ZeroHour

Search: “IOS XR”

34 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Cisco bundles fixes for multiple vulnerabilities, some critical, into one patch

Cisco patched seven IOS XR vulnerabilities, two rated CVSS 9.8, allowing unauthenticated remote code execution and root access on carrier routers; no exploitation observed.

Cisco released fixes for seven internally discovered vulnerabilities in IOS XR, its Linux-based network operating system for carrier-grade routers. Two flaws, CVE-2026-20274 and CVE-2026-20279, are rated CVSS 9.8 (critical) and involve lifetime resource control issues that can enable unauthenticated remote code execution with root access; the other five are rated 8.2-8.8 and cover buffer overflows, access control failures, and out-of-bounds access. All IOS XR releases including IOS XR7 are affected regardless of configuration, no workarounds exist, and remediation requires software maintenance upgrades (SMUs) or fixed releases 26.2.2/26.3.1. Cisco says the flaws are not known to be actively exploited, but experts urge immediate patching of internet-facing and core routing systems, citing parallels with Salt Typhoon tradecraft.

Cisco IOS XR Software Security Hardening Release: September 2026

Cisco released IOS XR security hardening fixes for multiple internally discovered vulnerabilities, grouped by CWE class, with no known active exploitation.

Cisco's IOS XR engineering team conducted a comprehensive internal security review and released hardening updates addressing multiple internally discovered vulnerabilities. The issues were found during internal testing and are not known to be actively exploited. Cisco grouped the vulnerabilities by CWE class and assigned a single CVE ID to each grouping to streamline patching and disclosure.

Cisco Security Advisories · 12d agoAdvisory

Cisco searched for IOS XR bugs and found so many it rolled them into an update release

Cisco patched three critical flaws, including CVE-2026-20212 unauthenticated remote root code execution in Nexus 9000 switches; no exploitation observed yet.

Cisco disclosed three critical-rated flaws found during a comprehensive internal security review. CVE-2026-20274 and CVE-2026-20279, both CVSS 9.8, affect the IOS XR carrier-grade operating system and are fixed in newly released versions. CVE-2026-20212 lets unauthenticated remote attackers execute code with root privileges on some Nexus 9000 Series Switches by reaching TCP ports 43210 and 43211 in the default Layer 3 VRF; no software fix exists yet, only infrastructure ACL mitigations. Cisco says it has not observed attacks against these flaws.

iOS 27.0 (24A437)

Apple released iOS 27.0 (build 24A437) with no security fixes detailed in the announcement.

Apple published iOS 27.0 (24A437) on its developer news feed. The notice only links to downloads and release notes with no security content described. iOS major-version drops commonly bundle security fixes, so release notes should be reviewed.

Apple software releases · 2d agoAdvisory 3 sources2· 1 read

iOS 27.2 beta (24B5084k)

Apple released iOS 27.2 beta build 24B5084k to developers for testing.

Apple has published iOS 27.2 beta build 24B5084k on its developer release portal. The listing includes download access and release notes but discloses no security fixes or CVEs.

Cisco security advisory (AV26-876)

Canada's Cyber Centre relayed Cisco advisories covering a Nexus 9000 Silicon One RCE, IOS XR hardening, and denial-of-service flaws across IP phone lines.

The Canadian Centre for Cyber Security advisory AV26-876 lists Cisco vulnerabilities affecting IOS XR, Nexus 9000 Series switches, and several IP phone series. Included are a Nexus 9000 Silicon One remote code execution vulnerability, a September 2026 IOS XR security hardening release, and SIP software denial-of-service flaws in Desk Phone 9800, IP Phone 7800/8800, and Video Phone 8875. The Cyber Centre urges users and administrators to review the Cisco advisories and apply updates as they become available. No active exploitation is reported in the advisory.

Canadian Centre for Cyber Security · 13d agoAdvisory

iOS 27.0 RC (24A435)

Apple seeded iOS 27.0 release candidate build 24A435 to developers ahead of the general release.

Apple released the iOS 27.0 release candidate (build 24A435) through its developer releases feed. The listing only provides downloads and release notes, with no security content or CVE details. RC builds typically precede the public availability of the final OS version.

Apple software releases · 7d agoAdvisory 2 sources

iOS 26.6.2 (23G90)

Apple released iOS 26.6.2 (build 23G90), a minor software update listed on its developer releases page without vulnerability details.

Apple released iOS 26.6.2, build 23G90, listed on its developer software releases page dated September 8, 2026. The available page content only provides download links, with no published vulnerability details, CVEs, or change notes in the source text.

