logo

Nearly 4-year-old Cisco vuln linked to recent Akira ransomware attacks

ID: 6ddb0086-8c16-50e2-9f5b-1b1f0fbf54ac

STIX ID: report--6ddb0086-8c16-50e2-9f5b-1b1f0fbf54ac

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-01-31

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Security vendor TrueSec observed multiple incident response engagements where the Akira ransomware group appears to have used Cisco AnyConnect/ASA/FTD memory-disclosure vulnerability CVE-2020-3259 as an entry point. Analysis of restored RADIUS logs showed attacker behavior consistent with exploiting the vulnerability (genuine-appearing logins across distinct accounts, no phishing or password-guessing evidence). The report urges organizations to confirm devices were patched, backtrack upgrade timelines, assume long-lived AnyConnect credentials and in-device secrets may be compromised, perform broad password resets, and enable MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.