Cisco has unveiled new initiative Resilient Infrastructure in response to recent security glitches affecting its services.
According to chief security and trust officer Anthony Grieco, the venture aims to make it “incredibly obvious when our customers are configuring insecure features that introduce new and unnecessary risks into their networks” with increased security warnings on insecure features that should be discontinued.
Future versions of Resilient Infrastructure will see features disabled by default or requiring additional steps for configuration, before eventually being removed entirely.
The networking giant will also disable services, including web servers, SNMP, and guest shell by default, to reduce users’ attack surface.
Resilient Infrastructure also updates default logging settings with new messages to capture critical configuration changes and other significant security events.
Visibility has also been expanded to provide greater insight into guest shell environments and low-level operating system events, while secure time synchronization has been improved through enhancements to Network Time Protocol (NTP), ensuring accurate timestamps for more effective incident logging.
The new features specifically tackle authentication protocols such as TACACS+ and RADIUS. The former has been leveraged in an exploit on Cisco’s Simple Network Management Protocol (SNMP) on retired networking devices. This attack, linked to the Russian Federal Security Service's (FSB) Center 16, was serious enough to see the FBI release an emergency briefing in August.
More recently, attackers have struck Cisco switch kits, allowing for remote code execution and persistent unauthorized access.
The exploit came after Cisco was pressed by the U.S. government over a separate exploit in its firewall offerings that may have allowed for a nation-state-backed breach.
The attacks, which take advantage of a remote code execution vulnerability (CVE-2025-20333) and a privilege escalation flaw (CVE-2025-20362), have been linked to the China-affiliated ArcaneDoor campaign, which Cisco reported on early last year.
Comments