homeland Security report that said Russian government hackers were targeting multiple U.S. industries, Cisco said.
Hackers, some of them backed by a nation-state, have attacked Cisco switches in multiple countries, the tech giant’s cyberthreat intelligence division has revealed.
Some of the attacks “are believed to be associated with nation-state actors, such as those described” in a recent Department of Homeland Security report that said Russian government hackers were targeting multiple U.S. industries, Cisco said.
The campaign disclosed by Cisco exploits a protocol in a tool called Cisco Smart Install Client that installs switches. The protocol can be abused to conduct a series of actions, including modifying a server setting, to let an attacker execute Cisco networking software commands. Cisco used the scanning tool Shodan to identify more than 168,000 systems that could be vulnerable to this attack.
A March 15 DHS report blamed Russian government hackers for a multi-stage hacking campaign against the nuclear, critical manufacturing, and other U.S. sectors. The U.S. effort to call out alleged Russian malicious activity in cyberspace continued Friday with a fresh round of sanctions against Russian oligarchs and companies.
Nick Biasini, a threat researcher at Cisco’s Talos Security Intelligence and Research Group, said that while the weakness in Cisco switch protocols was “not a vulnerability in the classic sense, the misuse of this protocol is an attack vector that should be mitigated immediately.” In a blog post, he described switch commands that customers can run to detect and mitigate the vulnerability.
“It can be easy to ‘set and forget’ [perimeter] devices, as they are typically highly stable and rarely changed,” Biasini continued. “Combine this with the advantages that an attacker has when controlling a network device, and routers and switches become very tempting targets.”
Tony Cole, CTO of cybersecurity firm Attivo Networks, told CyberScoop that the attacks on Cisco switches showed that organizations are still slow to detect advanced hackers that have breached their networks. “Today’s preventative-focused security infrastructure is and will continue to be somewhat inept at stopping attacks,” Cole said.
Top White House cybersecurity adviser Rob Joyce urged Cisco customers to fix the vulnerability, tweeting, “Beware! There is growing malicious activity targeting the Cisco Smart Install Clients tool.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/cisco-switches-hacked-talos-security/