daily cyber × ai intelligence

index

tagged

[fire-ant]

2 editions · 2 items

September 2, 2026

  • Fire Ant (China-nexus) has expanded beyond VMware hypervisors to Cisco IOS XR routers, TACACS servers, and Linux management hosts — compromising the authentication and routing layer rather than the endpoints on top of it, and blinding security logging in the process (The Record, The Hacker News). Sygnia's framing: "it compromised the trust layer those systems depend on" (earlier coverage). · Threat Activity

in OpenAI Says Astra Crossed the Line: Autonomous Zero-Day Discovery at "Critical" Cyber Risk

September 1, 2026

  • Fire Ant has expanded from VMware hypervisors into routing and authentication infrastructure, compromising Cisco IOS XR routers, TACACS servers and Linux management hosts for credential theft and security-log blinding. Sygnia found the activity after spotting a live GRE tunnel interface that appeared in neither the running config nor the commit history (Sygnia, BleepingComputer). · Threat Activity

in Attackers Are Living in the Management Plane