<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cisco on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/cisco/</link><description>Recent content in Cisco on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 04 Jun 2026 16:55:51 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/cisco/index.xml" rel="self" type="application/rss+xml"/><item><title>Cisco Unified CM CVE-2026-20230: SSRF to Root PoC</title><link>https://zxcloudsecurity.co.uk/posts/cisco-unified-cm-ssrf-privilege-escalation-cve-2026-20230/</link><pubDate>Thu, 04 Jun 2026 16:55:51 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cisco-unified-cm-ssrf-privilege-escalation-cve-2026-20230/</guid><description>Cisco patches CVE-2026-20230 in Unified CM — an SSRF flaw allowing unauthenticated attackers to write files and escalate to root. Public PoC now available.</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/cisco-patches-cve-2026-20230-in-unified.html">The Hacker News</a></p>
<hr>
<p>Cisco has patched a server-side request forgery (SSRF) vulnerability in Unified Communications Manager (Unified CM) that allows an unauthenticated network attacker to write arbitrary files to the system and escalate privileges to root. The flaw is tracked as CVE-2026-20230 and public proof-of-concept exploit code is already available, significantly lowering the barrier to exploitation. Cisco&rsquo;s PSIRT has not confirmed active exploitation in the wild, but the availability of working PoC code makes patching urgent.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Apply Cisco&rsquo;s patch immediately and treat any internet- or untrusted-network-exposed Unified CM instances as highest priority. As an interim control, restrict network access to Unified CM admin interfaces to trusted management VLANs only, and review ingress firewall rules to limit the blast radius while patching is under way.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/cisco-patches-cve-2026-20230-in-unified.html">Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public</a></p>
]]></content:encoded></item><item><title>Cisco Mythos AI Bug Hunting: What We Know So Far</title><link>https://zxcloudsecurity.co.uk/posts/cisco-mythos-ai-vulnerability-discovery-anthropic-project-glasswing/</link><pubDate>Tue, 02 Jun 2026 18:35:24 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cisco-mythos-ai-vulnerability-discovery-anthropic-project-glasswing/</guid><description>Cisco praises its Mythos AI model for finding vulnerabilities but won&amp;#39;t reveal the count. Here&amp;#39;s what cloud security teams should consider.</description><content:encoded><![CDATA[<p>🟢 <strong>Low</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/ai-and-ml/2026/06/02/cisco-praises-ai-bug-hunt-wont-reveal-flaw-tally/5250291">The Register — Security</a></p>
<hr>
<p>Cisco has publicly praised its AI model &lsquo;Mythos&rsquo; for its performance in automated vulnerability discovery but has declined to disclose the number of bugs it actually found. Separately, Anthropic has expanded its Project Glasswing initiative by adding 150 new partners, signalling growing industry investment in AI-driven security tooling. The opacity around Mythos&rsquo; results raises questions about transparency and how organisations should evaluate AI security claims.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Treat vendor claims about AI-driven vulnerability discovery with scepticism until independently verifiable metrics are published — when evaluating AI security tooling, demand concrete, auditable outputs such as CVE counts, false-positive rates, and coverage scope before committing to any platform.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/ai-and-ml/2026/06/02/cisco-praises-ai-bug-hunt-wont-reveal-flaw-tally/5250291">Cisco sings Mythos&rsquo; praises - but doesn&rsquo;t say how many bugs the model uncovered</a></p>
]]></content:encoded></item></channel></rss>