
November 2, 2025 - Daily Cybersecurity News
China-linked 'Bronze Butler' Exploits Lanscope Zero-Day (CVE-2025-61932)
CriticalWhat happened
The cyber-espionage group 'Bronze Butler' exploited a zero-day vulnerability (CVE-2025-61932) in Motex Lanscope Endpoint Manager to deploy an updated version of their Gokcpdoor malware, enabling unauthorized remote code execution with SYSTEM privileges.
Who is affected
Organizations using Motex Lanscope Endpoint Manager versions 9.4.7.2 and earlier are at risk, particularly those in sectors targeted by 'Bronze Butler'.
Why it matters
Exploitation of this vulnerability allows attackers to execute arbitrary code remotely, potentially leading to data theft, system compromise, and further network infiltration.
How it could have been prevented
Timely application of security patches released by Motex on October 20, 2025, and regular monitoring for unusual network activity.
Relevant professional terms
- Zero-Day Vulnerability
- A software flaw unknown to the vendor, exploited by attackers before a fix is available.
- Remote Code Execution (RCE)
- The ability of an attacker to run arbitrary code on a target system remotely.
Recommended reading: Sophos Reports on Bronze Butler Exploiting Lanscope Zero-Day
BADCANDY Attacks Exploiting Cisco IOS XE Vulnerability (CVE-2023-20198)
CriticalWhat happened
Cyber attackers are exploiting a critical vulnerability (CVE-2023-20198) in unpatched Cisco IOS XE devices to deploy a Lua-based web shell named BADCANDY, enabling unauthorized control over affected systems.
Who is affected
Organizations using unpatched Cisco IOS XE devices, particularly in Australia, with approximately 400 devices compromised since July 2025.
Why it matters
The exploitation allows attackers to gain elevated privileges, potentially leading to data breaches, service disruptions, and further network compromises.
How it could have been prevented
Applying the latest patches from Cisco, limiting public exposure of the web user interface, and adhering to Cisco's hardening guidelines.
Relevant professional terms
- Web Shell
- A malicious script that enables remote administration of a device.
- CVSS Score
- A standardized metric to assess the severity of security vulnerabilities.
Recommended reading: Cisco Security Advisory on CVE-2023-20198