A Cisco blog post recounting two real security incidents handled at the Black Hat Asia 2026 NOC, where multiple vendors (Cisco XDR, Splunk, Corelight, Arista, and Palo Alto Networks) collaborated to detect and respond to threats. The first incident involved an Apache RCE exploit attempt (CVE-2021-41773) from a malicious IP blocked by a Palo Alto firewall. The second involved an attendee transmitting credentials in cleartext over HTTP. Both cases highlight how cross-vendor data correlation, AI-driven attack storyboards, and integrated SIEM/XDR tooling enabled rapid triage and response without endpoint access.

7m read timeFrom blogs.cisco.com
Post cover image
Table of contents
Here’s the first example.Welcome to Black Hat, here’s your first morning’s activities!Investigation StepsHere’s the second example.Don’t hide your passwords in plain sight!Investigation StepsTakeaway and ResponseWhy This MattersAbout Black Hat
63 Impressions