Cisco AsyncOS 0-Day Vulnerability Exploited in the Wild to run System-level Commands
ID: 08f042d8-91c5-5e63-8066-cdc2f89aeae4
STIX ID: report--08f042d8-91c5-5e63-8066-cdc2f89aeae4
Feed Name: cybersecurityNews.com
Threat Score
An active campaign exploiting a Cisco AsyncOS zero-day (disclosed Dec 10) is being used to deploy a Python backdoor named "AquaShell" on email/web gateway appliances and managers; attackers established remote access (AquaTunnel/Chisel), removed logs (AquaPurge), and used multiple C2 IPs. Talos attributes the operation to UAT-9686 with ties to Chinese APT activity and provides hashes and IP indicators along with Cisco remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
