logo

UAT-4356 Exploits Cisco Firepower Devices with Persistent Backdoor Firestarter

ID: c2299c55-a4f5-58fe-a2c8-6192cfb97ecd

STIX ID: report--c2299c55-a4f5-58fe-a2c8-6192cfb97ecd

Feed Name: ThreatCluster

Threat Score
78/100

Date Published: 2026-04-23

Date Updated: 2026-04-24

...
...

UAT-4356, a state-sponsored actor, is exploiting CVE-2025-20333 and CVE-2025-20362 in Cisco Firepower devices to install a persistent backdoor named Firestarter that manipulates the Cisco Service Platform mount list to survive firmware updates and reboots; CISA and the UK NCSC have issued warnings and federal audits were mandated after September 2025 patches proved ineffective.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.