A China-affiliated threat actor has been abusing a zero-day vulnerability in multiple Cisco email appliances to gain access to the underlying system and establish persistence. Cisco confirmed the news in a blog post and a security advisory, urging users to apply provided recommendations and harden their networks.
In its announcement, Cisco said it first spotted the activity on December 10, and determined that it started at least in late November 2025. In the campaign, the threat actor tracked as UAT-9686 abused a bug in Cisco AsyncOS Software for Cisco Secure Email Gateway, and Cisco Secure Email and Web Manager, to execute system-level commands and deploy a persistent Python-based backdoor called Aquashell.
Read more…
Source: TechRadar News
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- Scammers target OnlyFans users with deepfakes
August 6, 2026
OnlyFans creators are used to posting adult videos of themselves online, but what happens if someone takes control of their images and uses them for fraud? This week, USA Today revealed how criminals are impersonating OnlyFans creators using AI tools. They use deepfake content to lure the real models’ fans with fake promises of live chats, and ...
- Token Jacking: Cybercriminals Could Be Stealing Your AI Resources
August 6, 2026
It’s three a.m., do you know what your AI agent is doing? Unit 42 has responded to a growing number of AI token jacking cases resulting in staggering financial losses. The financial loss comes from criminals gaining access to API keys used by legitimate developers for access to popular AI platforms. These keys are known ...
- TP-Link router owners update now — 15 flaws patched to stop hackers hijacking your devices
August 5, 2026
TP-Link has patched more than a dozen vulnerabilities across multiple business networking products which could have been chained to achieve remote code execution (RCE). Security researchers at Vedere Labs from Forescout found the flaws and published an in-depth report on the issues, which particularly affect TP-Link Omada, the company’s business networking platform for centrally managing enterprise and small-business ...
- How legitimate cloud platforms enable phishers to bypass MFA
August 4, 2026
Threat actors are increasingly exploiting legitimate cloud services to evade detection and streamline the deployment of their scam infrastructure. Cloud hosting services and decentralized networks have become primary platforms for hosting phishing pages and sites. Throughout 2025 and 2026, Kaspersky researchers have observed phishing operators steadily migrate toward platforms like Cloudflare Workers, Vercel, Netlify, GitHub ...
- Over 100,000 UK Police and staff have personal data leaked in attack on national database
August 4, 2026
The UK’s Police National Legal Database (PNLD) suffered a cyberattack recently, in which it allegedly lost sensitive data on more than 100,000 criminal justice professionals. In a short press release, PNLD confirmed the breach, saying it happened over a weekend. The threat actors, which were not named in the announcement, were said to have taken names, organizations, and ...
- CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild
August 4, 2026
On August 2, 2026, N-able published a security advisory for CVE-2026-18577, an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix for an earlier authentication bypass issue, CVE-2026-18556 was disclosed. CVE-2026-18577 allows a remote unauthenticated attacker to bypass authentication and obtain administrative control of vulnerable N-central servers in affected deployments. N-able N-central is a widely deployed Remote ...
