Bleepingcomputer
Ongoing BadCandy Infections Target Unpatched Cisco Devices in Australia
First seen 2 Nov 2025, 16:14 UTC
•
•85% similarity
•18.1
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The Australian government has issued a warning about ongoing cyberattacks exploiting CVE-2023-20198, a critical vulnerability in Cisco IOS XE devices. As of late October 2025, over 150 devices in Australia remain compromised with the BadCandy webshell, despite patches being available since October 2023. The flaw allows remote unauthenticated attackers to create local admin users via the web interface, enabling full control of the devices.
ThreatCluster AI