Hackers Turn Cisco and Citrix Zero Days into a Malware Nightmare


  • CVE-2025-20337 Allows Unauthenticated Remote Code Execution in Cisco ISE Systems
  • The attackers deployed custom in-memory web shells with advanced evasion and encryption techniques.
  • The exploits were widespread and indiscriminate, with no specific attribution to any industry or actor.

“Sophisticated” threat actors used a maximum severity zero-day vulnerability in Cisco Identity Service Engine (ISE) and Citrix systems to deploy custom backdoor malware, experts claimed.

Amazon’s threat intelligence team said it recently discovered insufficient validation of the user-provided input vulnerability in Cisco ISE deployments, allowing pre-authentication remote code execution on compromised endpoints and providing administrator-level access to systems.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top