logo

Amazon pins Cisco, Citrix zero-day attacks to APT group

ID: 69024da8-248c-57ed-88fe-7aeab0dd97a6

STIX ID: report--69024da8-248c-57ed-88fe-7aeab0dd97a6

Feed Name: CyberScoop

Threat Score
90/100

Date Published: 2025-11-12

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

Amazon’s threat intelligence detected a highly resourced APT exploiting zero-day vulnerabilities in Cisco Identity Services Engine (CVE-2025-20337) and Citrix NetScaler (CVE-2025-5777) before vendor disclosure; the actor used custom backdoors tailored to Cisco ISE with advanced evasion and conducted large-scale exploitation activity traced to May–July 2025, likely for espionage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.