Elttam says two packets and an offline crack of weak encryption let attackers run code on TACACS+ servers before login. Only the Shrubbery Networks build has a patch, leaving sites on the archived Facebook fork to migrate or limit who can reach port 49.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence45
Elttam says a TACACS+ server flaw lets attackers run code before login with two packets and an offline crack of the protocol's weak encryption. Of the two main server codebases, Shrubbery Networks' has a fix that still has no CVE and Facebook's archived fork will get none, so the first job is finding out which daemon answers on port 49.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives35
- Confidence40
Sygnia found the China-nexus group running packet captures, a tac_plus credential hook and two layers of log suppression on the gear that authenticates the rest of the estate, and it never established how the router was breached.
Perspective Coverage
6 publishers
- Builder
- Builder 33%
- Operator
- Operator 53%
- Investor
- Investor 14%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence64
Sens. Mark Warner and Ted Cruz filed a bill giving NTIA 18 months to write voluntary telecom security practices, with an optional third-party certification. Adopting them stays each carrier's choice, nearly a year after the mandatory post-breach rules were scrapped.
Perspective Coverage
3 publishers
- Builder
- Builder 18%
- Operator
- Operator 57%
- Investor
- Investor 25%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap0
- Incentives30
- Confidence68
Salt Typhoon used legitimate stolen credentials to reach Cisco devices in every telecom intrusion Cisco Talos investigated but one. It then pulled more logins from weakly encrypted router configs and captured TACACS and RADIUS keys, so credentials stored on network gear are the first exposure for defenders to close.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap−5
- Incentives55
- Confidence60
ESET traced more than a year of espionage against government organizations in eight Latin American countries and territories to a modular C++ implant that hooks CreateThread so every thread it spawns looks like AnimateWindow.
Perspective Coverage
5 publishers
- Builder
- Builder 22%
- Operator
- Operator 68%
- Investor
- Investor 10%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence68
Asus is the biggest name so far through the Conditional Approval process that the Defense and Homeland Security departments run. Applicants hand over a component-level supply chain report and a time-bound plan to build the router in the US.
Reality
- Evidence60
- Adoption68
- Hype gap+28
- Incentives58
- Confidence55
Intel 471's 18-month sweep of the underground counted 340 financial-sector extortion victims across 74 countries, 159 firms with access for sale and 562 claimed DDoS attacks. The dated intrusions came in through vendors and help-desk calls.
Reality
- Evidence40
- Adoption55
- Hype gap+22
- Incentives78
- Confidence47
Two of the seven flaws score 9.8, but the operational weight sits in the remediation path, which asks operators to upgrade a device first and then apply as many as 16 targeted patches. No clean fixed release exists yet.
Reality
- Evidence62
- Adoption20
- Hype gap−12
- Incentives55
- Confidence55
CVE-2026-20349 lets an unauthenticated attacker crash any ASA or FTD running Remote Access SSL VPN. There is no workaround, exploitation is confirmed, and attribution is a blank page.
Publishers:eclypsium.com
Reality
- Evidence61
- Adoption58
- Hype gap+9
- Incentives62
- Confidence63