SMART Group Systems Intl.

IT News

... focused on Cisco security news to keep you informed. Please feel free to contact us if you are missing some important information.

Newsletter December 2021

CISCO Services Price Changes

Cisco periodically reviews the pricing on our complete line of services. As a result, some service prices are being adjusted. The new price changes has been released on December 11, 2021 with more then 500 price changes. If you need more information please contact your SMART Group Systems Intl. Sales representative.

Verizon Business & Cisco with managed service offerings

Verizon, Cisco bolster business agility with new managed services  – December 1, 2021

NEW YORK, N.Y. – Verizon Business is enhancing its Network as a Service (NaaS) digitization strategy with the addition of Cisco managed SD-WAN services, including options for 4G/5G connectivity. Automation, artificial intelligence, 5G and Real Time Enterprise (RTE)1 present new requirements and complexities, which test the limits of legacy information technology (IT) infrastructures. With these new solutions, enterprises can leverage Verizon’s 4G and 5G networks, as well as the network as a service strategy, giving them the ability to scale, adopt the latest technology and remain agile to meet ever-changing customer demands.

“Organizations are challenged with finding flexible and secure networking solutions that enable the rapid transition to hybrid cloud and hybrid work while maximizing application performance for their users,” said Massimo Peselli, senior vice president, Global Enterprise, Verizon Business. “The addition of these Cisco solutions builds on our longstanding history of co-innovation and provides customers with the agility and scalability to meet today’s needs while future-proofing their operations.”

Besides enabling hybrid connectivity, Verizon’s NaaS with Cisco SD-WAN solutions helps simplify operations, employ an asset light model, optimize resources, allow network and security convergence, improve user experience from application-aware routing, and increase business agility.

The new solutions include:

Managed Cisco SD-WAN for the Cisco Catalyst 8000 Edge Platforms Family, and Integrated Services Router (ISR) 1000 and 4000 series, including management of the Cisco cellular Pluggable Interface Modules (PIM), and Cisco Catalyst Cellular Gateways. This new offer supports 4G and 5G cellular for gigabit connectivity to distributed cloud workloads. For a limited time, Verizon will provide customers one free Cisco Catalyst Cellular Gateway with each new Cisco SD-WAN 3-year device license purchase.
Verizon is delivering a Cisco SD-WAN performance suite including Cisco Umbrella for cloud security, Duo for zero trust application access, and ThousandEyes for network observability. This suite delivers the protection and visibility to enhance SD-WAN security and performance while reducing customer costs.
Cloud collaboration services with carrier-grade quality, reliability and security via Verizon’s fully private connection to Cisco Webex Calling and Webex Contact Center. Customers can capitalize on this private integration through wireline and wireless networks with Verizon Private IP and Verizon Wireless Private Network Traffic Management.
“In a hybrid work world, application performance and security are critical. We are committed to making it simpler for IT teams to deliver the best customer experiences," said Todd Nightingale, EVP and GM, Enterprise Networking and Cloud, Cisco. “Verizon’s new Cisco managed SD-WAN offer delivers cloud security and 5G capabilities, reduces complexity for customers, and enables private network connections to Cisco’s Webex service cloud."

Datagroup Takes Internet Speeds to New Heights Across Ukraine with Cisco Routed Optical Networking

KIEV, Ukraine, December 1, 2021 – Datagroup, a leading Ukrainian telecom operator for business and home users, launched a large-scale national project to modernize its backbone network with Cisco. The new Datagroup network is based on Cisco Routed Optical Networking and Converged SDN Transport solutions, which help service providers build high-speed networks with greater security and reliability.

The pandemic significantly increased the importance of fast and reliable internet connections for consumers and businesses across Ukraine. As a result, Datagroup’s network traffic increased by 35%. In 2021, traffic growth continued, increasing an additional 30% over a nine-month period. Datagroup decided to scale up its backbone network to promptly address the changing external environment, increasing throughput and bringing quality of services to new heights.

