CVE-2025-20393: Threat Campaign Targeting Cisco Secure Email Gateway, Cisco Secure Email and Web Manager
ID: 9bc71b0a-7469-5c1e-afd1-f48b0b9c04cf
STIX ID: report--9bc71b0a-7469-5c1e-afd1-f48b0b9c04cf
Feed Name: Arctic Wolf
Cisco disclosed an active campaign exploiting a zero-day (CVE-2025-20393) in Cisco AsyncOS Spam Quarantine that allows root-level command execution on affected Secure Email Gateway and Secure Email and Web Manager appliances; Cisco Talos observed deployment of the AquaShell backdoor and attributes the activity to UAT-9686 (moderate confidence, China-affiliated). Cisco and Arctic Wolf advise removing the Spam Quarantine service from the public internet, filtering access to trusted hosts, monitoring for IOCs, contacting Cisco TAC for inspections, and applying patches when released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
