A seven-year-old security hole in Cisco IOS and Cisco IOS XE software has been regularly exploited by Static Tundra, a Russian state-sponsored cyber espionage group, to gain continuous access to target networks.
According to Cisco Talos, which made the activity public, the attacks target companies in the manufacturing, telecommunications, and higher education sectors in North America, Asia, Africa, and Europe. According to the statement, recent efforts have been made against Ukraine and its allies since the start of the Russo-Ukrainian war in 2022, and prospective victims are selected based on their “strategic interest” to Russia.
The vulnerability in question is CVE-2018-0171 (CVSS score: 9.8), a serious weakness in Cisco IOS Software and Cisco IOS XE software’s Smart Install capability that could enable an unauthorized remote attacker to run arbitrary code or cause a denial-of-service (DoS) condition.
It’s important to note that the China-aligned Salt Typhoon (also known as Operator Panda) actors most likely used the security flaw as a weapon read more about FBI Warns FSB-Linked Hackers Exploiting Unpatched Cisco Devices for Cyber Espionage.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
