Cisco IOS XE: Ten days later
ID: 3c999eda-730f-507e-9524-eb1f70d3a3bd
STIX ID: report--3c999eda-730f-507e-9524-eb1f70d3a3bd
Feed Name: Censys Blog
Date Published: 2023-10-26
Date Updated: 2026-04-27
Author: Ivonne Francia; The Censys Research Team
**Executive Summary:** Censys researchers report a large-scale compromise of Cisco devices running OpenResty/Nginx where attackers installed configuration-based backdoors; attackers modified Nginx location directives to evade detection, and a targeted scan identified 28,910 hosts that responded with a default Openresty/Nginx 404 to a '/%25' request—an indicator the backdoor may be present, though detection is imperfect and the adversary has adapted to obscure visibility.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
