Story perspectives
Cybersecurity Alert: 400 Cisco Devices Compromised by BADCANDY
11/1/2025
25 3
1 of 1
Story summary
- Australian cybersecurity authorities warn Cisco IOS XE devices are exploited via CVE-2023-20198 to grant remote attackers elevated privileges.
- The implant, known as BADCANDY, has compromised over 400 devices since July 2025, with 150 infections in October alone.
- Threat actors continue to re-exploit systems by applying non-persistent patches that mask vulnerabilities.
- Security experts urge applying official Cisco patches and hardening guidelines to prevent future attacks.
