Cisco Systems has issued a critical advisory for a command injection vulnerability (CVE-2025-20161) affecting Nexus 3000 and 9000 Series Switches in standalone NX-OS mode. Attackers with admin access can execute arbitrary commands, posing risks of data exfiltration or service disruption. Cisco urges prompt upgrades and recommends verifying software integrity to mitigate risks.

Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2
The newly identified malware “Squidoor,” suspected to be created by a Chinese threat actor, is a sophisticated tool targeting sectors such as government, defence, telecommunications,