Australia warns of BadCandy infections on unpatched Cisco devices
ID: ad285209-0d5a-54f3-9d90-58258c2cc476
STIX ID: report--ad285209-0d5a-54f3-9d90-58258c2cc476
Feed Name: Bleeping Computer
**Overview:** The Australian Signals Directorate warns of active mass exploitation of CVE-2023-20198 in Cisco IOS XE devices by attackers deploying the BadCandy webshell to obtain root access; ASD reports over 400 devices potentially compromised and more than 150 still infected as of October 2025, with evidence of repeated re-infection and suspected state-sponsored involvement (Salt Typhoon). Administrators are urged to apply Cisco patches, follow hardening guidance, and coordinate incident response and notifications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
