Cyberattacks are getting sharper, faster, and harder to detect. The latest discovery involves two critical zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems. These flaws are being exploited by a skilled hacking group that has already breached live environments across the globe. What makes this story important is not just the technical side, but how quickly attackers moved before patches were available.
Quick Summary
- Hackers are exploiting Cisco and Citrix zero-days in live systems.
- The flaws allow remote code execution before login.
- A custom in-memory webshell hides from traditional antivirus tools.
- Amazon’s MadPot honeypot helped uncover the campaign.
- Businesses must act fast: patch, monitor, and isolate critical systems.
What Happened
The situation began when Amazon’s MadPot honeypot caught suspicious activity aimed at Citrix servers. Investigators later found it was exploiting an unknown flaw, now called Citrix Bleed Two (CVE-2025-5777). This vulnerability lets attackers run any command on a system without needing permission.
The same hacking group then turned its attention to Cisco Identity Services Engine (ISE), where they found another flaw, later named CVE-2025-20337. This one exploited a coding issue known as deserialization, allowing remote code execution even before the user logs in. Once inside, attackers gained full control of the system.
The frightening part? These attacks began before Cisco and Citrix publicly confirmed the issues or released patches. By the time companies were notified, intrusions had already started. Cybercriminals are not waiting for announcements. They monitor updates, test weaknesses instantly, and strike while defenses lag behind.
Relevant Source (AWS Security Blog): Amazon discovers APT exploiting Cisco and Citrix zero-days
Amazon’s MadPot team details how it first observed exploitation of Citrix Bleed Two and then uncovered a separate prelogin Cisco ISE flaw used in real attacks.
Relevant Source (Citrix Support): CVE-2025-5777 advisory for NetScaler ADC and Gateway
Citrix’s official notice explains affected products, versions, and patch guidance for Citrix Bleed Two, confirming the scope of the exploit activity.
Why It Matters: How This Impacts Real People
At first glance, this sounds like a corporate IT problem, but the fallout trickles down to everyone connected to a business network. Cisco ISE manages who can log in and what resources they can reach. When it’s compromised, attackers can impersonate employees, steal credentials, and spread malware throughout an organization.
For users, the risks include:
- Exposure of sensitive personal or company data.
- Business disruptions and service downtime.
- Identity theft or phishing using legitimate-looking accounts.
- Potential ransomware infections across entire systems.
Even if you don’t run Cisco or Citrix directly, you could be affected if your service provider or employer does. A breach in one network node often leads to wider exposure across supply chains and connected systems. When access control fails, every account becomes a potential doorway.
Relevant Source (CISA/NSA): Identity and Access Management Guidance
This joint guidance explains how weak identity controls lead to real-world compromise and maps best practices that reduce the user impact of credential theft and impersonation.
Relevant Source (FBI IC3): FBI Releases Annual Internet Crime Report
The latest IC3 figures quantify how compromises, phishing, and ransomware drive billions in losses for victims, illustrating the personal and business impact when access systems are abused.
How It Works
Let’s unpack what these hackers did in plain English. Cisco ISE processes data from users trying to log in. The attackers found a way to trick it into accepting and executing malicious data, even before authentication. That’s like someone convincing a security guard to open the door without showing an ID.
Once inside, the hackers installed a custom-built webshell called “IdentityAuditAction.” It disguises itself as part of Cisco’s normal files, runs entirely in memory, and never writes to the hard drive. This makes it nearly invisible to most antivirus tools.
The webshell uses clever tricks such as:
- Encryption (DES and Base64) to hide commands.
- Java reflection to blend in with existing code.
- Custom headers to activate only when specific signals are sent.
These features allow remote control of the system without leaving obvious traces. Analysts believe this group has advanced knowledge of Cisco and Citrix internals, suggesting either insider access or elite-level expertise. This is not random hacking. It’s strategic, stealthy, and professionally executed.

What To Do Now
Every organization, big or small, should treat this event as a serious warning. Even if you haven’t noticed problems, proactive action is crucial.
Immediate steps:
- Patch now. Apply Cisco and Citrix updates as soon as they are available.
- Restrict exposure. Keep management interfaces off public networks.
