The UK's National Cyber Security Centre (NCSC) has issued a warning to businesses using Cisco's SD-WAN technology, following the discovery of a critical security flaw that could give hackers administrative control over networks. The vulnerability, identified as CVE-2023-20857, was discovered by researchers and has been confirmed to be actively exploited by hackers.
The US Cybersecurity and Infrastructure Security Agency (CISA) has handed federal authorities a tight deadline to patch the flaw, with a 'perfect-10' score indicating the severity of the issue. The NCSC has echoed this warning, advising businesses to patch their systems as soon as possible to prevent a potential security breach.
SD-WAN technology is widely used by businesses to manage and secure their networks, and the vulnerability poses a significant risk to organisations that fail to address the issue. The NCSC has warned that a successful attack could result in data theft and disruption to business operations.
Experts have highlighted the importance of patching the vulnerability as soon as possible, with some warning that the risk of a successful attack is particularly high for organisations that have not kept their systems up to date. The UK's Information Commissioner's Office (ICO) has also issued guidance on the issue, advising businesses to take immediate action to protect their networks.
In related news, the EU's AI Act has sparked controversy over its impact on businesses, with some arguing that the regulations will stifle innovation. However, experts have highlighted the importance of regulations in protecting consumers and businesses from the risks associated with AI and other emerging technologies.
As the UK government continues to grapple with the implications of the AI Act, businesses are being urged to prioritise cybersecurity and take proactive steps to protect themselves from emerging threats. With the NCSC's warning and the CISA's deadline looming, businesses using Cisco SD-WAN technology must act quickly to prevent a potential security breach.