Related Threat Clusters
-
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
37 articles · Updated April 23, 2026 -
Exploitation of Remote Services in Cyber Attacks
Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…
2 articles · Updated June 3, 2026 -
Cisco ASA Zero-Day Exploited in State-Espionage Campaign
Cisco disclosed a state-espionage campaign targeting its Adaptive Security Appliances (ASA), which are used for firewall and VPN functions. Attackers exploited two zero-day vulnerabilities to infiltrate government…
27 articles · Updated December 18, 2025 -
Cisco Faces Multiple Critical Vulnerabilities in Unified CCX and Firewalls
Cisco has disclosed critical vulnerabilities in its Unified Contact Center Express (CCX) platform and Adaptive Security Appliances (ASA) that allow unauthenticated remote attackers to execute arbitrary code and…
10 articles · Updated November 10, 2025 -
Cisco Warns of New Attack Variant Targeting Firewalls
Cisco Systems has issued a warning regarding a new attack variant targeting its Secure Firewall devices, leveraging vulnerabilities CVE-2025-20333 and CVE-2025-20362. These vulnerabilities could potentially lead to…
4 articles · Updated November 6, 2025 -
APT Groups BITTER and ArcaneDoor Target Enterprises with Cyber Attacks
In November 2025, the Indian APT group BITTER launched a cyber attack targeting enterprises and carriers. Earlier, in September 2025, the APT group ArcaneDoor exploited a zero-day vulnerability in the Cisco Adaptive…
2 articles · Updated December 31, 2025 -
Cisco Firewalls Targeted by New Attack Variant Exploiting Critical Vulnerabilities
Cisco has reported ongoing attacks against its firewalls, specifically targeting vulnerabilities CVE-2025-20333 and CVE-2025-20362. These flaws allow remote code execution and unauthorized access, leading to potential…
20 articles · Updated November 14, 2025 -
ATT&CK v19 Release Introduces Major Changes in Defense Evasion Tactics
The ATT&CK framework has released version 19, which includes significant updates to its structure and coverage. Notably, the Defense Evasion Tactic has been split into two distinct categories: Stealth and Defense…
7 articles · Updated April 28, 2026
Recent Intelligence Reports
- External Remote Services — attack.mitre.org · June 3, 2026
- T1685: Disable or Modify Tools — attack.mitre.org · April 28, 2026
- Hackers Exploiting Cisco Firepower Devices’ Using n — Cybersecuritynews · April 25, 2026
- Firestarter malware survives Cisco firewall updates, security patches — Bleepingcomputer · April 24, 2026
- US, UK agencies warn hackers were hiding on Cisco firewalls long after patches were applied — Cyberscoop · April 23, 2026
- UAT-4356's Targeting of Cisco Firepower Devices — Blog.Talosintelligence · April 23, 2026
- ArcaneDoor Attack (Cisco ASA Zero-Day) — Filestore.Fortinet · December 18, 2025
- Cisco ASA firewalls still under attack; CISA issues guidance for patch — Scmagazine · November 14, 2025