Cisco SD-WAN Root Access and European Ransomware Surges [Prime Cyber Insights]
In the briefing room today, we're looking at a tactical shift toward edge device exploitation and a significant spike in European ransomware volume. This is Prime Cyber Insights for June 25th, 2026. <br/><i>acting_description:</i> professional, steady, authoritative <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 We're starting with a deep dive into the Cisco Catalyst SD-WAN zero-day, which Mandiant researchers now confirm was exploited months before public disclosure. <br/><i>acting_description:</i> engaged, clear, technical <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.2 The vulnerability is CVE 2026 20245, a high-severity command injection flaw. While Cisco initially disclosed it earlier this month, Mandiant reports that an unknown threat actor was exploiting it as early as March 2026. They gained root access to a communications service provider by chaining this with rogue peering connections. <br/><i>acting_description:</i> precise, analytical, direct <i>speed:</i> 0.98 <i>trailing_silence:</i> 0.4 What stands out here, Aaron, is the anti-forensic discipline. The attackers weren't just exploiting the flaw

