Nation-State Hackers Exploit Critical Cisco Vulnerability
A critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC) has been exploited by nation-state and ransomware actors, according to a recent report. The FMC is used for centrally managing multiple Cisco Secure Firewall devices across a network.
Additionally, hackers have discovered a chain of RouterOS vulnerabilities that can be exploited to hijack MikroTik devices without authentication. This exploit chain, known as 'MikroTrick,' allows an attacker to take full control of a device with SSH open to the internet.
Sophos has also reported that a rootkit was found on hacked F5 BIG-IP APM devices, which hides a web shell in memory instead of writing it to disk. This makes it difficult for security teams to detect and remove the malware.