logo

Chinese Hackers Exploiting Cisco Switches Zero-Day to Deliver Malware

ID: a6525d70-718f-54de-a854-c12a7a760c01

STIX ID: report--a6525d70-718f-54de-a854-c12a7a760c01

Feed Name: The Hacker News

Threat Score
76/100

Date Published: 2024-07-02

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Sygnia and reporting indicate that the China‑nexus APT 'Velvet Ant' exploited a Cisco NX-OS zero‑day (CVE-2024-20399) to achieve root command execution on affected Nexus/MDS switches and deploy custom malware for remote access and file execution; the flaw requires administrator credentials but allows stealthy command execution without syslog entries. The report also highlights in-the-wild exploitation evidence and separately calls out a critical, unpatched D-Link DIR-859 path traversal (CVE-2024-0769) being used to harvest router account data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.