Cisco email security products actively targeted in zero-day campaign

  • Cisco confirms zero‑day (CVE‑2025‑20393) in Secure Email appliances exploited by China‑linked actors
  • Attackers deployed Aquashell backdoor, tunneling tools, and log‑clearing utilities for persistence
  • CISA added flaw to KEV; agencies must remediate/stop use by December 24

A China-affiliated threat actor has been abusing a zero-day vulnerability in multiple Cisco email appliances to gain access to the underlying system and establish persistence.

Cisco confirmed the news in a blog post and a security advisory, urging users to apply provided recommendations and harden their networks.

In its announcement, Cisco said it first spotted the activity on December 10, and determined that it started at least in late November 2025. In the campaign, the threat actor tracked as UAT-9686 abused a bug in Cisco AsyncOS Software for Cisco Secure Email Gateway, and Cisco Secure Email and Web Manager, to execute system-level commands and deploy a persistent Python-based backdoor called Aquashell.

Two groups

The vulnerability is now tracked as CVE-2025-20393 and was given a severity score of 10/10 (critical).

The group was also seen deploying AquaTunnel (a reverse SSH tunnel) chisel (another tunneling tool), and AquaPurge (log-clearing utility).

Given the tools and infrastructure used, Cisco believes the attacks are being conducted by at least two groups – tracked as APT41, and UNC5174. Both are very active and quite dangerous – abusing legitimate cloud services, breaching VPNs, firewalls, and other tools, while engaging primarily in cyber-espionage.

At the same time, the US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalog, confirming abuse in the wild. Federal Civilian Executive Branch agencies have until December 24 to apply the provided fixes or stop using the vulnerable products entirely.

In the advisory, Cisco said customers should restore the devices exposed to the internet to a secure configuration. If they are prevented from doing so, they should reach out to Cisco to see if they were compromised or not.

“In case of confirmed compromise, rebuilding the appliances is, currently, the only viable option to eradicate the threat actors’ persistence mechanism from the appliance,” Cisco said. “In addition, Cisco strongly recommends restricting access to the appliance and implementing robust access control mechanisms to ensure that ports are not exposed to unsecured networks.”

Via The Record

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

Bungie’s Marathon shooter launches on March 5th

Bungie is putting an official date on Marathon today, its delayed extraction shooter. The slick-looking shooter from the makers of Halo and Destiny was...

A second US Sphere could come to Maryland

Sphere Entertainment, the company behind the eye-catching interactive venue in Las Vegas, has announced its "intent to develop" another Sphere in Maryland that will...

Musk claims Tesla will restart work on its Dojo supercomputer

Elon Musk posted on X that Tesla will be restarting work on Dojo3, the third generation of its in-house supercomputer project. The Dojo team...

Bungie’s Marathon arrives on March 5

Marathon, Bungie's long-awaited extraction shooter, will arrive on March 5, the studio announced today. Alongside a definitive release date, Bungie shared a new gameplay...

More malicious browser extensions uncovered – Chrome, Firefox, and Edge all affected

LayerX found 17 malicious browser extensions with 840,000+ downloads Extensions hijacked affiliate links, injected tracking, and enabled ad fraudAll extensions removed, but users must...

The world’s first Gemini-powered EV lands this week, but the Volvo EX60 needs to be better than Alexa+ on the BMW iX3

The Volvo EX60 will be the first to ship with Google Gemini built-inVolvo is promising "natural conversation" between man and machineLatest hardware from Nvidia...

MIO: Memories in Orbit is a pleasant stroll after the brutal ultramarathon of Hollow Knight: Silksong — and I’m here for it

When I booted up last year’s tough-as-nails and long-awaited Hollow Knight: Silksong, I knew I had to focus up and lock in – this...

Tour Down Under 2026 Free Streams: TV Channels, Schedule & Preview of UCI WorldTour Opener

Stream Tour Down Under 2026 completely *FREE* on 7Plus (AUS)Use NordVPN to watch from anywherePrologue: January 20 — Adelaide → Adelaide (3.6km)Start Time: 6pm...

How to watch The Secret of Me on Channel 4 — it’s *FREE*

Watch The Secret of Me for free on Channel 4 (UK restricted)Watch The Secret of Me for free on ABC iView (AUS restricted)Abroad? Watch...

ChatGPT now has ads, and before long Gemini might too – here’s what we can learn from Netflix, Prime Video, and other streaming services

The time has come, OpenAI has finally announced the thing we all knew was coming but didn't want to believe: ChatGPT is getting ads.The...