Cookie Consent by Free Privacy Policy Generator

Cyber Brief: Cisco flaws, ID theft service, Teams abuse

Today's brief highlights the operational reality that security incidents often stem from familiar patterns: unpatched infrastructure, exposed credentials, and social engineering through trusted collaboration tools. The stories selected reflect risks that UK organisations face daily, from critical vulnerabilities in widely deployed network equipment to sophisticated impersonation techniques that exploit the way teams actually work. Across these incidents, the common thread is the importance of practical discipline in patch management, identity verification, and access governance.

Cisco releases critical patches for network infrastructure vulnerabilities

The Register reports that Cisco has released security updates addressing multiple critical vulnerabilities across its IOS XR and Nexus 9000 product lines. The most severe flaw, CVE-2026-20212, affects Silicon One-based Nexus 9000 switches and carries a CVSS score of 9.8, allowing unauthenticated remote attackers to execute code as root. Cisco discovered so many vulnerabilities during internal security testing of IOS XR that it bundled seven CVEs into a single hardening release, including two rated 9.8, with no workarounds available for any affected IOS XR version. The Nexus 9000 vulnerability can be mitigated but not fully fixed in current releases.

For UK organisations running Cisco infrastructure, this represents a significant operational risk. Nexus 9000 switches are widely deployed in enterprise data centres and critical network segments, whilst IOS XR powers many service provider and large enterprise networks. The absence of workarounds for the IOS XR vulnerabilities means patching is the only effective defence, and the root-level access available through CVE-2026-20212 means an attacker could completely compromise affected switches. These are not theoretical risks; they affect core infrastructure that underpins business operations, and the vulnerabilities are now publicly documented.

Why it matters

For UK businesses running Cisco network equipment, this is a prompt to review which devices are affected and prioritise patching within your maintenance windows. Where immediate patching is not possible, consider whether affected devices can be isolated or whether additional monitoring can detect unusual activity. Ensure your asset inventory is current enough to identify which systems need attention.

Source: The Register

FBI investigates service selling 153 million driver's licence images

Krebs on Security reports that a new identity theft service launched on the dark web is selling digital scans of more than 153 million drivers licences from people in the United States and Canada. Based on interviews with individuals whose licences are available for purchase, the data appears to have been siphoned from a widely-used identity verification company based in Louisiana. The FBI's New Orleans field office is now investigating the breach. The service offers high-resolution scans of government-issued identity documents, creating significant risk for identity fraud, account takeover, and synthetic identity creation.

Whilst this breach affects a US-based verification service, the operational implications extend to UK organisations that rely on third-party identity verification providers, particularly those operating internationally or using shared platforms. The incident demonstrates how identity verification services, which hold sensitive biometric and document data at scale, represent high-value targets for attackers. For organisations that use such services for customer onboarding, employee verification, or compliance checks, this is a reminder that the security of your identity verification supply chain directly affects your own risk exposure. The availability of high-quality identity documents on criminal marketplaces also increases the sophistication of social engineering and account takeover attempts targeting your organisation.

Why it matters

For UK businesses using third-party identity verification services, this is a prompt to review who you rely on, how they protect the data they collect on your behalf, and what contractual assurances you have regarding breach notification and liability. Consider whether your onboarding and account recovery processes have sufficient controls to detect fraudulent identity documents, and whether your incident response plans account for compromise of identity data held by suppliers.

Source: Krebs on Security

Microsoft warns of IT support impersonation attacks via Teams

Microsoft Threat Intelligence has published research detailing a human-operated intrusion campaign that abuses Microsoft Teams external collaboration features to impersonate IT support staff. The Microsoft Security Blog reports that attackers use social engineering to convince targets to accept external Teams calls, then persuade them to grant remote access using legitimate tools such as Quick Assist or third-party remote desktop software. Once access is established, attackers deploy a Node.js-based implant and move laterally across the network using legitimate administrative tools. The campaign exploits the trust users place in internal IT support and the default external collaboration settings in Microsoft Teams.

