Cybersecuritydive Ongoing Exploitation of Cisco IOS XE Vulnerability with BadCandy Implant
Article Content
Browse articles
Cyberattacks exploiting a critical vulnerability in Cisco IOS XE (CVE-2023-20198) continue, with over 150 devices in Australia still infected with the BadCandy webshell as of late October 2025. Despite patches being available for over two years, many devices remain unpatched and vulnerable to re-infection. The Australian Signals Directorate warns that attackers can detect and reinstall the BadCandy implant if removed.
Ask AI about this cluster
Answers cite the sources they use
Updated 192d ago How this analysis works
More articles in this cluster (8)
Following this threat?
Track Salt Typhoon, Badcandy and CVE-2023-20198 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
Fire Ant Threat Actor Targets Trusted Infrastructure in 2026 The China-nexus threat actor known as Fire Ant has evolved its tactics in 2026, transitioning from targeting VMware hypervisors to compromising trusted infrastructure, including Cisco routers, TACACS authentication servers, and Linux management hosts. This shift allows Fire Ant to collect credentials, traffic, and…