emails
– SvetaZi/Getty Images

Cisco's trusted security reputation is being used against users as part of an email phishing scheme.

According to email security firm Raven AI, attackers have weaponized Cisco Safe Links, a feature within Cisco Secure Email and Secure Web Gateway that rewrites embedded URLs with a proxy hop.

Actors compromise an inbox inside a Cisco-protected organization or leverage a cloud service like an e-signature platform that routes mail through Cisco. The agent then sends themselves a message containing their payload URL, which is rewritten by Safe Links into a Cisco redirect that tricks users into its legitimacy.

Raven reported recovered Safe Links from earlier phishing attempts are also being recycled, giving attackers an endless supply of seemingly clean Cisco links to compromised sites or newly registered domains not yet identified by threat-intelligence feeds as malicious.

Most secure email and web gateways still prioritize domain reputation; if the host is Cisco, the message is deemed low risk and is allowed through. The redirected traffic is encrypted and carries a valid TLS certificate, meaning deep-packet inspection rarely flags concerns in time.

The vulnerability comes after a bad actor similarly hijacked Cisco’s trusted name as opposed to a weak spot, targeting a Cisco representative through a voice phishing attack to breach a third-party customer relationship management (CRM) system.

Microsoft 365’s similar Direct Send feature has also been the victim of phishing attacks, while Cloudflare’s link-wrapping tools were used to redirect victims to phishing URLs disguised as Microsoft Office 365 pages.

With static reputation scoring enabling such flaws, context-aware security solutions have come to the fore for network protection, underpinning recent deals and solutions involving Zscaler and Fortinet.

Context-awareness, real-time monitoring, and adaptive response are also crucial tenets of zero trust network access (ZTNA).

According to Gartner, ZTNA is seeing strong adoption among large and mid-market organizations and the firm forecasts 10% of large enterprises will have a mature and measurable zero-trust program by 2026.