Cisco Converged SDN Transport architecture, based on the Cisco NCS series of routers, will serve as the foundation for Datagroup’s updated backbone network. This architecture will help Datagroup deploy one of the most flexible, automated, and efficient networks in the Ukrainian telecom market. Combining services into a single automated infrastructure optimizes network performance by increasing the resiliency and scalability of the network and simplifying the commissioning of new services.

Cisco’s Routed Optical Networking solution, designed to combine DWDM and IP networks for improved operational efficiencies and simplicity, will also support Datagroup’s new network architecture. This converged infrastructure simplifies network design, planning and management, with the ability to save up to 45 percent in total cost of ownership (TCO). Cisco Routed Optical Networking integrates open data models and standard APIs, enabling Datagroup to focus on automation initiatives for a simpler topology.

“As part of the first stage to modernize our network, we have a fully operational central hub in Kiev built on Cisco equipment which has already increased the resiliency of our network and significantly improved the level of service for our corporate customers,” said Mikhail Shelemba, CEO of Datagroup. “For home subscribers, access to more capacious Internet channels and faster speeds is gradually becoming easier. We expect the completion of the first stage of modernization by the end of the year.”

Top-5 reasons for CISCO SMARTnet

Why CISCO SMARTnet ?

We take great pride in the clients we serve and will do everything we can to exceed your expectations.

1. You have access to Software update(s)

The top incentive to enroll in CISCO SMARTnet is because it allows you to update operating systems software.
While occasionally these upgrades include new features, the most important reason to keep up on upgrades is to perform ongoing maintenance, fix any bugs, and patch any vulnerabilities.

2. You can choose your level of support for hardware & software

Cisco knows businesses have different needs, which is why they offer products to meet a variety of needs.
CISCO SMARTnet is no different, and they offer several different models for customers to choose from. We find customers are typically interested kind of service level.

3. You receive support for software 24 hours a day, 7 days a week

If you call with an after-hours request, you’re likely talking to someone from the other side of the country or another county. Since Cisco is a global organization, they’re capable of empowering their business this way, though.
Having this support is important because it is what entitles you to updates.

4. You get access to Cisco Online ressources

Anytime access to Cisco.com and tools like TECHNICAL ASSISTENT CENTER (TAC), ONLINE KNOWLEDGE BASE or FORUMs.

5. Why Smart Group Systems Intl. & SMARTnet ?

We are authorized and certified CISCO partner with fast response times, highly qualified employees, own tools for support & contract management and much more.

Newsletter August 2021

CISCO Services Price Changes

Cisco periodically reviews the pricing on our complete line of services. As a result, some service prices are being adjusted. The new price changes has been released on August 2021 with more then 500 price changes. If you need more information please contact your SMART Group Systems Intl. Sales representative.

Cisco Completes Acquisition of Socio Labs

San Jose, Calif. – July 8, 2021
Cisco today announced the completion of the acquisition of privately-held, U.S.-based Socio Labs, Inc. Socio is a modern event technology platform that manages the full lifecycle of multi-session, multi-track virtual, in-person and hybrid conferences – from registration to post-event analytics.

By adding Socio Labs to its Webex portfolio, Cisco will provide event organizers a single platform with everything they need to successfully host nearly any type of event imaginable. Benefits include the ability to create: 

  • Equally inclusive experiences for both in-person and virtual attendees during events of any type, size and format
  • Highly customizable branded registration and ticketing experiences, dynamic ads, customized profiles and sponsor booths including gamification and lead generation components
  • Actionable data about event attendees, sponsors, exhibitors and more, offering deeper insight into attendee interests
  • Always-on, continuous engagement with attendees across multiple events, leveraging data about their virtual and in-person event behaviors and preferences to build personalized journeys

“Being able to offer novel, refreshing and inclusive experiences for all attendees – whether in person or virtual – is paramount in today’s new era of hybrid events,” said Jeetu Patel, executive vice president and general manager, Cisco Security and Collaboration. “The acquisition of Socio Labs is another example of how Cisco is rapidly addressing the evolving needs of our Webex customers and continuing to execute on our vision of providing the most seamless, inclusive, engaging and intelligent platform for meetings and events.”

