Technology

Hundreds of companies at risk from new Chinese cyber attack, experts warn

101
×

Hundreds of companies at risk from new Chinese cyber attack, experts warn

Share this article

The Hidden Threat: A New Chinese Hacking Campaign Targets Cisco Customers

A growing concern has emerged in the cybersecurity world as researchers warn that hundreds of Cisco customers are at risk from a sophisticated hacking campaign linked to a Chinese government-backed group. The vulnerability, known as CVE-2025-20393, is a zero-day flaw that has been exploited by hackers to gain unauthorized access to enterprise systems.

According to Piotr Kijewski, CEO of the Shadowserver Foundation, the scale of exposure appears to be in the hundreds rather than thousands or tens of thousands. While the number of affected systems is not yet clear, the foundation is actively monitoring the situation and tracking how many systems are vulnerable to the flaw.

The vulnerability affects several Cisco products, including its Secure Email Gateway and Secure Email and Web Manager. However, Cisco clarified that these systems are only vulnerable if they are reachable from the internet and have the “spam quarantine” feature enabled. Neither of these conditions are enabled by default, which may explain why the number of exposed systems is relatively low.

Despite the limited number of vulnerable systems, the lack of available patches poses a significant challenge for customers. Cisco recommends that affected users wipe and restore their appliances to a secure state as a way to mitigate the threat. This process is crucial in eradicating any persistence mechanisms used by the attackers.

Cisco security advisory on new hacking campaign

The hacking campaign has been ongoing since at least late November 2025, according to Cisco’s threat intelligence arm, Talos. While the attacks appear to be targeted, the potential for widespread damage remains a concern for organizations relying on Cisco’s products.

Censys, a cybersecurity firm, has observed 220 internet-exposed Cisco email gateways, one of the products known to be vulnerable. The company is also monitoring the situation closely to identify any additional threats.

As the cybersecurity landscape continues to evolve, the need for vigilance and proactive measures becomes increasingly important. Organizations must remain aware of potential vulnerabilities and take necessary steps to protect their systems from emerging threats.

Cybersecurity experts monitoring hacking activities

Leave a Reply

Your email address will not be published. Required fields are marked *