Badcandy: Angreifer brechen tausendfach in alte Cisco-IOS-XE-Lücke ein

Ein Update gegen die Cisco-IOS-XE-Lücke CVE-2023-20198 gibt es seit 2023. Die Shadowserver Foundation sieht 15.000 infizierte Geräte.

heise online

Radio Show Tells Scary Stories & The Myths Become True! | Bad Candy

#horror#Trailers#horrormovies#BadCandy – @DreadPresents – On Halloween night in New Salem, Radio DJs Chilly Billy and Paul tell a twisted anthology of terrifying local myths.

#ad #BadCandy #horror #Trailers

https://horrornerdonline.com/2025/11/radio-show-tells-scary-stories-the-myths-become-true-bad-candy/

📰 Australia Warns of 'BADCANDY' Malware Targeting Unpatched Cisco Devices

🇦🇺 Australia's ASD warns of 'BADCANDY' malware attacks on Cisco IOS XE devices. Hackers are exploiting critical flaw CVE-2023-20198 to take over routers. 150+ devices infected in October alone. #Cisco #CyberSecurity #BADCANDY #PatchNow

🔗 https://cyber.netsecops.io/articles/australian-government-warns-of-badcandy-malware-targeting-cisco-devices/?utm_source=mastodon&utm_medium=social&utm_campaign=twitter_auto

Australia Warns of 'BADCANDY' Malware Targeting Unpatched Cisco Devices

The Australian Signals Directorate (ASD) warns of ongoing attacks deploying 'BADCANDY' malware on unpatched Cisco IOS XE devices by exploiting the critical vulnerability CVE-2023-20198.

CyberNetSec.io
📢 Alerte ASD: l’implant BADCANDY exploite CVE‑2023‑20198 sur Cisco IOS XE
📝 Source et contexte: cyber.gov.au (Australian Government/ASD) publie une alerte sur l’implant « BADCANDY » observé depuis octobre 2023, avec un...
📖 cyberveille : https://cyberveille.ch/posts/2025-11-04-alerte-asd-limplant-badcandy-exploite-cve-2023-20198-sur-cisco-ios-xe/
🌐 source : https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/badcandy
#BADCANDY #CVE_2023_20198 #Cyberveille
Alerte ASD: l’implant BADCANDY exploite CVE‑2023‑20198 sur Cisco IOS XE

Source et contexte: cyber.gov.au (Australian Government/ASD) publie une alerte sur l’implant « BADCANDY » observé depuis octobre 2023, avec une activité renouvelée en 2024‑2025, ciblant des équipements Cisco IOS XE vulnérables à CVE‑2023‑20198. ⚠️ L’ASD décrit BADCANDY comme un web shell Lua « low equity » installé après exploitation de l’interface Web (UI) de Cisco IOS XE. Les acteurs appliquent souvent un patch non persistant post‑compromission pour masquer l’état de vulnérabilité lié à CVE‑2023‑20198. La présence de BADCANDY indique une compromission via cette faille. L’implant ne persiste pas après redémarrage, mais des accès peuvent perdurer si des identifiants ou d’autres mécanismes de persistance ont été acquis; le correctif de CVE‑2023‑20198 doit être appliqué et l’accès à l’UI Web restreint.

CyberVeille

Hey everyone! It's been a bit quiet over the last 24 hours, but we still have some critical updates to cover, including a university email system compromise, an ongoing exploitation campaign targeting Cisco devices, and a significant arrest in the cybercrime world. Let's dive in:

University of Pennsylvania Hit by Politically Motivated Email Attack ⚠️

- The University of Pennsylvania is investigating a fraudulent and offensive email sent to thousands of current and former students from a compromised Graduate School of Education (GSE) address.
- The email contained criticisms related to affirmative action and threatened a data leak, mirroring similar attacks on other universities (Columbia, NYU, UMN) following the Supreme Court's ruling on race-based admissions.
- This incident highlights how politically motivated actors are leveraging cyber means, specifically email system compromises, to push agendas and potentially exfiltrate sensitive data. Organisations should bolster email security and incident response plans.

🗞️ The Record | https://therecord.media/upenn-hacker-email-affirmative

Ongoing BADCANDY Attacks Exploiting Cisco IOS XE Vulnerability 🛡️

- The Australian Signals Directorate (ASD) has warned of persistent cyber attacks targeting unpatched Cisco IOS XE devices, exploiting the critical CVE-2023-20198 (CVSS 10.0) vulnerability.
- Attackers are deploying a new, low-equity Lua-based web shell implant called BADCANDY, which allows them to create privileged accounts and seize control. While non-persistent, threat actors are re-infecting devices after reboots if they remain unpatched.
- Defenders must immediately patch Cisco IOS XE devices, limit public exposure of the web user interface, and review configurations for any rogue privilege 15 accounts (e.g., "cisco_tac_admin") or unknown tunnel interfaces.

📰 The Hacker News | https://thehackernews.com/2025/11/asd-warns-of-ongoing-badcandy-attacks.html

Alleged 764 Leader Arrested, Faces Life in Prison 🚨

- Federal law enforcement has arrested Baron Cain Martin, the alleged leader of 764, a violent extremist group, on 29 charges including providing material support to terrorists, child exploitation, cyberstalking, and murder.
- Martin, also known as "Convict," is accused of producing and distributing a guide on how to identify, groom, and extort vulnerable children, particularly those with mental health issues.
- This significant arrest is part of a broader crackdown on 764 and "The Com" – a global collective involved in financially motivated, sexual, and violent cybercrimes, underscoring the severe real-world impact of online criminal enterprises.

🤫 CyberScoop | https://cyberscoop.com/baron-cain-martin-764-leader-arrested-charged/

#CyberSecurity #ThreatIntelligence #Vulnerability #Cisco #IOSXE #BADCANDY #CyberAttack #IncidentResponse #Cybercrime #LawEnforcement #ChildExploitation #InfoSec

University of Pennsylvania investigating offensive email sent through graduate school system

The University of Pennsylvania is investigating an email that was sent out to thousands of current and former students on Friday afternoon containing offensive language and threats of a data breach.

BadCandy Webshell threatens unpatched Cisco IOS XE devices, warns Australian government

Australia warns of attacks on unpatched Cisco IOS XE devices exploiting CVE-2023-20198, allowing BadCandy webshell install.

Security Affairs
Australia warns of BadCandy infections on unpatched Cisco devices

The Australian government is warning about ongoing cyberattacks against unpatched Cisco IOS XE devices in the country to infect routers with the BadCandy webshell.

BleepingComputer
Australia warns of BadCandy infections on unpatched Cisco devices

The Australian government is warning about ongoing cyberattacks against unpatched Cisco IOS XE devices in the country to infect routers with the BadCandy webshell.

BleepingComputer
Australia warns of BadCandy infections on unpatched Cisco devices

The Australian government is warning about ongoing cyberattacks against unpatched Cisco IOS XE devices in the country to infect routers with the BadCandy webshell.

BleepingComputer

Unpatched Cisco devices in Australia are still falling prey to the sneaky BadCandy webshell—even after patches were released! What happens when hundreds of systems remain at risk despite warnings? Read more to find out.

https://thedefendopsdiaries.com/australia-warns-of-badcandy-infections-on-unpatched-cisco-devices/

#badcandy
#ciscosecurity
#cyberthreats
#networksecurity
#cve202320198