{"id":212156,"date":"2025-12-19T20:15:02","date_gmt":"2025-12-19T20:15:02","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2025\/12\/19\/hundreds-of-cisco-customers-are-vulnerable-to-new-chinese-hacking-campaign-researchers-say-techcrunch\/"},"modified":"2025-12-19T20:15:02","modified_gmt":"2025-12-19T20:15:02","slug":"hundreds-of-cisco-customers-are-vulnerable-to-new-chinese-hacking-campaign-researchers-say-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2025\/12\/19\/hundreds-of-cisco-customers-are-vulnerable-to-new-chinese-hacking-campaign-researchers-say-techcrunch\/","title":{"rendered":"Hundreds of Cisco customers are vulnerable to new Chinese hacking campaign, researchers say | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">On Wednesday, Cisco revealed that <a href=\"https:\/\/techcrunch.com\/2025\/12\/17\/cisco-says-chinese-hackers-are-exploiting-its-customers-with-a-new-zero-day\/\" target=\"_blank\" rel=\"noopener\">a group of Chinese government-backed hackers is exploiting a vulnerability<\/a> to target its enterprise customers who use some of the company\u2019s most popular products.<\/p>\n<p class=\"wp-block-paragraph\">Cisco has not said how many of its customers have already been hacked, or may be running vulnerable systems. Now, security researchers say there are hundreds of Cisco customers who could potentially be hacked.<\/p>\n<p class=\"wp-block-paragraph\">Piotr Kijewski, the chief executive of the nonprofit Shadowserver Foundation that scans and monitors the internet for hacking campaigns, told TechCrunch that the scale of exposure \u201cseems more in the hundreds rather than thousands or tens of thousands.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Kijewski said the foundation was not seeing widespread activity, presumably because \u201ccurrent attacks are targeted.\u201d\u00a0<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"http:\/\/dashboard.shadowserver.org\/statistics\/combined\/tree\/?date_range=1&amp;source=http_vulnerable&amp;source=http_vulnerable6&amp;tag=cve-2025-20393%2B&amp;data_set=count&amp;scale=log&amp;auto_update=on\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Shadowserver has a page<\/a> where it\u2019s tracking the number of systems that are exposed and vulnerable to the flaw disclosed by Cisco, named officially as CVE-2025-20393. The vulnerability is known as a <a href=\"https:\/\/techcrunch.com\/2025\/04\/25\/techcrunch-reference-guide-to-security-terminology\/#zero-day\" target=\"_blank\" rel=\"noopener\">zero-day<\/a>, because the flaw was discovered before the company had time to make patches available. As of press time, India, Thailand, and the United States collectively have dozens of affected systems within their borders.<\/p>\n<p class=\"wp-block-paragraph\">Censys, a cybersecurity firm that monitors hacking activities across the internet, is also seeing a limited number of affected Cisco customers. <a href=\"https:\/\/censys.com\/advisory\/cve-2025-20393\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">According to a blog post<\/a>, Censys has observed 220 internet-exposed Cisco email gateways, one of the products known to be vulnerable.\u00a0\u00a0<\/p>\n<div class=\"article-block block--callout block--right has-green-500-background-color\">\n<h4 class=\"block--callout__title\">Contact Us<\/h4>\n<p>\t\t\tDo you have more information about this hacking campaign? Such as what companies were targeted? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or <a href=\"https:\/\/techcrunch.com\/2025\/12\/19\/hundreds-of-cisco-customers-are-vulnerable-to-new-chinese-hacking-campaign-researchers-say\/mailto:lorenzo@techcrunch.com\/\" target=\"_blank\" rel=\"noopener\">email<\/a><a href=\"https:\/\/techcrunch.com\/2025\/12\/19\/hundreds-of-cisco-customers-are-vulnerable-to-new-chinese-hacking-campaign-researchers-say\/mailto:lorenzo@techcrunch.com\/\" target=\"_blank\" rel=\"noopener\">.<\/a>\t\t<\/div>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sma-attack-N9bf4\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">In its security advisory<\/a> published earlier this week, Cisco said that the vulnerability is present in software found in several products, including its Secure Email Gateway and its Secure Email and Web Manager.<\/p>\n<p class=\"wp-block-paragraph\">Cisco said these systems are only vulnerable if they are reachable from the internet, and have its \u201cspam quarantine\u201d feature enabled. Neither of those two conditions are enabled by default, per Cisco, which would explain why there appears to be, relatively speaking, not that many vulnerable systems on the internet.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Cisco did not respond to a request for comment, asking if the company could corroborate the numbers seen by Shadowserver and Censys.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The bigger problem with this hacking campaign is that there are no patches available. Cisco recommends that customers wipe and \u201crestore an affected appliance to a secure state,\u201d as a way to remediate any breach.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201c\u200b\u200bIn case of confirmed compromise, rebuilding the appliances is, currently, the only viable option to eradicate the threat actors persistence mechanism from the appliance,\u201d the company wrote in its advisory.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">According to Cisco\u2019s threat intelligence arm Talos, the hacking campaign has been ongoing since \u201cat least late November 2025.\u201d<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2025\/12\/19\/hundreds-of-cisco-customers-are-vulnerable-to-new-chinese-hacking-campaign-researchers-say\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On Wednesday, Cisco revealed that a group of Chinese government-backed hackers is exploiting a vulnerability to target its enterprise customers who use some of the company\u2019s most popular products. Cisco has not said how many of its customers have already been hacked, or may be running vulnerable systems. Now, security researchers say there are hundreds [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":212157,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-212156","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/212156","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=212156"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/212156\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/212157"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=212156"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=212156"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=212156"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}