Cisco: Actively exploited firewall flaws now abused for DoS attacks
ID: e001cb9e-cfd4-5934-a293-afcffe4b5c38
STIX ID: report--e001cb9e-cfd4-5934-a293-afcffe4b5c38
Feed Name: Bleeping Computer
Threat Score
Cisco disclosed and patched multiple critical vulnerabilities in ASA/FTD and IOS devices (including CVE-2025-20362 and CVE-2025-20333) that are being actively exploited — when chained they allow unauthenticated remote takeover and can force devices into reboot loops; the activity is attributed to the state-sponsored ArcaneDoor group (UAT4356/STORM-1849), has prompted a CISA emergency directive, and Shadowserver reports over 34,000 exposed instances remaining.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