- Monitor behavior. Look for odd Tomcat activity or encrypted requests.
- Run threat scans. Use endpoint monitoring tools that detect memory-based attacks.
- Review access policies. Ensure only essential personnel have admin privileges.
Don’t assume that “no alerts” means you’re safe. These attacks are designed to leave no footprints. Ask your IT team today if your systems use Cisco ISE or Citrix. Confirm that updates are applied and management ports are not accessible online.
Relevant Source (CISA): Binding Operational Directive 23-02: Mitigating the Risk from Internet-Exposed Management Interfaces
This directive tells administrators to remove or restrict public access to management interfaces and tighten authentication, directly supporting steps to isolate Cisco and Citrix consoles and reduce attack surface.
Relevant Source (NSA): Network Infrastructure Security Guide
NSA’s hardening playbook covers device lockdown, management plane protections, logging, and least privilege, aligning with patching, interface restriction, and continuous monitoring recommendations.
The Bigger Picture: The Rise of Pre-Login Exploits
This campaign fits into a growing pattern of pre-authentication attacks, where hackers strike before login processes even begin. It marks a shift away from phishing and password theft toward direct exploitation of security tools themselves.
Such attacks expose a key flaw in modern cybersecurity: trust in trusted systems. Identity platforms like Cisco ISE are supposed to keep networks safe, but when they’re compromised, the entire trust model collapses.
Moving forward, organizations should invest in:
- Zero-trust architectures that verify every action, even from internal users.
- Behavioral monitoring to detect unusual data handling or traffic.
- Rapid patching pipelines to shrink the “patch-gap” window attackers exploit.
The new battlefield isn’t just passwords and phishing links. It’s the very software that defines who gets access in the first place.
Relevant Source (NIST): Zero Trust Architecture (SP 800-207)
NIST’s ZTA guidance explains how removing implicit trust and continuously verifying access reduces the blast radius of pre-login and identity-layer exploits.
Relevant Source (CISA): Hybrid Identity Solutions Architecture
CISA outlines hardening practices for identity platforms and management planes that help mitigate pre-authentication attack paths and trust failures in identity systems.
Conclusion: Trust Less, Verify More
The Cisco and Citrix zero-day campaign is a wake-up call for every business that handles sensitive data. Attackers no longer rely on old tricks; they target the backbone of network identity. The lesson is clear: patch quickly, restrict exposure, and assume that your most trusted tools can become targets.
FAQ
What is a zero-day vulnerability?
A zero-day is a flaw unknown to the software vendor, exploited before a fix is available.
How dangerous is this Cisco ISE exploit?
It allows full remote control before login, making it one of the most severe exploit types.
Can regular antivirus software detect this attack?
No. Since it runs only in memory, standard file-based scanners often miss it.
Who discovered the attack?
Amazon’s MadPot honeypot system identified the malicious activity first.
What should users do immediately?
Apply the latest patches, limit remote access, and monitor systems for strange traffic.
How JENI Helps You Stay Ahead of Cyber Threats
Cybersecurity risks like the Cisco and Citrix zero-days highlight a growing truth: prevention starts at the device level. When every second counts, users need tools that detect instability, maintain system integrity, and minimize performance gaps that attackers exploit. That’s where JENI comes in.
Why JENI Makes a Difference
- Smart system maintenance that cleans and repairs vulnerabilities before they become exploits.
- Real-time performance health checks to catch unusual behaviors early.
- Privacy-first design with no data harvesting or tracking of any kind.
JENI keeps systems stable, secure, and fast without running intrusive background services. It’s built for users who want a clean, efficient machine that performs reliably every time they log in. With its lightweight design and one-click optimization, JENI helps close the same cracks attackers love to exploit.
How We Protect Users Every Day
- On-demand protection that runs when you need it, using 0% CPU when idle.
- System-level cleanup that clears outdated logs and cached data that attackers often target.
JENI focuses on reducing your exposure by maintaining system hygiene and efficiency. By keeping endpoints in peak condition, it strengthens the first layer of digital defense, your computer. In a world where cyberattacks evolve faster than patches, JENI empowers users to stay resilient. It’s not just about optimization; it’s about digital readiness.

