Monday , August 24 2026
IOS

CISA warns Cisco IOS flaw, while VMware flaw allows bypassing authentication

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that hackers are using CVE-2008-4128, a CSRF flaw in Cisco IOS versions 12.4(12) and 12.4(4).

This weakness was included in CISA’s Known Exploited Vulnerabilities Catalog on July 13, 2026, showing that old networking flaws can still be security threats long after they are revealed.

Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

About thousands of leaked AWS keys Held Full Admin Rights

More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
About thousands of leaked AWS keys Held Full Admin Rights

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
US Bank investigates LockBit’s Data Breach Claims

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
“Zombie Card” attack revels expired Visa card may be used for contactless payments

Critical Zimbra RCE Flaw Actively Exploited in the Wild

CERT Polska has alerted that bad actors are actively exploiting a security flaw in Zimbra Collaboration Suite to execute code...
Read More
Critical Zimbra RCE Flaw Actively Exploited in the Wild

Operation CameraSwarm
A single hacker compromise 1400+ Dahua camera worldwide 

Operation CameraSwarm compromised 14,500+ Dahua IP cameras mostly in Ukraine and Russia. The operation lasted for at least 35 days...
Read More
Operation CameraSwarm  A single hacker compromise 1400+ Dahua camera worldwide 

Cl0p Ransomware Listed 40+ Victims of PTC Windchill Campaign

The Cl0p ransomware group has listed over 40 organizations that they say they targeted in a recent attack. This attack...
Read More
Cl0p Ransomware Listed 40+ Victims of PTC Windchill Campaign

CVE-2008-4128 is categorized under CWE-352, which addresses CSRF vulnerabilities. CSRF attacks occur when a victim with an authenticated browser session is deceived into visiting a malicious webpage or opening attacker-controlled content.

This flaw affects the web management of Cisco IOS. An attacker can use special requests to make an admin’s browser send commands to a Cisco IOS device without them knowing.

According to the CVE description, this issue can enable remote attackers to execute arbitrary commands via crafted requests that involve the “show privilege” command and the “/level/15/exec/-” URI.

VMware Avi Load Balancer flaws Let Attackers Bypass Authentication

VMware has revealed several security issues in its Avi Load Balancer platform that allow attackers to skip authentication and access the database without permission using special SQL queries.

The worst one, CVE-2025-22217, has a CVSSv3 score of 8.6 and does not need any login or user action to exploit. The primary issue is an unauthenticated blind SQL injection vulnerability rooted in improper input sanitization within the Avi Load Balancer’s controller components.

A bad actor with just network access can send special SQL commands to the system. This lets them skip login checks and get sensitive data from the database. A similar but less serious problem, CVE-2025-41233, lets an authenticated user with network access misuse SQL queries. It has a CVSS score of 6.8 and needs higher permissions to be activated.

Two more flaws revealed earlier raise the risk level: CVE-2024-22264, a bug that lets an admin-level attacker make, change, and remove files as root on the host system (CVSS 7.2), and CVE-2024-22266, a flaw that shows cloud connection details in plain text in system logs (CVSS 6.5).

Together, these vulnerabilities create a chain where authentication bypass, data exposure, and privilege escalation can compound one another in poorly segmented environments.

Mitigation Guidance

Apply Broadcom’s patched builds immediately, since no workarounds exist for CVE-2025-22217.
Upgrade version 30.1.1 to 30.1.2 first before layering on the 2p2 patch.
Restrict network-level access to Avi controller management interfaces to trusted administrative segments only.
Audit system logs for exposed cloud credentials tied to CVE-2024-22266 and rotate any potentially leaked secrets.
Review admin account privileges to limit exposure from the CVE-2024-22264 privilege escalation path.

Organizations using any Avi Load Balancer version from 30.1.1 to 30.2.2 need to fix problems right away. There are serious issues that can be attacked over the network and can bypass authentication. These load balancers are very important for cloud systems in companies.

Check Also

macOS

Apple Patches 28 Security Flaws in macOS, iOS, and iPadOS

Apple has put out security updates for macOS, iOS, and iPadOS. These updates fix 28 …