Cisco VPNs, Email Services Hit in Separate Threat Campaigns
ID: 3b4f11ca-3d3d-525e-9865-204426d5082e
STIX ID: report--3b4f11ca-3d3d-525e-9865-204426d5082e
Feed Name: Dark Reading
The report details active exploitation of a critical zero-day (CVE-2025-20393, CVSS 10) in Cisco AsyncOS by a China-linked APT identified as UAT-9686, which attains root on affected appliances and deploys backdoors and tunneling tools (AquaShell, AquaPurge, AquaTunnel, Chisel); separately, an automated credential-stuffing campaign from over 10,000 IPs generated ~1.7M authentication attempts against Palo Alto GlobalProtect and Cisco SSL VPNs, highlighting urgent mitigation steps (disable Spam Quarantine, enforce strong passwords and MFA, audit edge devices).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
