Skip to content
Auto-CTI
Back to today
NEW UAT-10820 CRITICAL B3

We've got one word for it, and it's usually the wrong one

B Cisco Talos Blog ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

Russian-Ukrainian cyber operations escalate with sophisticated multi-payload delivery chains; security teams in DACH must prepare for similar techniques (WebDAV abuse, stealer distribution).

Description

Cisco Talos analysed an incident at a Ukrainian government organization and attributed it to Russian threat actor UAT-10820. The campaign employs a complex WebDAV-based infection chain to deliver the Amatera stealer alongside secondary payloads such as ZigCryptoStealer and NetSupport Manager. The campaign is active and demonstrates increasing sophistication in payload delivery techniques. Cisco Talos is simultaneously tracking active exploitation of two vulnerabilities (CVE-2026-20079 and CVE-2026-20316) in Cisco Secure Firewall Management Center software; hotfixes are already available.

Risk score

80
strategic relevance
0.80

Path: strategic

ESC