RayInitiator is a malware family tracked across 4 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed November 2, 2025; most recent activity April 23, 2026.
RayInitiator is a malware family associated with campaigns targeting Cisco ASA firewalls, used to exploit exposed devices and establish footholds within compromised networks. It appears in the context of a broader wave of zero-day and exploit activity against Cisco firewall appliances, with indicators pointing to use by actors scanning and exploiting ASA devices worldwide. The family underscores growing perimeter-device risk and the critical need for rapid patching and monitoring.
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
Cisco has disclosed critical vulnerabilities in its Unified Contact Center Express (CCX) platform and Adaptive Security Appliances (ASA) that allow unauthenticated remote attackers to execute arbitrary code and…
Cisco Systems has issued a warning regarding a new attack variant targeting its Secure Firewall devices, leveraging vulnerabilities CVE-2025-20333 and CVE-2025-20362. These vulnerabilities could potentially lead to…
Cisco has reported ongoing attacks against its firewalls, specifically targeting vulnerabilities CVE-2025-20333 and CVE-2025-20362. These flaws allow remote code execution and unauthorized access, leading to potential…