By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Hundreds of Cisco customers are vulnerable to new Chinese hacking campaign, researchers say | News
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Hundreds of Cisco customers are vulnerable to new Chinese hacking campaign, researchers say | News
News

Hundreds of Cisco customers are vulnerable to new Chinese hacking campaign, researchers say | News

News Room
Last updated: 2025/12/19 at 3:24 PM
News Room Published 19 December 2025
Share
Hundreds of Cisco customers are vulnerable to new Chinese hacking campaign, researchers say |  News
SHARE

On Wednesday, Cisco revealed that a group of Chinese government-backed hackers is exploiting a vulnerability to target its enterprise customers who use some of the company’s most popular products.

Cisco has not said how many of its customers have already been hacked, or may be running vulnerable systems. Now, security researchers say there are hundreds of Cisco customers who could potentially be hacked.

Piotr Kijewski, the chief executive of the nonprofit Shadowserver Foundation that scans and monitors the internet for hacking campaigns, told News that the scale of exposure “seems more in the hundreds rather than thousands or tens of thousands.”

Kijewski said the foundation was not seeing widespread activity, presumably because “current attacks are targeted.” 

Shadowserver has a page where it’s tracking the number of systems that are exposed and vulnerable to the flaw disclosed by Cisco, named officially as CVE-2025-20393. The vulnerability is known as a zero-day, because the flaw was discovered before the company had time to make patches available. As of press time, India, Thailand, and the United States collectively have dozens of affected systems within their borders.

Censys, a cybersecurity firm that monitors hacking activities across the internet, is also seeing a limited number of affected Cisco customers. According to a blog post, Censys has observed 220 internet-exposed Cisco email gateways, one of the products known to be vulnerable.  

Contact Us

Do you have more information about this hacking campaign? Such as what companies were targeted? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.

In its security advisory published earlier this week, Cisco said that the vulnerability is present in software found in several products, including its Secure Email Gateway and its Secure Email and Web Manager.

Cisco said these systems are only vulnerable if they are reachable from the internet, and have its “spam quarantine” feature enabled. Neither of those two conditions are enabled by default, per Cisco, which would explain why there appears to be, relatively speaking, not that many vulnerable systems on the internet. 

Cisco did not respond to a request for comment, asking if the company could corroborate the numbers seen by Shadowserver and Censys. 

The bigger problem with this hacking campaign is that there are no patches available. Cisco recommends that customers wipe and “restore an affected appliance to a secure state,” as a way to remediate any breach. 

“​​In case of confirmed compromise, rebuilding the appliances is, currently, the only viable option to eradicate the threat actors persistence mechanism from the appliance,” the company wrote in its advisory. 

According to Cisco’s threat intelligence arm Talos, the hacking campaign has been ongoing since “at least late November 2025.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Who owns Trump Mobile? Who owns Trump Mobile?
Next Article The HackerNoon Newsletter: Meet Temmarie – HackerNoon Blogging Course Facilitator (12/19/2025) | HackerNoon The HackerNoon Newsletter: Meet Temmarie – HackerNoon Blogging Course Facilitator (12/19/2025) | HackerNoon
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Scientists Find Bizarre, Lemon-Shaped World Orbiting City-Size Star
Scientists Find Bizarre, Lemon-Shaped World Orbiting City-Size Star
News
China’s Pony.ai sees shares fall 7.7% in direct listing debut · TechNode
China’s Pony.ai sees shares fall 7.7% in direct listing debut · TechNode
Computing
Boost Your Connection While Saving Some Cash With These Wi-Fi Mesh Deals for December
Boost Your Connection While Saving Some Cash With These Wi-Fi Mesh Deals for December
News
What Is a Faceless Influencer or Creator? |
What Is a Faceless Influencer or Creator? |
Computing

You Might also Like

Scientists Find Bizarre, Lemon-Shaped World Orbiting City-Size Star
News

Scientists Find Bizarre, Lemon-Shaped World Orbiting City-Size Star

2 Min Read
Boost Your Connection While Saving Some Cash With These Wi-Fi Mesh Deals for December
News

Boost Your Connection While Saving Some Cash With These Wi-Fi Mesh Deals for December

16 Min Read
Australians will be soon able to use Apple Watch hypertension notifications
News

Australians will be soon able to use Apple Watch hypertension notifications

1 Min Read
Google sues web scraper for sucking up search results ‘at an astonishing scale’
News

Google sues web scraper for sucking up search results ‘at an astonishing scale’

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?