ZeroHour
Recorded Futurepublished ()ingested Insikt Group®

Recorded Future Briefing | Munich Security Conference 2025 Insights by Insikt Group

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-20198
Unauthenticated Privilege Escalation in Cisco IOS XE Web UI (Actively Exploited)

CVE-2023-20198 is a critical (CVSS 10.0) unauthenticated privilege escalation flaw in the web UI of Cisco IOS XE software, triggered by sending crafted network requests to the exposed web management interface. An attacker with no credentials can use the flaw to gain initial access and issue a privilege 15 command, creating a local user with normal login access; the attacker then chained CVE-2023-20273 (CVSS 7.2) to elevate that account to root and write an implant to the file system. Successful exploitation yields full administrative control of the device, including persistence via the planted implant, on Cisco IOS XE devices with the web UI enabled and reachable from the internet or untrusted networks, including Rockwell Automation Allen-Bradley Stratix 5200 and 5800 switches running IOS XE. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-10-16 with a BOD 23-02 directive, EPSS stands at 99.6% (100th percentile), and ongoing campaigns (including the 'BADCANDY' activity flagged by Australia's ASD and Cisco-related telecom intrusions attributed to Salt Typhoon) have been reported.

Do: Upgrade affected devices to the fixed releases listed in Cisco's advisory (use Cisco's Software Checker) and, as immediate mitigation, disable the web UI or restrict it to trusted networks/addresses only. Check for compromise by looking for unexpected local user accounts and the implant artifacts Cisco identified (unexpected cisco_tac_alarm.log and cisco_tac.log files in /tmp or /usr/binos/conf), and immediately report positive findings to CISA per BOD 23-02. Keep in mind that patching alone does not remove a root implant, so devices with evidence of compromise should be reimaged or otherwise cleaned per vendor instructions.

10.0100% KEV
  • Cisco IOS XE (Web UI feature)
  • Rockwell Automation Allen-Bradley Stratix 5200 firmware
  • Rockwell Automation Allen-Bradley Stratix 5800 firmware
large≈40,000–50,000 internet-exposed IOS XE devices at the time of disclosure (public scan data), within an IOS XE install base in the millions
CVE-2023-20273
Authenticated Command Injection (Root) in Cisco IOS XE Web UI

CVE-2023-20273 is an OS command injection flaw (CWE-78) in the web UI feature of Cisco IOS XE Software, caused by insufficient input validation. An authenticated, remote attacker triggers it by sending crafted input to the web UI, and a successful exploit injects commands that run on the underlying operating system with root privileges, yielding full device compromise (in the October 2023 mass-exploitation campaign it was typically chained with the unauthenticated CVE-2023-20198 to obtain initial access and install a persistent implant). Any Cisco IOS XE device with the web UI enabled and reachable from the internet or an untrusted network is affected; this data does not specify the affected release ranges, which are enumerated in Cisco's advisory. Exploitation is confirmed in the wild: CISA added the flaw to the KEV on 2023-10-23 with BOD 23-02 response actions, EPSS is ~90% (100th percentile), and IOS XE edge devices remain recurring targets of Chinese-nexus espionage campaigns (e.g., Salt Typhoon activity against telecoms).

Do: Upgrade affected devices to a fixed IOS XE release per Cisco's advisory; as an interim mitigation, disable the HTTP/HTTPS server (ip http server / ip https server) or restrict Web UI access to trusted hosts only. Per BOD 23-02, hunt for compromise on any exposed device — check for unexpected level-15 local accounts and the implant.lua backdoor in flash memory — and immediately report positive findings to CISA.

7.290% KEV
  • Cisco IOS XE Software (Web UI feature)
mass≈100,000+ internet-exposed IOS XE devices (public scans observed ~40,000+ compromised within days of disclosure)
Full article490 words · extracted from recordedfuture.com · click to collapse
Insikt Group Briefing - February 13th 2025

Overview

This document provides an overview of Recorded Future’s Insikt Group intelligence reporting and analysis published during the 2025 Munich Security Conference. Links to the full reports are included.

Subject

Adversarial Actors — China, Russia, Iran, and North Korea — are adapting to and exploiting Western openness and fragmentation through hostile cyber, economic, and military actions.

Reporting and Analysis

  1. The Risk of a Taiwan Invasion Is Rising Fast
  2. Russian Influence Operations Target German Elections
  3. RedMike (Salt Typhoon) Exploits Vulnerable Cisco Devices of Global Telecommunications Providers
  4. Inside the Scam: North Koreaʼs IT Worker Threat

The Risk of a Taiwan Invasion Is Rising Fast

Click here to read the report.

Key Takeaways

  • An invasion is currently unlikely, but political, economic, and military trends suggest that by 2027, China’s leadership will be able to consider an invasion while minimizing the costs.
  • A protracted war over Taiwan would have profound consequences for the global economy, disrupting critical shipping lanes and devastating technology supply chains in East Asia.
  • Bottom Line: Businesses should begin investing in contingency plans to protect and diversify their operations in case China invades or undertakes other significant military action against Taiwan in the coming decade.

Russian Influence Operations Target German Elections

Click here to read the report.

Key Takeaways

  • The forthcoming German elections are a target of Russian influence operations. As of mid-February, these operations have not meaningfully altered voter behavior or public opinion.
  • These operations aim to inflame German sociopolitical divisions, spread manipulated content, foster anti-US and EU sentiment, and weaken NATO unity in line with Kremlin objectives.
  • Bottom Line: These influence operations have had limited voter impact, but their persistence and evolving tactics elevate the threat of a breakout influence event.

RedMike (Salt Typhoon) Exploits Vulnerable Cisco Devices of Global Telecommunications Providers

Click here to read the report.

Click here to read the Wired article.

Key Takeaways

  • Insikt group observed RedMike exploiting privilege escalation vulnerabilities CVE-2023-20273 and CVE-2023-20198 to compromise unpatched Cisco network devices running Cisco IOS XE software.
  • RedMike compromised devices of a US-based affiliate of a UK telecommunications company, a South African telecommunications company, and attempted to exploit over 1,000 Cisco devices between December 2024 and January 2025.
  • Bottom Line: Despite media coverage and US sanctions, RedMike (Salt Typhoon) continues to target and penetrate telecommunications providers globally, including in the US.

Inside the Scam: North Koreaʼs IT Worker Threat

Click here to read the report.

Key Takeaways

  • PurpleBravo has targeted at least seven entities, three of which are in the cryptocurrency sector, including a market-making firm, an online casino, and a blockchain software company.
  • PurpleBravo was active on at least three hiring websites, Telegram, and GitHub, regularly posting job advertisements and updating repositories.
  • Insikt Group identified at least seven suspected North Korea-linked front companies operating in China spoofing legitimate IT firms in China, India, Pakistan, Ukraine, and the United States.
  • Bottom Line: North Korea’s malign cyber activity continues at scale.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.recordedfuture.com/blog/munich-security-conference