Governments issue alerts after 'sophisticated' state-backed actor found exploiting flaws in Cisco security boxes
ID: 3905744c-fc99-5006-ae98-7f15973aef12
STIX ID: report--3905744c-fc99-5006-ae98-7f15973aef12
Feed Name: The Register (Security)
Threat Score
Security researchers and multiple national CERTs warn that a sophisticated, likely state-sponsored group (tracked as UAT4356/STORM-1849) has been exploiting high- and medium-severity Cisco ASA/FTD vulnerabilities to implant custom malware (Line Dancer and Line Runner) in order to conduct espionage against VPN and perimeter network devices worldwide; Cisco, CISA and partner agencies have released advisories and patches and urge investigation and patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