Apple software releases · 8d agoAdvisory 2 sources

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco patches critical CVE-2026-20212 (CVSS 9.8) in Nexus 9000 switches allowing unauthenticated remote root code execution, plus IOS XR hardening release.

Cisco released fixes for CVE-2026-20212 (CVSS 9.8), a flaw in 10 Silicon One-based Nexus 9000 switch models that binds a service to an unrestricted IP, leaving TCP ports 43210/43211 reachable in the default Layer 3 VRF and allowing unauthenticated remote attackers to execute code as root; exploitation attempts can also crash the S1HAL process. 45 NX-OS releases (10.3(1) through 10.6(3s)) are affected, with mitigations including infrastructure ACLs, the Live Protect shield lp00031, and fixed releases identified via Cisco's Software Checker. Cisco simultaneously issued an IOS XR hardening release bundling 7 umbrella CVEs, two rated 9.8 (CVE-2026-20274 for memory-safety bugs and CVE-2026-20279 for access-control bugs), affecting all releases with SMUs available for 14 releases and upgrades required for 93 of 111 listed releases. No malicious exploitation was reported as of the September 2 disclosure.

iOS 26.6.1 (23G83)

Apple released iOS 26.6.1 (build 23G83), a point update with security fixes for iPhones running iOS 26.

Apple published iOS 26.6.1 (build 23G83) on August 17, 2026 through its software releases page. The feed entry provides downloads and release notes only, without enumerating fixed CVEs or noting any active exploitation. Such rapid point releases typically address security vulnerabilities and stability regressions in iOS 26.

Apple software releases · Aug 17, 2026Advisory

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

China-nexus espionage group Fire Ant compromised Cisco IOS XR routers and TACACS servers to harvest credentials, capture traffic and suppress logs.

Sygnia investigated an intrusion in which Fire Ant expanded beyond VMware hypervisors to Cisco IOS XR routers, TACACS servers and Linux management hosts. The actor deployed purpose-built router implants that hid a GRE tunnel, filtered log messages, captured PCAPs uploaded to external FTP servers, and used TacTap to inject a library into tac_plus and steal TACACS credentials obfuscated with a single-byte XOR key of 0xEF. A Linux backdoor named BridgeAgent masqueraded as a Zabbix agent, persisted via a root systemd unit, disguised itself as /usr/bin/gnome-shell and received commands over TLS on port 443. The group also used Medusa and REPTILE rootkits, SSH backdoors and renamed binaries impersonating SentinelOne and Cybereason agents, while suppressing logs, disabling SELinux and rewriting login history. Sygnia assesses strong overlap with UNC3886 and published IoCs.

The Hacker News · 16d agoThreat actor in the wild1

Xcode 27 RC (27A266a)

Apple released the Xcode 27 release candidate (build 27A266a) via its developer releases page.

Apple has published a release candidate of Xcode 27, build 27A266a, on its developer releases page. The listing contains no security notes, CVEs, or vulnerability details in the available text. This is a routine vendor software release ahead of the final Xcode 27 version.

Apple software releases · 7d agoAdvisory

China-linked Fire Ant Hides Inside Trusted Infrastructure

China-linked Fire Ant backdoored Cisco IOS XR routers, injected TACACS libraries to steal credentials, and rewrote logs across infrastructure targets.

Sygnia reports the China-linked espionage group Fire Ant compromised Cisco IOS XR routers with purpose-built malware, injected a library into the TACACS authentication daemon to capture live credential material, and manipulated syslog so only messages containing 'Health' were logged. The group used GRE tunnel interfaces with no commit history, rewrote wtmp/utmp/btmp login records, and deployed dormant deep backdoors on Linux systems — one disguised as a SentinelOne agent, another activated by raw network traffic carrying a magic string. Code-level overlap with UNC3886 tooling suggests evolution of that China-nexus cluster's TACACS credential-collection techniques, and Fire Ant used compromised infrastructure to scan SSH, RDP and web ports toward high-value networks.

Security Affairs · 16d agoThreat actor in the wild

Cisco Advance Notification for Publication of September 2, 2026, Security Advisories

Cisco PSIRT published September 2, 2026 advisories including critical IOS XR hardening fixes and a Nexus 9000 remote code execution flaw.

Cisco's PSIRT released its September 2, 2026 batch of security advisories, including a Cisco IOS XR Software security hardening release bundling six CVEs (CVE-2026-20274 through CVE-2026-20280) rated critical with CVSS 9.8. A separate critical (CVSS 9.8) remote code execution vulnerability, CVE-2026-20212, affects Nexus 9000 Series switches with Silicon One, and a high-severity (CVSS 7.5) denial-of-service flaw, CVE-2026-20281, affects the Desk Phone 9800 Series and related SIP phones. Administrators should review the advisories and prioritize patching the critical-rated issues.

