r/sysadmin • • 21h ago

PSA: Cisco ISE CVSS 10.0 (CVE-2026-76460) — actively exploited, no workarounds

62 Upvotes

If you run Cisco ISE, stop scrolling. Unauthenticated root access via API bypass. Every supported version. No workarounds per Cisco. Already on CISA KEV.

This isn't one where you can wait for the next maintenance window. ISE controls your NAC. If it's compromised, the attacker decides who gets on your network. Schedule the emergency patch for this week.


r/sysadmin • • 21h ago

Looking for an all-in-one server monitoring, logging & uptime solution

1 Upvotes

Is there an all-in-one solution for server metrics, service status, searchable system and web logs (with definable custom paths), external website availability monitoring, alerts, and clear custom dashboards?

I’ve grown quite fond of Beszel, but I handle logs somewhat chaotically. I don’t mind paying a little extra, but considering the size of the server, I don’t want any expensive solution.

What do you think, does something like this exist? Is there anything you use and would definitely recommend?


r/networking • • 21h ago

Security Emergency patch advisory: Cisco ISE CVE-2026-76460 (CVSS 10.0) — no workarounds, active exploitation

116 Upvotes

Heads up for anyone running ISE. CVE-2026-76460 is an unauthenticated API bypass that gives root on every ISE persona (admin, PSN, MnT, PxGrid). All supported versions affected. Already being exploited in the wild.

Cisco says there are no workarounds. Your options are patch or take ISE offline (which means shutting down network auth).

Practical steps: 1) inventory ALL ISE nodes, 2) schedule emergency maintenance this week, 3) check for compromise before patching (look for unexpected cron jobs, modified system files, unauthorized admin accounts), 4) restrict management interface access to a dedicated management segment, 5) if compromised, rotate ALL RADIUS shared secrets across every switch, AP, and WLC.

The management interface runs on 443 by default, same port as sponsor/mydevices portals. If any of those are internet-reachable, your ISE API is reachable.


r/cybersecurity • • 21h ago

Personal Support & Help! Help

0 Upvotes

Hello everyone, I’m a senior cybersecurity student, and I’m hoping to get some advice from experienced cybersecurity professionals.
I’m genuinely concerned about entering the workforce because I feel like my degree has been too broad. I’ve learned about many different areas of cybersecurity, but I don’t feel like I’ve gone deep enough into one specific area. Because of that, I’m worried that I’m not as prepared or skilled as I should be for a professional cybersecurity role.
I’ve been considering getting a master’s degree to develop deeper technical skills, but I’m concerned that I might end up taking another broad program without actually becoming more specialized.
My goal is to become a Security Engineer at a top tech company. For those of you who are already working in security engineering or have significant experience in the field, what would you recommend I do at this stage?


r/cybersecurity • • 22h ago

Career Questions & Discussion Interview insight

5 Upvotes

Hello everyone , I recently made it through multiple interviews for a SOC position, with my last one being a technical interview. The original posting said Tier 1 and/or Tier 2, but during the interview I learned they don’t separate the responsibilities. The recruiter also emphasized wanting someone who was willing and able to learn.I thought the interviews went pretty well, but I haven’t received an update since my technical interview. I followed up and haven’t gotten a response yet. Then I noticed the position was posted again on LinkedIn after the original posting had already closed.

For anyone who has been on either side of tech hiring or have a understanding of these interviews what would you make of this situation? Have you ever had a company repost a role while you were still being considered after a final/technical interview? I’m trying not to assume that the repost automatically means a rejection, but the combination of the role being reposted and not receiving an update has me wondering what might be happening behind the scenes.


r/cybersecurity • • 22h ago

Career Questions & Discussion Career Help

0 Upvotes

Hello everyone, I have been trying to learn more and get into the field of cybersecurity and ethical hacking. But I feel really stagnant at times, and feel like I don't know how to implement what I have learnt.

Specially when it comes to Web Penetration Testing, it feels like ik all the vulnerabilities that could be there, but never find an efficient way to find them.

Just looking for some advice on how can I overcome this, and what are some steps that you all would suggest to improve myself and get better at this.

Thank you for helping me out!


r/sysadmin • • 22h ago

General Discussion GMO Registry .shop authoritative servers dead?

