Multiple network security products, including those from Fortinet, SonicWall, Cisco, and WatchGuard, have been actively targeted by threat actors exploiting recently disclosed vulnerabilities. Cisco reported that CVE-2025-20393, a critical flaw in AsyncOS, has been abused by a China-nexus APT group (UAT-9686) to deliver malware such as ReverseSSH, Chisel, AquaPurge, and AquaShell, with the vulnerability remaining unpatched. SonicWall confirmed exploitation of CVE-2025-40602, a local privilege escalation flaw in SMA 100 series appliances, which, when chained with CVE-2025-23006, enables unauthenticated remote code execution with root privileges. These attacks highlight a growing trend of adversaries focusing on firewalls and edge appliances to gain deep visibility into network traffic, VPN connections, and downstream systems.
Security researchers and vendors have issued warnings and patches in response to these incidents. Fortinet's FortiGate firewalls are also being exploited via CVE-2025-59718, allowing attackers to bypass authentication and export system configuration files. The rapid exploitation of these vulnerabilities underscores the critical need for organizations to promptly apply security updates and monitor for signs of compromise in their network infrastructure. The incidents reflect a broader shift in attacker tactics, with a focus on exploiting trusted network devices to achieve persistent access and facilitate further malicious activity within targeted environments.

See which actors are running it and whether you're in range.
9 events from the most recent confirmed update back to the earliest known activity.
Authorities dismantled the E-Note cryptocurrency exchange, which had been used to launder proceeds from cybercrime. The takedown represented a notable law enforcement action against criminal financial infrastructure.
The FBI issued a warning about advanced impersonation campaigns, highlighting the threat of attackers abusing trusted identities and social engineering techniques.
Researchers reported on a global phishing operation dubbed Scripted Sparrow that targeted finance teams with sophisticated business email compromise tactics.
ESET disclosed a new China-aligned APT tracked as LongNosedGoblin. The group was observed abusing Windows Group Policy to target government entities in Southeast Asia and Japan.
SoundCloud confirmed that it had suffered a security breach and was also dealing with continuing denial-of-service attacks. The company publicly acknowledged both incidents during the week.
A local privilege escalation zero-day, CVE-2025-40602, in SonicWall SMA 1000 appliances was reported as actively exploited. The disclosure led to urgent warnings for affected organizations.
Attackers were reported exploiting CVE-2025-59718, an authentication bypass vulnerability affecting Fortinet FortiGate firewalls. The activity prompted urgent security advisories urging defenders to patch quickly.
Apple released security updates to fix two WebKit vulnerabilities, CVE-2025-14174 and CVE-2025-43529, that were being actively exploited in the wild.
Cisco email security appliances were found compromised and backdoored in an intrusion attributed to a suspected Chinese-nexus threat actor. The flaw used in the attacks remained unpatched at the time of reporting.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.