Connect with us

Tech

Cisco Catalyst SD-WAN users targeted in series of cyber attacks | Computer Weekly

Published

on

Cisco Catalyst SD-WAN users targeted in series of cyber attacks | Computer Weekly


The UK’s National Cyber Security Centre (NCSC) and its partner agencies in the Anglophone Five Eyes intelligence-sharing group have warned users of Cisco Catalyst Software Defined Wide Area Networks (SD-WAN) to take immediate action after identifying a cluster of threat activity targeting the widely used products.

The activity appears indiscriminate in its targeting, but the modus operandi is largely the same – following compromise, the as-yet-unnamed threat actors add a malicious rogue peer before conducting follow-on actions to achieve root access and maintain persistent access to the victim’s network.

“Our new alert makes clear that organisations using Cisco Catalyst SD-WAN products should urgently investigate their exposure to network compromise and hunt for malicious activity, making use of the new threat hunting advice produced with our international partners to identify evidence of compromise,” said NCSC chief technology officer (CTO) Ollie Whitehouse.

“UK organisations are strongly advised to report compromises to the NCSC, and to apply vendor updates and hardening guidance as soon as practicable to reduce the risk of exploitation,” he added.

The NCSC said the activity itself appeared to date back to 2023, and a series of vulnerabilities in Catalyst SD-WAN Manager and Catalyst SD-WAN Controller have now been patched by Cisco.

Chief among these issues, and of most concern to Cisco, is CVE-2026-20127, an authentication bypass vulnerability in Catalyst SD-WAN.

In an advisory, Cisco said the vulnerability arose due to a failure of the peering authentication mechanism on an affected system.

“An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric,” the supplier said.

“Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.”

Organisations with management interfaces exposed to the public internet appear to be at greatest risk of compromise – exposing management interfaces to the internet is extremely ill-advised.

Besides performing threat hunting for evidence of compromise as detailed in a newly-published Hunt Guide – available here – security teams should immediately update to the appropriate fixed latest versions of Catalyst SD-WAN Manager and Controller, and apply the Cisco Catalyst SD-WAN Hardening Guide now available from Cisco.

UK-based organisations that discover they may have been compromised are advised to immediately collect artefacts from the relevant device and report it to the NCSC.

In the US, the Cybersecurity and Infrastructure Security Agency (Cisa) has issued a parallel emergency directive instructing government organisations to take action by 23:59 EST (04:59 GMT) on Thursday 26 February, and to have fully applied the patches by 17:00 EST on Friday.

Threat actor targets CNI operators

Meanwhile, Cisco’s threat intel unit Talos has been tracking active exploitation of CVE-2026-20127, and has assigned the cluster the designation UAT-8616.

Talos said it was confident that UAT-8616 is a “highly sophisticated cyber threat actor” given the historical extent of its activity dating back to 2023, and additional investigation, which found that its hackers likely escalated to root user by downgrading the software version then exploiting another flaw – CVE-2022-20775 – in the Catalyst software command line interface (CLI) before restoring back to the original.

Talos said UAT-8616 demonstrated an ongoing trend of targeting network edge devices in order to establish beachheads at high-value organisations, such as operators of critical national infrastructure (CNI).

While it stopped short of attributing the activity outright, the targeting of utilities and similar organisations could indicate UAT-8616 is backed by a nation-state.



Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Tech

A Lot of Shops Won’t Fix Electric Bikes. Here’s Why

Published

on

A Lot of Shops Won’t Fix Electric Bikes. Here’s Why


If you Ask any bike shop owner or manager if they fix electric bikes, you get an interesting array of stories.

“I know a guy who has lost a finger working on ebikes,” says MacKenzie Hardt, owner of Hardt Family Cyclery in Aurora, Colorado, and the former executive director of the nonprofit bike shop and community hub Bikes Together. Hardt has torn tendons in his own hand after accidentally triggering a cadence sensor that caused the wheel to spin out of control on the stand, even when the motor and battery were disconnected.

He now has a message on the company voicemail that informs customers the shop will not repair any ebike without third-party UL 2849 certification, the gold standard that certifies that an ebike’s entire package, from electrical drive train to battery to charger system, has been thoroughly tested. (Check out our guide to How to Buy an Electric Bike for more info.)

