[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f9NuTkOLoK_7B1F3FRNSyuXZQppId2ryvh0p8FcvyIGk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"8fef53f3-99f5-41c7-b6fc-5f524e768a7e","critical-infrastructure-vulnerabilities-under-active-exploitation","cb985918-aff1-4f62-a4b0-3f7b97a693a3","Critical Infrastructure Vulnerabilities Under Active Exploitation","CISA's addition of Cisco, Chrome, and Arista vulnerabilities to the KEV catalog signals active exploitation by threat actors targeting critical network infrastructure. The situation is particularly concerning because Arista has chosen not to release a patch, leaving organizations dependent on potentially inadequate mitigations. This highlights the critical importance of rapid vulnerability assessment and emergency patching procedures, especially for internet-facing network appliances that attackers commonly target as entry points into corporate networks.","**Immediate actions:**\n- Apply available patches for Cisco SD-WAN Manager and Chrome V8 immediately\n- Implement Arista's recommended mitigations and monitor affected EOS systems closely\n- Scan network infrastructure for these specific vulnerabilities using automated tools\n\n**Long-term improvements:**\n- Establish emergency patching procedures with defined timelines for critical infrastructure\n- Maintain a comprehensive asset inventory including all network appliances and their software versions\n- Implement network segmentation to isolate critical infrastructure from potential compromise\n\n**Monitoring measures:**\n- Enable enhanced logging on all affected systems to detect potential exploitation attempts\n- Set up automated alerts for KEV catalog updates to ensure rapid response to new threats",[12,13,14,15,16],"CIS Control 7 (Continuous Vulnerability Management)","NIST SP 800-40 (Patch Management)","CIS Control 1 (Inventory and Control of Enterprise Assets)","CIS Control 12 (Network Infrastructure Management)","NIST CSF PR.IP-12 (Vulnerability Response Plan)","published","2026-06-10T17:21:50.157246+00:00","2026-06-10T17:21:49.876+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F06\u002Fcisa-adds-cisco-chrome-and-arista-flaws.html","cisa-adds-cisco-chrome-and-arista-flaws-to-kev-catalog-amid-active-exploitation-68b80d","CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":32,"name":33,"slug":34,"description":35,"color":36},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[38],{"id":39,"date":40,"edition":41,"title":42,"audio_url":43},"63831e91-6118-446e-a405-719b1ab22fee","2026-06-11","morning","ThreatNoir Morning Brief — June 11","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-06-11\u002Fthreatnoir-morning-brief-2026-06-11.mp3"]