logo

Renewed "ArcaneDoor" Campaign Targeting 0-day Vulnerabilities in Cisco ASA (Campaign)

ID: e21e6d3d-2275-5711-8004-3b2894df4a6d

STIX ID: report--e21e6d3d-2275-5711-8004-3b2894df4a6d

Feed Name: Wiz Cloud Threat Landscape

Threat Score
90/100

Date Published: 2025-09-26

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Renewed "ArcaneDoor" activity is exploiting two zero-day Cisco ASA vulnerabilities (CVE-2025-20333 — RCE, and CVE-2025-20362 — local privilege escalation) in the wild; NCSC and CISA corroborate the activity, attribute it to the same actor behind the early‑2024 ArcaneDoor campaign, and report use of malware dubbed RayInitiator and LINE VIPER, with US federal remediation mandated by September 26, 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.