Secure Email Gateway — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
15
occurrences
First Seen
December 17, 2025
Last Seen
June 11, 2026

Secure Email Gateway is a technology platform tracked across 12 threat clusters and 15 intelligence report mentions on ThreatCluster. First observed December 17, 2025; most recent activity June 11, 2026.

Related Threat Clusters

  • Cisco Fixes Critical AsyncOS Vulnerability Under Attack

    Cisco has addressed a maximum-severity vulnerability in AsyncOS, tracked as CVE-2025-20393, which has been actively exploited for at least a month. The flaw affects Secure Email Gateway (SEG) and Secure Email and Web…

    11 articles · Updated January 15, 2026
  • Cisco AsyncOS Zero-Day Exploited by Chinese APT Group

    A zero-day vulnerability in Cisco AsyncOS Software has been actively exploited since late November 2025. The attack targets Secure Email Gateway and Secure Email and Web Manager, allowing attackers to execute…

    2 articles · Updated December 18, 2025
  • China-linked APT UAT Exploits Cisco AsyncOS Flaw CVE-2025-20393

    Cisco identified a critical zero-day vulnerability, tracked as CVE-2025-20393, in its Secure Email products, which was actively exploited by the China-linked APT group UAT-9686. The flaw, affecting Secure Email Gateway…

    3 articles · Updated January 16, 2026
  • Cisco Issues Warning for Critical Zero-Day Vulnerability in Unified Communications

    Cisco has disclosed a critical zero-day remote code execution vulnerability, CVE-2026-20045, affecting multiple Unified Communications products. This flaw allows unauthenticated attackers to execute arbitrary commands…

    4 articles · Updated January 22, 2026
  • China-Linked Hackers Exploit CVE-2025-20393 Zero-Day Vulnerability

    China-linked hackers are exploiting a critical zero-day vulnerability tracked as CVE-2025-20393. This vulnerability affects Secure Email Gateway and Secure Email and Web Manager appliances, posing risks to organizations…

    4 articles · Updated December 18, 2025
  • AI-Driven Email Attacks Escalate with Frontier AI Technologies

    The emergence of Frontier AI technologies has significantly transformed the landscape of email security. Anthropic's Claude Mythos Preview can now generate convincing phishing lures at unprecedented speeds, allowing…

    2 articles · Updated June 11, 2026
  • Chinese Hackers Exploit Cisco's AsyncOS Zero-Day Vulnerability

    Cisco has reported that Chinese hackers are exploiting a zero-day vulnerability in its AsyncOS software, which allows unauthorized root access to Secure Email appliances. The flaw affects Cisco's Secure Email Gateway…

    5 articles · Updated December 18, 2025
  • Cisco ASA Zero-Day Exploited in State-Espionage Campaign

    Cisco disclosed a state-espionage campaign targeting its Adaptive Security Appliances (ASA), which are used for firewall and VPN functions. Attackers exploited two zero-day vulnerabilities to infiltrate government…

    27 articles · Updated December 18, 2025
  • Cisco Confirms Exploitation of AsyncOS Zero-Day by Chinese Hackers

    Cisco has reported an unpatched zero-day vulnerability (CVE-2025-20393) in its AsyncOS software, affecting Secure Email Gateway and Secure Email and Web Manager appliances. The vulnerability is being actively exploited…

    5 articles · Updated December 17, 2025
  • Automated Credential Campaign Targets VPN Services

    GreyNoise is monitoring a coordinated credential-based attack campaign aimed at enterprise VPN authentication systems, specifically targeting Cisco SSL VPN and Palo Alto Networks GlobalProtect services. The campaign…

    5 articles · Updated December 17, 2025

Recent Intelligence Reports

  • The frontier AI era demands better email security architecture — Proofpoint · June 11, 2026
  • China-linked APT UAT — Securityaffairs.Co · January 16, 2026
  • Cisco 0 — Cybersecuritynews · January 16, 2026
  • Cisco's Zero-Day Nightmare: China-Linked Hackers Breach Email Defenses — Webpronews · January 16, 2026
  • Cisco finally fixes max-severity bug under attack for weeks — Theregister · January 15, 2026
  • Cisco finally fixes max — Theregister · January 15, 2026
  • President Trump Orders Divestment in $2.9 Million Chips Deal to Protect US Security Interests — Securityweek · January 3, 2026
  • LeakWatch 2025 - Security incidents, IT scandals and alerts for calendar week 51 — Igorslab.De · December 20, 2025

CVSS v3.1 Breakdown