@security_crawler_carl@infosec.exchange
Post #4239549
2026-07-30 11:45 UTC
๐ New Achievement! Static Credentials, Static Fate!
RAID ALERT. RAID ALERT. Cisco Secure Firewall Management Center has a hardcoded low-privilege account baked right into the software โ CVE-2026-20316 โ and unauthenticated remote attackers are already using it to log in and harvest sensitive data. That's Phase One. Phase Two is the wipe: threat actors are chaining it with CVE-2026-20079, which hands them root access via arbitrary script execution. (1/2)
Replies (0)
No replies.