logo

Cisco AsyncOS 0-Day Vulnerability Exploited in the Wild to run System-level Commands

ID: 08f042d8-91c5-5e63-8066-cdc2f89aeae4

STIX ID: report--08f042d8-91c5-5e63-8066-cdc2f89aeae4

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-18

Date Updated: 2026-04-21

Author: Guru Baran

...
...

An active campaign exploiting a Cisco AsyncOS zero-day (disclosed Dec 10) is being used to deploy a Python backdoor named "AquaShell" on email/web gateway appliances and managers; attackers established remote access (AquaTunnel/Chisel), removed logs (AquaPurge), and used multiple C2 IPs. Talos attributes the operation to UAT-9686 with ties to Chinese APT activity and provides hashes and IP indicators along with Cisco remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.