InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: ASD warns of ongoing BADCANDY attack exploiting Cisco IOS XE vulnerability
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > ASD warns of ongoing BADCANDY attack exploiting Cisco IOS XE vulnerability
Technology

ASD warns of ongoing BADCANDY attack exploiting Cisco IOS XE vulnerability

November 1, 2025 3 Min Read
Share
ASD warns of ongoing BADCANDY attack exploiting Cisco IOS XE vulnerability
SHARE

The Australian Signals Directorate (ASD) has previously identified an undocumented ‘ bad candy.

According to the intelligence community, this activity included the exploitation of CVE-2023-20198 (CVSS score: 10.0), a critical vulnerability that allows a remote, unauthenticated attacker to create an account with elevated privileges and use it to seize control of a susceptible system.

This security flaw has been actively exploited since last year in 2023, and China-linked threat actors such as Salt Typhoon have weaponized it to infiltrate telecommunications providers in recent months.

ASD noted that BADCANDY variants have been detected since October 2023, and new attacks continue to be recorded in 2024 and 2025. It is estimated that up to 400 devices in Australia have been compromised by the malware since July 2025, with 150 devices infected in October alone.

“BADCANDY is a low-capital Lua-based web shell that cyber attackers typically apply non-persistent patches to after a breach to hide the vulnerability status of devices related to CVE-2023-20198,” the paper said. “In these examples, the presence of the BADCANDY implant indicates compromise of Cisco IOS XE devices with CVE-2023-20198.”

The lack of a persistence mechanism means that it cannot survive a system reboot. However, if a device is left unpatched and exposed to the internet, threat actors can reintroduce malware and regain access to the device.

ASD has assessed that threat actors can detect when the implant is removed and the device becomes reinfected. This is based on the fact that the re-exploitation occurred on a device for which authorities had previously issued a notice to affected organizations.

See also  Chinese apt deploys egg stream fireless malware to infringe Philippine military systems

That being said, a reboot will not undo any other actions taken by the attacker. Therefore, it is important that system operators apply patches, limit exposure of the web user interface, and follow any necessary hardening guidelines issued by Cisco to prevent future exploitation attempts.

Some of the other measures outlined by the agency are listed below.

  • Check the run settings for accounts with permission 15 and remove unexpected or unauthorized accounts
  • Check for accounts containing random strings or “cisco_tac_admin,” “cisco_support,” “cisco_sys_manager,” or “cisco” and remove them if they are not legitimate.
  • Check the running configuration of the unknown tunnel interface.
  • Check TACACS+ AAA command accounting logging for configuration changes (if enabled)
Share This Article
Twitter Copy Link
Previous Article Roblox Music Codes November 2025 - Best Song IDs Roblox Music Codes November 2025 – Best Song IDs
Next Article Governor Gavin Newsom and Kamala Harris rally Californians to vote on Proposition 50 Governor Gavin Newsom and Kamala Harris rally Californians to vote on Proposition 50

Latest News

Silver Fox uses fake Microsoft Teams installer to spread ValleyRAT malware in China

Silver Fox uses fake Microsoft Teams installer to spread ValleyRAT malware in China

threat actor known as silver fox In attacks targeting Chinese…

December 4, 2025
Critical RSC bug in React and Next.js allows unauthenticated remote code execution

Critical RSC bug in React and Next.js allows unauthenticated remote code execution

A maximum severity security flaw has been disclosed in React…

December 3, 2025
India orders messaging apps to work only with active SIM cards to prevent fraud and abuse

India orders messaging apps to work only with active SIM cards to prevent fraud and abuse

India's Department of Telecommunications (DoT) has directed app-based telecom service…

December 2, 2025
India orders mobile phone manufacturers to pre-install Sanchar Saathi app to prevent wire fraud

India orders mobile phone manufacturers to pre-install Sanchar Saathi app to prevent wire fraud

India's Ministry of Telecommunications has reportedly asked major mobile device…

December 1, 2025
CISA adds actively exploited XSS bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

CISA adds actively exploited XSS bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated…

November 30, 2025

You Might Also Like

Hackers exploit Triofox flaw to install remote access tools via antivirus
Technology

Hackers exploit Triofox flaw to install remote access tools via antivirus

3 Min Read
North Korean hacker combines BeaverTail and OtterCookie to create advanced JS malware
Technology

North Korean hacker combines BeaverTail and OtterCookie to create advanced JS malware

6 Min Read
A Cybercrime Merger Like No Other — Scattered Spider, LAPSUS$, and ShinyHunters Team Up
Technology

A Cybercrime Merger Like No Other — Scattered Spider, LAPSUS$, and ShinyHunters Team Up

6 Min Read
GPT-5 agent that automatically detects and fixes code defects
Technology

GPT-5 agent that automatically detects and fixes code defects

3 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?