Cisco warns IOS device users on attack 'evolution'

Attackers have been observed substituting Cisco’s IOS bootstrap with a malicious ROMMON image after first accessing the company’s IOS devices, according to an alert issued by Cisco Product Security Incident Response Team (PSIRT). The PSIRT said it began contacting customers regarding the “evolution” detected in attacks launched against its IOS Classic platforms. “In all cases … Read more

How to find the JETPLOW on Cisco firewalls installed

JETPLOW is a firmware persistence implant for Cisco PIX Series and ASA (Adaptive Security Appliance) firewalls. It persists DNT’s BANANAGLEE software implant. JETPLOW also has a persistent back-door capability. JETPLOW is a firmware persistence implant for Cisco PIX Series and ASA (Adaptive Security Appliance) firewalls. It persists DNT’s BANANAGLEE software implant and modifies the Cisco … Read more

Why the Russian Hackers strikes back

The Russian Federation holds an interesting, albeit a dubious position in the ranks of nation state cyber-actors. While ranked third among countries in terms of volume of cyber activity (behind the U.S. and China, according to Deutsche Telekom’s honeypot network data), Russia is widely regarded as a having the most sophisticated and skilled hackers. Unlike … Read more