logo

China’s ‘Velvet Ant’ hackers caught exploiting new zero-day in Cisco devices

ID: ab5b6dfb-e51a-5eb3-a90b-2bf608b09c2b

STIX ID: report--ab5b6dfb-e51a-5eb3-a90b-2bf608b09c2b

Feed Name: The Record from Recorded Future News

Threat Score
88/100

Date Published: 2024-07-01

Date Updated: 2026-05-01

...
...

Sygnia and Cisco disclosed exploitation of a zero-day vulnerability (CVE-2024-20399) in Cisco NX-OS affecting Nexus switches; state-backed Chinese group Velvet Ant leveraged administrator credentials to install custom malware, gain remote control, and maintain long-term access for espionage. Cisco released updates to remediate the flaw, noting active exploitation in April and no available workaround.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.