The Wild, Wild West

A lot of the problem in fixing ebikes is related to the fact that a surprising number of electric vehicles that are sold as ebikes are not, in fact, ebikes. According to PeopleForBikes, the third-party advocacy group, an ebike is a low-speed electric vehicle that “closely resembles traditional bicycles in their equipment, handling characteristic, size, and speed.”

A mechanic works on a bicycle.Photograph: Dikushin/Getty Images

In 46 states, all ebikes fall under a Class 1, 2, or 3 distinction. The distinction depends on the bike’s maximum motor-assisted speed and how it’s powered. However, many ebikes sold online are way more powerful than the maximum 28 mph speed allowed on a Class 3 ebike, and they operate more like a moped or even a motorcycle.

“That’s really the heart and soul of the service problem,” says Cory Oseland, manager of the Ski Hut, a high-end bike shop in Duluth, Minnesota. “Once you slide out of the three classes, you run into a lot of parts and equipment that aren’t part of the bike industry.”

Repairing an ebike can also land the shop in a quagmire of liability issues. As bike shops are part of the product liability chain, they can be held responsible if they so much as inflate a tire on an electric vehicle and the rider later injures themselves or another person. Ebike-related injuries have jumped more than 1,020 percent nationwide from 2020 to 2024, according to hospital data, so this is not an unforeseen occurrence. “I have known people who have lost their shirt,” says Hardt.

In most states, if the bike doesn’t fit the Class 1-3 classification system, the shop’s insurance will likely be null and void. The problem, says Hardt, is that “we don’t regulate nationally what an ebike is. What is legal here may not be legal somewhere else.” Working on an unregulated bike, he adds, “is like if somebody brought in a Tesla to fix.”



Source link

Continue Reading

Tech

No 2-in-1 Laptop Is Perfect, but These Are the Best I’ve Tested

Published

on

No 2-in-1 Laptop Is Perfect, but These Are the Best I’ve Tested


There will always be a use case for owning both a laptop and a tablet as stand-alone products. But the 2-in-1 laptop is the utopian dream of combining these two into a single device.

Of all the models I’ve tested, no 2-in-1 laptop is equally good at being both a tablet and a laptop. They always lean toward one or the other. But that doesn’t mean you shouldn’t buy one, especially since the convenience of having both in one device makes it an easier pill to swallow, price-wise.

The products below should meet most people’s needs. But if none are a fit for you, check out our other computer buying guides, including the Best Cheap Laptops, the Best Tablets, and the Best iPad.

Table of Contents

Detachable Tablets

Microsoft

Surface Pro 13-inch (11th Edition, 2024)

If you want a 2-in-1, think first about a detachable tablet. These are basically tablets that attach to a keyboard. This form factor emphasizes being able to switch between tablet and laptop modes. It’s just as functional as a tablet as it is as a laptop. The Surface Pro is the epitome of this design, pioneering the idea of a tablet with a built-in kickstand that runs a full version of Windows.

Microsoft has refined the hardware over the years, but it wasn’t until the 2024 model that it came into its own. That’s largely thanks to the Qualcomm Snapdragon X Elite (and Plus) processor, which finally gave the device an appropriate amount of performance and battery life. While it’s not cheap (especially once you include the Type Cover), I love that you can now use the keyboard while detached from the screen, making it even more adaptable in scenarios away from a desk. To compete with the iPad Pro, there’s even an OLED model (with 120-Hz refresh rate) available, which really brings visuals on the display to life.

Last year, Microsoft came out with a smaller and more affordable model, the Surface Pro 12. This is the most successful small tablet Microsoft has ever made, and a big reason is because it doesn’t cheap out on quality or shrink down the size too much. With a 12-inch screen, it still allows the keyboard to be large enough to be comfortable typing on. It doesn’t have the option for an OLED screen, but this is still a surprisingly premium-feeling device that is even more portable than its older sibling.

Not only is the Surface Pro 12 cheaper overall, it’s also the only 256-GB storage model on offer. Because Surface devices run a full version of Windows, they are the best 2-in-1 devices to use as full laptop replacements. While the hardware is there to make for a good tablet, Windows isn’t so friendly with touch and doesn’t have a touch-first app ecosystem to support it. That’s where iPads come into play.

