logo

Cisco customers hit by fresh wave of zero-day attacks from China-linked APT

ID: 6e90b808-dcc2-57e6-9548-e6797ac3b468

STIX ID: report--6e90b808-dcc2-57e6-9548-e6797ac3b468

Feed Name: CyberScoop

Threat Score
90/100

Date Published: 2025-12-18

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

Cisco disclosed active attacks since at least late November exploiting a critical zero-day (CVE-2025-20393) in AsyncOS for Secure Email Gateway and Secure Email and Web Manager that allows full command execution and persistent backdoors; Cisco attributes the activity to Chinese APT UAT-9686, no patch is available, and exploitation requires a publicly exposed spam quarantine feature. CISA added the vulnerability to its known exploited vulnerabilities catalog and Cisco recommends isolation or rebuilding of affected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.