Close Menu
  • Business
  • Education
    • Science
  • HBCU
  • Music
  • Politics
  • Tech
Featured Stories

A blizzard warning dropped on the Cascades this evening

March 11, 2026

Isaiah Monroe sentenced to 22 years for raping a 12 year old girl

March 11, 2026

The Falcons signs Channing Tindall on a one-year deal

March 11, 2026
Load More
What's Hot

A blizzard warning dropped on the Cascades this evening

March 11, 2026

Isaiah Monroe sentenced to 22 years for raping a 12 year old girl

March 11, 2026

The Falcons signs Channing Tindall on a one-year deal

March 11, 2026
Facebook X (Twitter) Instagram
Trending
  • A blizzard warning dropped on the Cascades this evening
  • Isaiah Monroe sentenced to 22 years for raping a 12 year old girl
  • The Falcons signs Channing Tindall on a one-year deal
  • Stryker’s systems goes dark after a pro-Iran hacking group struck
  • Michael Jackson estate faces fierce scrutiny over $625,000 legal fee request
  • The Patriots landed K.J. Britt on a near-minimum deal
  • Google bought Wiz for its biggest security bet in years
  • How one Black family turned a fear of water into a proud swimming legacy
  • Culture
  • Money
  • World
Facebook X (Twitter) Instagram
Black TimesBlack Times
Subscribe
Wednesday, March 11
  • Business
  • Education
    • Science
  • HBCU
  • Music
  • Politics
  • Tech
Black TimesBlack Times
Home»Tech

Cisco’s dangerous secret has been hiding since 2023

A perfect 10.0 severity bug in a widely used Cisco networking product has been quietly exploited for years — and governments are now sounding the alarm
Jeric MacaraanBy Jeric MacaraanFebruary 26, 2026 Tech No Comments4 Mins Read
Cisco
Photo credit: Shutterstock.com / PJ McDonnell
Share
Facebook Twitter LinkedIn Pinterest Email

A critical security flaw hiding inside one of Cisco’s most widely deployed enterprise networking products has been actively exploited by hackers for at least three years — and the damage may run far deeper than anyone currently knows. The vulnerability, carrying a maximum severity score of 10.0, affects Cisco’s Catalyst SD-WAN products, the backbone infrastructure that large corporations and government agencies rely on to connect offices and private networks across long distances.

The implications are severe. By exploiting the flaw remotely over the internet, attackers can gain the highest level of system permissions on affected devices, allowing them to burrow deep into a target’s network and maintain a persistent, hidden presence — sometimes for years — without triggering any alarms. That kind of invisible access opens the door to prolonged espionage, quiet data theft and infrastructure manipulation on a massive scale.

How Long Has This Been Going On

After identifying the vulnerability, Cisco’s own researchers traced active exploitation as far back as 2023 — meaning attackers may have had undetected access to affected networks for over three years before the flaw was publicly disclosed. Among the confirmed victims are organizations classified as critical infrastructure, a broad designation that can cover everything from power grids and water systems to transportation networks and financial institutions.

The company has not named specific targets, but the profile of affected organizations makes the breach window particularly alarming. Three years of silent access inside critical infrastructure is not just a cybersecurity problem — it is a national security concern.

Governments Around the World Are Responding

The response from global authorities has been swift and unusually coordinated. Australia, Canada, New Zealand, the United Kingdom and the United States jointly issued a warning that threat actors are actively targeting organizations on a global scale. The alert represents a rare unified front from the Five Eyes intelligence alliance, signaling that the threat is considered both widespread and serious.

In the United States, the Cybersecurity and Infrastructure Security Agency issued an emergency directive ordering all civilian federal agencies to patch their systems by end of day Friday — tomorrow. CISA described the situation as an imminent threat posing unacceptable risk to the federal government and confirmed it is aware of ongoing exploitation happening right now.

What makes the directive even more striking is the context surrounding it. CISA is currently operating at reduced capacity due to a partial government shutdown, and it is still treating this vulnerability as urgent enough to issue an emergency order with a next-day deadline.

Who Is Behind the Attacks

Neither Cisco, Google, nor any of the governments involved has publicly attributed the attacks to a specific threat group or nation state. However, investigators have tracked one cluster of related activity under the designation UAT-8616. The lack of attribution does not diminish the severity — if anything, it signals that whoever is responsible has been skilled enough to avoid leaving a clear fingerprint across three or more years of active intrusion.

This Is Not Cisco’s First 10.0 Vulnerability This Year

The timing adds an uncomfortable layer to an already serious situation. Just last December, Cisco disclosed a separate maximum-severity vulnerability — also rated 10.0 — in the Async software that powers the majority of its product lineup. That flaw was also being actively used to compromise customer networks at the time of disclosure.

Two perfect-10 vulnerabilities within months of each other in widely deployed enterprise infrastructure raises uncomfortable questions about the security architecture of products that sit at the core of some of the world’s most sensitive networks. For IT and security teams managing Cisco environments, the message from governments and the company itself could not be clearer — patch now, not later.

Source: Tech Crunch

catalyst sdwan cisa directive cisco security critical vulnerability cybersecurity threat enterprise security Featured federal agencies network breach tech news
Jeric Macaraan

Keep Reading

Google bought Wiz for its biggest security bet in years

Matt Snell dies at 84 after defining the Jets forever

Oracle beats the odds in Q3 while raising its 2027 outlook to $90 billion

Jayson Tatum’s leaked January workout footage reveals just how badly he wanted to come back sooner

Stryker Corporation cyberattack strands 4,000 Irish workers

WhatsApp now lets parents manage pre-teen accounts safely

0 0 votes
Article Rating
Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
Our Picks
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Don't Miss

A blizzard warning dropped on the Cascades this evening

News March 11, 2026

A blizzard warning took effect this evening across the Cascade Mountains and the Olympic Peninsula…

Isaiah Monroe sentenced to 22 years for raping a 12 year old girl

March 11, 2026

The Falcons signs Channing Tindall on a one-year deal

March 11, 2026

Stryker’s systems goes dark after a pro-Iran hacking group struck

March 11, 2026

Subscribe to Updates

Get the latest creative news from SmartMag about art & design.

Editors Picks
Latest Posts

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Culture
  • Money
  • Sports
© 2026 ThemeSphere. Designed by ThemeSphere.

Type above and press Enter to search. Press Esc to cancel.

wpDiscuz