IdentityAuditAction stealth web shell deployment on Cisco ISE
Malware Activity
Summary
Hide ▲
Show ▼
A custom web shell, IdentityAuditAction, was deployed on Cisco ISE endpoints after exploitation of CVE-2025-20337, creating a stealthy post-exploitation foothold. It posed persistence and evasion risk by masquerading as a legitimate ISE component and intercepting requests as an HTTP listener. The implant also used Java reflection and Tomcat thread injection to reduce detection and complicate forensics.
Related Happenings
Cisco security patch release for CVE-2026-20184
Security Patch Release
H score44
First: 16.04.2026 14:27
Last: 16.04.2026 14:27
Sources 1
About this happening:
Cisco released patches for four critical flaws affecting Identity Services Engine (ISE), ISE-PIC, and Webex Services, closing paths to arbitrary code executi...
Cisco security patch release for CVE-2026-20184
Security Patch ReleaseAbout this happening: Cisco released patches for four critical flaws affecting Identity Services Engine (ISE), ISE-PIC, and Webex Services, closing paths to arbitrary code executi...
Cisco ISE and ISE-PIC input-validation RCE (CVE-2026-20147)
Vulnerability
H score39
First: 16.04.2026 14:27
Last: 16.04.2026 14:27
Sources 1
About this happening:
Cisco's CVE-2026-20147 flaw in Identity Services Engine (ISE) and ISE-PIC can let authenticated admins reach remote code execution by sending crafted HTTP reques...
Cisco ISE and ISE-PIC input-validation RCE (CVE-2026-20147)
VulnerabilityAbout this happening: Cisco's CVE-2026-20147 flaw in Identity Services Engine (ISE) and ISE-PIC can let authenticated admins reach remote code execution by sending crafted HTTP reques...
BPFDoor Linux backdoor with HTTPS-hidden trigger packets
Malware Activity
H score23
First: 26.03.2026 19:40
Last: 26.03.2026 19:40
Sources 1
About this happening:
A newly disclosed BPFDoor variant is hiding trigger packets inside HTTPS traffic and using ICMP between infected hosts, making the Linux backdoor harder to detect...
BPFDoor Linux backdoor with HTTPS-hidden trigger packets
Malware ActivityAbout this happening: A newly disclosed BPFDoor variant is hiding trigger packets inside HTTPS traffic and using ICMP between infected hosts, making the Linux backdoor harder to detect...
BeyondTrust Remote Support and Privileged Remote Access CVE-2026-1731 active exploitation wave
Exploitation Wave
H score76
First: 12.02.2026 23:34
Last: 12.02.2026 23:34
Sources 1
About this happening:
CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access is now seeing first in-the-wild exploitation, putting exposed appliances at risk of remote...
BeyondTrust Remote Support and Privileged Remote Access CVE-2026-1731 active exploitation wave
Exploitation WaveAbout this happening: CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access is now seeing first in-the-wild exploitation, putting exposed appliances at risk of remote...
React/Next.js applications React2Shell RCE flaw (CVE-2025-55182)
Vulnerability
H score54
First: 09.02.2026 10:37
Last: 09.02.2026 10:37
Sources 1
About this happening:
React2Shell (CVE-2025-55182) has been repeatedly exploited against React Server Components (RSC) and Next.js systems, with Huntress saying the first attempt it saw cam...
React/Next.js applications React2Shell RCE flaw (CVE-2025-55182)
VulnerabilityAbout this happening: React2Shell (CVE-2025-55182) has been repeatedly exploited against React Server Components (RSC) and Next.js systems, with Huntress saying the first attempt it saw cam...
Latest development: 09.03.2026 23:45
Google reports that newly disclosed third-party flaws are increasingly being exploited for initial access to cloud environments, with React2Shell (CVE-2025-55182) and CVE-2025-24893 highlighted as frequent RCE examples. The report says attackers are weaponizing new flaws within days, with cryptominers observed within 48 hours of vulnerability disclosure.
Timeline
-
12.11.2025 16:00 2 articles · 8mo ago
Amazon identifies IdentityAuditAction web shell on Cisco ISE
Technical Analysis UpdateAmazon Threat Intelligence linked exploitation of CVE-2025-20337 on Cisco Identity Service Engine (ISE) to a custom web shell named IdentityAuditAction, describing pre-auth admin access, a previously undocumented endpoint that used vulnerable deserialization logic, and post-exploitation behavior disguised as a legitimate ISE component.
Show sources
- Hackers exploited Citrix, Cisco ISE flaws in zero-day attacks — www.bleepingcomputer.com — 12.11.2025 16:00
- Hackers exploited Citrix, Cisco ISE flaws in zero-day attacks — www.bleepingcomputer.com — 12.11.2025 16:00