State-Sponsored Hackers Exploit Two Cisco Zero-Day Vulnerabilities for Espionage
ID: 6a76a78b-de55-59c2-8bbb-0cbad59ff209
STIX ID: report--6a76a78b-de55-59c2-8bbb-0cbad59ff209
Feed Name: The Hacker News
Threat Score
Cisco Talos reported a campaign dubbed 'ArcaneDoor' (attributed to UAT4356/Storm-1849) that used two zero-day vulnerabilities in Cisco ASA/Firepower appliances to install two implants—Line Runner (persistent Lua HTTP implant) and Line Dancer (in-memory backdoor)—enabling configuration changes, packet capture/exfiltration, and stealthy espionage; CISA added the flaws to its KEV and vendors released fixes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
