TechBriefly
  • Tech
  • Business
  • Crypto
  • Science
  • Geek
  • How to
  • About
    • About TechBriefly
    • Terms and Conditions
    • Privacy Policy
    • Contact Us
    • Languages
      • 中文 (Chinese)
      • Dansk
      • Deutsch
      • Español
      • English
      • Français
      • Nederlands
      • Italiano
      • 日本语 (Japanese)
      • 한국인 (Korean)
      • Norsk
      • Polski
      • Português
      • Pусский (Russian)
      • Suomalainen
      • Svenska
No Result
View All Result
TechBriefly
Home Tech Security
Cisco announces hackers exploiting AsyncOS zero-day

Cisco announces hackers exploiting AsyncOS zero-day

Aytun ÇelebibyAytun Çelebi
19 December 2025
in Security
Reading Time: 2 mins read
Share on FacebookShare on Twitter

Cisco announced on Wednesday that hackers are exploiting a critical zero-day vulnerability in several of its popular products, enabling full takeover of affected devices. No patches are currently available.

The company disclosed the hacking campaign in a security advisory, stating it discovered the activity on December 10. The attacks target Cisco AsyncOS software used in physical and virtual appliances, including Cisco Secure Email Gateway, Cisco Secure Email, and Web Manager. Vulnerable devices have the “Spam Quarantine” feature enabled and are accessible from the internet. Cisco noted that this feature is not enabled by default and does not require internet exposure.

Michael Taggart, a senior cybersecurity researcher at UCLA Health Sciences, told TechCrunch that “the requirement of an internet-facing management interface and certain features being enabled will limit the attack surface for this vulnerability.”

Kevin Beaumont, a security researcher who tracks hacking campaigns, described the situation to TechCrunch as particularly problematic. He pointed out that many large organizations use the affected products, no patches exist, and the duration of the hackers’ backdoors in compromised systems remains unclear. Cisco has not disclosed the number of affected customers.

Cisco spokesperson Meredith Corley told TechCrunch that the company “is actively investigating the issue and developing a permanent remediation.” She did not respond to additional questions. In the advisory, Cisco recommends wiping and rebuilding affected appliances as the only current option to remove the threat actors’ persistence mechanisms. The advisory states: “In case of confirmed compromise, rebuilding the appliances is, currently, the only viable option to eradicate the threat actors persistence mechanism from the appliance.”

Cisco Talos, the company’s threat intelligence team, linked the hackers to China and known Chinese government hacking groups in a blog post. Talos reported that the actors are using the zero-day vulnerability to install persistent backdoors. The campaign has been active since at least late November 2025.

Tags: CiscoZero-day exploit
ShareTweet
Aytun Çelebi

Aytun Çelebi

Starting with coding on Commodore 64 in elementary school moving to web programming in his teenage years, Aytun has been around technology for over 30 years, and he has been a tech journalist for over 20 years now. He worked in many major Turkish outlets (newspapers, magazines, TV channels and websites) and managed some. Besides journalism, he worked as a copywriter and PR manager (for Lenovo, HP and many international brands ) in agencies. He founded his agency, Linkmedya in 2019 to execute his way of producing content. He is recently interested in AI, automation and MarTech.

Related Posts

Google patches critical Gemini flaw that turned invites into attack vectors

Google patches critical Gemini flaw that turned invites into attack vectors

21 January 2026
Microsoft issues emergency fix for Windows 11 shutdown bugs

Microsoft issues emergency fix for Windows 11 shutdown bugs

19 January 2026
Ashley St. Clair sues xAI over Grok deepfakes

Ashley St. Clair sues xAI over Grok deepfakes

16 January 2026
YouTube launches Shorts timers to combat teen doomscrolling

YouTube launches Shorts timers to combat teen doomscrolling

15 January 2026

LATEST

OpenAI appoints Barret Zoph to lead enterprise sales

Vimeo begins global staff reductions following Bending Spoons acquisition

LiveKit reaches unicorn status with $100 million in new funding

Substack launches TV app for Apple and Google platforms

Oracle and Silver Lake lead consortium in landmark TikTok US deal

JBL enters the practice amp market with AI-driven Stem separation technology

Google Search adds “Personal Intelligence” to AI Mode

Amazon set to launch second wave of corporate layoffs next week

Blue Origin’s New Glenn-3 mission to deploy AST SpaceMobile’s BlueBird 7

Anthropic redesigns hiring tests after Claude 4.5 “aces” human interview

TechBriefly

© 2021 TechBriefly is a Linkmedya brand.

  • Tech
  • Business
  • Science
  • Geek
  • How to
  • About
  • Privacy
  • Terms
  • Contact
  • | Network Sites |
  • Digital Report
  • LeaderGamer

Follow Us

No Result
View All Result
  • Tech
  • Business
  • Crypto
  • Science
  • Geek
  • How to
  • About
    • About TechBriefly
    • Terms and Conditions
    • Privacy Policy
    • Contact Us
    • Languages
      • 中文 (Chinese)
      • Dansk
      • Deutsch
      • Español
      • English
      • Français
      • Nederlands
      • Italiano
      • 日本语 (Japanese)
      • 한국인 (Korean)
      • Norsk
      • Polski
      • Português
      • Pусский (Russian)
      • Suomalainen
      • Svenska