Cybersecuritydive
Ongoing Exploitation of Cisco IOS XE Vulnerability with BadCandy Implant
First seen 2 Dec 2025, 18:33 UTC
•



+2
•82% similarity
•28.9
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Cyberattacks exploiting a critical vulnerability in Cisco IOS XE (CVE-2023-20198) continue, with over 150 devices in Australia still infected with the BadCandy webshell as of late October 2025. Despite patches being available for over two years, many devices remain unpatched and vulnerable to re-infection. The Australian Signals Directorate warns that attackers can detect and reinstall the BadCandy implant if removed.
ThreatCluster AI