logo

Attacks pummeling Cisco AsyncOS 0-day since late November

ID: b95bd0a7-7c66-52dc-83fd-fc19b493a415

STIX ID: report--b95bd0a7-7c66-52dc-83fd-fc19b493a415

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-12-17

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Suspected Chinese-government-linked APT UAT-9686 has been actively exploiting a critical Cisco AsyncOS zero-day (CVE-2025-20393) since at least late November 2025 to gain root on internet-exposed Secure Email Gateway and SEWM appliances, deploying a Python backdoor (AquaShell), reverse-tunneling and tunneling tools (AquaTunnel, chisel) and a log-wiping utility (AquaPurge); Cisco and CISA have published advisories and mitigations while a permanent fix timeline remains unclear.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.