#CISCO

2025-12-20

December 20th, 2025 - CryptoGen Cyber Threat Intelligence Advisory #8792 -Zero-Day Vulnerability in Cisco AsyncOs has been Patched

Pulse ID: 6946809ea5bcc20ecd930697
Pulse Link: otx.alienvault.com/pulse/69468
Pulse Author: cryptocti
Created: 2025-12-20 10:55:26

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Cisco #CryptoGen #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Vulnerability #ZeroDay #bot #cryptocti

Andrea :prami: 🇮🇹 🇬🇧andreab@social.lol
2025-12-20

Three years ago, I was at a crossroads.

I already had my CCIE Routing & Switching for quite some time, and I was asking myself the big question: what’s next?
DevNet? CCIE Security? I started exploring both… but something kept pulling me towards one thing: design. The kind of work where you don’t just make networks run, you make them make sense.

So I went all-in.

I poured every spare hour into the CCDE path, starting with the written exam (400-007). In June 2024 I passed the CCDE Written in Las Vegas and thought, right, now it’s “just” the practical.

I knew the practical would be tough.
I did not expect it to take a year and a half of my life.

Early mornings. Most weekends. A few nights every week with the study group.
And, if I’m being brutally honest, a lot of it was time borrowed from my family. Time they graciously sacrificed with me, even when it wasn’t fun, even when it dragged on.

But today… I walked into the Cisco office in London knowing it was the day.
Almost 7 hours exam (yes, I finished a bit early). Then, I waited. Waited. And waited. In the end, the email arrived.

“𝗬𝗼𝘂𝗿 𝗖𝗖𝗗𝗘 𝘀𝘁𝗮𝘁𝘂𝘀 𝗶𝘀 𝗖𝗲𝗿𝘁𝗶𝗳𝗶𝗲𝗱 (𝗖𝗖𝗗𝗘 𝟮𝟬𝟮𝟱𝟬𝟬𝟲𝟰)”

I’m proud. I’m relieved. And I’m genuinely grateful.

To my study group: you kept me accountable when motivation wasn’t enough.
To my family: you carried a chunk of this journey with me.
To everyone who’s grinding through something big right now: keep going, but don’t forget why you started.

Now… I’m going to take a breath. Then I’ll decide what’s next. 🙂

#CCDE #CCIE #CCNP #CCNA #NetworkDesign #Cisco #CareerJourney #Learning #NeverStopLearning

2025-12-20

Hàng trăm khách hàng Cisco đang đối mặt với chiến dịch tấn công mạng từ các tin tặc Trung Quốc khai thác lỗ hổng zero-day. Lỗ hổng này cho phép truy cập từ xa vào router, switch và firewall, đe dọa dữ liệu và an ninh mạng. Các tổ chức cần cập nhật phần mềm, áp dụng biện pháp bảo mật, kiểm tra hệ thống định kỳ.

#Cisco #CyberAttack #ZeroDay #ChinaHackers #CyberSecurity #BảoMậtMạng #TấnCôngMạng #AnToànThôngTin #CyberThreat #LỗHổngBảoMật

dev.to/yagyaraj_sharma_6cd4101

Fortiguard Outbreak Alerts posted this critical vulnerability yesterday:

Cisco ASA and FTD Firewall RCE fortinet.com/fortiguard/labs @fortinet #infosec #Cisco

CyberNetsecIOnetsecio
2025-12-19

📰 China-Linked Hackers Exploit Critical Cisco Email Gateway Zero-Day

🇨🇳 A China-linked APT is exploiting a critical 10.0 CVSS zero-day (CVE-2025-20393) in Cisco Email Gateways for root-level RCE. CISA has added it to the KEV catalog. Patch immediately! 🛡️

🔗 cyber.netsecops.io/articles/ch

Security Landsecurityland
2025-12-19

Chinese threat actor UAT-9686 has been compromising Cisco email security systems since late November with a custom backdoor called AquaShell. Organizations should immediately check Cisco Talos advisories for indicators and remediation guidance.

Read More: security.land/uat-9686-chinese

2025-12-19

Najsłynniejsza arena świata z nowym cyfrowym sercem. Cisco wchodzi do Madison Square Garden

Jeśli kiedykolwiek próbowaliście wysłać wideo z koncertu przy pełnej sali i widzieliście tylko kręcące się kółko ładowania, wiecie, jak ważna jest infrastruktura.

Madison Square Garden Entertainment (MSG) właśnie ogłosiło wieloletnie partnerstwo z Cisco, które ma sprawić, że cyfrowe doświadczenia w „The Garden” będą równie legendarne, jak występy na scenie.

Cisco oficjalnie dołącza do grona partnerów MSG, jednej z najbardziej rozpoznawalnych aren na świecie. Cel jest prosty: stworzenie skalowalnego, bezpiecznego i niezawodnego środowiska dla milionów fanów odwiedzających obiekt każdego roku.

Co siedzi w ścianach The Garden?

Współpraca nie jest tylko marketingowym zabiegiem – MSG już korzysta z szerokiego portfolio rozwiązań Cisco, a nowa umowa ma to jeszcze pogłębić. Fundamentem sieci są przełączniki Cisco Catalyst, które odpowiadają za stabilność połączeń. Całością zarządza Cisco Catalyst Center, co daje zespołom IT pełną widoczność i analitykę niezbędną do optymalizacji działania sieci w czasie rzeczywistym.

