Cisco FMC zero-day requires hunting and secret rotation, not patching…OWAReaper persistence survives credential rotation and endpoint…OpenAI evaluation incident expanded to four external service accountsAnalog Devices confirms files were exfiltrated in June intrusion
Security.io Daily — Thursday, 30 July 2026 — 06:00 America / · Executive decision brief
Cisco FMC zero-day requires hunting and secret rotation, not patching alone
Cisco confirmed active exploitation of a static credential in on-premises Secure Firewall Management Center and published a log artefact that should determine whether teams patch normally or invoke incident response.
Security.io Intelligence Desk · Thursday, 30 July 2026
Executive consequence
Organisations operating Cisco Secure Firewall Management Center must identify affected appliances immediately, run Cisco’s exploitation check before modifying evidence, deploy the correct hot fix and rotate credentials, keys and certificates when compromise is suspected.
Decision today
Inventory every on-premises Cisco Secure FMC appliance and record its release.
Read the full decision briefPrimary reporting: Cisco Security Advisory · CISA Known Exploited Vulnerability Alert · SecurityWeek · BleepingComputer
Decision intelligence, not a headline feed.Every edition ranks what security leaders should read first, assign today and monitor next.
Six-minute executive briefing
Security.io Daily Headlines
Five equally weighted stories: what happened and the leadership decision each creates.
Operators of on-premises Exchange with Outlook Web Access should apply Microsoft’s CVE-2026-42897 protection and hunt for OWAReaper’s server-side permissions, browser storage, OAuth tokens, domains and payload hash. Password changes and endpoint rebuilding alone do not evict the implant.
Do today
Apply Microsoft protection for CVE-2026-42897 across on-premises Exchange.
Customers and partners should seek scoped assurance rather than assume operational compromise. Analog Devices says operations continued, but the contents of the stolen files, affected parties and relationship to supplier or customer data remain under investigation.
Do today
Identify sensitive data shared with Analog Devices.
Security.io scores each dimension from 0–100 using management-plane privilege, confirmed exploitation, remediation window, detection evidence and potential control-plane impact. These are editorial risk scores, not vendor metrics. Source: Security.io assessment based on Cisco’s advisory and CISA KEV action.
Appointments, dinners & sponsored intelligence
Current paid placements · clearly separated
Registration open
Sponsor's Notice · Information Security Network
Security.io Executive Roundtable: The 2027 CISO Agenda