
























An article from
A federal agency was impacted by a hacking campaign that exploited flaws in Cisco devices.
U.S. and U.K. authorities have issued warnings about backdoor malware used against vulnerable Cisco devices that can maintain persistence despite being patched.
The backdoor malware, dubbed Firestarter, was discovered during a forensic investigation at a federal civilian executive branch agency during a forensic investigation, according to the Cybersecurity and Infrastructure Security Agency.
CISA issued an emergency directive in September 2025 for federal agencies to immediately take steps to mitigate against the attacks, which were linked to the ArcaneDoor activity initially identified in early 2024.
The campaign was linked to a threat actor tracked as UAT-4356, according to a Thursday blog post from Cisco Talos.
The attacks targeted Cisco Firepower and Secure Firewall products that used Adaptive Security Appliance or Firepower Threat Defense software, CISA warned in an advisory released Thursday.
The hackers exploited two critical vulnerabilities: CVE-2025-20333 and CVE-2025-20362.
CISA said it found suspicious connections on a Firepower device running Adaptive Security Appliance software at the federal agency. The investigation discovered that hackers deployed an implant called Line Viper and used Firestarter malware in order to maintain persistence on the device.
Cisco released a security bulletin Thursday with guidance on how to mitigate the threat and issued an update Friday.
CISA has issued new guidance for all FCEB agencies to check for potential compromise and take additional mitigation measures
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。