Hacker emerging from laptop with data streams

November 2, 2025 - Daily Cybersecurity News

China-linked 'Bronze Butler' Exploits Lanscope Zero-Day (CVE-2025-61932)

Critical

What happened

The cyber-espionage group 'Bronze Butler' exploited a zero-day vulnerability (CVE-2025-61932) in Motex Lanscope Endpoint Manager to deploy an updated version of their Gokcpdoor malware, enabling unauthorized remote code execution with SYSTEM privileges.

Who is affected

Organizations using Motex Lanscope Endpoint Manager versions 9.4.7.2 and earlier are at risk, particularly those in sectors targeted by 'Bronze Butler'.

Why it matters

Exploitation of this vulnerability allows attackers to execute arbitrary code remotely, potentially leading to data theft, system compromise, and further network infiltration.

How it could have been prevented

Timely application of security patches released by Motex on October 20, 2025, and regular monitoring for unusual network activity.

Relevant professional terms

Zero-Day Vulnerability
A software flaw unknown to the vendor, exploited by attackers before a fix is available.
Remote Code Execution (RCE)
The ability of an attacker to run arbitrary code on a target system remotely.

Recommended reading: Sophos Reports on Bronze Butler Exploiting Lanscope Zero-Day

BADCANDY Attacks Exploiting Cisco IOS XE Vulnerability (CVE-2023-20198)

Critical

What happened

Cyber attackers are exploiting a critical vulnerability (CVE-2023-20198) in unpatched Cisco IOS XE devices to deploy a Lua-based web shell named BADCANDY, enabling unauthorized control over affected systems.

Who is affected

Organizations using unpatched Cisco IOS XE devices, particularly in Australia, with approximately 400 devices compromised since July 2025.

Why it matters

The exploitation allows attackers to gain elevated privileges, potentially leading to data breaches, service disruptions, and further network compromises.

How it could have been prevented

Applying the latest patches from Cisco, limiting public exposure of the web user interface, and adhering to Cisco's hardening guidelines.

Relevant professional terms

Web Shell
A malicious script that enables remote administration of a device.
CVSS Score
A standardized metric to assess the severity of security vulnerabilities.

Recommended reading: Cisco Security Advisory on CVE-2023-20198