logo

Cisco VPNs, Email Services Hit in Separate Threat Campaigns

ID: 3b4f11ca-3d3d-525e-9865-204426d5082e

STIX ID: report--3b4f11ca-3d3d-525e-9865-204426d5082e

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-12-19

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

The report details active exploitation of a critical zero-day (CVE-2025-20393, CVSS 10) in Cisco AsyncOS by a China-linked APT identified as UAT-9686, which attains root on affected appliances and deploys backdoors and tunneling tools (AquaShell, AquaPurge, AquaTunnel, Chisel); separately, an automated credential-stuffing campaign from over 10,000 IPs generated ~1.7M authentication attempts against Palo Alto GlobalProtect and Cisco SSL VPNs, highlighting urgent mitigation steps (disable Spam Quarantine, enforce strong passwords and MFA, audit edge devices).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.