New Cisco firewall malware can only be killed by pulling the plug
ID: 8d2a25af-8d05-5740-ba2d-5f0c12c2b45d
STIX ID: report--8d2a25af-8d05-5740-ba2d-5f0c12c2b45d
Feed Name: Help Net Security
Threat Score
CISA and the UK NCSC warn that a state-linked group (UAT-4356) has used exploits for CVE-2025-20333 and CVE-2025-20362 to deploy a persistent backdoor called Firestarter on Cisco ASA/Firepower devices; Firestarter embeds into the device boot sequence and can be reactivated via a specially crafted WebVPN request, resists removal without a hard power cycle, and requires targeted hunting, core-dump collection, patching, and potentially reimaging to remediate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
