logo

Cisco says Chinese hackers are exploiting its customers with a new zero-day

ID: f453548f-acf3-55cb-ba0c-206cd1597a8b

STIX ID: report--f453548f-acf3-55cb-ba0c-206cd1597a8b

Feed Name: TechCrunch Security News

Threat Score
90/100

Date Published: 2025-12-17

Date Updated: 2026-04-23

Author: Lorenzo Franceschi-Bicchierai

...
...

A critical zero-day vulnerability in Cisco AsyncOS (impacting Secure Email Gateway, Cisco Secure Email, and Web Manager) is being actively exploited in the wild to install persistent backdoors; there is currently no patch and Cisco recommends rebuilding compromised appliances. Cisco Talos links the campaign to Chinese state-affiliated groups and reports the activity has been ongoing since at least late November 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.