View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

China-Linked Fire Ant Compromises Cisco Routers to Steal Credentials

๐Ÿšจ ACTIVE EXPLOITATION

  • China-Linked Fire Ant Compromises Cisco Routers to Steal Credentials
    Fire Ant compromised Cisco routers and TACACS servers to steal credentials and hide activity.
    • The campaign targeted organizations using Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts.
    • Fire Ant collected router traffic and administrative credentials while probing paths to connected high-value environments; confirmed compromise of those networks was not reported.
    • A GRE tunnel from a legacy Linux host pivoted into an edge router, while IOS XR malware filtered logs and command output to conceal activity.
    • TacTap injected /lib/libseconfd.so into tac_plus; credentials were stored in /var/log/.tacplus.acct and obfuscated with XOR key 0xEF.
    • BridgeAgent persisted through zabbix_agent.service and used TLS on port 443; other implants included /usr/bin/acpid (SHA1 be6b27f429324a4af05a310d8ec9635e37c68a94) and /var/tmp/ping (SHA1 5ba1242050b5b447052b210788a5a25593d6987d).
      ๐Ÿ“„ Source: sygnia.co ยท ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

๐Ÿ“‹ ADVISORIES

  • UK NCSC Cyber Assessment Framework reaches version 4.0
    The UK NCSC has released Cyber Assessment Framework version 4.0.

    • CAF 4.0 applies mainly to critical-sector organizations and essential-service suppliers.
    • It covers energy, healthcare, transportation, water, digital infrastructure, telecommunications and government.
    • The framework has four objectives, 14 principles and 41 contributing outcomes.
    • Released in August 2025, CAF 4.0 adds AI risks, threat hunting, monitoring and secure software development.
    • Organizations assess outcomes as Achieved, Partially Achieved, Not Achieved or Not Applicable.
      ๐Ÿ“Ž Coverage: centraleyes.com ยท ๐Ÿ‘ via securityboulevard.com (discovered)
  • ๐Ÿ“„ Source for Manchester Airports Group confirms data breach affecting 8.7 million customers โ€” manchesterairport.co.uk

  • ๐Ÿ“„ Source for Rhysida Claims Berlin State Network Data Theft, Demands 30 Bitcoin โ€” berlin.de

๐Ÿ”“ CVEs & KEV

  • CVE-2026-82860 โ€” CVSS 9.3 โ€” @hulumi/policies before 1.3.2 Admin Policy Bypass@hulumi/policies versions be...

  • CVE-2026-82866 โ€” CVSS 8.9 โ€” @pdfme/common before 5.5.10 SSRF via Unvalidated URL Fetch@pdfme/common befor...

  • CVE-2026-82863 โ€” CVSS 8.7 โ€” @hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection@hulumi/...

  • CVE-2026-82861 โ€” CVSS 8.7 โ€” @hulumi/policies before 1.3.2 SecureBucket Parent Spoof Bypass@hulumi/policie...

  • CVE-2026-82862 โ€” CVSS 8.6 โ€” Hulumi before v1.3.2 Helper Script Shadowing via Workspace FilesHulumi versio...

  • CVE-2026-82871 โ€” CVSS 8.2 โ€” ToolJet before v3.16.208 Cross-Organization Data Read via Database RoutesTool...

  • CVE-2026-82869 โ€” CVSS 8.2 โ€” ToolJet Database before v3.16.44 Privilege Escalation via join_tablesToolJet ...

  • CVE-2026-81624 โ€” CVSS 7.5 โ€” Undertow-core: undertow: websocketcontainer defaults for buffers and timeouts...

  • CVE-2026-82872 โ€” CVSS 7.1 โ€” ToolJet before v3.16.208 Cross-Workspace Authorization BypassToolJet before v...

  • CVE-2026-82864 โ€” CVSS 7.1 โ€” pdfme pdf-lib before 5.5.10 Denial of Service via Decompression Bombpdfme pdf...

  • CVE-2026-82870 โ€” CVSS 7.0 โ€” ToolJet before v3.16.208 Cross-Tenant Database ManipulationToolJet before v3....

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check