“Cisco shares in our commitment to creating technology that drives authentic connections and personalized experiences, which is one of the many reasons why joining forces with Cisco is great for our team and our customers,” said Yarkin Sakucoglu, Socio Labs co-founder and CEO. “Together, we will be able to accelerate this mission and continue building the best event technology platform for the hybrid future of events.”

The Socio Labs team joins Cisco’s Collaboration Group.

Cisco Completes Acquisition of Kenna Security

San Jose, Calif. – June 30, 2021
Cisco today announced the completion of the acquisition of Kenna Security, Inc. With the addition of Kenna Security’s industry-leading risk-based vulnerability management platform, Cisco customers will solve critical security posture challenges by working cross-functionally to rapidly automate prediction, identification, prioritization and remediation of cybersecurity threats.

Adding Kenna’s vulnerability management platform to Cisco’s SecureX platform’s market leading detection and response capabilities (XDR) will give customers the ability to discover and prioritize an organization’s assets with a centralized, contextual view. This will speed decision making, accelerate and simplify response with orchestration and reduce friction associated with compliance efforts. Kenna’s technology integrates with all major industry vulnerability assessment platforms.

“Cisco is helping customers and partners reimagine a future of work that is hybrid. As they work from anywhere, continue their transition to the cloud and manage the rapidly evolving threat landscape, we are focused on radically simplifying security. By taking a risk-based approach to vulnerability management, we are able to speed and automate threat detection and response, allowing users to quickly address the most pressing issues first,” said Jeetu Patel, executive vice president and general manager, Cisco Security and Collaboration. “Combined with SecureX, Kenna Security will weave threat management and risk-based vulnerability management together to further extend our lead in providing the broadest XDR capabilities in the industry – truly transforming how teams effectively manage the overall risk for an organization."

“Every security team wants to work more efficiently, and every leader needs the data to support critical decisions about risk. Kenna Security's sophisticated, data-driven platform combined with Cisco's breadth and scale will help our customers continue to do both,” said Karim Toubba, Kenna Security CEO. “Together we will reshape the way the industry at large addresses risk by applying proven data science and machine learning at scale."

Top-5 reasons for CISCO SMARTnet

Why CISCO SMARTnet ?

We take great pride in the clients we serve and will do everything we can to exceed your expectations.

1. You have access to Software update(s)

The top incentive to enroll in CISCO SMARTnet is because it allows you to update operating systems software.
While occasionally these upgrades include new features, the most important reason to keep up on upgrades is to perform ongoing maintenance, fix any bugs, and patch any vulnerabilities.

2. You can choose your level of support for hardware & software

Cisco knows businesses have different needs, which is why they offer products to meet a variety of needs.
CISCO SMARTnet is no different, and they offer several different models for customers to choose from. We find customers are typically interested kind of service level.

3. You receive support for software 24 hours a day, 7 days a week

If you call with an after-hours request, you’re likely talking to someone from the other side of the country or another county. Since Cisco is a global organization, they’re capable of empowering their business this way, though.
Having this support is important because it is what entitles you to updates.

4. You get access to Cisco Online ressources

Anytime access to Cisco.com and tools like TECHNICAL ASSISTENT CENTER (TAC), ONLINE KNOWLEDGE BASE or FORUMs.

5. Why Smart Group Systems Intl. & SMARTnet ?

We are authorized and certified CISCO partner with fast response times, highly qualified employees, own tools for support & contract management and much more.

Newsletter July 2021

CISCO ASA under active attack

 

Cisco Adaptive Security Appliance (ASA) was found to be vulnerable after researchers from Positive Technologies shared a proof-of-concept (PoC) exploit for (CVE-2020-3580) on Twitter coming from known cross-site scripting (XSS) vulnerability surface in-the-wild attacks primarily targeting its security appliance.

Mikhail Klyuchnikov, one of the security researchers at Positive Technologies, highlighted that many researchers are found to be after an exploit for the bug, dubbed as “low-hanging” fruit. For the flaws in the flaws, which he referred to as the “low-hanging” fruit.

At the same time, Tenable researchers also alerted PoC, stating that it has begun to see cyber attacks that exploit this vulnerability to attack targets in the wild.

