Cisco IOS XE is a network operating system used on Cisco routers and switches.
Cisco IOS XE is a network operating system used on Cisco routers and switches. Recent activity shows an old vulnerability, named BadCandy, being actively exploited to implant the BADCANDY webshell on exposed devices, enabling persisted remote access and control of network infrastructure. The incidents have prompted warnings from Australian authorities, underscoring the risk to unpatched IOS XE deployments and the potential impact on critical networks.
A joint advisory from 21 global cybersecurity agencies warns that Russian state hackers from the FSB's Center 16 are exploiting poorly configured routers to infiltrate critical infrastructure networks worldwide. The…
Cisco has released critical security advisories for multiple vulnerabilities affecting its IOS XE and Catalyst SD-WAN Software. The advisories, published on August 5, 2026, detail vulnerabilities that could allow…
At Black Hat USA 2026, researcher Malcolm Stagg disclosed NatJack, a new attack class exploiting design flaws in Network Address Translation (NAT) systems. All 32 tested NAT products across Windows, Linux, and macOS…
Chinese hackers, identified as part of the Salt Typhoon operation, have infiltrated at least nine major U.S. communications networks, raising alarms among U.S. policymakers. The operation has been characterized by…
In July 2025, an advanced persistent threat actor known as UNC3886 targeted Singapore's four telecommunications companies, compromising critical infrastructure. The attack was detected by the Infocomm Media Development…
Cisco has patched a vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products. The flaw, tracked as CVE-2026-20029, allows remote attackers with admin-level privileges to…
Hackers are actively exploiting a vulnerability in Cisco IOS XE to deploy the BADCANDY web shell. This attack targets devices running the affected software, allowing unauthorized access and control. The ongoing…
China-linked hackers have targeted a U.S. non-profit organization as part of a long-term espionage campaign. The attack is attributed to a group known as UNC6384, which has also exploited a Windows zero-day…
Hackers are actively exploiting a vulnerability in Cisco IOS XE to deploy the BADCANDY web shell. This exploitation is occurring in the wild, affecting systems running the vulnerable software. The BADCANDY web shell…
Cyberattacks exploiting a critical vulnerability in Cisco IOS XE (CVE-2023-20198) continue, with over 150 devices in Australia still infected with the BadCandy webshell as of late October 2025. Despite patches being…