Federal civilian executive branch agency hit by network compromise
Incident
Summary
Hide ▲
Show ▼
A federal civilian executive branch agency was compromised in an early September 2025 intrusion that left attackers with persistent access on Cisco Firepower and Secure Firewall devices. The intrusion involved Line Viper as the initial loader and Firestarter as the backdoor that kept access alive after patching. Attackers are believed to have entered through CVE-2025-20333 and/or CVE-2025-20362. The compromise matters because Firestarter can survive reboots, firmware updates, and security patches, making remediation harder and prolonging exposure.
Related Happenings
CISA Microsoft SharePoint hardening guidance for exploited zero-days
Advisory/Mitigation
H score46
First: 15.07.2026 17:07
Last: 15.07.2026 17:07
Sources 1
About this happening:
CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...
CISA Microsoft SharePoint hardening guidance for exploited zero-days
Advisory/MitigationAbout this happening: CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...
CISA BOD 26-04 SharePoint remediation deadline
Public Sector Action
H score77
First: 15.07.2026 12:44
Last: 15.07.2026 12:44
Sources 1
About this happening:
CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...
CISA BOD 26-04 SharePoint remediation deadline
Public Sector ActionAbout this happening: CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector Action
H score34
First: 15.07.2026 08:30
Last: 15.07.2026 08:30
Sources 1
About this happening:
CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector ActionAbout this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...
CISA sets June 28 patch deadline for Cisco Unified Communications Manager Server
Public Sector Action
H score35
First: 26.06.2026 22:43
Last: 26.06.2026 22:43
Sources 1
About this happening:
CISA ordered federal agencies to patch CVE-2026-20230 in Cisco Unified Communications Manager Server by June 28, tightening exposure around an actively exploited...
CISA sets June 28 patch deadline for Cisco Unified Communications Manager Server
Public Sector ActionAbout this happening: CISA ordered federal agencies to patch CVE-2026-20230 in Cisco Unified Communications Manager Server by June 28, tightening exposure around an actively exploited...
CISA KEV order for Copy Fail on federal Linux devices
Public Sector Action
H score33
First: 08.05.2026 10:45
Last: 08.05.2026 10:45
Sources 1
About this happening:
CISA added Copy Fail to the Known Exploited Vulnerabilities (KEV) Catalog, making the Linux flaw a federal remediation priority. The agency ordered federal agencies*...
CISA KEV order for Copy Fail on federal Linux devices
Public Sector ActionAbout this happening: CISA added Copy Fail to the Known Exploited Vulnerabilities (KEV) Catalog, making the Linux flaw a federal remediation priority. The agency ordered federal agencies*...
Timeline
-
24.04.2026 23:34 2 articles · 2mo ago
Firestarter disclosure on Cisco firewall devices
Initial DisclosureU.S. and U.K. cybersecurity agencies warned that the Firestarter backdoor persists on Cisco Firepower and Secure Firewall devices running ASA or FTD software, and attributed the activity to UAT-4356, a threat actor linked to ArcaneDoor. The agencies said the adversary likely obtained initial access by exploiting CVE-2025-20333 and/or CVE-2025-20362, and Cisco issued mitigations, workarounds, and indicators of compromise alongside guidance to reimage or upgrade affected devices.
Show sources
- Firestarter malware survives Cisco firewall updates, security patches — www.bleepingcomputer.com — 24.04.2026 23:34
- Firestarter malware survives Cisco firewall updates, security patches — www.bleepingcomputer.com — 24.04.2026 23:34