logo

Patch Now: Cisco Zero-Day Under Fire From Chinese APT

ID: a652fed6-d204-5e90-b896-454bb9bae2fa

STIX ID: report--a652fed6-d204-5e90-b896-454bb9bae2fa

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-07-02

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Cisco patched a command-line injection flaw (CVE-2024-20399, CVSS 6.0) in NX-OS that allows authenticated admin users to execute arbitrary root commands; Sygnia reports the China-backed APT Velvet Ant has actively exploited the bug to jailbreak the NX-OS CLI, deploy custom malware to compromised Nexus switches, and maintain persistence as part of a broader multiyear campaign—organizations are advised to apply Cisco updates, restrict admin access, enforce MFA/PAM, limit outbound connections from switches, and follow strong patch and password hygiene.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.