Drooid Logo
Back to today’s briefing

Story perspectives

Cybersecurity Alert: 400 Cisco Devices Compromised by BADCANDY

11/1/2025

25 3

1 of 1

Story summary
  • Australian cybersecurity authorities warn Cisco IOS XE devices are exploited via CVE-2023-20198 to grant remote attackers elevated privileges.
  • The implant, known as BADCANDY, has compromised over 400 devices since July 2025, with 150 infections in October alone.
  • Threat actors continue to re-exploit systems by applying non-persistent patches that mask vulnerabilities.
  • Security experts urge applying official Cisco patches and hardening guidelines to prevent future attacks.