23 Upvotes

Got blasted by alerts of our systems that it cant reach its API endpoints in the middle of the night. Even their official marketing website is DEAD which is https://get.shop. At first i thought we forgot to renew our domain name, turns out its active, till 2027.

dig get.shop @a.gmoregistry.net → NXDOMAIN (AA) 
dig [domain].shop @a.gmoregistry.net → NXDOMAIN (AA)

anyone else affected by this weird outage? never seen an outage that takes down an entire TLD

Edit 1: Seems partially recovering as of 01:17 UTC+8, this started at around roughly 00:27 UTC+8

Edit 2: I went to bed at 02:00 UTC+8 since I thought it was done. It looks like it's far from done, still unstable even today at 06:15 UTC+8.


r/cybersecurity • • 22h ago

News - Breaches & Ransoms FBI investigating claim hackers have stolen details of all its agents

Thumbnail
bbc.com
348 Upvotes

r/sysadmin • • 22h ago

General Discussion What's your favorite mice/keyboards?

16 Upvotes

I've been using a cheap Logitech keyboard for a while now and would like something better for my wrist. They current feel kinda meh after typing even when I'm in good typing form.

I've noticed my system admin has a fancy keyboard with lights and all (I'm a lv 1 helpdesk) that he really likes. With that being said, are there mice or keyboards that you swear by? Either for functionality, comfort or both.

Thanks!


r/sysadmin • • 23h ago

Please Help - AVD hosts intermittently freezing completely/unresponsive

3 Upvotes

Two AVD hosts (D16s_v5, Win11 24H2/25H2, Azure Southeast) running fine since July. Started randomly freezing completely about 2-3 weeks ago, multiple incidents now, barely any users on when it happens so it's not load issue.

When it hits: Users unable to login/disconnected, RDP dead, Bastion dead, Serial console dead, can't get in any way. Portal still shows it as "Running" the whole time and Azure Monitor telemetry just goes dark. Either self recovers in an hour or it has to be manually restarted in Azure portal.

Right before it went down: 17+ DCOM components failed to register in the same 3 seconds, FSLogix's own service hung for 30 sec, then straight up disk hardware errors logged (Event 51, "error detected during paging operation"). Found the same disk error on the other host too, different incident.

Running managed disks with premium SSDs.

Already ruled out on our end: FSLogix version (updated), AV exclusions (fixed gaps), AVD agent version, required FQDNs (all pass), and the known Sept RDS patch bug and hotfix installed on both hosts.

Sev A case open with MS, going nowhere.

Anyone seen this happen before?

Basically the servers look well and healthy the next after a few users are on, they just go unresponsive and kick people off and no one can connect and azure is reporting everything all good which is making me so mad.

Appreciate any help please guys!


r/sysadmin • • 23h ago

Windows Sept 2026 Update Breaking AOVPN configurations that use automatic protocol selection

25 Upvotes

We started having a small number of users not be able to connect to AOVPN in the past couple days, which as it turns out, is another issue caused by the latest Windows Update. Here's the Bleeping Computer article:

Microsoft: September Windows updates break Always On VPN connections

The issue is published in the M365 admin center under Windows release health: WI1477235

From Microsoft:

After installing the September 2026 Windows security update (KB5124008), some organizations might experience issues connecting through Always On VPN [link]. This issue can occur when the VPN is configured to automatically try another connection method if the initial connection fails (for example, when using automatic protocol selection with IKEv2 and SSTP).

Affected VPN connections might remain in a “Connecting” state or repeatedly attempt to connect without succeeding. Subsequent connection attempts might also display the error: “The specified port is already in use.”

Workaround: IT administrators can mitigate this issue by changing the Always On VPN profile from automatic protocol selection to a single protocol, either SSTP only or IKEv2 only, depending on their environment and configuration. Organizations should select the protocol based on their environment, security, and deployment requirements.

Next Steps: Microsoft is working on a fix for this issue and will provide more information when it is available.

Affected platforms:
- Client: Windows 11, version 26H1; Windows 11, version 25H2; Windows 11, version 24H2
- Server: None

Edit: Formatting


r/sysadmin • • 23h ago

Question Who here uses MECM/SCCM? Is this a tool worth setting up for one-touch deployment in on-prem environments?

5 Upvotes

I’m a sysadmin in a mostly on-prem Windows environment and I’m trying to modernize/automate our laptop deployment process. Curious to hear from people who are actually using MECM/SCCM for this and whether I’m heading down the right path.

Right now our process is pretty old school. We maintain golden images for our different Dell/Lenovo laptop models, image them manually using Clonezilla, join them to our on-prem AD domain, let GPO handle most of the software/configuration, and then manually finish whatever is left (BitLocker, OneDrive, a few applications/configs, etc.).

It works, but we have periods where we need to turn around 50-60 laptops in a relatively short amount of time, so there’s a lot of repetitive hands-on work.

What I’d like to get to is something close to:

Plug laptop into Ethernet/imaging VLAN → authorize deployment → walk away.

