logo

State-Sponsored Hackers Exploit Two Cisco Zero-Day Vulnerabilities for Espionage

ID: 6a76a78b-de55-59c2-8bbb-0cbad59ff209

STIX ID: report--6a76a78b-de55-59c2-8bbb-0cbad59ff209

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-04-25

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Cisco Talos reported a campaign dubbed 'ArcaneDoor' (attributed to UAT4356/Storm-1849) that used two zero-day vulnerabilities in Cisco ASA/Firepower appliances to install two implants—Line Runner (persistent Lua HTTP implant) and Line Dancer (in-memory backdoor)—enabling configuration changes, packet capture/exfiltration, and stealthy espionage; CISA added the flaws to its KEV and vendors released fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.