back to article Governments issue alerts after 'sophisticated' state-backed actor found exploiting flaws in Cisco security boxes

A previously unknown and "sophisticated" nation-state group compromised Cisco firewalls as early as November 2023 for espionage purposes — and possibly attacked network devices made by other vendors including Microsoft, according to warnings from the networking giant and three Western governments. These cyber-spy campaigns, …

  1. Anonymous Coward
    Anonymous Coward

    IOW...

    "Governments issue alerts after fourteen-year-old script kiddie finds NSA backdoor built into Cisco security boxes"

  2. stiine Silver badge
    Facepalm

    Another name for a password is...

    "Line Dancer can also trick the AAA (Authentication, Authorization and Accounting) function into allowing the attacker to connect using a magic number authentication capability to establish a remote access VPN tunnel."

    Wouldn't the word 'password' have been much quicker to type? Or is it much more subtle?

  3. ChoHag Silver badge

    > The mysterious nation-state group "utilized bespoke tooling ...

    Oh god! Did the bad guys learn python? Now you're really going to have to up your game.

  4. ExpatZ

    "In addition to the alert we have not confirmed evidence of this activity affecting US government networks at this time," as CISA spokesperson told The Register.

    And now we know who the state actor is.

  5. Anonymous Coward
    Anonymous Coward

    Have I Mentioned Fort Meade Before?

    So.....the weakness was embedded BY CISCO at the behest of paymasters in Fort Meade????? What do you think?

    1. Anonymous Coward
      Anonymous Coward

      Re: Have I Mentioned Fort Meade Before?

      Closed source at work here..................

      ..........of course, the patch to "fix" this problem will almost certainly include a replacement "weakness"!!!!

      Quote: (William Burroughs) "The paranoid is a person who knows a little of what is going on."

      1. Anonymous Coward
        Anonymous Coward

        Alternative Scenario.......

        Just a thought......maybe Cisco would be a useful target (like SolarWinds)? Who knows what mayhem might transpire?

        ......or maybe it's ALREADY HAPPENED??

  6. Anonymous Coward
    Anonymous Coward

    Stop using cisco

    I stopped using cisco ASA around v5.2ish and old IOS @ 12.3 as it was an unsecure pos and found it highly annoying you had to repeatedly pay for their next backdoored code version. I suppose somebody has to pay for the devs to think up new ways to obfuscate the *required holes in their system.Those using cisco gear are the same breed as the lemmings that continue to jump off Microsoft's cliffs despite the escalating numbers of injured. *Plenty of information out there for you to see.

    Two months since the last cisco backdoor discovery.

    1. Sandtitz Silver badge
      Facepalm

      Re: Stop using cisco

      You forgot to mention in your rant what firewall apparatus you are using now.

  7. John Brown (no body) Silver badge

    "first spotted in early January and revealed on Wednesday."

    Is this because they've released patched to block the intrusions or did it just take this long to get around to telling people their security is leaking like a sieve?

    I can understand a delay in announcing a vuln that's not being actively exploited since that would give the bad guys a clear window of opportunity while the fix is being developed, but when it's an actively exploited vuln, would it not be better to announce it ASAP so at least the victims and potential can try to do something to protect themselves?

  8. jvf

    I don't get it

    One after another. Does anybody test their crap in-house or do they just wait for something to happen?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like