Related Threat Clusters
-
Advanced Threat Actor Exploits Cisco and Citrix Zero-Day Vulnerabilities
An advanced persistent threat actor exploited zero-day vulnerabilities in Cisco Identity Service Engine and Citrix NetScaler products. The attacks utilized custom malware and were detected by Amazon's MadPot honeypot…
8 articles · Updated November 12, 2025 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Critical Ivanti EPMM Vulnerabilities Under Active Exploitation
Two critical vulnerabilities in Ivanti's Endpoint Manager Mobile (EPMM), CVE-2026-1281 and CVE-2026-1340, have been actively exploited in the wild, allowing unauthenticated remote code execution (RCE) with a CVSS score…
64 articles · Updated January 29, 2026 -
Zero-Day Exploits Target Cisco ISE and Citrix Vulnerabilities
Amazon reported that a threat actor is exploiting two critical vulnerabilities, CVE-2025-20337 and CVE-2025-5777, in Cisco ISE and Citrix products as zero-days. These vulnerabilities have been identified as being…
2 articles · Updated November 13, 2025 -
APT Exploits Zero-Day Vulnerabilities in Cisco and Citrix Systems
An advanced persistent threat (APT) group exploited zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems, specifically CVE-2025-5777 and CVE-2025-20337. The attacks were detected by…
16 articles · Updated November 18, 2025 -
Cisco ASA Zero-Day Exploited in State-Espionage Campaign
Cisco disclosed a state-espionage campaign targeting its Adaptive Security Appliances (ASA), which are used for firewall and VPN functions. Attackers exploited two zero-day vulnerabilities to infiltrate government…
27 articles · Updated December 18, 2025 -
Cisco Faces Multiple Critical Vulnerabilities in Unified CCX and Firewalls
Cisco has disclosed critical vulnerabilities in its Unified Contact Center Express (CCX) platform and Adaptive Security Appliances (ASA) that allow unauthenticated remote attackers to execute arbitrary code and…
10 articles · Updated November 10, 2025 -
Cisco Patches ISE Vulnerability with Public Exploit Code
Cisco has patched a vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products. The flaw, tracked as CVE-2026-20029, allows remote attackers with admin-level privileges to…
7 articles · Updated January 8, 2026 -
Cisco Firewalls Targeted by New Attack Variant Exploiting Critical Vulnerabilities
Cisco has reported ongoing attacks against its firewalls, specifically targeting vulnerabilities CVE-2025-20333 and CVE-2025-20362. These flaws allow remote code execution and unauthorized access, leading to potential…
20 articles · Updated November 14, 2025 -
Cyber Threats: Oracle RCE and Ransomware Attacks Identified
Recent cybersecurity reports detail multiple threats, including Oracle Concurrent Processing Remote Code Execution and various Clop ransomware variants. Affected systems include those protected by Check Point IPS and…
2 articles · Updated December 1, 2025
Recent Intelligence Reports
- Ivanti EPMM Zero-Day Flaws: RCE Attacks and Critical Patches — Technadu · January 30, 2026
- Cisco Releases Emergency Patch For ISE Vulnerability After Proof-of — Linkedin · January 8, 2026
- Ruh-roh, there's a Cisco ISE bug POC on the loose • The Register — Theregister · January 8, 2026
- Patch Cisco ISE bug now before attackers abuse proof-of — Theregister · January 8, 2026
- Cisco warns of Identity Service Engine flaw with exploit code — Bleepingcomputer · January 8, 2026
- Cisco Vulnerability Exploit: Chinese Hackers Target Email Gateways — Technadu · December 18, 2025
- CVE-2025-20337: Actionable Report for SOC Teams — Socprime · November 18, 2025
- 17th November — Research.Checkpoint · November 17, 2025