ArcaneDoor – New campaign found targeting network devices
blog.talosintelligence.com
blog.talosintelligence.com
So update but probably remain vulnerable - there is no reason to think CISCO has fixed the original vulnerability.
Irrelevant aside: CISCO could have just reported a couple of zero-days they already knew of. Maybe vendors will start stockpiling zero-days ;-P
i wouldn't want to be a network appliance vendor in the usa or cn at this last decade!
E.g. say a dedicated team is being financed with $xM.
E.g. say that they are setting up honeypot devices to capture the initial vector.
E.g. say that code is having a complete external audit and fuzz.
I'm not a security expert but if I were a customer I would be pretty dissapointed in the timeline so far and very dissappointed in their respose.
It looks like the vulnerabilities fixed only prevent the Line Runner malware reinstalling itself on boot. And nothing is done about Line Dancer.
Cisco has enough money to fund their own security company which lets them also investigate issues and issue statements of the form: We are so significant that nation-states target our equipment. We are also so dedicated to security we will write up these reports to show this dedication.
Part of it is it makes them look cool. Part of it is if they don't they risk the govt dragging them through the mud, like CISA did for the MSFT email breach. CISA already releases a lot of alerts on Cisco as it is.
Maybe if they didn't lobby so hard, they would have been spared and Huawei would have been targeted instead. /s
> they risk the govt dragging them through the mud
Lol. Chances are they're probably already in bed with all sorts of 3-letter agencies for things we'll never learn.
[1] https://www.reuters.com/world/europe/german-minister-says-pa...
Pistorius said. "The reason the air force call could nonetheless be recorded was because of an individual's operational mistake."
No need to blame their security systems/protocols that permitted insecure comms!Cisco says hackers subverted its security devices to spy on governments
Nice copy.
—"multiple vendors" = Cisco and Microsoft... and others
"these devices need to be routinely and promptly patched; using up-to-date hardware"
Contact sales at xxx...
"Cisco’s position as a leading global network infrastructure vendor gives Talos’ Intelligence and Interdiction team immense visibility into the general state of network hygiene. This also gives us uniquely positioned investigative capability into attacks of this nature."
—Is this a security bulletin or a prospectus? When is a liability an asset? You decide
"Early in 2024, a vigilant customer reached out to both Cisco’s Product Security Incident Response Team (PSIRT) and Cisco Talos to discuss security concerns..."
—More fine copy.
"Cisco Secure Firewall (formerly Next-Generation Firewall and Firepower NGFW) appliances such as Threat Defense Virtual, Adaptive Security Appliance and Meraki MX can detect malicious activity associated with this threat."
—ABC: Always Be Closing!
"This threat demonstrates several techniques of the MITRE ATT&CK framework, most notably..."
—Several = 15
—List of 100s of vectors and effects over years
"As a part of our ongoing investigation, we have also conducted analysis on possible attribution of this activity. Our attribution assessment is based on the victimology..."
—We still don't know what's going on or why. Order now!
—Re Talos: back in 2008 there was a little upset in bank derivatives due to the standards and practices of a little sector of the bond market called The Ratings Agencies.
—In the tech sector Cisco stock rose sharply on HW sales surge after a critical vulnerability in government systems was exposed in existing HW...
THANK YOU THANK YOU I'LL BE HERE ALL WEEK TRY THE VEAL
This sounds interesting. I'm eager to see some code.