Chinese Hackers Exploiting Cisco Switches Zero-Day to Deliver Malware
ID: a6525d70-718f-54de-a854-c12a7a760c01
STIX ID: report--a6525d70-718f-54de-a854-c12a7a760c01
Feed Name: The Hacker News
Sygnia and reporting indicate that the China‑nexus APT 'Velvet Ant' exploited a Cisco NX-OS zero‑day (CVE-2024-20399) to achieve root command execution on affected Nexus/MDS switches and deploy custom malware for remote access and file execution; the flaw requires administrator credentials but allows stealthy command execution without syslog entries. The report also highlights in-the-wild exploitation evidence and separately calls out a critical, unpatched D-Link DIR-859 path traversal (CVE-2024-0769) being used to harvest router account data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
