4/29/2023 0 Comments Vstack vulnerability![]() ![]() ![]() It seems that the attack is mostly targeting the Russian-speaking segment of the Internet, yet other segments are clearly more or less affected as well. The scale of the attack is yet to be determined, however, it might be really big – with entire Internet-providers and data-centers impacted. That results in some data centers being unavailable, and that, in turn, results in some popular sites being down.Īccording to Cisco Talos, there are more than 168,000 devices found on Shodan, that have this vulnerability. Once it finds a vulnerable switch, it exploits the Smart Install Client, rewrites the config – and thus takes another segment of the Internet down. It seems that there’s a bot that is searching for vulnerable Cisco switches via the IoT search engine Shodan and exploiting the vulnerability in them (or, perhaps, it might be using Cisco’s own utility that is designed to search for vulnerable switches). The malefactors then rewrite the Cisco IOS image on the switches and change the configuration file, leaving a message that reads “Do not mess with our elections” there. An unknown threat actor is exploiting a vulnerability in a piece of software called Cisco Smart Install Client, which allows them to run arbitrary code on the vulnerable switches. The attack seems to be happening in the following manner. There’s a reason for that according to our sources, there’s a massive attack against Cisco switches going on right now – these switches are used in data-centers all across the globe. Let’s say that your internet connection suddenly went down or, perhaps, you cannot reach your favorite website. KasperskyPremium Support and Professional Services.KasperskyEndpoint Security for Business Advanced.KasperskyEndpoint Security for Business Select. ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |