Cybercriminals increasingly exploit admin software for network infrastructure

A new report from Eclypsium's InfraTrust Pulse highlights a surge in attacks targeting management platforms for enterprise network devices, with several critical flaws exploited before patches were available. Between late August and mid-September, the report tracked 158 advisories covering 1,699 vulnerabilities, including 42 critical ones and 71 remotely exploitable without authentication. Notably, the most dangerous exploited flaws were in administrative software, prompting a warning to treat these systems as high-value targets for patching and monitoring.
The report's findings underscore a shift in attacker strategy, with management platforms becoming preferred entry points because compromising them grants broad control over entire device fleets. The Cisco FMC attacks involved multiple threat clusters, including state-sponsored groups and ransomware operators, who chained two separate vulnerabilities together. Attackers used built-in tools for reconnaissance, deployed tunneling utilities, and harvested credentials before deploying Qilin ransomware. A recovered Linux implant, identified as a Cyclops Blink variant linked to the Sandworm group, further illustrates the sophistication of these campaigns. Cisco's separate disclosure of six additional FMC flaws and three maximum-severity ISE vulnerabilities, one already exploited, reinforces the pattern of management software as a primary attack surface.
This trend could significantly raise operational risks for enterprises, as compromised management platforms give attackers privileged access to core network infrastructure, potentially enabling widespread data theft or ransomware deployment. Organizations relying on these systems may face difficult patching decisions, especially when vendors disclose flaws only after exploitation begins. Smaller firms with limited security teams could be disproportionately affected, as hardening management interfaces requires specialized expertise. The involvement of state-sponsored actors suggests these attacks may also serve espionage purposes, potentially affecting critical infrastructure sectors and supply chains.