Find notable cyber news and cases, enriched with sources, timelines, and signals.

FIRESTARTER malware on Cisco ASA and FTD devices

Malware Activity
First reported
Last updated
Happening score
H score 33
2 unique sources, 2 articles

Summary

Hide ▲

CISA has published analysis of FIRESTARTER, a malware strain that enables remote access and control on Cisco Firepower and Secure Firewall devices, raising the risk of persistent compromise. The assessment says an APT actor used CVE-2025-20333 and CVE-2025-20362 in Cisco ASA firmware to gain initial access and deploy the malware. FIRESTARTER can survive post-patching persistence, so remediation may not remove an existing intruder. CISA also issued new required actions in Emergency Directive 25-03 for FCEB agencies and urged defenders to check for compromise and apply vendor updates.

Related Happenings

CISA Microsoft SharePoint hardening guidance for exploited zero-days

Advisory/Mitigation
H score46 First: 15.07.2026 17:07 Last: 15.07.2026 17:07 Sources 1

About this happening: CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...

CISA BOD 26-04 SharePoint remediation deadline

Public Sector Action
H score77 First: 15.07.2026 12:44 Last: 15.07.2026 12:44 Sources 1

About this happening: CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...

CISA KEV catalog addition for SonicWall SMA 1000 flaws

Public Sector Action
H score34 First: 15.07.2026 08:30 Last: 15.07.2026 08:30 Sources 1

About this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...

CISA sets June 28 patch deadline for Cisco Unified Communications Manager Server

Public Sector Action
H score35 First: 26.06.2026 22:43 Last: 26.06.2026 22:43 Sources 1

About this happening: CISA ordered federal agencies to patch CVE-2026-20230 in Cisco Unified Communications Manager Server by June 28, tightening exposure around an actively exploited...

CISA BOD 26-04 three-day remediation directive

Public Sector Action
H score36 First: 24.06.2026 17:35 Last: 24.06.2026 17:35 Sources 1

About this happening: CISA's BOD 26-04 requires federal agencies to apply available security updates or vendor-recommended mitigations within three days, accelerating remediation for acti...

Timeline

  1. 24.04.2026 23:34 1 articles · 2mo ago

    CISA, NCSC-UK, and Cisco detail Firestarter persistence on Cisco Firepower and Secure Firewall devices

    Technical Analysis Update

    CISA, NCSC-UK, and Cisco detailed Firestarter persistence on Cisco Firepower and Secure Firewall devices running ASA or FTD software, attributing the backdoor to UAT-4356 and linking the activity to ArcaneDoor. The malware modifies CSP_MOUNT_LIST, stores a copy in /opt/cisco/platform/logs/var/log/svc_samcore.log, restores itself to /usr/bin/lina_cs, and relaunches after termination or reboot; Cisco recommends reimaging and upgrading to fixed releases, or using a cold restart only if reimaging is not possible.

    Show sources
  2. 23.04.2026 15:00 1 articles · 2mo ago

    CISA and NCSC-UK disclose FIRESTARTER on Cisco ASA and FTD devices

    Initial Disclosure

    CISA and the United Kingdom National Cyber Security Centre published a malware analysis report on FIRESTARTER, a backdoor targeting Cisco Firepower and Secure Firewall products running ASA or FTD software; they assessed that an APT actor exploited CVE-2025-20333 and CVE-2025-20362 in Cisco ASA firmware to gain initial access and deploy FIRESTARTER, and CISA issued Emergency Directive 25-03 requiring FCEB agencies to identify affected devices, collect forensic data, and apply vendor-provided updates.

    Show sources