logo

Hackers Actively Exploiting Cisco and Citrix 0-Days in the Wild to Deploy Webshell

ID: f2030438-6768-5efa-a857-987229aa67e2

STIX ID: report--f2030438-6768-5efa-a857-987229aa67e2

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-11-12

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Amazon's MadPot honeypot detected an advanced group actively exploiting zero-day RCEs in Citrix (CVE-2025-5777) and Cisco ISE (CVE-2025-20337) to deploy a Cisco-specific, in-memory webshell (disguised as IdentityAuditAction) that grants full administrative control while avoiding forensic detection; the campaign was widespread and occurred before vendor patches, prompting urgent recommendations to harden access to management portals, monitor anomalous web traffic, and prioritize patching and layered defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.