Malicious hackers exploit Cisco zero-day for highest access level at communications service provider

2026-06-24T20:51:48Z1518293b93be2b61be4c63792d94c8426160126b14fb3031dbbb7c98dba78dd4
amadeybotnet-takedownciscocommunications-service-providerdeepfakesdoj-seizureincident-responsemandiantopen-source-securitypost-quantumprivilege-escalationsd-wansocgholishstealczero-day

What happened

CyberScoop reports that Mandiant detailed exploitation of a Cisco SD‑WAN zero‑day that allowed attackers to obtain the highest access level at a communications service provider; attribution and full scope of internal visibility remain unclear. The feed also highlights related law‑enforcement and industry activity: Microsoft disrupted Amadey and StealC C2 infrastructure, the DOJ seized infrastructure tied to Huione Group, authorities disrupted Evil Corp’s SocGholish/SocGholish‑infected sites, and broader policy and risk stories including post‑quantum executive orders, rising open‑source supply‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
1518293b93be2b61be4c63792d94c8426160126b14fb3031dbbb7c98dba78dd4
Enrichment time
2026-06-24T20:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.