China-linked APT UAT-9686 abused now patched maximum severity AsyncOS bug
ID: 544f769d-bc18-5570-ba35-2ed8fe7c9929
STIX ID: report--544f769d-bc18-5570-ba35-2ed8fe7c9929
Feed Name: Security Affairs
Threat Score
**Cisco fixed a CVE-2025-20393 maximum-severity AsyncOS zero-day that was actively exploited by China-linked APT UAT-9686 to achieve root execution on exposed Secure Email Gateway and Secure Email and Web Manager appliances; attackers deployed a Python backdoor (AquaShell), reverse-tunneling tools (AquaTunnel, chisel), and a log-wiping utility (AquaPurge) to maintain stealth and persistence, and Cisco/Talos have published impacted releases and remediation guidance.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
