logo

China-nexus Campaign Exploits CVE-2025-20393 in Cisco Email Security Devices (Campaign)

ID: 2804672c-a570-5ff4-b359-f9c0eafccda8

STIX ID: report--2804672c-a570-5ff4-b359-f9c0eafccda8

Feed Name: Wiz Cloud Threat Landscape

Threat Score
90/100

Date Published: 2025-12-17

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Cisco disclosed an active exploitation campaign targeting a zero-day (CVE-2025-20393) in Cisco Secure Email Gateway and related management appliances that allows remote code execution when the Samp Quarantine feature is internet-exposed; Talos attributes the intrusions to UAT-9686 (assessed as a China-nexus state-backed actor) and observed deployment of multiple malicious tools (AquaShell, AquaPurge, AquaTunnel and Chisel) with no patch or workaround available at the time.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.