INTEL_REPORT
Mandiant / Google Threat Intelligence Blog · published 6/24/2026, 11:00:00 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability ( CVE-2026-20245 ) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account …
https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager
sha256:35e595a87337864d03efb8f7a2473223a31a37eb5856273e8c2567560813807d
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| 153.186.231.233 |
| Open → |
| ip | 167.179.79.189 | Open → |
| ip | 207.190.37.94 | Open → |
| ip | 209.137.225.101 | Open → |
| ip | 23.245.7.178 | Open → |
| ip | 45.32.38.160 | Open → |
| ip | 76.92.245.217 | Open → |
| ip | 20.15.4.5 | Open → |
| ip | 20.15.5.3 | Open → |
| ip | 20.18.3.1 | Open → |
| domain | scripts.log | Open → |