Cisco Warns of Active Hacking Campaign targeting Email Security Appliances – china-Linked Threat Actors Exploiting Zero-Day Vulnerability
Updated December 17, 2025 – Cisco has issued a critical security advisory detailing an ongoing hacking campaign exploiting a zero-day vulnerability in its Secure Email Gateway, Secure Email, and web Manager products. The attacks, linked to Chinese government-affiliated hacking groups, pose a meaningful risk to organizations with internet-facing appliances and the “Spam Quarantine” feature enabled. This article provides a thorough overview of the situation, potential impact, and recommended mitigation steps.
What’s Happening?
On December 10th, cisco discovered a targeted campaign exploiting a previously unknown vulnerability – a zero-day - within its AsyncOS software. This software powers several key email security products widely used by businesses of all sizes.
Specifically, the vulnerability impacts:
* Cisco Secure Email Gateway
* Cisco Secure Email
* Cisco Secure Web Manager
The threat is particularly acute for devices with the “Spam Quarantine” feature activated and accessible from the public internet. While this feature isn’t enabled by default, and doesn’t need to be exposed, its presence combined with internet accessibility creates an attack vector.
Why is This Significant?
Security researchers are divided on the scope of the issue.While the requirement for internet exposure and specific feature enablement limits the attack surface, the potential impact is significant.
Here’s what makes this campaign particularly concerning:
* Widespread Use: Many large organizations rely on the affected Cisco products.
* No Immediate Patch: Currently, no software patch is available to address the vulnerability.
* potential for Long-Term Compromise: The duration of the hackers’ presence within affected systems remains unclear, raising concerns about data exfiltration and persistent backdoors.
* Chinese Government Link: cisco Talos, the company’s threat intelligence arm, attributes the campaign to threat actors linked to China and known Chinese government hacking groups.
What Do You Need to Know?
Cisco is actively investigating the issue and developing a permanent fix. Though, the company has not yet disclosed the number of affected customers. When contacted for comment, Cisco spokesperson Meredith Corley offered no specific answers, stating only that a remediation is in advancement.
What Should You Do Now?
Given the lack of a patch, Cisco’s current recommendation is drastic but necessary: rebuild the affected appliances from scratch. This is the only currently viable method to ensure complete eradication of any potential backdoors installed by the attackers.
Here’s a breakdown of the recommended action:
- Identify Affected appliances: Determine if you are using Cisco Secure Email Gateway, Secure Email, or Web Manager.
- Check Spam Quarantine Status: Verify if the “Spam Quarantine” feature is enabled on your systems.
- Assess internet Exposure: Confirm whether your appliances are directly accessible from the internet.
- Rebuild if Compromised: If you suspect a compromise, or meet the criteria above, instantly rebuild the affected appliances. This involves a complete software wipe and reinstallation.
Understanding the Threat: A Zero-Day Exploitation
The vulnerability being exploited is classified as a “zero-day.” This means the flaw was unknown to Cisco and the security community before it was actively exploited by attackers. Zero-day vulnerabilities are particularly hazardous because there’s no existing defence against them until a patch is developed and deployed.
According to cisco Talos, the campaign has been underway since at least late November 2025. The attackers are leveraging the zero-day to establish persistent backdoors, granting them continued access to compromised systems.
Staying Informed & Seeking Help
This is a rapidly evolving situation. We will continue to update this article as more information becomes available.
If you have information about this hacking campaign, particularly regarding targeted companies, please reach out securely:
* Signal: +1 917 257 1382
* telegram/Keybase: @lorenzofb
* Email: [email protected]
Resources:
Worth a look
- AI News: Anthropic Testing Mishap, Nvidia’s Cyber Initiative, and AWS Revenue Surge
- iPhone Air 2: 5 New Features, Upgraded Cameras, and Wider Display Leaks
- The Secret of the Chinese Snacks: A Train Journey Discovery (archynewsy.com)
- Israel Raises Security Concerns Over Trump-Brokered Hamas Disarmament Deal (time.news)