What We Know
REST OF WORLD:Constitutional Court vote may influence Puigdemont’s arrest warrant and return to CataloniaGAMING:Control Resonant’s launch hotfix eases combat and strengthens Dylan’s early progressionSPORTS:Maple Leafs acquire Kirill Marchenko from Blue Jackets and sign him to six-year extensionMARKETS:August U.S. Inflation Rose Less Than Expected as Spending Stayed Strong and Price Pressures PersistedCYBERSECURITY:Citrix NetScaler zero-days prompt global alerts and urgent mitigation effortsPOLITICS:Iran-US Nuclear and Hormuz Discussions Continue Amid Mediation and Doubts Over a DealAI:The EU advances AI Act enforcement as draft rules and provider letters emergeTOP STORIES:Ukraine develops affordable interceptor drones as jet-powered threats expose defense gapsREST OF WORLD:Constitutional Court vote may influence Puigdemont’s arrest warrant and return to CataloniaGAMING:Control Resonant’s launch hotfix eases combat and strengthens Dylan’s early progressionSPORTS:Maple Leafs acquire Kirill Marchenko from Blue Jackets and sign him to six-year extensionMARKETS:August U.S. Inflation Rose Less Than Expected as Spending Stayed Strong and Price Pressures PersistedCYBERSECURITY:Citrix NetScaler zero-days prompt global alerts and urgent mitigation effortsPOLITICS:Iran-US Nuclear and Hormuz Discussions Continue Amid Mediation and Doubts Over a DealAI:The EU advances AI Act enforcement as draft rules and provider letters emergeTOP STORIES:Ukraine develops affordable interceptor drones as jet-powered threats expose defense gaps
Older than 2 weeksJust now

Mandiant reveals how Cisco SD-WAN zero-day attacks gained root...

  • 8 sources analyzed
  • Source mix: Web
  • Momentum: Older than 2 weeks

What We Know

Mandiant has published technical findings showing that a previously unknown vulnerability in Cisco Catalyst SD‑WAN Manager (tracked as CVE‑2026‑20245) was exploited in the wild to gain root access to compromised appliances. Multiple reports describe an attack chain that delivered privileged access: attackers used an upload or input vector (reported in some writeups as a malicious CSV upload) and network-level techniques that researchers describe as "rogue peering" to reach SD‑WAN devices, obtain administrative privileges, and then escalate to root.

The exploitation occurred before public disclosure, with reporting that attackers were active at least weeks or months earlier; at least one communications service provider was confirmed as a victim where the attacker achieved the highest access level. The incident is being documented by vendors and cloud security teams (including a Google Cloud writeup) and sits amid a series of SD‑WAN zero‑days reported in 2026, prompting advisories and patching guidance from security stakeholders.

Source Comparison

Aligned reporting
6 corroborates - 2 adds context - 0 conflicts

Corroborates