logo

HIGH ALERT: New steps for organisations running Cisco Firepower and Secure Firewall products

ID: ec82dcab-1271-5235-a15e-7dc953ffdcad

STIX ID: report--ec82dcab-1271-5235-a15e-7dc953ffdcad

Feed Name: ASD's ACSC - Alerts RSS

Threat Score
85/100

Date Published: 2026-04-24

Date Updated: 2026-07-24

Author: Australian Cyber Security Centre (ACSC)

...
...

This advisory from ASD/ACSC (citing CISA and NCSC) warns of FIRESTARTER malware that maintains persistence on Cisco Secure ASA and Firepower/FTD devices—surviving upgrades and enabling re-access after patching via historical exploitation of CVE-2025-20333 and CVE-2025-20362. The alert lists affected Firepower and Secure Firewall series, directs operators to vendor advisories and detection commands (IOC, show checkheaps, show tech-support detail), recommends generating core dumps and running provided YARA rules, and instructs impacted organisations to report incidents and upgrade devices to patched releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.