CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◉ Threat Intelligence

Sophisticated threat actor targeting zero-day flaws in Cisco ISE and Citrix - Cybersecurity Dive

Cybersecurity Dive Archived Mar 17, 2026 ✓ Full text saved

Sophisticated threat actor targeting zero-day flaws in Cisco ISE and Citrix Cybersecurity Dive

Full text archived locally
✦ AI Summary · Claude Sonnet


    Sophisticated threat actor targeting zero-day flaws in Cisco ISE and Citrix Hackers use custom malware to access multiple vulnerabilities, researchers from Amazon warn. Published Nov. 12, 2025 David Jones Reporter Share License Add us on Google Getty Images An advanced persistent threat actor has been targeting zero-day vulnerabilities in Cisco Identity Service Engine as well as Citrix, according to a blog post published Wednesday by security researchers at Amazon. Amazon said it had previously detected threat activity targeting the CitrixBleed 2 vulnerability, tracked as CVE-2025-5777, through its MadPot honeypot service. The detection indicated the exploitation activity was taking place prior to public disclosure. Citrix released guidance in June to address CitrixBleed 2.  Additional investigation found an “anomalous payload” targeting a previously undocumented endpoint in Cisco ISE that used vulnerable deserialization logic, CJ Moses, CISO of Amazon Integrated Security, said in the blog.  The vulnerability, tracked as CVE-2025-20337, lets an attacker achieve pre-authentication remote code execution on Cisco ISE. This allows administrator-level access to compromised systems.  The hacker deployed a custom web shell that was disguised to appear as a legitimate Cisco ISE component named IdentityAuditAction. The malware was not off the shelf, according to Amazon researchers, but was instead a backdoor specifically designed to target Cisco ISE environments.  Cisco previously released software updates to address the problem.   Add us on Google Share PURCHASE LICENSING RIGHTS Filed Under: Vulnerability, Threats
    💬 Team Notes
    Article Info
    Source
    Cybersecurity Dive
    Category
    ◉ Threat Intelligence
    Published
    Archived
    Mar 17, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