“Tenable has also received a report that attackers are exploiting CVE-2020-3580 in the wild,” according to its Thursday alert. “With this new information, Tenable recommends that organizations prioritize patching CVE-2020-3580.”

Positive Technologies PoC's tweets received many “Oh, thank you" and “Thank you so much" replies, probably from potential hackers.

“Researchers often develop PoCs before reporting a vulnerability to a developer, and publishing them allows other researchers to both check their work and potentially dig further and discover other issues,” Claire Tills, senior research engineer at Tenable, told Threatpost. “Defenders can also use PoC's to develop detections for vulnerabilities. Unfortunately, giving that valuable information to defenders means it can also end up in the hands of attackers.”

He pointed out that because the patch for this vulnerability has been released for several months, organizations can protect themselves, which is not the case with zero-day disclosure. " “However, unpatched vulnerabilities continue to haunt many organizations,” Tillis added. “The public availability of a PoC is another stark reminder that effective patching is a vital step for organizations to protect themselves.”

Cisco ASA is a network security perimeter defense device that combines firewall, antivirus, intrusion prevention, and virtual private network (VPN) functions, all of which are designed to prevent threats from reaching the corporate network. The compromise of this device is similar to opening the door of a castle to attack a cyber attacker. XSS attacks occur when malicious scripts are injected into other benign and trustworthy websites; any visitor to the infected website will be attacked from inside.

Successful exploitation, in this case, means that unauthenticated, remote attackers could “execute arbitrary code within the [ASA] interface and access sensitive, browser-based information,” Tenable added.

According to Leo Pate, nVisium's application security consultant, once in, they can adjust the device's settings. However, the target must be connected to the ASA for the attacker to see any fun..Although “While this sounds dangerous, exploiting this vulnerability requires an administrative user to login and navigate to the webpage where the attacker uploaded the malicious code,” he added.

As Tenable researchers said: “An attacker would need to convince a user of the interface’ to click on a specially crafted link.” This can be accomplished via a spear-phishing email campaign targeting probable ASA users using malicious links or via watering-hole attacks.

“The attack vector to get this in the hands of the right people is complex, requiring a firewall administrator to be duped into clicking a cleverly crafted link,” Andrew Barratt, managing principal for solutions and investigations at Coalfire, told Threatpost. “Firewall administrators will need to ensure they’re not accessing links to the ASA interface that appear to originate from outside.”

When asked by Threatpost, Tenable declined to provide more information about real-world attacks. Due to its large footprint (even within the Fortune 500), Cisco ASA is no stranger to the attention of cyber-attackers. For example, last year, a public PoC for another device vulnerability (CVE-2020-3452) began to circulate, leading to many exploits.

The vulnerability tracked as CVE-2020-3580 was fixed on October 21 as part of a set of XSS issues with Cisco ASA and Firepower Threat Defense (FTD) software, which is a unified firewall image that includes management of HANDLE.

“All four vulnerabilities exist because Cisco ASA and FTD software web services do not sufficiently validate user-supplied inputs,” the guide notes that this error is 6.1 out of 10 on the CVSSv3 severity rating.

The number of vulnerable systems can be exceptionally substantive. Rapid7 analysts tracked down that 85,000 ASA gadgets were accessible on the Internet last year. The more significant part of these weaknesses is configurable.

“Exploits for appliances that may sit on the vanishing perimeter generally garner interest [from hackers], but fortunately, in this case, at least two things are working against rampant exploitation,” Tim Wade, technical director for the CTO team at Vectra, told Threatpost. “First, a patch has been available since October. Second, an element of social engineering is required. This should provide some level of confidence for organizations with reasonable patch cycles and a security awareness program.”

Of course, we recommend that you update your software to the latest version on this device.

CISCO Smart Switches with severe Security Holes

Cisco has flagged and patched several high-severity security vulnerabilities in its Cisco Small Business 220 Series Smart Switches that could allow session hijacking, arbitrary code execution, cross-site scripting and HTML injection.

