• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

ASD Warns of Ongoing BADCANDY Assaults Exploiting Cisco IOS XE Vulnerability

Admin by Admin
November 1, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Nov 01, 2025Ravie LakshmananSynthetic Intelligence / Vulnerability

The Australian Alerts Directorate (ASD) has issued a bulletin about ongoing cyber assaults focusing on unpatched Cisco IOS XE gadgets within the nation with a beforehand undocumented implant referred to as BADCANDY.

The exercise, per the intelligence company, entails the exploitation of CVE-2023-20198 (CVSS rating: 10.0), a crucial vulnerability that enables a distant, unauthenticated attacker to create an account with elevated privileges and use it to grab management of inclined techniques.

The safety defect has come beneath energetic exploitation within the wild since final 2023, with China-linked risk actors like Salt Hurricane weaponizing it in current months to breach telecommunications suppliers.

DFIR Retainer Services

ASD famous that variations of BADCANDY have been detected since October 2023, with a contemporary set of assaults persevering with to be recorded in 2024 and 2025. As many as 400 gadgets in Australia are estimated to have been compromised with the malware since July 2025, out of which 150 gadgets have been contaminated in October alone.

“BADCANDY is a low fairness Lua-based net shell, and cyber actors have usually utilized a non-persistent patch post-compromise to masks the gadget’s vulnerability standing in relation to CVE-2023-20198,” it stated. “In these cases, the presence of the BADCANDY implant signifies compromise of the Cisco IOS XE gadget, through CVE-2023-20198.”

The dearth of a persistence mechanism means it can not survive throughout system reboots. Nonetheless, if the gadget stays unpatched and uncovered to the web, it is doable for the risk actor to re-introduce the malware and regain entry to it.

ASD has assessed that the risk actors are capable of detect when the implant is eliminated and are infecting the gadgets once more. That is primarily based on the truth that re-exploitation has occurred on gadgets for which the company has beforehand issued notifications to affected entities.

That having stated, a reboot won’t undo different actions undertaken by the attackers. It is subsequently important that system operators apply the patches, restrict public publicity of the online consumer interface, and comply with essential hardening tips issued by Cisco to stop future exploitation makes an attempt.

CIS Build Kits

A number of the different actions outlined by the company are listed beneath –

  • Overview the working configuration for accounts with privilege 15 and take away sudden or unapproved accounts
  • Overview accounts with random strings or “cisco_tac_admin,” “cisco_support,” “cisco_sys_manager,” or “cisco” and take away them if not respectable
  • Overview the working configuration for unknown tunnel interfaces
  • Overview TACACS+ AAA command accounting logging for configuration modifications, if enabled
Tags: ASDAttacksBADCANDYCiscoExploitingiOSOngoingVulnerabilitywarns
Admin

Admin

Next Post
Detecting and Fixing ‘Lifeless Neurons’ in Basis Fashions

Detecting and Fixing 'Lifeless Neurons' in Basis Fashions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

Reconeyez Launches New Web site | SDM Journal

Reconeyez Launches New Web site | SDM Journal

May 15, 2025
Safety Amplified: Audio’s Affect Speaks Volumes About Preventive Safety

Safety Amplified: Audio’s Affect Speaks Volumes About Preventive Safety

May 18, 2025
Flip Your Toilet Right into a Good Oasis

Flip Your Toilet Right into a Good Oasis

May 15, 2025
Apollo joins the Works With House Assistant Program

Apollo joins the Works With House Assistant Program

May 17, 2025
Discover Vibrant Spring 2025 Kitchen Decor Colours and Equipment – Chefio

Discover Vibrant Spring 2025 Kitchen Decor Colours and Equipment – Chefio

May 17, 2025

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

Tech Life – Chatbots altering minds

Tech Life – Chatbots altering minds

February 11, 2026
Subsequent Gen Spotlights: Turning Behavioural Intelligence right into a Highly effective Instrument In opposition to Fraud and Crime – Q&A with Paddy Lawton, Co-Founding father of FACT360

Subsequent Gen Spotlights: Turning Behavioural Intelligence right into a Highly effective Instrument In opposition to Fraud and Crime – Q&A with Paddy Lawton, Co-Founding father of FACT360

February 11, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved