Cisco warns of unpatched AsyncOS zero-day exploited in attacks
ID: f498c64b-5119-5867-91ed-b277bed1a05e
STIX ID: report--f498c64b-5119-5867-91ed-b277bed1a05e
Feed Name: Bleeping Computer
Cisco Talos warns of a high-severity, actively exploited, unpatched AsyncOS zero-day (CVE-2025-20393) impacting Cisco Secure Email Gateway and Secure Email and Web Manager appliances with exposed Spam Quarantine; the attacker, tracked as UAT-9686 (Chinese-nexus APT), is observed deploying AquaShell persistence, reverse-tunnel implants (AquaTunnel, Chisel), and log-purging tools, with IOCs published and Cisco recommending restricting access, rebuilding compromised appliances, and following mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
