Hackers exploited Citrix, Cisco ISE flaws in zero-day attacks
ID: ab7120c5-18bc-502f-898b-310eb69e4b77
STIX ID: report--ab7120c5-18bc-502f-898b-310eb69e4b77
Feed Name: Bleeping Computer
Amazon Threat Intelligence observed an advanced actor exploiting two zero-day vulnerabilities—Citrix Bleed 2 (CVE-2025-5777) in NetScaler ADC/Gateway and a critical Cisco ISE flaw (CVE-2025-20337)—to gain pre-auth access and deploy a stealthy custom web shell named 'IdentityAuditAction' that uses Java reflection, DES with custom base64 encoding, and HTTP-header gated access; exploits occurred before public disclosure, vendors published patches, and organizations are advised to apply updates and restrict edge device access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