For UK organisations using Microsoft Teams, this attack technique is particularly concerning because it leverages the collaboration tools that employees use daily and exploits the reasonable expectation that IT support may contact them. The attackers are not exploiting a technical vulnerability; they are exploiting the operational reality that users are accustomed to receiving help from IT teams and may not question an unexpected support call, especially if it appears to come through a trusted platform. The use of legitimate remote access tools also makes detection harder, as these tools are often present in enterprise environments for legitimate purposes.

Why it matters

For UK businesses, this is a prompt to review your Microsoft Teams external collaboration settings, ensure users understand how your IT team actually makes contact, and establish clear verification procedures for remote access requests. Consider whether your security awareness training covers impersonation via collaboration platforms, and whether your monitoring can detect unusual remote access tool usage or lateral movement patterns following external Teams interactions.

Source: Microsoft Security Blog

G7 nations urge organisations to prepare for post-quantum encryption

CyberScoop reports that the G7 nations have issued a joint statement urging governments and industry to accelerate preparations for post-quantum cryptography. The statement warns that quantum computing capable of breaking current encryption standards can no longer be treated as a distant or theoretical possibility, and that organisations must begin transitioning to quantum-resistant algorithms now. The warning reflects growing concern that adversaries may already be harvesting encrypted data with the intention of decrypting it once quantum computing capabilities mature, a threat known as "harvest now, decrypt later". The G7 statement emphasises that the transition to post-quantum cryptography will take years and requires coordinated action across supply chains, standards bodies, and critical infrastructure sectors.

For UK organisations, this represents a significant governance and planning challenge. Post-quantum cryptography is not a simple software update; it requires identifying where cryptography is used across your estate, understanding which systems and protocols are vulnerable, and planning a phased transition that maintains security and interoperability throughout. The "harvest now, decrypt later" threat means that data encrypted today using current standards may be at risk in the future, which has particular implications for organisations handling long-lived sensitive data such as health records, financial information, intellectual property, or government secrets. The G7 statement signals that this is now a priority at the highest levels of government, and that regulatory or compliance expectations may follow.

Why it matters

For UK businesses, this is a prompt to begin understanding your cryptographic inventory and where post-quantum risks may affect your organisation. Consider whether your long-term data protection strategies account for future quantum threats, and whether your technology roadmaps include post-quantum cryptography as a planning assumption. This is not an immediate crisis, but it is a transition that requires early planning and coordination with suppliers and standards bodies.

Source: CyberScoop

Today's Key Actions

  • Review your Cisco network infrastructure to identify affected Nexus 9000 and IOS XR devices, prioritise patching, and consider interim monitoring or isolation where immediate updates are not possible.
  • Assess your reliance on third-party identity verification services, review contractual protections, and ensure your onboarding and account recovery processes can detect fraudulent identity documents.
  • Review Microsoft Teams external collaboration settings, establish clear verification procedures for IT support contact, and ensure security awareness training covers impersonation via collaboration platforms.
  • Begin understanding your cryptographic inventory and consider whether your long-term data protection strategies account for post-quantum risks, particularly for sensitive data with long retention periods.
  • Ensure clear ownership of vulnerability management, supplier security governance, identity verification controls, and cryptographic planning across your organisation, so that these areas are actively managed rather than assumed.

Secarma Insight

The incidents highlighted today reflect a consistent theme: effective security comes from understanding where your organisation is exposed and ensuring the right disciplines are in place before incidents occur. Whether it is knowing which infrastructure needs patching, understanding what your suppliers do with sensitive data, or ensuring your teams can recognise social engineering, the common thread is practical governance and clear ownership. Organisations that maintain current asset inventories, review supplier security regularly, and ensure their teams understand how attackers actually operate are better positioned to respond calmly and effectively when issues arise. Security is not about reacting to every headline; it is about building the habits and disciplines that make your organisation resilient by design.

News and blog posts
Today's brief highlights the operational reality that security incidents often...
The Register reports that Cisco has released security updates addressing...
Krebs on Security reports that a new identity theft service launched on the...
Microsoft Threat Intelligence has published research detailing a human-operated...