Cisco zero-day, Acronis backup flaw & a record month for ransomware
Three signals from this week that should be on every buyer's radar:
- **Cisco Identity Services Engine zero-day is being actively exploited.** Cisco released emergency patches for a maximum-severity vulnerability (CVEredacted, CVSSredactedin ISE — the access control platform that manages who gets onto the network. CISA added it to the KEV catalog on September 16 with a federal patch deadline of September 19. If your target uses Cisco ISE for network access and hasn't patched, every login is a potential entry point. (Source: BleepingComputer, CISA)
- **CISA also flagged Acronis Backup and Google Pixel this week.** The Acronis Backup flaw (CVEredactedis notable — Acronis is backup software used by thousands of SMBs and MSPs. If your target's backup solution is compromised, the last line of defense is gone. The Google Pixel vulnerability (CVEredactedaffects mobile devices — and most diligence checklists don't even ask about phone security. (Source: CISA, Sep 16)
- **August set a record: 997 ransomware attacks globally.** Utilities, healthcare, and business services saw the biggest spikes. For acquirers, this is a trend signal: the businesses you're evaluating are in the sectors getting hit hardest. A new report also found that manufacturing companies are leaving themselves open through basic identity management failures — the exact gap ransomware groups exploit. (Source: Industrial Cyber, Cybersecurity Dive)
**The deal lens:** This week's signals tell you what to check in diligence. Network access control (Cisco ISE) — is it patched? Backup integrity (Acronis) — is the last line of defense secure? Mobile device security (Pixel) — does the target even have a phone policy? And the ransomware trend: if your target is in utilities, healthcare, or manufacturing, the risk isn't theoretical — it's statistical.
What's the one system in your target's stack you haven't verified this week?
#CyberSecurity #ThreatIntel #SMBAcquisition #DueDiligence #PatchTuesday