Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

OpenClaw integrates VirusTotal scanning to detect malicious ClawHub skills

Kids ‘picked last in gym class’ prepare for Super Bowl

NBA star Giannis Antetokounmpo joins Calci as an investor

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Hackers deploy Linux rootkits via Cisco SNMP flaw in ‘Zero Disco’ attack
Identity

Hackers deploy Linux rootkits via Cisco SNMP flaw in ‘Zero Disco’ attack

userBy userOctober 16, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

October 16, 2025Ravi LakshmananVulnerabilities / Linux

Linux rootkit

Cybersecurity researchers have revealed details of a new campaign that exploits recently disclosed security flaws affecting Cisco IOS Software and IOS XE Software to deploy Linux rootkits on older, unprotected systems.

The activity, codenamed “Operation Zero Disco” by Trend Micro, involves the weaponization of CVE-2025-20352 (CVSS score: 7.7), a stack overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow an authenticated, remote attacker to execute arbitrary code by sending crafted SNMP packets to a susceptible device. This intrusion was not caused by any known attacker or group.

The flaw was fixed by Cisco late last month, but not before it was exploited as a zero-day attack in the wild.

DFIR retainer service

“This operation primarily affected Cisco 9400, 9300, and legacy 3750G series devices. There was also an attempt to exploit a modified Telnet vulnerability (based on CVE-2017-3881) to gain memory access,” researchers Dove Chiu and Lucien Chuang said.

The cybersecurity firm also noted that the rootkit allowed attackers to remotely execute code and gain permanent unauthorized access by setting a universal password and installing hooks in the Cisco IOS daemon (IOSd) memory space. IOSd runs as a software process within the Linux kernel.

Another notable aspect of this attack was that it identified victims running older Linux systems without endpoint detection and response solutions enabled, allowing them to fly under the radar and deploy the rootkit. Additionally, the attackers allegedly used spoofed IPs and Mac email addresses for the breach.

In addition to CVE-2025-20352, attackers have also been observed attempting to exploit a Telnet vulnerability that is a modified version of CVE-2017-3881 to allow memory read/write at arbitrary addresses. However, the exact nature of the function remains unknown.

CIS build kit

The name “Zero Disco” comes from the fact that the embedded rootkit sets a universal password containing the word “disco”, which is “Cisco” with one letter changed.

“The malware then installs several hooks on IOSd, which results in the fileless component disappearing after a reboot,” the researchers note. “The new switch model provides some protection through Address Space Layout Randomization (ASLR), which reduces the success rate of intrusion attempts. However, be aware that repeated attempts may still be successful.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleToyota to launch world’s first EV with solid-state battery by 2027 – expected to have a longer lifespan and charge faster
Next Article Jack & Jill raises $20 million to bring conversational AI to job hunting
user
  • Website

Related Posts

OpenClaw integrates VirusTotal scanning to detect malicious ClawHub skills

February 8, 2026

Warning of signal phishing targeting German government agencies, politicians, military personnel and journalists

February 7, 2026

The Legal Revolution is Digital: Meet TwinH, Your AI Partner in the Courtroom of the Future

February 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

OpenClaw integrates VirusTotal scanning to detect malicious ClawHub skills

Kids ‘picked last in gym class’ prepare for Super Bowl

NBA star Giannis Antetokounmpo joins Calci as an investor

New York state lawmaker proposes three-year moratorium on new data centers

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.