Threat Analysis: Cisco ISE Zero-Day and GhostCode OAuth Phishing, What UK SMBs Need to Know Today

Threats & Attacks

Threat Analysis: Cisco ISE Zero-Day and GhostCode OAuth Phishing, What UK SMBs Need to Know Today

This is your Daily Threat Analysis for the 17th of September 2026.

Two items today. Both require action before the end of the working day. One is a vendor vulnerability with a perfect CVSS score under active exploitation. The other is a phishing technique that is going to catch businesses off guard because it bypasses the controls most of them think are sufficient. I will take them in order of severity.

Cisco ISE Authentication Bypass, CVSS 10.0, Actively Exploited

Cisco disclosed a critical authentication bypass vulnerability in Cisco Identity Services Engine today. The score is 10.0. That is the maximum. Exploitation is confirmed as active.

Cisco ISE is the network access control platform many mid-sized organisations use to manage who and what can connect to their networks, VPN authentication, device posture checking, guest access, 802.1X wired and wireless. If your organisation uses it, or if your managed service provider runs network infrastructure that depends on it, this is a direct path to your network perimeter.

The advisory attributes active exploitation to the vulnerability. What the advisory does not spell out, but what the operational pattern here suggests, is that network access control systems are high-value targets precisely because compromising them does not trigger the same alerts as compromising an endpoint. An attacker who can bypass authentication in ISE is not attacking one machine. They are potentially changing the access rules for your entire network.

This is also the second Cisco zero-day in rapid succession. The fact that two are arriving within days of each other is worth noting. It is not necessarily coordinated, but it does suggest active research focus on Cisco products at this moment. That is not the time to defer patching.

What to do:

  • If you manage Cisco ISE directly, apply the patch now. Consult the Cisco security advisory for the specific affected versions.
  • If your MSP manages your network infrastructure, contact them today and ask specifically whether ISE is in scope and what their timeline is for this patch. If they tell you it is already done, ask for confirmation. If they tell you they are scheduling it, ask why it is not already done.
  • If you are not sure whether your network uses ISE, that question is worth answering before something else answers it for you.

GhostCode, OAuth Device Code Phishing via Business Contact Forms

This one is subtler, and it is going to hit businesses that consider themselves reasonably well-defended.

eSentire has documented a phishing kit called GhostCode, identified in late August. The campaign works like this: a threat actor registers a domain that looks convincingly like a legitimate business, in the documented case, an imitation of a wholesale retailer, and uses it to send emails impersonating procurement officers. The target is your contact form. Your staff receive what looks like a legitimate supplier or customer enquiry.

That is not the interesting part. The interesting part is what happens next.

GhostCode abuses Microsoft’s OAuth 2.0 device authorisation grant flow. This is the legitimate mechanism designed for devices without keyboards, smart TVs, printers, where a user is asked to visit a URL and enter a code to authenticate. The attacker generates a real Microsoft device code and presents it to the victim as part of the phishing interaction. The victim, believing they are completing a legitimate authentication step, enters the code. Microsoft’s own infrastructure hands the attacker a valid session token for the victim’s Microsoft 365 account.

There is no password prompt. There is no MFA challenge of the kind most businesses have deployed. The token is legitimate. Microsoft has no way to distinguish this from normal device authentication.

The consequences are account takeover, access to email and documents, and, depending on the permissions associated with the account, potential access to connected services. In a business email compromise context, that means an attacker with access to a staff member’s inbox who can read ongoing conversations, intercept payment discussions, and impersonate your organisation to your clients and suppliers.

The advisory notes the campaign used residential proxies to make the traffic appear to originate from legitimate consumer IP ranges, further complicating detection.

What the advisory does not say explicitly is that this technique has been observed in the wild as a precursor to ransomware deployment. Device code phishing produces valid tokens that can persist beyond a password reset. Organisations that reset passwords after detecting suspicious access but do not also revoke all active tokens find the attacker simply continues operating.

What to do:

  • Enforce phishing-resistant MFA on all Microsoft 365 accounts. FIDO2 security keys or certificate-based authentication are resistant to this technique. SMS one-time codes and authenticator app push notifications are not.
  • Review your Microsoft 365 conditional access policies. Restrict device code flow authentication if your organisation does not have a legitimate operational need for it. Microsoft’s conditional access can block this specific grant type.
  • Train staff specifically on device code phishing. The warning signs are different from credential phishing, there is no fake login page. Staff are being asked to enter a code into a legitimate-looking Microsoft URL. That is the tell.
  • If you receive a business enquiry via your contact form that asks you to take any authentication step, entering a code, scanning a QR code, approving a notification, stop and verify through a separate channel before proceeding.
  • After any suspected compromise, revoke all active Microsoft 365 sessions, not just reset the password.

A Note on Ransomware Group Targeting of Smaller Businesses

Cisco Talos published analysis today of ransomware activity in Japan during the first half of 2026. The Japan numbers are not directly relevant to UK SMBs, but one statistic is worth noting because the pattern is consistent across geographies: 80% of ransomware victims in the dataset had capital under JPY 1 billion. That is the small and medium enterprise segment. The Qilin group, active in the UK, appeared in this data as the second most active group and showed evidence of AI-assisted operations.

Qilin has been associated with UK incidents. The targeting profile matches. If you operate in the sub-£5m revenue bracket and have assumed that makes you a lower-priority target, the data does not support that assumption. It supports the opposite conclusion.

Worth Knowing: Windows 11 24H2 End of Support, October 2026

Microsoft has confirmed that Windows 11 24H2 Home and Pro editions reach end of support next month. Devices running these editions will stop receiving security updates. This is not an emergency today, but it is a countdown. If you have machines in your fleet that have not been updated to 25H2, the window for managing that transition in an orderly way is closing. Unpatched Windows endpoints are consistently the entry point in post-breach analysis. This is not the kind of thing to discover after an incident.

Check your fleet. Identify any devices that have not yet moved to a supported release. If there are hardware compatibility reasons preventing the update, document them and discuss mitigation with your IT provider now, not in November.


If Threat Analysis is useful to you, follow the show wherever you listen so tomorrow’s briefing lands automatically. And if you know someone who should be reading this, a business owner, an office manager, an IT provider who looks after small businesses, pass it on. The people who most need this information are often the last to find it.

Sources

SourcePublication
The RegisterCisco drops another exploited zero-day, this time a perfect 10
eSentireGhostCode: Dissecting a Novel Device Code Phishing Kit
Cisco Talos BlogRansomware incidents in Japan in the first half of 2026
NCSCAdversary simulation: what you need to know
BleepingComputerWindows 11 24H2 Home and Pro reach end of support in October
SOCRadarVectraRAT: An Undocumented Full-Stack MaaS Built From Scratch

Filed under

  • smb-security
  • uk-business
  • credential-theft
  • ransomware-groups
  • social-engineering
  • remote-access
  • business-risk