Chinese hackers targeting ‘high value’ North American critical infrastructure, Cisco says
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-53690 | Unauthenticated ViewState Deserialization RCE in Sitecore XM/XP CVE-2025-53690 is a critical (CVSS 9.0) deserialization-of-untrusted-data flaw (CWE-502) in Sitecore Experience Manager (XM) and Experience Platform (XP) through version 9.0 that enables unauthenticated code injection. Public threat reporting (Google Cloud/Mandiant) and news coverage tie the flaw to ASP.NET ViewState deserialization performed using exposed (default or leaked) ASP.NET machine keys, so a remote attacker who can reach a Sitecore site can submit a crafted, signed ViewState payload that is deserialized server-side, resulting in remote code execution. A successful unauthenticated attacker gains arbitrary code execution on the web server with the scope-changed (S:C) impact of high confidentiality, integrity and availability loss. Organizations running internet-facing Sitecore XM/XP deployments — including Experience Commerce and Managed Cloud deployments — are in scope. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-09-04, and reporting links the activity to a China-linked APT (UAT-8837) targeting North American critical infrastructure. Do: Apply Sitecore's security updates to all affected XM/XP deployments (through 9.0) and follow the vendor's mitigations as required by CISA KEV/BOD 22-01, or discontinue use if patching is not possible. Per the public reporting, rotate any exposed or default ASP.NET machineKey values (e.g., in web.config) on internet-facing Sitecore servers, since exposed machine keys enable the ViewState deserialization attacks. Inventory internet-exposed Sitecore instances and review them for signs of compromise. | 9.0 | 51% | KEV PoC |
| largetens of thousands of internet-exposed Sitecore deployments (order of magnitude ~10^4–10^5) |
Full article411 words · extracted from therecord.media · click to collapse
Chinese hackers successfully breached multiple critical infrastructure organizations in North America over the last year using a combination of compromised credentials and exploitable servers, researchers at Cisco Talos found. In findings published Thursday, the researchers documented a campaign starting last year where Chinese government-backed hacking groups were tasked with obtaining initial access to “high-value” organizations. Cisco Talos refers to the group as “UAT-8837.” After getting access, the threat actors used a variety of tools to steal credentials, security configurations and other information to enable broader access to victim organizations. While the group has used multiple vulnerabilities to gain access, Cisco Talos tracked several intrusions involving the exploitation of CVE-2025-53690 — a bug affecting products from software company SiteCore. The zero-day vulnerability was spotlighted by federal cybersecurity officials in the Fall, and all federal civilian agencies were ordered to patch the bug by September 25. At the time, Google published its own examination of an incident involving the bug and mentioned at least four of the same post-exploitation tools that were highlighted by Cisco Talos. Cisco Talos said the group’s targeting of the bug indicates the Chinese group “may have access to zero-day exploits.” One of the tools used by the hacking group, called Earthworm, allows threat actors to expose internal endpoints to attacker-owned remote infrastructure. Cisco Talos said Earthworm has been used extensively by Chinese-speaking threat actors during intrusions in order to determine which internal endpoints are undetectable by endpoint protection products. “The undetected version is then used to create a reverse tunnel to attacker-controlled servers,” they explained. Concerns about Chinese hackers targeting critical infrastructure were revived following an incident in December when the group Salt Typhoon was detected compromising an email platform used by Congressional staffers. The staffers targeted in the attacks work on the House of Representatives’ China committee and several others covering foreign affairs. U.S. officials have repeatedly warned of Chinese government-backed hacking groups targeting federal agencies and other critical infrastructure organizations. On Wednesday, a group of Western cyber agencies released an alert about the growing digital threats facing the operational technology at the heart of industrial systems used by many critical infrastructure organizations.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/china-hackers-apt-cisco-talos