UAT-4356 Exploits Cisco Firepower Devices with Persistent Backdoor Firestarter
ID: c2299c55-a4f5-58fe-a2c8-6192cfb97ecd
STIX ID: report--c2299c55-a4f5-58fe-a2c8-6192cfb97ecd
Feed Name: ThreatCluster
Threat Score
UAT-4356, a state-sponsored actor, is exploiting CVE-2025-20333 and CVE-2025-20362 in Cisco Firepower devices to install a persistent backdoor named Firestarter that manipulates the Cisco Service Platform mount list to survive firmware updates and reboots; CISA and the UK NCSC have issued warnings and federal audits were mandated after September 2025 patches proved ineffective.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