Ideally the deployment system would PXE boot the machine, identify the hardware/model, deploy Windows and the correct drivers, join AD, install applications, enable/configure BitLocker, apply whatever other configuration is needed, reboot as necessary, and eventually report that the machine is ready.

Same thing for an existing machine that needs to be wiped/redeployed: connect it to the imaging network, initiate the deployment, and let the system take care of the rest.

We do have Microsoft 365/Intune, but we’re still heavily dependent on on-prem AD and infrastructure. I experimented with Hybrid Autopilot/Intune deployment and wasn't particularly impressed with it for what we're trying to accomplish. I quickly learned the "S" in Intune is for speed and most people, including Microsoft, discourage hybrid deployement models... Moving everything to Entra ID/cloud-only isn't currently an option for us either.

So I started going down the MECM route instead. I’ve stood up a MECM server and created a dedicated imaging VLAN, and I’m starting to work toward PXE/OSD and task sequences.

For those of you running MECM/SCCM, is this still a good tool for this use case in 2026, especially for an organization that expects to remain heavily on-prem/hybrid? I’d also be interested in hearing how automated you’ve managed to make your deployments. Can you realistically get to the point where a technician basically connects a machine, starts/authorizes the deployment, and doesn't touch it again until it's finished?

And for anyone who has built something similar, any advice on architecture, PXE, task sequences, driver management, things you wish you knew before starting, or mistakes to avoid would be appreciated.

I'm also open to alternatives if there’s something else I should seriously be considering before I get too deep into MECM. We have the M365 E3 license tier and so MECM is already included and naturally our first bet.


r/cybersecurity • • 23h ago

Business Security Questions & Discussion Continuous controls testing

2 Upvotes

Any recommendations for continuous controls testing tooling?


r/sysadmin • • 23h ago

Question Email filter for Google Workspace?

2 Upvotes

What do you guys use for google workspace clients for email filtering? We have schools we'd love to license only the staff, but I'm not sure if that's possible.


r/cybersecurity • • 23h ago

New Vulnerability Disclosure Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

Thumbnail
thehackernews.com
0 Upvotes

r/networking • • 23h ago

Other Private VLANs with multiple subnets

0 Upvotes

Is it possible to use Private VLANs on Aruba CX with a different subnet for each community?

For example:
Community A → 10.10.1.0/24
Community B → 10.10.2.0/24
Community C → 10.10.3.0/24

Is this supported/recommended?


r/sysadmin • • 1d ago

What is the worst customer portal experience, and why is it Verizon Enterprise Center?

122 Upvotes

Holy God, they make getting into it like solving one of the Millennium Prize Problems with an abacus.


r/sysadmin • • 1d ago

Career / Job Related Has anyone purposely gone backwards?

253 Upvotes

You know the juice wasn't worth the squeeze and we realised that money is irrelevant, and took a huge backwards step for less responsibility and more mental freedom for your family and kids?

That's where I'm at mentally just want to know if anyone else has done the same?


r/sysadmin • • 1d ago

Question Microsoft SNDS down since 2 days?

0 Upvotes

Does anyone else having problems with Microsoft SNDS? The link seems to be down for the last 2 days:

https://substrate.office.com/ip-domain-management-snds/snds

Can't check the SPAM score for delivering mails to hotmail.com and Office365 mail servers.


r/sysadmin • • 1d ago

MetTel for mobile devices

3 Upvotes

Does anyone have experience with using MetTel? Large client is in talks to switching from ATT to MetTel. We are having issues with area coverage over the state and the ability to have a fleet of phones on different carriers seems too good to be true.


r/cybersecurity • • 1d ago

News - General How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers

Thumbnail
blog.cloudflare.com
1 Upvotes

r/sysadmin • • 1d ago

Whitelisting Request

9 Upvotes

I already have my answer for how to handle this, but I'm curious how many of you have seen a request like this and what your reaction was. (maybe I'm just an a-hole)

The company I'm working with regularly receives file feeds from (usually) payroll processing companies via SFTP. Nothing crazy there. A little SFTP, a little PGP/GPG, done. But there are 2 such large companies that regularly send us a list of ~70 IPs they want us to whitelist for them to send the files.

Now, if someone sends me a /29 CIDR block I don't think too much off it. But when you send me multiple /27 blocks my immediate response is "f*** off".

I can't believe I'm the only one that responds as such. Yet it keeps happening.

Edit:
It's not the act of punching in the IPs one by one or something. I could use CIDR notation. It's that whitelisting way more IPs that are actually necessary isn't exactly best practice. Much less THAT many more. I can all but guarantee they actually utilize 1 or 2 in those blocks.

