CISA Issues Emergency Directive Over Exploited Cisco SD-WAN Flaws
2026-03-12T14:52:19Z•bbc9f1d535630024be57b838a92bc37246c16e1232d37810433f9a777fd24419
BlackSantaCISACisco SD-WANCorunaEDR-killerElastic Cloud SIEMFreeScoutGoogle LookerLLM guardrailsLeakyLookerMail2ShellShinyHuntersStrykerTycoon2FA takedownWordPress compromiseactive exploitationdata breachemergency directiveexploit kitinfostealerpatchesransomwarevulnerabilitieswiper malwarezero-day
What happened
Multiple high-impact incidents and actively exploited vulnerabilities were reported. CISA issued an emergency directive after attackers began exploiting critical Cisco SD‑WAN flaws that can grant administrative network access; Cisco also released patches across many products. Researchers disclosed severe issues in cloud and AI tooling (eg. Google Looker ‘LeakyLooker’, LLM guardrail bypasses, ContextCrush) and multiple zero-click/remote‑code bugs (eg. Mail2Shell/FreeScout), while threat actors conducted destructive and broad campaigns — including a claimed wiper attack on Stryker, large WordPr
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- bbc9f1d535630024be57b838a92bc37246c16e1232d37810433f9a777fd24419
- Enrichment time
- 2026-03-12T14:52:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.