The Australian Signals Directorate (ASD) has issued an alert about ongoing cyber attacks targeting unpatched Cisco IOS XE equipment in the country with a previously undocumented implant known as BADCANDY.
CVE-2023-20198 (CVSS score: 10.0), a critical vulnerability that enables a remote, unauthenticated attacker to create an account with elevated privileges and use it to take control of vulnerable systems, is what the intelligence agency claims is being exploited in this action.
Since 2023, the security flaw has been actively exploited in the wild; in recent months, threat actors with ties to China, such as Salt Typhoon, have weaponized it to compromise telecom companies.
Variants of BADCANDY have been identified since October 2023, according to ASD, and new attacks are still being reported in 2024 and 2025. According to estimates, the malware has infected up to 400 computers in Australia since July 2025, with 150 of those devices being affected in October alone read more about ASD Warns of Ongoing BADCANDY Attacks Exploiting Cisco IOS XE Vulnerability.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
