Australian Government Warns of Ongoing Attacks Targeting Unpatched Cisco IOS XE Devices, Risk of “BadCandy” Webshell Infection
442/68 Tuesday, November 4, 2025 The Australian Signals Directorate (ASD) has issued a warning about ongoing cyberattacks exploiting the vulnerability CVE-2023-20198 in Cisco IOS XE devices. Attackers are using the flaw to implant a malicious webshell known as BadCandy, which gives them administrator-level control over the device. The vulnerability carries the highest severity rating, CVSS […]
