Get a Pentest and security assessment of your IT network.

Cyber Security

Cisco fixes 6-month-old AnyConnect VPN zero-day with exploit code

Cisco has fixed a zero-day vulnerability found in the Cisco AnyConnect Secure Mobility Client VPN software. The company disclosed the bug in November 2020 without releasing security updates but provided mitigation measures to decrease the attack surface. The vulnerability affects all Windows, Linux, and macOS client versions with vulnerable configurations; however, mobile iOS and Android clients are not impacted. There is no evidence of attackers exploiting it in the wild, but the vulnerability is not remotely exploitable, as it requires local credentials on the end-user device for the attacker to take action on the local system.

Source: https://www.bleepingcomputer.com/news/security/cisco-fixes-6-month-old-anyconnect-vpn-zero-day-with-exploit-code/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security