Attackers are increasingly targeting infrastructure management systems, with exploited flaws in Cisco Secure Firewall Management Center, Cisco Identity Services Engine, SonicWall SMA 1000, and Check Point products enabling remote code execution and full device control. The report also highlights widespread supply-chain impact from the Linux kernel βCopyFailβ flaw and firmware weaknesses affecting Cisco, AMI Aptio-based systems, and Insyde. #Cisco #SonicWall #CheckPoint #Arista #CopyFail #CyclopsBlink #Sandworm #Qilin
Keypoints
- Attackers are focusing on management platforms that control enterprise infrastructure.
- Cisco FMC and ISE flaws were actively exploited and added to CISAβs KEV catalog.
- SonicWall SMA 1000 and Check Point vulnerabilities enabled unauthenticated remote code execution.
- The Linux kernel βCopyFailβ flaw appeared across 19 advisories from six vendors.
- Firmware and Secure Boot weaknesses affected Cisco, AMI Aptio, Insyde, and other systems.