CISA Issues Emergency Directive Over Exploited Cisco SD-WAN Flaws

2026-03-12T14:52:19Zbbc9f1d535630024be57b838a92bc37246c16e1232d37810433f9a777fd24419
BlackSantaCISACisco SD-WANCorunaEDR-killerElastic Cloud SIEMFreeScoutGoogle LookerLLM guardrailsLeakyLookerMail2ShellShinyHuntersStrykerTycoon2FA takedownWordPress compromiseactive exploitationdata breachemergency directiveexploit kitinfostealerpatchesransomwarevulnerabilitieswiper malwarezero-day

What happened

Multiple high-impact incidents and actively exploited vulnerabilities were reported. CISA issued an emergency directive after attackers began exploiting critical Cisco SD‑WAN flaws that can grant administrative network access; Cisco also released patches across many products. Researchers disclosed severe issues in cloud and AI tooling (eg. Google Looker ‘LeakyLooker’, LLM guardrail bypasses, ContextCrush) and multiple zero-click/remote‑code bugs (eg. Mail2Shell/FreeScout), while threat actors conducted destructive and broad campaigns — including a claimed wiper attack on Stryker, large WordPr​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
bbc9f1d535630024be57b838a92bc37246c16e1232d37810433f9a777fd24419
Enrichment time
2026-03-12T14:52:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.