top of page

Amazon Discovers Advanced Threat Exploiting Cisco and Citrix Zero-Day Vulnerabilities

  • Grace N
  • 1 day ago
  • 1 min read

Amazon’s threat intelligence team has uncovered a sophisticated attack exploiting previously undisclosed zero-day vulnerabilities in Cisco and Citrix systems. Through its MadPot honeypot service, Amazon detected exploitation attempts targeting Citrix's Bleed Two vulnerability (CVE-2025-5777) and a critical flaw in Cisco Identity Service Engine (ISE) (CVE-2025-20337).


The attack involved custom malware that enabled remote code execution on Cisco ISE systems, granting attackers administrator-level access. The threat actor used advanced techniques, including deploying a custom web shell disguised as a legitimate Cisco ISE component, to evade detection.


This highlights the growing trend of attackers targeting critical infrastructure like identity and network access control systems. Amazon urges security teams to enhance defenses and limit access to vulnerable components to mitigate such threats.


Comments


Recent Posts

Get In Touch

Want to learn more about our past work or

explore how we can support your current initiatives?

Reach out today and let Fiduciary Tech be your trusted partner.

Headquarters

1100 106th Avenue NE, Suite 101F
Bellevue, WA 98004
425-998-8505

info@fiduciarytech.com

Seoul Office

Address: Geunshin Building 506-1, 20 Samgae-ro, Mapo-gu, Seoul, 04173, Republic of Korea
02-71
2-2227

info@fiduciarytech.com

fiduciary technology consulting

© 2025 by Fiduciary Technology Solutions 

bottom of page