#network security
37 stories taggednetwork security.

F5's BIG-IP Flaw Was Already Being Exploited Before a Patch Existed
A critical security hole in widely used network hardware is under active attack. Federal agencies have three days to patch. Here's what the flaw does and who is at risk.

Cisco Patches Eight Flaws in Network Software Used by Telecoms Worldwide, Two Rated Near-Maximum Severity
Cisco's own engineers found the vulnerabilities using artificial intelligence tools. No fixes exist beyond the patches, and two of the flaws score 9.8 out of 10 on the standard severity scale.

Hackers Are Exploiting a Fortinet Flaw to Plant Remote-Control Malware on Network Devices
A security bug in Fortinet's firewall and switch software is being used to silently take over devices and steal data. More than 178 machines are already infected, attacks have been running since at least July 2026, and the US government is telling federal agencies they have three days to patch.

Cisco's Network Gatekeeper Has a Perfect-10 Flaw and Hackers Are Already Inside
A zero-day in Cisco Identity Services Engine lets anyone on the internet walk past the login screen entirely. Federal agencies have three days to patch. There is no workaround.

Hackers Are Taking Over MikroTik Routers Left Open on the Internet
Poland's national cyber team warns that criminals are grabbing full control of MikroTik routers through an exposed remote-access service, with attacks running since at least early September.

Cisco patches critical Nexus 9000 bug that lets attackers run code as root
A flaw tracked as CVE-2026-20212 scores 9.8 out of 10. Cisco also shipped a bundled fix for seven separate IOS XR bugs, two of them equally severe, with no workaround available.

WatchGuard Patches Five Critical Flaws That Could Let Attackers Seize Control Remotely
WatchGuard has fixed more than two dozen vulnerabilities in its firewall software and management tools, including five rated 9.3 out of 10 in severity.

China-Linked 'Fire Ant' Crew Breaks Into Cisco Routers to Steal Passwords and Hide Its Tracks
Sygnia says the espionage group has jumped from VMware servers to core network gear, tampering with logs and siphoning credentials from TACACS authentication servers.

Microsoft says the patching window is shrinking fast. Here is what that means for ordinary people.
Software flaws are being turned into working attacks within hours of being made public. Microsoft says companies can no longer patch their way out fast enough, and is pushing a network-level defensive layer to buy time.

Zombie Cards, Cut Cables, and a Botnet: The Week's Cybercrime Stories You May Have Missed
T-Mobile physically severed a network cable to stop an active intrusion, a new Linux botnet called Evooo1Bot is spreading across hijacked servers, and Threema's encrypted messaging service was knocked offline by a DDoS attack. Here is what happened.

Cisco Patches Four Maximum-Severity Flaws in Crosswork Network Software
Fifteen vulnerabilities fixed across Cisco products, with three scoring a perfect 10 out of 10 on the standard severity scale. None are known to be exploited yet.

Six flaws in CISA's own Malcolm network tool let low-level users run code and slip past access checks
The US cyber agency's open-source traffic analyzer, used by defenders worldwide, shipped with a file-upload bug that hands attackers a shell as the web user, plus two authorization gates that fall open on a simple URL trick.

Fortinet Patches Eight Flaws, Including Two That Let Attackers Log In Without Real Credentials
Two high-severity bugs in Fortinet's security products could let criminals talk their way past login screens they should never be able to reach.

SonicWall Patches Critical Flaws in a Security Platform It Already Retired
Two vulnerabilities scored near-perfect danger ratings and could let criminals break into systems without a password. One of the affected products was officially shut down last October.

NatJack: New Attack Hijacks TCP Sessions by Abusing Network Address Translation
Researcher Malcolm Stagg showed at Black Hat USA 2026 how to twist NAT tables to steal live connections, fake DNS answers, and unmask hidden users.