logo

Governments on high alert after CISA snuffs out Firestarter backdoor on fed network

ID: a6e42dd8-d072-5e2e-b434-c0414a02c119

STIX ID: report--a6e42dd8-d072-5e2e-b434-c0414a02c119

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2026-04-24

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Firestarter, a previously unknown backdoor targeting Cisco ASA/FTD devices, was used to successfully compromise a U.S. federal agency according to CISA and the U.K. NCSC; the malware provides persistent remote access to networking devices even after updates, enabling re-entry without new vulnerabilities. CISA warns the incident may be part of a wider campaign against government and critical national infrastructure, ties the activity to group UAT-4356, references exploitation of recent Cisco CVEs, and advises organizations to collect evidence, run YARA rules, and perform memory/core-dump analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.