Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. (cisa.gov) CISA and NCSC-UK Warn of FIRESTARTER Malware Targeting Cisco ASA, Firepower, and Secure Firewall Devices

(cisa.gov) CISA and NCSC-UK Warn of FIRESTARTER Malware Targeting Cisco ASA, Firepower, and Secure Firewall Devices

Scheduled Pinned Locked Moved Uncategorized
cybersecuritythreatintel
1 Posts 1 Posters 8 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • orlysec@swecyb.comO This user is from outside of this forum
    orlysec@swecyb.comO This user is from outside of this forum
    orlysec@swecyb.com
    wrote last edited by
    #1

    (cisa.gov) CISA and NCSC-UK Warn of FIRESTARTER Malware Targeting Cisco ASA, Firepower, and Secure Firewall Devices

    URGENT: FIRESTARTER malware achieves post-patching persistence on Cisco ASA/Firepower/FTD devices via CVE-2025-20333 & CVE-2025-20362. CISA/NCSC-UK report confirms APT exploitation.

    In brief - CISA and NCSC-UK warn of FIRESTARTER, a remote access malware targeting Cisco ASA, Firepower, and Secure Firewall devices. The APT actor exploits two firmware vulnerabilities to deploy the implant, which persists even after patching. Federal agencies must act under Emergency Directive 25-03.

    Technically - FIRESTARTER targets Cisco ASA/FTD software, leveraging CVE-2025-20333 and CVE-2025-20362 for initial access. Its post-patching persistence mechanism survives firmware updates, complicating remediation. CISA’s report provides IOCs, forensic guidance, and detection methods. FCEB agencies must enumerate affected devices, collect forensic data, and apply vendor updates to mitigate the threat.

    Source: https://www.cisa.gov/news-events/news/cisa-warns-firestarter-malware-targeting-cisco-asa-including-firepower-and-secure-firewall-products

    #Cybersecurity #ThreatIntel

    1 Reply Last reply
    1
    0
    • R relay@relay.infosec.exchange shared this topic
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Tags
    • Popular
    • World
    • Users
    • Groups