logo

Australia warns of BadCandy infections on unpatched Cisco devices

ID: ad285209-0d5a-54f3-9d90-58258c2cc476

STIX ID: report--ad285209-0d5a-54f3-9d90-58258c2cc476

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-10-31

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

**Overview:** The Australian Signals Directorate warns of active mass exploitation of CVE-2023-20198 in Cisco IOS XE devices by attackers deploying the BadCandy webshell to obtain root access; ASD reports over 400 devices potentially compromised and more than 150 still infected as of October 2025, with evidence of repeated re-infection and suspected state-sponsored involvement (Salt Typhoon). Administrators are urged to apply Cisco patches, follow hardening guidance, and coordinate incident response and notifications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.