It also issued fixes for high-severity problems in the AnyConnect secure mobility client, the Cisco DNA Center and the Cisco Email Security Appliance, along with a slew of patches for medium-severity vulnerabilities in AnyConnect, Jabber, Meeting Server, Unified Intelligence Center and Webex.

The high-severity issues are as follows:

  • CVE-2021-1566: Cisco Email Security Appliance and Cisco Web Security Appliance (Certificate-Validation Vulnerability)
  • CVE-2021-1134: Cisco DNA Center (Certificate Validation Vulnerability)
  • CVE-2021-1541 through 1543
  • CVE-2021-1571: Cisco Small Business 220 Series Smart Switches (Session Hijacking, Arbitrary Code-Execution, Cross-Site Scripting, HTML Injection)
  • CVE-2021-1567: Cisco AnyConnect Secure Mobility Client for Windows with VPN Posture (HostScan) Module (DLL Hijacking)

The most severe issue in this crop of patches is tracked as CVE-2021-1542, in the Cisco Small Business 220 Series Smart Switches. These are entry-level switches that act as the basic building blocks for small- and medium-sized business networks. They’re responsible for sharing network resources and connecting various clients, including computers, printers and servers, to the network and each other, along with security, governing network performance and more.

The bug rates 7.5 on the 10-point CVSS vulnerability-severity scale, and arises from weak session management for the web-based management interface of the switches. An unauthenticated, remote attacker could use it to bypass authentication protections and gain unauthorized access to the interface, according to the advisory. The attacker could then obtain the privileges of the highjacked session account, which could include administrative privileges, and thus gain free rein on the switch.

“This vulnerability is due to the use of weak session management for session identifier values,” according to Cisco. “An attacker could exploit this vulnerability by using reconnaissance methods to determine how to craft a valid session identifier. A successful exploit could allow the attacker [to] take actions within the management interface with privileges up to the level of the administrative user.”

There are also multiple other security flaws in the same web-management interface. For instance, the bug tracked as CVE-2021-1541 is an arbitrary code-execution vulnerability that would allow an authenticated, remote attacker to execute arbitrary commands as a root user on the underlying operating system.

CISCO wons $1.2B contract with DISA

The Defense Information Systems Agency has awarded Cisco a $1.2 billion indefinite-delivery/indefinite-quantity contract for software services, the Department of Defense announced Monday.

The software Cisco will be providing is “Cisco Smart Net Total Care and Software Support Services,” according to a public release about the contract. The performance period will start with a one-year base but could be extended up to three years if all goes well.

The DOD’s request received three proposals, the department said.

Cisco’s Smart Net software is designed to help resolve IT issues and keep enterprise software for large organizations up to date, according to its website. It’s tech that “that keeps your IT running smoothly,” a promotional video claims.

DISA has been consolidating the networks of combat support agencies and taking on the responsibility to run their help desks. It’s unclear if this contract is directly related to that initiative.

Top-5 reasons for CISCO SMARTnet

Why CISCO SMARTnet ?

We take great pride in the clients we serve and will do everything we can to exceed your expectations.

1. You have access to Software update(s)

The top incentive to enroll in CISCO SMARTnet is because it allows you to update operating systems software.
While occasionally these upgrades include new features, the most important reason to keep up on upgrades is to perform ongoing maintenance, fix any bugs, and patch any vulnerabilities.

2. You can choose your level of support for hardware & software

Cisco knows businesses have different needs, which is why they offer products to meet a variety of needs.
CISCO SMARTnet is no different, and they offer several different models for customers to choose from. We find customers are typically interested kind of service level.

3. You receive support for software 24 hours a day, 7 days a week

If you call with an after-hours request, you’re likely talking to someone from the other side of the country or another county. Since Cisco is a global organization, they’re capable of empowering their business this way, though.
Having this support is important because it is what entitles you to updates.

4. You get access to Cisco Online ressources

Anytime access to Cisco.com and tools like TECHNICAL ASSISTENT CENTER (TAC), ONLINE KNOWLEDGE BASE or FORUMs.

5. Why Smart Group Systems Intl. & SMARTnet ?

We are authorized and certified CISCO partner with fast response times, highly qualified employees, own tools for support & contract management and much more.