logo

CISA: US agency breached through Cisco vulnerability, FIRESTARTER backdoor allowed access through March

ID: b72a72a1-33b0-557c-9350-68c3b2f153a5

STIX ID: report--b72a72a1-33b0-557c-9350-68c3b2f153a5

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2026-04-23

Date Updated: 2026-05-01

...
...

CISA reported that a U.S. federal civilian agency was breached through Cisco ASA/Firepower vulnerabilities (CVE-2025-30333 and CVE-2025-20362). Attackers installed FIRESTARTER malware to retain persistence and used Line Viper to establish illegitimate VPN sessions that bypass authentication, exposing administrative credentials, certificates and private keys; CISA issued updated advisories and mandatory actions for federal agencies, requiring device inventories and forensic checks, and warned that patched devices may still be compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.