A cross-scripting bug plaguing Cisco's Adaptive Security Appliance is being actively exploited ... threat actors to remotely inject arbitrary web script or HTML via an unspecified parameter.