Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

The fastest-growing jobs in the creator economy aren’t in front of the camera.

Lee Suk-Quin explores the truth with new album “72RHR”

Vote for Sombre, Phoebe Bridgers and more

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » ASD warns of ongoing BADCANDY attack exploiting Cisco IOS XE vulnerability
Celebrities

ASD warns of ongoing BADCANDY attack exploiting Cisco IOS XE vulnerability

By November 1, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

November 1, 2025Ravi LakshmananArtificial intelligence/vulnerabilities

The Australian Signals Directorate (ASD) has issued information regarding an ongoing cyberattack targeting unpatched Cisco IOS XE devices in the country and a previously undocumented implant known as BADCANDY.

According to the intelligence community, this activity included the exploitation of CVE-2023-20198 (CVSS score: 10.0), a critical vulnerability that allows a remote, unauthenticated attacker to create an account with elevated privileges and use it to seize control of a susceptible system.

This security flaw has been actively exploited since last year in 2023, and China-linked threat actors such as Salt Typhoon have weaponized it to infiltrate telecommunications providers in recent months.

DFIR retainer service

ASD noted that BADCANDY variants have been detected since October 2023, and new attacks continue to be recorded in 2024 and 2025. It is estimated that up to 400 devices in Australia have been compromised by the malware since July 2025, with 150 devices infected in October alone.

“BADCANDY is a low-capital Lua-based web shell that cyber attackers typically apply non-persistent patches to after a breach to hide the vulnerability status of devices related to CVE-2023-20198,” the paper said. “In these examples, the presence of the BADCANDY implant indicates compromise of Cisco IOS XE devices with CVE-2023-20198.”

The lack of a persistence mechanism means that it cannot survive a system reboot. However, if a device is left unpatched and exposed to the internet, threat actors can reintroduce malware and regain access to the device.

ASD has assessed that threat actors can detect when the implant is removed and the device becomes reinfected. This is based on the fact that the re-exploitation occurred on a device for which authorities had previously issued a notice to affected organizations.

That being said, a reboot will not undo any other actions taken by the attacker. Therefore, it is important that system operators apply patches, limit exposure of the web user interface, and follow any necessary hardening guidelines issued by Cisco to prevent future exploitation attempts.

CIS build kit

Some of the other measures outlined by the agency are listed below.

Check the running configuration for accounts with privilege 15 and remove any unexpected or unauthorized accounts. Check for accounts containing random strings or “cisco_tac_admin,” “cisco_support,” “cisco_sys_manager,” or “cisco” and remove them if they are not legitimate. Check the running configuration of the unknown tunnel interface. Check TACACS+ AAA command accounting logging for configuration changes (if enabled).


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleChimpanzees ‘think’ to weigh evidence and plan actions, new study suggests
Next Article AI researchers begin to ’embodi’ LLM into robots and channel Robin Williams

Related Posts

Bettina Anderson reveals the designer of her wedding dress

June 26, 2026

Queen Letizia of Madrid Sports Sleeveless Hugo Boss Dress

June 26, 2026

Zendaya & Tom Holland’s ‘Spider-Man’ Press Tour Couple Style

June 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

The fastest-growing jobs in the creator economy aren’t in front of the camera.

Lee Suk-Quin explores the truth with new album “72RHR”

Vote for Sombre, Phoebe Bridgers and more

Bettina Anderson reveals the designer of her wedding dress

Trending Posts

Vote for Sombre, Phoebe Bridgers and more

June 26, 2026

Bettina Anderson reveals the designer of her wedding dress

June 26, 2026

Queen Letizia of Madrid Sports Sleeveless Hugo Boss Dress

June 26, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.