CVE-2024-20353 and CVE-2024-20359
ID: 65aeb474-abd8-50c0-abc7-f03e05b5178a
STIX ID: report--65aeb474-abd8-50c0-abc7-f03e05b5178a
Feed Name: Arctic Wolf Blog
Cisco Talos and government agencies disclosed an active espionage campaign targeting Cisco ASA/FTD devices that abused CVE-2024-20353 (DoS) and CVE-2024-20359 (persistent local code execution) to establish persistence; adversaries deployed Line Dancer (memory-resident shellcode loader) and Line Runner (persistent Lua HTTP backdoor) to exfiltrate data, disable logging, execute commands, and create persistent remote access. Cisco and partners recommend upgrading to fixed software versions and applying device hardening and access controls to mitigate the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
