A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user. This vulnerability is due to insufficient input validation when Cisco Webex App processes a meeting invite link. An attacker could exploit this vulnerability by persuading a user to click a crafted meeting invite link and download arbitrary files. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the targeted user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-app-client-rce-ufyMMYLC
This Palestinian Prisoners’ Day, the Palestinian-led BDS movement calls for BDS pressure on HP, Microsoft and Cisco to hold companies accountable for helping Israel’s carceral system, which turn prisons into sites of mass torture and systematic abuse. https://bdsmovement.net/news/bnc-statement-palestinian-prisoners%E2%80%99-day
On April 17th, #PalestinianPrisonersDay, the #BDS movement, calls for holding #Microsoft, #HP and #Cisco #accountable for their roles in maintaining Israel’s illegal apartheid regime and for their particular role in Israel’s prison system which is well known for its egregious human rights violations.
https://bdsmovement.net/news/bnc-statement-palestinian-prisoners%E2%80%99-day
Après la France et le Portugal, OpenDNS quitte la Belgique
https://next.ink/brief_article/apres-la-france-et-le-portugal-opendns-quitte-la-belgique/
En juin de l’année dernière, une décision de justice demandait à #Cisco (propriétaire d’OpenDNS), #Google et #CloudFlare de bloquer l'accès à plus d’une centaine de sites.
En réponse : À compter du 28 juin 2024, en raison d’une décision de justice en France […] le service OpenDNS n’est plus disponible pour les utilisateurs en France. Nous nous excusons pour la gêne occasionnée.
[…] problèmes de sécurité / continuité de service, en particulier chez des fabricants d'objets connectés qui ont[…] codé en dur une unique solution DNS basée sur #OpenDNS
En juin de l’année dernière, une décision de justice demandait à Cisco (propriétaire d’OpenDNS), Google et CloudFlare de bloquer l’accès à plus d’une centaine de sites. La réponse du résolveur ne s’était pas fait attendre : « À compter du 28 juin 2024, en raison d’une décision de justice en France rendue en vertu de […]
New.
- Cisco Webex App Client-Side Remote Code Execution Vulnerability - CVE-2025-20236 (high) https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-app-client-rce-ufyMMYLC
- Cisco Secure Network Analytics Privilege Escalation Vulnerability - CVE-2025-20178 (medium) https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sna-prvesc-4BQmK33Z
- Cisco Nexus Dashboard LDAP Username Enumeration Vulnerability - CVE-2025-20150 (medium) https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nd-unenum-2xFFh472 @TalosSecurity #Cisco #cybersecurity #Infosec
A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user. This vulnerability is due to insufficient input validation when Cisco Webex App processes a meeting invite link. An attacker could exploit this vulnerability by persuading a user to click a crafted meeting invite link and download arbitrary files. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the targeted user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-app-client-rce-ufyMMYLC