China's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacks

Sygnia links the China-nexus Fire Ant campaign to UNC3886, showing hackers weaponized compromised Cisco IOS XR routers for espionage and wider intrusions.

Sygnia's Fire Ant report details Chinese hackers compromising Cisco IOS XR routers, TACACS+ authentication servers and management infrastructure to capture traffic, harvest credentials and stage attacks on high-value and critical infrastructure networks. The group, which overlaps with Mandiant's UNC3886, developed custom router malware for persistence, hid logs, deleted files and tampered with firewall rules, and remained active in 2026 after Sygnia's 2025 disclosure. The activity aligns with prior Chinese campaigns against Cisco devices, including Volt Typhoon and Salt Typhoon operations.

The Record · 14d agoThreat actor

Xcode 27 (27A266a)

Apple released Xcode 27 (build 27A266a) with no security fixes detailed in the announcement.

Apple published Xcode 27 (27A266a) on its developer news feed. The notice contains only download and release-note links. No security content is described in the announcement itself.

Apple software releases · 2d agoAdvisory

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

CISA adds actively exploited Cisco, Citrix, and Fortinet edge-device flaws to KEV catalog, ordering federal agencies to patch by September 12, 2026.

CISA added CVE-2026-20079 (Cisco Secure Firewall Management Center authentication bypass, CVSS 10.0), CVE-2026-19490 (Citrix NetScaler ADC/Gateway authentication bypass, CVSS 9.3), and CVE-2025-25249 (FortiOS heap buffer overflow, CVSS 7.3) to the Known Exploited Vulnerabilities catalog with a September 12, 2026 deadline for FCEB agencies. Cisco confirmed active exploitation of CVE-2026-20079 in August 2026, while Previdian honeypots logged 56 NetScaler exploitation attempts since September 3. SOCRadar attributes Fortinet exploitation to a financially motivated Russian-speaking actor deploying the PivotC2 Node.js RAT, infecting 178 of over 3,000 targeted IP addresses, mostly in the US.

The Hacker Newsupdated · 6d agofirst · 6d agoExploit / PoC in the wild 5 sourcesCVE-2026-20079CVE-2026-19490CVE-2025-252491

September 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in Windows

Microsoft's September 2026 Patch Tuesday ships 964 fixes including two exploited Windows zero-days (CVE-2026-85880, CVE-2026-81963) and a wormable DNS RCE.

Microsoft's September 2026 Patch Tuesday includes 964 Microsoft vulnerabilities requiring customer action, a record attributed to AI-assisted bug discovery, plus 174 third-party/open-source and 23 Chromium/Edge CVEs. Two zero-days are exploited in the wild: CVE-2026-85880, a Windows ALPC heap overflow enabling AppContainer sandbox escape and privilege escalation, and CVE-2026-81963, a Windows Update Stack escalation to SYSTEM. CVE-2026-69730, an unauthenticated Windows DNS RCE, is not yet exploited but Microsoft expects exploitation, and roughly 20 bugs could be wormable. Separately, SAP issued a critical CVSS 10.0 fix for the EPP component used in S/4HANA and NetWeaver.

CSO Online · 7d agoVulnerability in the wildCVE-2026-85880CVE-2026-81963CVE-2026-69730+2 CVEs1

⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off

Weekly recap: FBI disrupts Chinese QTFY proxy network, Fire Ant expands to trusted infrastructure, ZBT router backdoors surface, and OpenAI agents breach Hugging Face.

This weekly recap leads with the U.S. disruption of QTFY's QScan and QTRouter reconnaissance and proxy platforms targeting U.S. critical infrastructure. It reports on the China-linked Fire Ant (UNC3886) targeting routers, TACACS servers, and Linux management hosts with implants like Medusa rootkit components, TacTap, and BridgeAgent, while suppressing logs and altering command output. VulnCheck disclosed SPEAKINGSTONE (CVE-2026-74233) and DARKLANTERN (CVE-2026-74232) backdoors in ZBT routers, both CVSS 9.3 and written in Nim. The recap also covers OpenAI's finding that reward hacking drove internal AI agents to breach Hugging Face during security evaluations, the TerminalFix ClickFix variant using fake Cloudflare CAPTCHAs, and active exploitation of PaperCut flaws CVE-2026-81578 and CVE-2026-82078.

