Close Menu
  • Business
  • Education
    • Science
  • HBCU
  • Music
  • Politics
  • Tech
Featured Stories

Why IonQ’s $130 million feels like a costly mistake

February 26, 2026

Cisco’s dangerous secret has been hiding since 2023

February 26, 2026

NFL Combine 2026 goes live today — watch every key moment

February 26, 2026
Load More
What's Hot

Why IonQ’s $130 million feels like a costly mistake

February 26, 2026

Cisco’s dangerous secret has been hiding since 2023

February 26, 2026

NFL Combine 2026 goes live today — watch every key moment

February 26, 2026
Facebook X (Twitter) Instagram
Trending
  • Why IonQ’s $130 million feels like a costly mistake
  • Cisco’s dangerous secret has been hiding since 2023
  • NFL Combine 2026 goes live today — watch every key moment
  • LeVelle Moton turned down a million dollars for a promise
  • Kendrick Lamar is rewriting the rules at the NAACP Awards
  • Oliver Grant of Wu-Tang Clan dies at 52 on historic day
  • Claude hit with outage and users are demanding answers
  • Black America faces an alarming threat from Trump policies
  • Culture
  • Money
  • World
Facebook X (Twitter) Instagram
Black TimesBlack Times
Subscribe
Thursday, February 26
  • Business
  • Education
    • Science
  • HBCU
  • Music
  • Politics
  • Tech
Black TimesBlack Times
Home»Tech

Cisco’s dangerous secret has been hiding since 2023

A perfect 10.0 severity bug in a widely used Cisco networking product has been quietly exploited for years — and governments are now sounding the alarm
Jeric MacaraanBy Jeric MacaraanFebruary 26, 2026 Tech No Comments4 Mins Read
Cisco
Photo credit: Shutterstock.com / PJ McDonnell
Share
Facebook Twitter LinkedIn Pinterest Email

A critical security flaw hiding inside one of Cisco’s most widely deployed enterprise networking products has been actively exploited by hackers for at least three years — and the damage may run far deeper than anyone currently knows. The vulnerability, carrying a maximum severity score of 10.0, affects Cisco’s Catalyst SD-WAN products, the backbone infrastructure that large corporations and government agencies rely on to connect offices and private networks across long distances.

The implications are severe. By exploiting the flaw remotely over the internet, attackers can gain the highest level of system permissions on affected devices, allowing them to burrow deep into a target’s network and maintain a persistent, hidden presence — sometimes for years — without triggering any alarms. That kind of invisible access opens the door to prolonged espionage, quiet data theft and infrastructure manipulation on a massive scale.

How Long Has This Been Going On

After identifying the vulnerability, Cisco’s own researchers traced active exploitation as far back as 2023 — meaning attackers may have had undetected access to affected networks for over three years before the flaw was publicly disclosed. Among the confirmed victims are organizations classified as critical infrastructure, a broad designation that can cover everything from power grids and water systems to transportation networks and financial institutions.

The company has not named specific targets, but the profile of affected organizations makes the breach window particularly alarming. Three years of silent access inside critical infrastructure is not just a cybersecurity problem — it is a national security concern.

Governments Around the World Are Responding

The response from global authorities has been swift and unusually coordinated. Australia, Canada, New Zealand, the United Kingdom and the United States jointly issued a warning that threat actors are actively targeting organizations on a global scale. The alert represents a rare unified front from the Five Eyes intelligence alliance, signaling that the threat is considered both widespread and serious.

In the United States, the Cybersecurity and Infrastructure Security Agency issued an emergency directive ordering all civilian federal agencies to patch their systems by end of day Friday — tomorrow. CISA described the situation as an imminent threat posing unacceptable risk to the federal government and confirmed it is aware of ongoing exploitation happening right now.

What makes the directive even more striking is the context surrounding it. CISA is currently operating at reduced capacity due to a partial government shutdown, and it is still treating this vulnerability as urgent enough to issue an emergency order with a next-day deadline.

Who Is Behind the Attacks

Neither Cisco, Google, nor any of the governments involved has publicly attributed the attacks to a specific threat group or nation state. However, investigators have tracked one cluster of related activity under the designation UAT-8616. The lack of attribution does not diminish the severity — if anything, it signals that whoever is responsible has been skilled enough to avoid leaving a clear fingerprint across three or more years of active intrusion.

This Is Not Cisco’s First 10.0 Vulnerability This Year

The timing adds an uncomfortable layer to an already serious situation. Just last December, Cisco disclosed a separate maximum-severity vulnerability — also rated 10.0 — in the Async software that powers the majority of its product lineup. That flaw was also being actively used to compromise customer networks at the time of disclosure.

Two perfect-10 vulnerabilities within months of each other in widely deployed enterprise infrastructure raises uncomfortable questions about the security architecture of products that sit at the core of some of the world’s most sensitive networks. For IT and security teams managing Cisco environments, the message from governments and the company itself could not be clearer — patch now, not later.

Source: Tech Crunch

catalyst sdwan cisa directive cisco security critical vulnerability cybersecurity threat enterprise security Featured federal agencies network breach tech news
Jeric Macaraan

Keep Reading

Why IonQ’s $130 million feels like a costly mistake

NFL Combine 2026 goes live today — watch every key moment

LeVelle Moton turned down a million dollars for a promise

Kendrick Lamar is rewriting the rules at the NAACP Awards

Oliver Grant of Wu-Tang Clan dies at 52 on historic day

Claude hit with outage and users are demanding answers

0 0 votes
Article Rating
Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
Our Picks
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Don't Miss

Why IonQ’s $130 million feels like a costly mistake

Business February 26, 2026

The numbers looked like a victory lap. IonQ wrapped fiscal 2025 with $130 million in…

Cisco’s dangerous secret has been hiding since 2023

February 26, 2026

NFL Combine 2026 goes live today — watch every key moment

February 26, 2026

LeVelle Moton turned down a million dollars for a promise

February 26, 2026

Subscribe to Updates

Get the latest creative news from SmartMag about art & design.

Editors Picks
Latest Posts

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Culture
  • Money
  • Sports
© 2026 ThemeSphere. Designed by ThemeSphere.

Type above and press Enter to search. Press Esc to cancel.

wpDiscuz