UPDATE: Cisco IOS XE Web UI CVE-2023-20198 version 2 BadCandy implant detection has dropped again 2023-11-03: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&source=compromised_website&source=compromised_website6&tag=device-implant%2B&group_by=geo&style=stacked
Note on 2023-11-02 Cisco updated their threat advisory on CVE-2023-20198/BadCandy with observations of a version 3:
https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/
Over 2200 unique IPs seen with CVE-2023-20198 attempts on 2023-11-03 in our honeypot sensors (many different actors now probing)
https://dashboard.shadowserver.org/statistics/honeypot/monitoring/vulnerability/?category=monitoring&statistic=unique_ips&d2=2023-11-03&limit=100