Governments on high alert after CISA snuffs out Firestarter backdoor on fed network
ID: a6e42dd8-d072-5e2e-b434-c0414a02c119
STIX ID: report--a6e42dd8-d072-5e2e-b434-c0414a02c119
Feed Name: The Register (Security)
Firestarter, a previously unknown backdoor targeting Cisco ASA/FTD devices, was used to successfully compromise a U.S. federal agency according to CISA and the U.K. NCSC; the malware provides persistent remote access to networking devices even after updates, enabling re-entry without new vulnerabilities. CISA warns the incident may be part of a wider campaign against government and critical national infrastructure, ties the activity to group UAT-4356, references exploitation of recent Cisco CVEs, and advises organizations to collect evidence, run YARA rules, and perform memory/core-dump analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
