Adversaries
Threat actors
Actors and campaigns linked to CVEs across your products, from AI research.
Salt Typhoon
Threat actor · China (state)
Living-off-the-land across telecom carriers; JumbledPath Go tool for packet capture and log erasure.
Static Tundra
Threat actor · Russia (state)
Smart Install exploitation of unpatched/EoL Cisco devices for intelligence collection (~250k exposed 4786).
UNC3886
Threat actor · China (state)
Six TINYSHELL backdoor variants on Junos MX routers; Veriexec bypass via memory injection.
Volt Typhoon
Threat actor · China (state)
Bronze SilhouetteVanguard Panda
VersaMem in-memory Java web shell hooks Director auth to steal credentials; access via port 4566.
BadCandy mass exploitation (unattributed)
Campaign · Unknown (Oct 2023)
Chained the IOS XE Web UI zero-days to implant the BadCandy Lua web shell on 40,000+ devices.
J-Magic / cd00r
Campaign · Unknown (Lumen)
cd00r
In-memory magic-packet backdoor on enterprise Junos routers / VPN gateways; RSA-gated reverse shell. Not QFX.