GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 18-Dec-2025 02:33:29 JST Kevin Beaumont Kevin Beaumont
    • Shodan

    Cisco have found an in the wild zero day in Cisco Secure Email Gateway And Cisco Secure Email and Web Manager being used to backdoor appliances for later access.

    Now CVE-2025-20393.

    No patch available.

    They recommend nuking boxes and reinstalling from scratch if you opened spam quarantine port (6025) to internet, and closing port.

    It is unclear how long boxes have been backdoored for.

    Port isn't scanned by @shodan yet so scope isn't known.

    https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4

    In conversation about 8 months ago from cyberplace.social permalink

    Attachments



    1. No result found on File_thumbnail lookup.
      Cisco Security Advisory: Reports About Cyberattacks Against Cisco Secure Email Gateway And Cisco Secure Email and Web Manager
      On December 10, Cisco became aware of a new cyberattack campaign targeting a limited subset of appliances with certain ports open to the internet that are running Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. This attack allows the threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance. The ongoing investigation has revealed evidence of a persistence mechanism planted by the threat actors to maintain a degree of control over compromised appliances. Cisco strongly recommends that customers follow the guidance provided in the Recommendations section of the security advisory in order to assess exposure and mitigate risks. For more information, see the Recommendations section of this advisory.  This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 18-Dec-2025 02:44:01 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • GreyNoise

      Your admins may know the product as Ironport, that was the branding years ago.

      @greynoise might want to have a look at ports 6025, 7025, 82 and 83 for anomalies.

      In conversation about 8 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 18-Dec-2025 02:46:21 JST Kevin Beaumont Kevin Beaumont
      in reply to

      I think Cisco likely need to pivot on being far more open about this one ASAP, e.g. they need to openly provide:

      - IOCs
      - Oldest known time of backdoor installation
      - Ports used during exploitation

      At the minute they've got the bare minimal in there and I don't really want to write a blog and use MSPaint.exe

      In conversation about 8 months ago permalink
    • Embed this notice
      𝙲𝚘𝚕𝚒𝚗 𝙶𝚛𝚊𝚍𝚢 (colingrady@infosec.exchange)'s status on Thursday, 18-Dec-2025 02:52:18 JST 𝙲𝚘𝚕𝚒𝚗 𝙶𝚛𝚊𝚍𝚢 𝙲𝚘𝚕𝚒𝚗 𝙶𝚛𝚊𝚍𝚢
      in reply to

      @GossiTheDog https://blog.talosintelligence.com/uat-9686/

      In conversation about 8 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: blog.talosintelligence.com
        UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager
        Cisco Talos is tracking the active targeting of Cisco AsyncOS Software for Cisco Secure Email Gateway, formerly known as Cisco Email Security Appliance (ESA), and Cisco Secure Email and Web Manager, formerly known as Cisco Content Security Management Appliance (SMA).
    • Embed this notice
      tehfishman (tehfishman@ioc.exchange)'s status on Thursday, 18-Dec-2025 02:59:46 JST tehfishman tehfishman
      in reply to

      @GossiTheDog "don't make me open mspaint" is a threat I plan on using in catastrophically dumb meetings.

      In conversation about 8 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 18-Dec-2025 03:02:11 JST Kevin Beaumont Kevin Beaumont
      in reply to

      If anybody interested, this group jump to residential proxies to Tor exit nodes to Linode, Vultr and Kaopu boxes via VPN tunnels (boxes usually in the same geography as the target, down to the city, to avoid triggering impossible travel rules).

      They also had a CitrixBleed 2 exploit before it was public knowledge or a patch was available, also one for CVE-2025-7775 (CitrixDeelb), the iSCSI one. They're pretty good at what they do.

      In conversation about 8 months ago permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 18-Dec-2025 03:02:13 JST Kevin Beaumont Kevin Beaumont
      in reply to

      IOCs (which should probably be linked on the Cisco support page)

      https://blog.talosintelligence.com/uat-9686/

      172.233.67.176 (linode)
      172.237.29.147 (linode)
      38.54.56.95 (Kaopu Cloud HK Limited)

      I suspect probably China, has overlaps with a group doing Cisco ASA backdooring with #CyberWillyWave a few months ago

      In conversation about 8 months ago permalink

      Attachments


      1. Invalid filename.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 18-Dec-2025 20:49:20 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Additional IOC for this

      trendmicro-update.com

      reverse shell from ironport boxes, same threat actor

      In conversation about 8 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.