The iPad Air and iPad Pro are the best tablets you can buy, largely thanks to the breadth of touch-first apps available in the App Store. In many ways, that’s what makes an iPad such an ideal 2-in-1 laptop, especially if you actually want to use it as a tablet. They are also easier to hold in one hand, as they are lighter than the Surface devices. These days, these iPads are increasingly legitimate laptop replacements too. With the Magic Keyboard attachment, you can add an additional USB-C port and a full-size keyboard and trackpad. I like that this design doesn’t rely on a kickstand either, which makes it easier to use on your lap than the Surface.

iPadOS still isn’t perfect, but with the introduction of windowing and better cursor support, they work as laptops better than ever. The latest model I tested, the M4 iPad Air, is immensely powerful, and with the Magic Keyboard attached, it’s a really solid 2-in-1 laptop that comes in cheaper than the Surface Pro with the keyboard included. It’s plenty of performance for just about anything you’d want to do with an iPad, especially if you opt for the larger 13-inch model. My only real complaint is that the palm rests on the Magic Keyboard are quite small.



Source link

Continue Reading

Tech

The Screenmaxxers Who Spend Every Waking Hour on Their Phones

Published

on

The Screenmaxxers Who Spend Every Waking Hour on Their Phones


Morgan Dreiss, a copy editor in Orlando, has severe ADHD that they say requires them to always be “doing at least three things at once.” The result? A daily average screen time of 18 hours and 55 minutes.

“I’m reading a book or playing a game pretty much from waking to sleeping,” Dreiss tells WIRED. What they read comes from the library app Libby, so the books count toward overall screen engagement. Dreiss currently keeps their phone’s autolock feature disabled so they can continuously run a mobile game that pays out $35 for every 110 hours logged. (They’ve earned about $16 so far.)

For years, studies have brought forth worrying data about the potential negative effects of excessive screen time on both physical and cognitive health. Concerns over the neural development and mental health of young people glued to their phones have led to major legislative and courtroom battles; recently a jury found Meta and YouTube liable for designing their platforms with addictive features.

While the question of whether one can be clinically “addicted” to something like social media remains a subject of fierce contention, there seems to be a broad consensus in this decade that people would be better off scrolling less. On the more extreme end, there are virtual communities that share strategies for ditching smartphones and digital detox retreats where no notifications can find you.

Yet there are those, like Dreiss, who resist the emerging common wisdom about reducing screen time. You might call them “screenmaxxers.” It’s not that they necessarily have some totalizing concept of their habits; journalist Taylor Lorenz is likely in the minority of screenmaxxers eager to put the screen directly inside her brain, as she recently confessed to WIRED. It’s just that, for various reasons, they’re on their devices pretty much all the time, and they don’t see that as a problem whatsoever.

Part of the equation, of course, is work. Corina Diaz, 45, who lives in a remote forested region of Ontario, Canada, works in video game marketing and does influencer management for a game publisher. “So, a lot of screen time,” she says.

Diaz met her husband online in 2005 and had a child three years ago—her screen time increased when she was awake at strange hours because of her newborn, she says.

But Diaz has sought friendships online since the 1990s, when that meant availing herself of tools like Internet Relay Chat and bulletin board systems. “I’ve always felt screens, phone or otherwise, connected me to things I care about,” she says. “In particular, niche social groups that don’t have great mainstream visibility.” Now that she lives two and a half hours outside Toronto, the closest major city, her screen is “a bit of a connection lifeline,” she says.

Daniel Rios is in a similar position. A computer programmer, he lives in the South American country where he grew up after having lived abroad for years. Most of his friends moved away and didn’t return.

As a result, Rios keeps in touch with people over Discord, his primary social outlet. Not living in a city, he doesn’t go out all that much, and screens fill his days—though he says it’s “hard to quantify” exactly how many hours it all adds up to. “When I’m not working at the [desktop] computer, I’m playing at the computer or watching TV,” he says. “If I’m not at the computer, I’m looking at my phone. If I’m not doing any of the above, and I’m out of the house, I’m still probably listening to something on my phone.”



Source link

Continue Reading

Trending