Microsoft and Cisco reveal sophisticated multi‑actor and zero‑day cyber threats
Microsoft's security research team reported that a single network breach was actually being exploited by two distinct cybercriminal groups at the same time. The groups operated independently within the compromised environment, pursued different objectives, and demonstrated how modern attackers can converge on the same target, complicating detection and response.
Separately, Mandiant disclosed a zero‑day vulnerability (CVE‑2026‑20245) in Cisco Catalyst SD‑WAN Manager that allowed an attacker to upload a malicious CSV file, create a rogue root‑level account named “troot”, and gain full control over a service provider’s network infrastructure. The intrusion spanned several months, involved credential theft, anti‑forensic techniques, and highlighted the growing focus of threat actors on enterprise network‑management platforms.