<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Network-Infrastructure on CuraSec</title><link>https://curasec.metacog.co.kr/tags/network-infrastructure/</link><description>Recent content in Network-Infrastructure on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 31 Aug 2026 18:00:29 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/network-infrastructure/index.xml" rel="self" type="application/rss+xml"/><item><title>Chinese Fire Ant APT backdoors Cisco IOS XR routers via hidden GRE tunnels</title><link>https://curasec.metacog.co.kr/insights/2026-08-31-chinese-fire-ant-hackers-turn-cisco-routers-into-spying-plat/</link><pubDate>Mon, 31 Aug 2026 18:00:29 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-31-chinese-fire-ant-hackers-turn-cisco-routers-into-spying-plat/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Fire Ant is actively implanting GRE tunnel interfaces on Cisco IOS XR routers that persist invisibly outside running configuration and commit history — audit all IOS XR devices for unexplained GRE interfaces and cross-check interface state against configuration databases.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active Chinese APT campaign against network edge devices warrants an assume-breach sweep; hunt for GRE tunnel interfaces on IOS XR routers that lack corresponding config entries, and look for anomalous GRE-encapsulated flows in NetFlow or firewall logs.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A Chinese state-sponsored actor is using Cisco IOS XR routers as persistent espionage platforms — confirm whether IOS XR is in your environment, task the network team with an audit, and flag this to leadership given the espionage implications for sensitive traffic traversing core routing infrastructure.&lt;/li>
&lt;/ul></description></item><item><title>Arista patches VeloCloud Orchestrator zero-day exploited in attacks</title><link>https://curasec.metacog.co.kr/insights/2026-07-28-arista-patches-velocloud-orchestrator-zero-day-exploited-in/</link><pubDate>Tue, 28 Jul 2026 13:01:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-28-arista-patches-velocloud-orchestrator-zero-day-exploited-in/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Maximum-severity command injection in VeloCloud Orchestrator is actively exploited — if you run on-premises VeloCloud Orchestrator, patch immediately and audit for signs of compromise.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation of a max-severity edge orchestrator means assume-breach posture for any environment running on-prem VeloCloud Orchestrator — hunt for anomalous command execution or lateral movement from those hosts since before the patch date.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> A maximum-severity zero-day actively exploited in SD-WAN infrastructure warrants immediate confirmation of whether VeloCloud Orchestrator is in use on-premises, and if so, direct the team to patch and assess exposure before this surfaces as a board-level incident.&lt;/li>
&lt;/ul></description></item><item><title>CERT discloses six serious CVEs in dnsmasq</title><link>https://curasec.metacog.co.kr/insights/2026-07-14-cert-is-releasing-six-cves-for-serious-security-vulnerabilit/</link><pubDate>Tue, 14 Jul 2026 12:08:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-14-cert-is-releasing-six-cves-for-serious-security-vulnerabilit/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Dnsmasq is embedded in Kubernetes nodes, containers, and network appliances at scale; six CERT-issued serious CVEs warrant auditing all deployments and scheduling patches as soon as vendor-specific builds are available — no exploitation signals yet, but the network-accessible attack surface (DNS/DHCP) is historically high-value.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Noteworthy as a potential systemic risk given dnsmasq&amp;rsquo;s ubiquity in Linux and embedded network gear, but without confirmed exploitation or a Log4Shell-scale event there is no leadership action required today — confirm teams are tracking patches.&lt;/li>
&lt;/ul></description></item></channel></rss>