Amazon pins Cisco, Citrix zero-day attacks to APT group
ID: 69024da8-248c-57ed-88fe-7aeab0dd97a6
STIX ID: report--69024da8-248c-57ed-88fe-7aeab0dd97a6
Feed Name: CyberScoop
Threat Score
Amazon’s threat intelligence detected a highly resourced APT exploiting zero-day vulnerabilities in Cisco Identity Services Engine (CVE-2025-20337) and Citrix NetScaler (CVE-2025-5777) before vendor disclosure; the actor used custom backdoors tailored to Cisco ISE with advanced evasion and conducted large-scale exploitation activity traced to May–July 2025, likely for espionage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
