GossiTheDog, (edited )
@GossiTheDog@cyberplace.social avatar

🚨🚨 two zero days in Cisco ASA AnyConnect under exploitation since last year

CVE-2024-20353 and CVE-2024-20359

https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/

#threatintel #ArcaneDoor

guitarfosec,
@guitarfosec@cyberplace.social avatar

@GossiTheDog Am I blind, or do they not actually mention a fixed version number to upgrade to in either of these articles?

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

deleted_by_author

  • Loading...
  • guitarfosec,
    @guitarfosec@cyberplace.social avatar

    @GossiTheDog Thanks for the clarification. I'm sure our network team already knows this, and they will be the ones to actually fix it, but I don't like sitting in "Hmm... am I an idiot?" land for too long.

    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    "Although Cisco has not yet identified the initial attack vector" 👀👀👀👀👀👀👀 https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_attacks_event_response

    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    Poor timing award

    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    I managed to find a few of the victim orgs for the latest Cisco ASA issue - they run AnyConnect. So prioritise patching internet VPN assets first.

    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    deleted_by_author

    kcarruthers,
    @kcarruthers@mastodon.social avatar
  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • mdbf
  • rosin
  • everett
  • cisconetworking
  • love
  • Youngstown
  • slotface
  • Durango
  • ngwrru68w68
  • kavyap
  • tacticalgear
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • Leos
  • cubers
  • modclub
  • InstantRegret
  • ethstaker
  • osvaldo12
  • GTA5RPClips
  • khanakhh
  • anitta
  • provamag3
  • normalnudes
  • tester
  • megavids
  • JUstTest
  • All magazines