Attacks pummeling Cisco AsyncOS 0-day since late November
ID: b95bd0a7-7c66-52dc-83fd-fc19b493a415
STIX ID: report--b95bd0a7-7c66-52dc-83fd-fc19b493a415
Feed Name: The Register (Security)
Suspected Chinese-government-linked APT UAT-9686 has been actively exploiting a critical Cisco AsyncOS zero-day (CVE-2025-20393) since at least late November 2025 to gain root on internet-exposed Secure Email Gateway and SEWM appliances, deploying a Python backdoor (AquaShell), reverse-tunneling and tunneling tools (AquaTunnel, chisel) and a log-wiping utility (AquaPurge); Cisco and CISA have published advisories and mitigations while a permanent fix timeline remains unclear.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
