
- Cisco confirms zero‑day (CVE‑2025‑20393) in Secure Email appliances exploited by China‑linked actors
- Attackers deployed Aquashell backdoor, tunneling tools, and log‑clearing utilities for persistence
- CISA added flaw to KEV; agencies must remediate/stop use by December 24
A China-affiliated threat actor has been abusing a zero-day vulnerability in multiple Cisco email appliances to gain access to the underlying system and establish persistence.