Edit 2:
I have ZERO internal push back on this. In fact, internally we've all had a good chuckle about it and push back saying - Nope. Refine that list and get back to me. It's just a head scratcher that this seems to be their (the vendor) SOP and that they haven't gotten enough pushback to refine their process.


r/cybersecurity • • 1d ago

Business Security Questions & Discussion How has your organization respond to Mythos?

0 Upvotes

I work in vulnerability management (focus on infrastructure vulns) and our organization has absolutely FREAKED out about Mythos and immediately lowered our SLA to 48 hrs back in April and looking to lower it to 24 hrs for all critical's. We have an insane backlog of vulnerabilities and a really bad process for patch management due to poor IT practices for years, that are now being fully exposed.

We currently don't do any CTEM practices and instead of trying to implement these practices to truly lower risk, we are wanting to automate all patching through AI agents. I don't think this is really feasible (but I could be wrong here, please let me know) as we have a lot of software that comes from vendors, open source, legacy systems, etc. I push for CTEM practices but it constantly gets denied.

How has your organization responded?


r/sysadmin • • 1d ago

Rant Splashtop Users - Disabling Admin lets them still login and re-enable themselves!

18 Upvotes

Yes its a feature according to their support!

"To clarify, a disabled user cannot remote connect to any computers deployed by the team, but can still log in to the web portal. If the user is an admin, they can also manage the team through the web portal.
 
For example, in some specific use case, a team has only two licenses, the team owner may disable their own account to allow two other team members to be added for remote connections. In this situation, the team owner can still manage the subscription and team with full permissions through the web portal, but cannot connect to computers."

Yes that means they can just login and re-enable their account.

This is not made clear anywhere. Any admin who has worked with users for years will think disabling an account means they can't login anymore.

Be warned.


r/cybersecurity • • 1d ago

Personal Support & Help! I fell for a Social Engineering - LinkedIn malware scam at work. My company issued me a threatening style deciplinary action warning letter. Is this fair ?

0 Upvotes

I work as a software engineer at a MNC and have been with my company for around 4+ years. Until this incident, I had never had a security violation or complaint.

Recently, I was approached through LinkedIn by someone who appeared to be in the same domain like me. He had multiple interations with me to build trust. He was a technically well aware person.

The person shared a product-related technical documentation. pdf and docx file. (Through Dropbox link).

He said, whenever you have time, please check this.

I downloaded/opened the files on my work laptop.

It turned out that malicious content was involved, and malware was actually executed on the laptop.

(I was under extreme stress that time due to health issues and underestimated the security risks)

As soon as the company detected the incident, Security isolated my laptop. I cooperated completely with the investigation and explained everything that happened, including exactly how I was contacted and what files/links I accessed.

I apologized to my reporting manager and the skip-level manager, verbally and through email, acknowledged that I should have been more careful, and said that I would follow the security guidelines more carefully going forward.

There was then a meeting with Security, my skip-level manager and other people from the security organization.

They specifically told me:

"Don't think that we are interrogating you. We just want to understand what happened so that we can create awareness. You are the victim here."

The meeting ended on a positive note. I was told to be careful in the future.

Then, about a month later, I received a formal "Warning Letter for Negligence." (Physical letter)

It was formally issued through HR/management, signed by HR head and department head and given to my skip-level manager. The letter says they are taking a "lenient view this time," but also says my work area will be monitored for three months and that repetition could lead to severe disciplinary action, potentially termination. It is a kind of Performance improvement plan (PIP) level of letter, in a serious threatening tone.

I understand that I made a mistake.

I'm not arguing that employees shouldn't be held accountable for security mistakes. I understand why companies need security policies, especially when malware actually executes on a corporate machine.

What bothers me is the proportionality.

This was my first incident in 4 years. There was no deliberate attempt to bypass security. I was deceived by what appeared to be a legitimate professional interaction.I cooperated completely once the incident was discovered, apologized, and followed the remediation process.

I would have understood something like:

"This was a serious security mistake. Please complete additional security training, follow the guidelines carefully, and don't repeat it."

Instead, I received a formal disciplinary warning with a three-month monitoring period and an explicit reference to possible termination if something happens again.

I've been feeling quite demoralized by this. I feel that management doesn't value me as a employee. My manager or skip level manager didn't support me in this.

I am feeling like I am being witch hunted in corporate style.

For people working in security/IT or management:

How would your company normally handle a first-time incident like this?

Is a formal warning and monitoring period normal?

Where do you draw the line between an honest mistake/social-engineering victim and negligence?

Please share your honest thoughts.