Hackers are turning Cisco and Citrix zero-days into a malware nightmare


  • CVE-2025-20337 allows unauthorized remote code execution in Cisco ISE systems
  • Attackers implemented in-memory custom web shells with advanced evasion and encryption techniques
  • Exploitation was widespread and indiscriminate with no specific industry or actor attribution

“Sophisticated” threat actors have used a maximum severity zero-day vulnerability in Cisco Identity Service Engine (ISE) and Citrix systems to deploy custom backdoor malware, experts have claimed.

Amazon’s threat intelligence team said it recently stumbled upon an insufficient validation of user-supplied input vulnerability in Cisco ISE deployments, which achieved pre-authentication, remote code execution on compromised endpoints and provided administrator-level access to the systems.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top