Hackers Actively Exploiting Cisco and Citrix 0-Days in the Wild to Deploy Webshell
ID: f2030438-6768-5efa-a857-987229aa67e2
STIX ID: report--f2030438-6768-5efa-a857-987229aa67e2
Feed Name: cybersecurityNews.com
Amazon's MadPot honeypot detected an advanced group actively exploiting zero-day RCEs in Citrix (CVE-2025-5777) and Cisco ISE (CVE-2025-20337) to deploy a Cisco-specific, in-memory webshell (disguised as IdentityAuditAction) that grants full administrative control while avoiding forensic detection; the campaign was widespread and occurred before vendor patches, prompting urgent recommendations to harden access to management portals, monitor anomalous web traffic, and prioritize patching and layered defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
