Related Threat Clusters
-
Cisco AsyncOS Zero-Day Exploited by Chinese APT Group
A zero-day vulnerability in Cisco AsyncOS Software has been actively exploited since late November 2025. The attack targets Secure Email Gateway and Secure Email and Web Manager, allowing attackers to execute…
2 articles · Updated December 18, 2025 -
Critical RCE Vulnerability in n8n Affects Over 100K Servers
A critical remote code execution vulnerability (CVE-2025-68613) in the n8n workflow automation platform has been disclosed, potentially impacting over 100,000 servers, primarily in the United States. The flaw, which has…
4 articles · Updated December 24, 2025 -
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
1438 articles · Updated February 9, 2026 -
Chinese Hackers Exploit Cisco's AsyncOS Zero-Day Vulnerability
Cisco has reported that Chinese hackers are exploiting a zero-day vulnerability in its AsyncOS software, which allows unauthorized root access to Secure Email appliances. The flaw affects Cisco's Secure Email Gateway…
5 articles · Updated December 18, 2025 -
Cisco ASA Zero-Day Exploited in State-Espionage Campaign
Cisco disclosed a state-espionage campaign targeting its Adaptive Security Appliances (ASA), which are used for firewall and VPN functions. Attackers exploited two zero-day vulnerabilities to infiltrate government…
27 articles · Updated December 18, 2025 -
Cisco Patches ISE Vulnerability with Public Exploit Code
Cisco has patched a vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products. The flaw, tracked as CVE-2026-20029, allows remote attackers with admin-level privileges to…
7 articles · Updated January 8, 2026 -
Cisco Confirms Exploitation of AsyncOS Zero-Day by Chinese Hackers
Cisco has reported an unpatched zero-day vulnerability (CVE-2025-20393) in its AsyncOS software, affecting Secure Email Gateway and Secure Email and Web Manager appliances. The vulnerability is being actively exploited…
5 articles · Updated December 17, 2025 -
Automated Credential Campaign Targets VPN Services
GreyNoise is monitoring a coordinated credential-based attack campaign aimed at enterprise VPN authentication systems, specifically targeting Cisco SSL VPN and Palo Alto Networks GlobalProtect services. The campaign…
5 articles · Updated December 17, 2025
Recent Intelligence Reports
- Ransomware gang exploits Cisco flaw in zero — Bleepingcomputer · March 18, 2026
- Cisco Issues Emergency Patches for Critical Firewall Management Vulnerabilities — Linkedin · March 4, 2026
- Cisco warns of max severity Secure FMC flaws giving root access — Bleepingcomputer · March 4, 2026
- Cisco Releases Emergency Patch For ISE Vulnerability After Proof-of — Linkedin · January 8, 2026
- Cisco warns of Identity Service Engine flaw with exploit code — Bleepingcomputer · January 8, 2026
- CVE-2025-68613: Critical RCE Vulnerability Disclosed in n8n Workflow Automation — Socradar · December 23, 2025
- New password spraying attacks target Cisco, PAN VPN gateways — Bleepingcomputer · December 18, 2025
- Cisco says Chinese hackers are exploiting its customers with a new zero-day — Techradar · December 18, 2025