CISA warns of hackers abusing Cisco Smart Install feature
ID: 631166d4-18e6-5bc4-908f-874228db0e9f
STIX ID: report--631166d4-18e6-5bc4-908f-874228db0e9f
Feed Name: Bleeping Computer
CISA warns that legacy Cisco Smart Install (SMI) is being actively abused to steal and tamper with switch configuration files and system images; administrators are advised to disable SMI, follow NSA/CISA guidance, and ensure Cisco device passwords use NIST-approved Type 8 (PBKDF2 SHA-256 with 20,000 iterations). The advisory notes historical APT exploitation (e.g., Dragonfly/Crouching Yeti), ongoing scanning of exposed devices (Shadowserver tracks >6,000 IPs), and emphasizes fixing weak password types to prevent credential cracking and further compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
