Ransomware crooks exploit unpatched 0-day in Cisco security appliances

With no patch available yet, users must enable workarounds. The best: enforce MFA.

https://arstechnica.com/security/2023/09/ransomware-crooks-exploit-unpatched-0-day-in-cisco-security-appliances/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

Cisco security appliance 0-day is under attack by ransomware crooks

With no patch available yet, users must enable workarounds. The best: enforce MFA.

Ars Technica
@arstechnica @hacks4pancakes [hugs her MFA-only ASA remote access VPN boxes]
@rmd1023 @arstechnica @hacks4pancakes damn straight 😊. Although it should have been self evident to anyone that putting a web interface in front of any VPN technology was always going to end in tears. VPNs peaked at IPSec 🤣