Product

Cisco networking & security

Made by Cisco. No known exploited vulnerabilities on record.

Coverage

Severity: ElevatedAction: Be aware

The Fine Art of Frustrating the Adversary

What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier. From deception and behavioral detection to breaking attack dependencies and resisting manufactured urgency.

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Cisco warns of new SD-WAN zero-day exploited in attacks

CISA added CVE-2026-76504 (Cisco Catalyst SD-WAN Manager) to its Known Exploited Vulnerabilities catalog on September 30, 2026, which means there is reliable evidence of exploitation in the wild. Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI…

Why it matters

CISA lists this as exploited in the wild. Unpatched Cisco networking & security and Catalyst SD-WAN Manager systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Severity: ElevatedAction: Be aware

The Closed Quorum: Inside the first reported autonomous AI C2 implant

CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without operator involvement.

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability (CVE-2026-76460) is being actively exploited, CISA warns

CISA added CVE-2026-76460 (Cisco Identity Services Engine) to its Known Exploited Vulnerabilities catalog on September 16, 2026, which means there is reliable evidence of exploitation in the wild. Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized…

Why it matters

CISA lists this as exploited in the wild. Unpatched Cisco networking & security and Identity Services Engine systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Recent intelligence

The latest developments from the last 30 days, newest first.

  1. Coverage

    The Fine Art of Frustrating the Adversary

    Basis: Cisco Talos Intelligence (security research)

  2. DisclosedCVE-2026-76504

    Cisco warns of new SD-WAN zero-day exploited in attacks

    Basis: Reporting by BleepingComputer

  3. Coverage

    China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor

    Basis: Cisco Talos Intelligence (security research)