• Cisco confirms zero‑day (CVE‑2025‑20393) in Safe Electronic mail home equipment exploited by China‑linked actors
  • Attackers deployed Aquashell backdoor, tunneling instruments, and log‑clearing utilities for persistence
  • CISA added flaw to KEV; businesses should remediate/cease use by December 24

A China-affiliated risk actor has been abusing a zero-day vulnerability in a number of Cisco e-mail home equipment to achieve entry to the underlying system and set up persistence.

Cisco confirmed the information in a weblog put up and a safety advisory, urging customers to use offered suggestions and harden their networks.




Source link