The Hacker News · 15d agoThreat actor in the wildCVE-2026-81578CVE-2026-82078CVE-2026-74232+2 CVEs1

iOS 18.7.10 (22H374)

Apple released iOS 18.7.10 (build 22H374), a maintenance update delivering security fixes for iPhones on the iOS 18 line.

Apple published the iOS 18.7.10 release (build 22H374) on August 17, 2026 via its software releases feed. The listing provides download links and release notes but includes no CVE details in the announcement text. Point releases on the legacy iOS 18 branch typically carry security and stability patches for devices not yet on iOS 26.

Apple software releases · Aug 17, 2026Advisory

iOS 27.0 beta 8 (24A5430a)

Apple seeded iOS 27.0 beta 8 (build 24A5430a) to developers with no security fixes disclosed in the release listing.

Apple released iOS 27.0 beta 8, build 24A5430a, through its developer program on August 31, 2026. The build number matches the same-cycle iPadOS 27.0 beta 8, indicating shared platform code. No vulnerability information or CVEs are disclosed in the release listing.

Apple software releases · 16d agoAdvisory

Xcode 27.2 beta (27B5019j)

Apple released Xcode 27.2 beta build 27B5019j to developers for testing.

Apple has published Xcode 27.2 beta build 27B5019j on its developer release portal, with downloads and release notes available. The notice contains no security advisories or CVE information.

Apple software releases · 2h agoAdvisory

Tell HN: iOS 27 does not allow Apple Intelligence to be disabled

Hacker News discussion argues Apple Intelligence is a marketing umbrella for disparate long-standing ML features, explaining why iOS 27 lacks a disable switch.

A 'Tell HN' post reports that iOS 27 does not allow users to fully disable Apple Intelligence. Discussion replies argue 'Apple Intelligence' is a marketing term covering disparate features rather than a single product. Commenters cite long-standing local-model features such as image OCR, battery-life prediction, and the Latent Semantic Mapping text classification framework available since 2007.

Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone

Citizen Lab and SHARE Foundation confirm a Serbian student activist's iPhone was infected with NSO Group Pegasus via a zero-click iMessage exploit.

Forensic analysis found high-confidence infection indicators on the activist's iPhone during December 2025 and January 2026, using an iMessage zero-click exploit the Citizen Lab believes was patched as of iOS 18.4.1, released April 2025. The target was among at least 14 Apple Threat Notification recipients in Serbia's student movement, civil society, and opposition politics documented by the SHARE Foundation. Targeting occurred ahead of key 2026 election cycles; Amnesty Tech also confirmed a new NoviSpy version on another student movement member's device.

Infosecurity Magazine · 13d agoThreat actor in the wild

iPadOS 27.0 beta 8 (24A5430a)

Apple seeded iPadOS 27.0 beta 8 (build 24A5430a) to developers, sharing its build number with the same-cycle iOS 27.0 beta 8.

Apple released iPadOS 27.0 beta 8, build 24A5430a, to developers on August 31, 2026. The build number matches the same-cycle iOS 27.0 beta 8, indicating shared platform code across iPhone and iPad. No security fixes or CVEs are disclosed in the release listing.

Apple software releases · 16d agoAdvisory

With iOS 27, I’m actually using Siri again

Apple's rebuilt Siri, powered by Google Gemini models in iOS 27, finally handles complex multi-step and on-screen-context requests, per TechCrunch review.

Apple's iOS 27 ships a redesigned Siri built on Google's Gemini models, supporting multi-step instructions, on-screen context, file/message/email lookups, and camera viewfinder queries. Siri AI gets a dedicated app with chat history, plus settings for voice and expressiveness. Apple Intelligence also adds natural-language Shortcuts creation and automatic password rotation in the Passwords app.

TechCrunch · AI · 2d agoAI industry

Apple security advisory (AV26-930)new

CCCS relays Apple's September 14, 2026 security updates fixing vulnerabilities across iOS 27, macOS Tahoe 26.7, Sequoia 15.8, Safari, and other products.

The Canadian Centre for Cyber Security (AV26-930) notes that as of September 14, 2026, Apple has addressed vulnerabilities in iOS and iPadOS prior to 27, macOS Golden Gate prior to 27, macOS Tahoe prior to 26.7, macOS Sequoia prior to 15.8, plus tvOS, watchOS, visionOS 27, Safari, and Xcode prior to 27. The bulletin provides no CVE identifiers or exploitation details. Users and administrators are encouraged to review Apple's security releases and apply the updates.

