惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
J
Java Code Geeks
博客园 - 聂微东
Microsoft Azure Blog
Microsoft Azure Blog
量子位
T
Tailwind CSS Blog
Vercel News
Vercel News
I
InfoQ
Stack Overflow Blog
Stack Overflow Blog
U
Unit 42
Engineering at Meta
Engineering at Meta
L
LangChain Blog
大猫的无限游戏
大猫的无限游戏
D
Docker
博客园_首页
P
Proofpoint News Feed
月光博客
月光博客
T
The Blog of Author Tim Ferriss
MyScale Blog
MyScale Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Martin Fowler
Martin Fowler
腾讯CDC
N
Netflix TechBlog - Medium
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

The Register - Security: Patches

Homeland security cybercops say patch TrueConf (Russia Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update Year-long Russian attacks infect users as soon as they look at an email Cisco SD-WAN make-me-root bug under attack Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9 AI is making Patch Tuesday (kinda) fun again Anthropic to release Mythos-class models to the public Clear your calendar, Drupal user: You have a critically urgent patch to install Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs Critical cPanel, WHM flaw probs exploited as 0-day, pros say Microsoft patch fell short. New Windows flaw exploited More Cisco SD-WAN bugs battered in attacks Critical Fortinet sandbox bugs allow auth bypass and RCE Ancient Excel bug comes out of retirement for active attacks Microsoft's massive Patch Tuesday: It's raining bugs Ransomware scum, other crims exploit 4 old Microsoft bugs Attackers exploited the FortiClient EMS bug as a 0-day Citrix NetScaler bug may be multiple flaws in one Ransomware crims abused Cisco 0-day weeks before disclosure Google rushes Chrome update to fix zero-days under attack CISA warns max-severity n8n bug is being exploited in the wild Cisco warns of two more SD-WAN bugs under active attack LexisNexis Legal & Professional confirms data breach Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover Patch these 4 critical, make-me-root SolarWinds bugs ASAP Attacker gets into France's DB listing all bank accounts CISA gives feds 3 days to patch actively exploited Dell bug CISA gives feds 3 days to patch actively exploited Dell bug Google fixes exploited Chrome CSS zero-day
50K Cisco firewalls remain vulnerable to advanced attacks
Connor Jones Connor Jones · 2025-10-01 · via The Register - Security: Patches

Patches

Warnings about Cisco vulns under active exploit are falling on deaf ears

50,000 firewall devices still exposed

Nearly 50,000 Cisco ASA/FTD instances vulnerable to two bugs that are actively being exploited by "advanced" attackers remain exposed to the internet, according to Shadowserver data.

The internet monitoring outfit said that as of Monday, the internet-facing Cisco firewalls are potentially exploitable, with the vast majority of those – more than 19,000 – located in the US.

The vulnerabilities in question are CVE-2025-20333 (9.9) and CVE-2025-20362 (6.5), which affect Cisco's Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices.

National security agencies such as the UK's NCSC and its equivalents in Canada, France, and the Netherlands each issued separate advisories warning of the threat the vulnerabilities present to organizations.

Sign in to sound off

Register for The Register's Forums here.

CISA issued a rare order to all federal civilian executive branch (FCEB) agencies to patch the vulnerabilities within 24 hours.

When bugs like this are added to CISA's Known Exploited Vulnerability catalog, FCEB agencies are typically afforded a three-week window in order to apply patches.

A 24-hour window is rare, but not unheard of, and is only used in cases where the likelihood of exploitation is especially high.

CISA told all agencies that failing to patch affected devices would introduce an "unacceptable risk" to government systems.

The vulnerabilities affect Cisco ASA software versions: 9.12, 9.14, 9.16 to 9.20, and 9.22 to 9.23. They also affect ASA and FTD versions 7.0 to 7.4, and 7.6 to 7.7.

Both the NCSC and CISA said the successful attacks seen so far are highly likely launched by those behind the ArcaneDoor attack campaign, who previously targeted the same Cisco products in 2024 by exploiting zero-days.

This time, the NCSC said the attackers are deploying malware called RayInitiator and Line Viper. RayInitiator, a bootkit designed to ensure stealthy and persistent access to devices and target networks, facilitates the deployment of Line Viper, a shellcode loader.

The NCSC said the deployment of malware via a persistent bootkit represents a sophisticated evolution in tradecraft compared to the ArcaneDoor campaign.

The devices at risk of exploitation are 5500-X-series firewalls. All of the targeted attacks so far have focused on devices either no longer supported with security updates or whose support ends today.

Some 5500-X-series devices go EOL in August 2026, which should be patched, but if there are no updates available for your deployment, then it's time to rip it out for good, the natsec agencies advised.

"It is critical for organizations to take note of the recommended actions highlighted by Cisco today, particularly on detection and remediation," NCSC CTO Ollie Whitehouse said last week.

"We strongly encourage network defenders to follow vendor best practices and engage with the NCSC's malware analysis report to assist with their investigations.

"End-of-life technology presents a significant risk for organizations. Systems and devices should be promptly migrated to modern versions to address vulnerabilities and strengthen resilience." ®