Hackers Exploit Cisco Firepower N-Day Flaws for Unauthorized Access
ID: 17baf8bd-02c6-56f8-832e-2cb238bf055f
STIX ID: report--17baf8bd-02c6-56f8-832e-2cb238bf055f
Feed Name: GBHackers
Threat Score
State-sponsored actor UAT-4356 is actively exploiting two known FXOS vulnerabilities (CVE-2025-20333 and CVE-2025-20362) in Cisco Firepower devices to install a custom backdoor called FIRESTARTER that replaces a WebVPN XML handler in the LINA process to achieve stealthy RCE and persistence across graceful reboots; the advisory provides technical TTPs, IOCs (file paths, process, ClamAV signature, Snort rules) and remediation guidance from Cisco Talos and CISA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