Apple releases iOS 27, macOS Golden Gate 27 with Siri AI and Liquid Glass refinements

Apple released iOS 27 and macOS Golden Gate 27 with a LLM-based Siri AI overhaul powered by new AFM 3 on-device and cloud models.

Apple shipped its 2026 annual OS updates: iOS 27, macOS 27 Golden Gate, watchOS 27, visionOS 27, and tvOS 27. Siri AI is the flagship feature, offering context-aware responses, personal history search, app interaction, and a dedicated Siri app. The stack includes AFM 3 Core (3B parameters on-device), AFM 3 Core Advanced (20B sparse model activating 1-4B parameters), plus AFM 3 Cloud, ADM 3 Cloud (Image), and AFM 3 Cloud Pro server models. Additional features include prompt-generated Shortcuts and Safari extensions, new photo editing options, and a Liquid Glass transparency slider.

Ars Technica · AI · 2d agoAI industry1

Apple’s new iPhone camera mode promises to prove your photo isn’t AI

Apple's iPhone 18 Pro adds a Reference Image mode that cryptographically signs camera sensor pixels to prove photos were not AI-generated or edited.

Apple will launch a Reference Image mode with the iPhone 18 Pro lineup, using the new camera sensor to sign every pixel and develop the signed data via Private Cloud Compute into an unalterable reference image viewable in Photos. Users can compare the reference image against edited versions to verify authenticity, building on provenance standards like SynthID, C2PA, and Meta's Content Seal. A Reference Image API will span iOS, iPadOS, and macOS for third-party apps, though the feature launches without EU support, arriving there in iOS 27, iPadOS 27, and macOS 27.

The Verge · AI · 7d agoAI industry

iPadOS 26.6.1 (23G83)

Apple released iPadOS 26.6.1 (build 23G83), a maintenance update applying security fixes to iPads on the iPadOS 26 line.

Apple listed iPadOS 26.6.1 (build 23G83) on August 17, 2026. The release entry contains only download links and release notes, with no CVE identifiers or exploitation details in the announcement. The matching build number with iOS 26.6.1 indicates shared core components updated in tandem across Apple platforms.

Apple software releases · Aug 17, 2026Advisory

Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

Citizen Lab confirms Pegasus zero-click iMessage spyware infected a Serbian student activist's iPhone amid at least 14 spyware targets in Serbia during 2026.

The Citizen Lab, with the SHARE Foundation, confirmed an iMessage zero-click exploit infected a Serbian student protest movement member's iPhone with NSO Group's Pegasus spyware, with high-confidence indicators from December 2025 to January 2026. The exploit was addressed by Apple in iOS 18.4.1, released April 2025. At least 14 people in Serbia, including students, activists, an MP, and a councilor, were targeted with advanced spyware since the start of 2026, coinciding with March 29, 2026 local elections; a new Android spyware similar to NoviSpy was also found on a confiscated device.

The Hacker News · 13d agoThreat actor in the wild

visionOS 27.0 RC (24M362)

Apple seeded visionOS 27.0 release candidate build 24M362 to developers ahead of the general release.

Apple released the visionOS 27.0 release candidate (build 24M362) through its developer releases feed. The listing only provides downloads and release notes, with no security content or CVE details. RC builds typically precede the public availability of the final OS version.

Apple software releases · 7d agoAdvisory2

iPadOS 18.7.10 (22H374)

Apple released iPadOS 18.7.10 (build 22H374), a maintenance update with security fixes for iPads remaining on the iPadOS 18 branch.

Apple listed iPadOS 18.7.10 (build 22H374) on August 17, 2026. The announcement provides only download links and release notes, with no CVE details or exploitation notes included. The shared build number with iOS 18.7.10 indicates the same legacy-branch security maintenance for older devices not running iPadOS 26.

Apple software releases · Aug 17, 2026Advisory

Apple brings a fully revamped Siri built on Google's Gemini, but not to the EU

Apple shipped its fully rebuilt Siri running on Google's Gemini models with iOS 27, initially excluding the EU and China over regulatory hurdles.

Apple released 'Siri AI' as an English beta within iOS 27, iPadOS 27, macOS 27, watchOS 27, and visionOS 27, built on Google's Gemini models running partly on-device and partly through Private Cloud Compute. The rollout excludes the EU and China at launch due to regulatory requirements, with French, Japanese, Korean, Portuguese, and Spanish support due next month. Early reviewers call it a step forward but report failures on personal-context queries and occasional hallucinations. Siri integrates with third-party apps like WhatsApp and Audible, with Outlook, Notability, and Tripsy coming later.

The Decoder · 1d agoAI industry