logo

Hackers exploited Citrix, Cisco ISE flaws in zero-day attacks

ID: ab7120c5-18bc-502f-898b-310eb69e4b77

STIX ID: report--ab7120c5-18bc-502f-898b-310eb69e4b77

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-11-12

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Amazon Threat Intelligence observed an advanced actor exploiting two zero-day vulnerabilities—Citrix Bleed 2 (CVE-2025-5777) in NetScaler ADC/Gateway and a critical Cisco ISE flaw (CVE-2025-20337)—to gain pre-auth access and deploy a stealthy custom web shell named 'IdentityAuditAction' that uses Java reflection, DES with custom base64 encoding, and HTTP-header gated access; exploits occurred before public disclosure, vendors published patches, and organizations are advised to apply updates and restrict edge device access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.