Matthew Van Gundy of Cisco ASIG has discovered many vulnerabilities at Talos, a threat intelligence organization dedicated to providing protection before, during, and after cybersecurity threats.
The company is facing security issues, following a report published on October 21 by Cisco, in which the latter states that it has identified multiple vulnerabilities in the former's Network Time Protocol Daemon (NTPD).
“Cisco evaluates the security of software components using our products. Open source software plays a critical role in many Cisco products, and as such, securing open source software components is critical, especially in light of major vulnerabilities such as Heartbleed and Shellshock,” the company said in a statement.
According to the company, there is a flaw within NTPD that manifests itself due to incorrect condition handling associated with certain crypto-NAK packets.
According to the researcher, NTPD is a widely used software package used to synchronize time between hosts. It includes a wide variety of network and embedded devices, as well as desktop and server operating systems, including Mac OS X, major Linux distributions, and BSDs.
Cisco has released eight advisories for vulnerabilities identified by the Talos Group and the Advanced Security Initiatives Group (ASIG) within Cisco.
Talos, for its part, has released rules that detect attempts to exploit these vulnerabilities to protect its customers.
“Please contact the Defense Center, FireSIGHT Management Center, or Snort.org,” he added.

