Listen to this Post

In a startling revelation, Amazon’s threat intelligence team has uncovered an ongoing cyber campaign exploiting previously unknown zero-day vulnerabilities in enterprise systems. The attack, targeting Cisco Identity Services Engine (ISE) and Citrix environments, demonstrates the capabilities of highly sophisticated adversaries with deep knowledge of corporate infrastructure. The campaign leverages custom-built webshells and advanced evasion techniques, enabling attackers to gain administrative access across compromised networks without authentication. This discovery underscores the growing risks facing identity management and remote access systems, highlighting the urgent need for organizations to bolster their defenses.
Summary of the Threat
Amazon’s MadPot honeypot service first identified the exploitation of the Citrix Bleed Two vulnerability before it was publicly disclosed, revealing that threat actors had already weaponized this flaw in active attacks. During further investigation, a companion zero-day affecting Cisco ISE was discovered, exploiting a deserialization vulnerability on an undocumented endpoint to achieve pre-authentication remote code execution.
CVE-2025-20337, affecting Cisco ISE, allows attackers administrator-level access without valid credentials, a capability with devastating implications for enterprise networks. Simultaneously, CVE-2025-5777 in Citrix systems was actively exploited. Both vulnerabilities were targeted indiscriminately, suggesting a highly resourced threat actor with access to non-public vulnerability information or advanced internal research capabilities.
Following exploitation, attackers deployed a custom webshell designed to masquerade as a legitimate Cisco ISE component named IdentityAuditAction. This webshell operated entirely in memory, leaving minimal forensic traces. It leveraged Java reflection to inject into running application threads, registered as an HTTP request listener on the Tomcat server, and used non-standard DES encryption combined with custom Base64 encoding to evade detection. Access required specific HTTP headers and an additional authentication layer, reflecting a level of sophistication often associated with nation-state or well-funded cybercriminal groups.
The attackers’ tools reveal deep expertise in enterprise Java applications, Tomcat server internals, and Cisco ISE architecture—knowledge rarely available in public documentation. Organizations relying on identity management and remote access systems face significant risks and must adopt defense-in-depth strategies, robust anomaly detection, and firewall restrictions to protect critical endpoints.
CVE ID Affected Product Severity Status
CVE-2025-20337 Cisco Identity Service Engine (ISE) Critical Zero-day (Active Exploitation)
CVE-2025-5777 Citrix Systems Critical Zero-day (Active Exploitation)
What Undercode Say:
The discovery of these zero-days reflects a worrying evolution in cyber threats. By targeting critical enterprise systems like Cisco ISE and Citrix, attackers are aiming for the crown jewels of corporate infrastructure—identity management and remote access tools that, if compromised, can provide near-total control of organizational networks.
The sophistication of the deployed webshells indicates that these are not opportunistic attacks but meticulously planned campaigns. Operating entirely in memory and using advanced obfuscation techniques demonstrates a high level of technical prowess, pointing to either state-sponsored actors or highly funded criminal operations. The exploitation of a deserialization vulnerability in an undocumented endpoint is particularly notable, as such flaws are typically overlooked in standard security audits.
This campaign also reveals a shift in the threat landscape: attackers are no longer waiting for vulnerabilities to be publicly disclosed before weaponizing them. The early targeting of the Citrix Bleed Two vulnerability shows proactive reconnaissance and rapid exploitation capabilities, which drastically reduces the time organizations have to respond.
Security teams need to rethink traditional defense approaches. Detection systems reliant on file-based signatures are insufficient against memory-resident threats. Behavioral monitoring, anomaly detection, and proactive threat hunting become critical. Network segmentation and stringent access controls for sensitive management interfaces can mitigate the damage of pre-authentication exploits.
Additionally, the sophistication of the threat actor implies a continuous cycle of vulnerability research and zero-day exploitation. Organizations must prepare for rapid patching, comprehensive incident response planning, and constant monitoring to stay ahead. Ignoring this threat could result in catastrophic breaches, as administrative-level access allows attackers to manipulate, exfiltrate, or destroy critical enterprise data.
This case also underscores the importance of collaborative threat intelligence. Early detection by honeypot systems like MadPot can provide organizations with the necessary lead time to implement mitigations. Sharing findings across enterprises and security communities will be critical in combating adversaries capable of such advanced attacks.
🔍 Fact Checker Results
✅ Amazon Threat Intelligence reported active exploitation of zero-days in Cisco ISE and Citrix systems.
✅ CVE-2025-20337 allows pre-authentication remote code execution in Cisco ISE.
❌ The attacks are not isolated; they represent a coordinated campaign targeting enterprise identity infrastructure.
📊 Prediction
Expect an uptick in attacks targeting identity management and remote access systems over the next 12 months. Organizations that fail to adopt memory-based detection, network segmentation, and proactive vulnerability research are likely to face breaches. Cybercriminals and state-sponsored groups will continue refining webshells and zero-day exploits, potentially expanding to other enterprise-critical platforms. Early intelligence sharing and automated patch deployment will become key differentiators between organizations that survive and those that suffer catastrophic compromises.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.pinterest.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




