Remote, unauthenticated callers can skip Cisco Identity Services Engine login with crafted requests, and Cisco has pushed an emergency patch because the bug is already being used. If ISE is the box that grants switch ports, VPN posture, and 802.1X, that is a live hole in the decision plane your cybersecurity program treats as authoritative. The same news cycle made the pattern hard to miss. NightEagle is chaining Active Directory and RDP after the gate. Google is shipping a Pixel modem fix for limited, targeted attacks. CISA published decoy guidance because Zero Trust models still leave observation gaps you can actually instrument.

Unauthenticated Crafted Requests Bypassed Cisco ISE Login

SecurityWeek’s reporting is blunt: remote, unauthenticated attackers can bypass authentication with crafted requests. You don’t need a stolen password, a phished session, or a RADIUS brute-force hit to get through. The request itself is the credential. That’s a bad look for any network access control deployment that still treats a green ISE posture as proof of identity.

Network enforcement gear standing in for Cisco ISE and the access layer it feeds
ISE sits in front of the switches and VPNs your firewall already trusts. An auth bypass there poisons every allow rule downstream.

ISE occupies a privileged spot most teams still inventory as “just NAC.” It talks to switches, wireless controllers, VPN concentrators, and directory services. It often holds certificates, RADIUS secrets, and guest-portal sessions. When the control plane that issues network access can be talked into skipping login, every downstream firewall rule that assumes ISE already checked becomes decorative.

Your SOC probably already has dashboards for failed 802.1X and RADIUS brute-force noise. Keep them. They will not fire on a request that never offers a username. Hunt for successful sessions with no matching authentication event, odd network access device pairings, and posture results that appear without an EAP conversation. If you cannot join those logs today, the gap is operational.

Patch the emergency release on every ISE node, including secondary and monitoring personas, then treat the pre-patch window as a possible compromise. Unauthenticated bypass plus active exploitation is enough to start incident response at the NAC, not at the first noisy endpoint. Export running configuration and live logs before you reboot a node to finish the upgrade. You want the policy sets and identity sources as they were while the bug was live.

GhostContainer and GitHub Tooling Reached AD and RDP

Kaspersky GERT’s NightEagle write-up is the second hop. The group is using the GhostContainer backdoor, hosting tooling on GitHub, and exploiting weaknesses in Active Directory and RDP against Russian companies. You don’t need to be in that victim set to copy the lesson. Once a caller is past the access broker, directory and remote desktop are the shortest path to durable control.

Kaspersky graphic for the NightEagle campaign using GhostContainer and tunneling tools
Kaspersky GERT ties NightEagle to GhostContainer, GitHub-hosted tools, and AD/RDP exploitation after the first foothold.

GitHub-hosted tools are a gift to defenders who actually watch egress. They’re also a reminder that allowlists for developer sites are a command channel with a TLS certificate your proxy already trusts. NightEagle’s mix of public repos plus AD and RDP abuse is a defense in depth failure you can measure: the identity plane stayed wide, and threat detection was still waiting for malware on a workstation.

RDP after a NAC failure is especially ugly. Restricted admin, NLA, and VPN-required stickers do not save you if the switch port or tunnel was granted by a lying ISE node. On the directory side, look for new replication partners, unexpected Kerberos service tickets, and RDP logons from jump hosts that ISE never enrolled. That’s cyber security work you can do this afternoon with logs you already pay for.

Identity-Plane Hardening After an Auth Bypass

Stop treating NAC, directory, and remote access as three tickets. They are one blast radius. Security hardening here is unglamorous and vendor-neutral. You can run it without a new console.

  • Apply the ISE emergency patch on every node, then rotate RADIUS shared secrets, admin passwords, and PxGrid certificates. Assume the previous set left the building.
  • Cut management-plane exposure: ISE admin, AD Web Services, and RDP belong on a dedicated jump network, not on the VLAN your guests hit.
  • Alert on authentications that succeed with no EAP, no MFA, or no matching NAD syslog. That is your threat-protection signal for this class of bug.
  • Plant decoys CISA-style on the same segments ISE can authorize: fake file shares, fake AD computers, and fake RDP listeners that should never see a real user.

Immediate actions are the patch, the secret rotation, and a 72-hour hunt across ISE, domain controllers, and RDP brokers. Ongoing work is tighter enrollment: disable unused policy sets, require certificate-based EAP where you can, and deny MAC-auth fallback except for a short, inventoried printer list. Defense in depth only counts if the second control still works when ISE says yes by mistake.

Incident response should start with identity artifacts, not disk images. If you find a session that ISE authorized without a corresponding EAP success, revoke that endpoint’s certificates, disable the computer object, and treat the user account as stolen until you prove otherwise. Reimaging the laptop can wait. Revoke the identity first. Snapshot domain controller security logs and RDP gateway logs in the same window so you can see who used the bypass, not only that a node was upgraded.

Pixel Modem Exploitation and CISA Decoys for Cybersecurity Gaps

Google’s September Pixel update closes 110 vulnerabilities. One of them is a modem flaw already used in limited, targeted attacks. That’s a different layer than ISE, and it’s the same class of miss: the path that never hits your firewall. Baseband code processes radio frames below Android’s app sandbox. Endpoint agents, MDM, and most mobile threat detection never see the packet. If you issue Pixels, the patch is a radio-adjacent privilege boundary, not a convenience update.

CISA agency branding used with federal guidance on cyber decoys
CISA’s decoy guidance is built for the hour after a trusted control has already said yes.

CISA’s decoy guidance lands in that same blind spot on purpose. Decoys complement Zero Trust by giving you something to detect, observe, and block after a trusted control has already failed. You plant fake assets where a bypassed ISE, a stolen RDP session, or a modem-side implant would naturally recon. Then you wire those decoys into the same incident response queue that handles domain-admin alerts. A decoy that pages nobody is interior design.

Place them where this week’s bugs actually bite. A honey computer object next to your real jump hosts. A fake ISE admin URL that should never receive traffic from user VLANs. A canary SMB share that only an AD-enumerating tool would open after GhostContainer-style access. Keep the set small enough that every alert is real. You want signal, not a new scanner tarpit.

Patch ISE. Patch Pixels. Watch GitHub egress from servers that have no developers. Instrument decoys on the segments you still call trusted. Identity brokers, directory, RDP, and employee radios are in production this week. Treat them that way.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.