Co ciekawe, infrastruktura jest już przygotowywana pod rozwiązania oparte na sztucznej inteligencji. W centrach danych MSG pracują przełączniki Cisco Nexus 9000 zarządzane przez Nexus Dashboard, które zapewniają wydajność niezbędną dla środowisk AI.

Bezpieczeństwo i wygoda

W dobie cyfrowej, bezpieczeństwo sieci w takim obiekcie jest kluczowe. Za kontrolę dostępu odpowiada tu Cisco Identity Services Engine (ISE), który automatyzuje procesy i pilnuje standardów bezpieczeństwa podczas każdego wydarzenia. Dla przeciętnego fana najważniejsza będzie jednak infrastruktura bezprzewodowa, która ma zapewniać stabilne Wi-Fi, kluczowe dla dzisiejszych cyfrowych doświadczeń.

– Kompetencje Cisco w zakresie budowy wydajnej i niezawodnej infrastruktury sieciowej pozwalają nam zapewnić stabilną łączność artystom, zespołom produkcyjnym i publiczności – podsumował Doug Jossem z MSG Entertainment.

Cisco: rok 2026 będzie rokiem spłaty „długu technologicznego”. AI dusi obecną infrastrukturę

#Cisco #CiscoCatalyst #infrastrukturaSieciowa #MadisonSquareGarden #MSGEntertainment #technologieSceniczne #WiFi
Cisco Madison Square GardenCisco Madison Square Garden
2025-12-19

Cisco is offering 200+ free training courses to help you master AI and networking. In this interview, we discuss why 78% of tech roles now require AI skills and how to future - proof your career in 2025.

Watch the video on YouTube: youtube.com/watch?v=tASaKmXLI7Y

A big thank you to Cisco for sponsoring this video and sponsoring my trip to the Cisco Partner Summit San Diego 2025

#cisco #ciscops25 #freetrainingvideos

New.

CISA Releases Nine Industrial Control Systems Advisories cisa.gov/news-events/alerts/20

KEV updates, from yesterday:

CVE-2025-20393: Cisco Multiple Products Improper Input Validation Vulnerability cve.org/CVERecord?id=CVE-2025-

CVE-2025-40602: SonicWall SMA1000 Missing Authorization Vulnerability cve.org/CVERecord?id=CVE-2025-

CVE-2025-59374: ASUS Live Update Embedded Malicious Code Vulnerability cve.org/CVERecord?id=CVE-2025- #CISA #infosec #ASUS #Cisco #SonicWall

BGDon 🇨🇦 🇺🇸 👨‍💻BrentD@techhub.social
2025-12-18

Cisco is reporting a zero day vulnerability that Chinese threat actors are using to to install persistent backdoors in virtual appliances running Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager.

The vulnerability enables actors to execute arbitrary commands with root privileges on the underlying operating system, and they can maintain a degree of control over compromised appliances.

At the time of writing there is no patch, Cisco is recommending rebuilding affected appliance(s). sec.cloudapps.cisco.com/securi #Cisco #ZeroDay #Security #Hackers #CyberAttack #CyberHack #CyberSecurity

Cisco Logo

Security Week: China-Linked Hackers Exploiting Zero-Day in Cisco Security Gear securityweek.com/china-linked- @SecurityWeek

Cisco:

- Critical: CVE-2025-20393: Reports About Cyberattacks Against Cisco Secure Email Gateway And Cisco Secure Email and Web Manager sec.cloudapps.cisco.com/securi

- Critical: CVE-2025-55182: Remote Code Execution Vulnerability in React and Next.js Frameworks: December 2025 sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #Cisco #vulnerability #zeroday

2025-12-18

Onsdag meddelte #Cisco, at hackere udnytter en kritisk sårbarhed- #0day i nogle af de mest populære produkter, som gør det muligt at overtage fuld kontrol over de berørte enheder

Det værste er, at der på nuværende tidspunkt ikke findes nogen patches.

.. oplyste Cisco, at man den 10. december havde opdaget en kampagne rettet mod Cisco AsyncOS-software, og i særdeleshed de fysiske og virtuelle enheder Cisco Secure Email Gateway, Cisco Secure Email og Web Manager
techcrunch.com/2025/12/17/cisc

2025-12-18

Hackers Actively Attacking Cisco and Palo Alto Networks VPN Gateways to Gain Login Access

Threat actors launched a coordinated brute-force campaign against
enterprise VPN gateways,

Pulse ID: 6943ec7aad5a67ddce4c075e
Pulse Link: otx.alienvault.com/pulse/6943e
Pulse Author: cryptocti
Created: 2025-12-18 11:58:50

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Cisco #CyberSecurity #InfoSec #OTX #OpenThreatExchange #PaloAlto #RCE #VPN #bot #cryptocti

2025-12-18

Active Cisco unpatched vulneratbility exploited in Secure Email Gateway appliances.
✔ Root-level access
✔ Chinese-linked APT
✔ No patch - wipe & rebuild recommended

Details:
technadu.com/cisco-zero-day-vu

#ZeroDay #EmailSecurity #Cisco

Cisco Zero-Day Vulnerability in Secure Email Gateways Exploited in Chinese Hacking Campaign
2025-12-18

Attacks on Zero-Day Vulnerabilities: Cisco, Sonicwall, and Asus Live Update

CISA warns of observed attacks on Cisco, Sonicwall, and Asus security vulnerabilities. Updates are partially available.

heise.de/en/news/Attacks-on-Ze

#Asus #Cisco #Cyberangriff #IT #Security #Sicherheitslücken #Dell #Updates #news

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst