CVE-2025-20333
published 2025-09-25CVE-2025-20333: A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD)…
PriorityP197critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-09-26
Exploited in the wild
EPSS
40.39%
98.5th percentile
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device.
This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests. An attacker with valid VPN user credentials could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as root, possibly resulting in the complete compromise of the affected device.
Affected
355 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | >= 9.12 < 9.12.4.72 | 9.12.4.72 |
| cisco | adaptive_security_appliance_software | >= 9.14 < 9.14.4.28 | 9.14.4.28 |
| cisco | adaptive_security_appliance_software | >= 9.16 < 9.16.4.85 | 9.16.4.85 |
| cisco | adaptive_security_appliance_software | >= 9.17.0 < 9.18.4.67 | 9.18.4.67 |
| cisco | adaptive_security_appliance_software | >= 9.17.0 < 9.17.1.45 | 9.17.1.45 |
| cisco | adaptive_security_appliance_software | >= 9.18 < 9.18.4.47 | 9.18.4.47 |
| cisco | adaptive_security_appliance_software | >= 9.19 < 9.20.4.10 | 9.20.4.10 |
| cisco | adaptive_security_appliance_software | >= 9.19 < 9.19.1.37 | 9.19.1.37 |
| cisco | adaptive_security_appliance_software | >= 9.20 < 9.20.3.7 | 9.20.3.7 |
| cisco | adaptive_security_appliance_software | >= 9.22 < 9.22.2.14 | 9.22.2.14 |
| cisco | adaptive_security_appliance_software | >= 9.22 < 9.22.1.3 | 9.22.1.3 |
| cisco | adaptive_security_appliance_software | >= 9.23 < 9.23.1.19 | 9.23.1.19 |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
Detection & IOCsextracted from sources · hover to see the quote
sigma↗
dataset = cisco_asa_raw | alter alert_level = arrayindex(regextract(_raw_log, "\s%.*?(ASA\-[\d])\-[\d]{1,}\:"), 0)- →Hunt for evidence of ROMMON modification on Cisco ASA devices, which indicates threat actor persistence across reboots and software upgrades. ↗
- →Focus detection on Cisco ASA 5500-X series devices without secure boot enabled, as these are the primary targets for LINE VIPER and RayInitiator deployment. ↗
- →Monitor WebVPN client authentication sessions over HTTPS and anomalous ICMP traffic with raw TCP responses from ASA devices, as LINE VIPER uses these channels for C2. ↗
- →Use the Cortex XDR/XSIAM hunting query graphing all log types from Cisco ASA devices to identify gaps or sudden drops in log volume that may indicate logging was disabled by the threat actor. ↗
- →Exploitation targets VPN web services on ASA/FTD; monitor for crafted HTTP(S) requests to restricted VPN URL endpoints that arrive without authentication. ↗
- →A new attack variant (disclosed November 5, 2025) causes unexpected device reloads leading to DoS — monitor for abnormal ASA/FTD reload events on unpatched devices. ↗
- ·CVE-2025-20333 requires the VPN web server to be enabled on the targeted ASA/FTD device; attacks specifically targeted 5500-X Series devices with VPN web services enabled. ↗
- ·RayInitiator and LINE VIPER are only deployed to Cisco ASA 5500-X series devices that do not have secure boot enabled; devices with secure boot are not susceptible to this persistence mechanism. ↗
- ·Temporary mitigations (e.g., disabling SSL/TLS-based VPN web services) carry their own operational risks and are not a substitute for patching. ↗
- ·End-of-support ASA devices cannot be patched and must be permanently disconnected; CISA mandated disconnection of end-of-support devices by September 30. ↗
CVSS provenance
nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vulncheck9.9CRITICAL
cisa9.9CRITICAL
vendor_cisco9.9CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vg93-6w2x-3cvp: A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FT
ghsa_unreviewed·2025-09-25
CVE-2025-20333 [CRITICAL] CWE-120 GHSA-vg93-6w2x-3cvp: A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FT
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device.
This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests. An attacker with valid VPN user credentials could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as root, possibly resulting in the complete compromise of the affected device.
VulnCheck
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability
vulncheck·2025·CVSS 9.9
CVE-2025-20333 [CRITICAL] CWE-120 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution. This vulnerability could be chained with CVE-2025-20362.
Affected: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
Required Action: The KEV due date refers to the deadline by which FCEB agencies are expected to review and begin implementing the guidance outlined in Emergency Directive (ED) 25-03 (URL listed below in Notes). Agencies must follow the mitigation steps provided by CISA (URL listed below in Notes) and vendor’s instruc
VulnCheck
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability
vulncheck·2025·CVSS 9.9
CVE-2025-20362 [CRITICAL] CWE-862 Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulnerability. This vulnerability could be chained with CVE-2025-20333.
Affected: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
Required Action: The KEV due date refers to the deadline by which FCEB agencies are expected to review and begin implementing the guidance outlined in Emergency Directive (ED) 25-03 (URL listed below in Notes). Agencies must follow the mitigation steps provided by CISA (URL listed below in Notes) and vendor’s instructions (URL listed below in
VulnCheck
Cisco ASA and FTD Denial of Service Vulnerability
vulncheck·2024·CVSS 8.6
CVE-2024-20353 [HIGH] CWE-835 Cisco ASA and FTD Denial of Service Vulnerability
Cisco ASA and FTD Denial of Service Vulnerability
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition.
Affected: Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-websrvs-dos-X8gNucD2; https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_attacks_event_response; https://www.cisa.gov/news-events/alerts/2024/04/24/cisco-releases-security-updates-addressing-arcane
VulnCheck
Cisco ASA and FTD Privilege Escalation Vulnerability
vulncheck·2024·CVSS 6.0
CVE-2024-20359 [MEDIUM] CWE-94 Cisco ASA and FTD Privilege Escalation Vulnerability
Cisco ASA and FTD Privilege Escalation Vulnerability
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a privilege escalation vulnerability that can allow local privilege escalation from Administrator to root.
Affected: Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-rce-FLsNXF4h; https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_attacks_event_response; https://www.cisa.gov/news-events/alerts/2024/04/24/cisco-releases-security
CISA
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability
cisa·2025-09-25·CVSS 9.9
CVE-2025-20333 [CRITICAL] CWE-120 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability
Vulnerability: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability
Affected: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution. This vulnerability could be chained with CVE-2025-20362.
Required Action: The KEV due date refers to the deadline by which FCEB agencies are expected to review and begin implementing the guidance outlined in Emergency Directive (ED) 25-03 (URL listed below in Notes). Agencies must follow the mitigation steps provided by CISA (URL listed below in Notes) and ve
CISA
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability
cisa·2025-09-25·CVSS 9.9
CVE-2025-20362 [CRITICAL] CWE-862 Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability
Vulnerability: Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability
Affected: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulnerability. This vulnerability could be chained with CVE-2025-20333.
Required Action: The KEV due date refers to the deadline by which FCEB agencies are expected to review and begin implementing the guidance outlined in Emergency Directive (ED) 25-03 (URL listed below in Notes). Agencies must follow the mitigation steps provided by CISA (URL listed below in Notes) and vendor’s instructions (URL l
Cisco
Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Unauthorized Access Vulnerability
vendor_cisco·2025-09-25·CVSS 9.9
CVE-2025-20362 [CRITICAL] CWE-862 Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Unauthorized Access Vulnerability
Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Unauthorized Access Vulnerability
Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS) conditions. Cisco strongly recommends that all customers upgrade to the fixed software releases that are listed in the Fixed Software section of this advisory.
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could all
Cisco
Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Remote Code Execution Vulnerability
vendor_cisco·2025-09-25·CVSS 9.9
CVE-2025-20333 [CRITICAL] CWE-120 Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Remote Code Execution Vulnerability
Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Remote Code Execution Vulnerability
Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS) conditions. Cisco strongly recommends that all customers upgrade to the fixed software releases that are listed in the Fixed Software section of this advisory.
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could a
Cisco
Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Unauthorized Access Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20362 Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Unauthorized Access Vulnerability
CVE-2025-20362: Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Unauthorized Access Vulnerability
Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS) conditions. Cisco strongly recommends that all customers upgrade to the fixed software releases that are listed in the Fixed Software section of this advisory. A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Soft
Cisco
Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Unauthorized Access Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20333 Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Unauthorized Access Vulnerability
CVE-2025-20333: Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Unauthorized Access Vulnerability
Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS) conditions. Cisco strongly recommends that all customers upgrade to the fixed software releases that are listed in the Fixed Software section of this advisory. A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Soft
Suricata
ET WEB_SERVER Cisco ASA/FTD Authenticated Buffer Overflow (CVE-2025-20333)
suricata·2025-10-06·CVSS 9.9
CVE-2025-20333 [CRITICAL] ET WEB_SERVER Cisco ASA/FTD Authenticated Buffer Overflow (CVE-2025-20333)
ET WEB_SERVER Cisco ASA/FTD Authenticated Buffer Overflow (CVE-2025-20333)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SERVER Cisco ASA/FTD Authenticated Buffer Overflow (CVE-2025-20333)"; flow:established,to_server; http.uri; content:"/+CSCOE+/files/file_action.html"; fast_pattern; content:!"fs|3d|"; content:"mode|3d|upload"; content:"server|3d|"; content:"path|3d|"; http.cookie; content:"webvpn|3d|"; http.content_type; pcre:"/^[^\x3b]*?\x3b\s*?[^\x3d]+\x3d[^$]{8192,}/"; reference:url,attackerkb.com/topics/Szq5u0xgUX/cve-2025-20362/rapid7-analysis; reference:cve,2025-20333; classtype:web-application-attack; sid:2065052; rev:1; metadata:affected_product Cisco_ASA, affected_product Cisco_FTD, attack_target Server, tls_state TLSDecrypt, created_at 2025_10_06, cve CVE_2025_20333,
No public exploits indexed.
Microsoft
From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence
blogs_microsoft·2026-05-22·CVSS 8.8
CVE-2025-33073 [HIGH] From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence
After compromising the Confluence server, the threat actor obtained credentials and used them to attempt authentication against Windows infrastructure from the following files:
/opt/atlassian/confluence/conf/server.xml
/var/atlassian/application-data/confluence/confluence.cfg.xml
This was followed by Kerberos relay attacks and exploitation of CVE-2025-33073, highlighting the risk of credential theft from internal web applications and the importance of monitoring cross-system authentication events.
nxc smb [REDACTED_IP] -d [REDACTED_DOMAIN].com -u Jiraservices -p '********* -M coerce_plus -o M=PetitPotam L="localhost1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA"
python3 CVE-2025-33073.py -u [REDACTED_DOMAIN].com\Jiraservices -p ******** --attacker-ip [REDACTED_IP] --dns-ip [REDACTED_IP]
Bleepingcomputer
New Cisco DoS flaw requires manual reboot to revive devices
blogs_bleepingcomputer·2026-05-06·CVSS 9.9
CVE-2026-20188 [CRITICAL] New Cisco DoS flaw requires manual reboot to revive devices
## New Cisco DoS flaw requires manual reboot to revive devices
## Sergiu Gatlan
Cisco released security updates to fix a Crosswork Network Controller (CNC) and Network Services Orchestrator (NSO) denial-of-service (DoS) vulnerability that requires manually rebooting targeted systems for recovery.
Large enterprises and service providers leverage the CNC software suite to simplify multivendor network management and operations handling with automation, while the NSO orchestration platform helps them manage network devices and resources.
Tracked as CVE-2026-20188 , this high-severity security flaw stems from inadequate rate limiting on incoming network connections and can be exploited remotely by unauthenticated threat actors to crash unpatched Cisco CNC and Cisco NSO systems through low-c
Hackernews
⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
blogs_hackernews·2026-04-27
CVE-2025-20333 ⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
Everything is dumb again. This week feels broken in a very familiar way. Old tricks are back. New tools are doing shady crap. Supply chains got hit. Fake help desks worked. Weird research showed how easy some attacks still are.
Most of it feels like stuff we should have fixed years ago. Bad extensions. Stolen creds. Remote tools are getting abused. Malware hides in places people trust. Same mess, cleaner packaging.
Coffee is cold. The vuln list is ugly. Let’s get into it.
## ⚡ Threat of the Week
New fast16 Malware Was Developed Y
Bleepingcomputer
Firestarter malware survives Cisco firewall updates, security patches
blogs_bleepingcomputer·2026-04-24·CVSS 9.9
CVE-2025-20333 [CRITICAL] Firestarter malware survives Cisco firewall updates, security patches
## Firestarter malware survives Cisco firewall updates, security patches
## Bill Toulas
Cybersecurity agencies in the U.S. and U.K. are warning about a custom malware called Firestarter persisting on Cisco Firepower and Secure Firewall devices running Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software.
The backdoor has been attributed to a threat actor that Cisco Talos tracks internally as UAT-4356, known for cyberespionage campaigns, including ArcaneDoor .
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the U.K. National Cyber Security Center (NCSC) believe that the adversary obtained initial access by exploiting a missing authorization issue (CVE-2025-20333) and/or a buffer overflow bug (CVE-2025-20362).
In one incident at a federal civ
Hackernews
FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches
blogs_hackernews·2026-04-24·CVSS 9.9
CVE-2025-20333 [CRITICAL] FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed that an unnamed federal civilian agency's Cisco Firepower device running Adaptive Security Appliance (ASA) software was compromised in September 2025 with malware called FIRESTARTER .
FIRESTARTER, per CISA and the U.K.'s National Cyber Security Centre (NCSC), is assessed to be a backdoor designed for remote access and control. It's believed to be deployed as part of a "widespread" campaign orchestrated by an advanced persistent threat (APT) actor to obtain access to
Talos
It pays to be a forever student
blogs_talos·2026-04-23
CVE-2025-20333 It pays to be a forever student
## It pays to be a forever student
Welcome to this week’s edition of the Threat Source newsletter.
If I haven’t said it in a newsletter before, I'll say it now: If you want to be good at cybersecurity, be a forever student. Cultivating and feeding your desire to know how things work is one of the key ingredients to being a hacker. It’s not always about understanding the micro details, but the macro of how systems work. And not just computers or software or networking systems — those are ecosystems we’re usually quite familiar with — but what about economics? agriculture? material sciences? human behavior? music and art? Do any of those carry any value into this profession?
They damn sure do. Many, many times I have had to branch my technical research into domains that arbitrarily seem t
Talos
UAT-4356's Targeting of Cisco Firepower Devices
blogs_talos·2026-04-23·CVSS 9.9
CVE-2025-20333 [CRITICAL] UAT-4356's Targeting of Cisco Firepower Devices
## UAT-4356's Targeting of Cisco Firepower Devices
Cisco Talos is aware of UAT-4356 's continued active targeting of Cisco Firepower devices’ Firepower eXtensible Operating System (FXOS). UAT-4356 exploited n-day vulnerabilities ( CVE-2025-20333 and CVE-2025-20362 ) to gain unauthorized access to vulnerable devices, where the threat actor deployed their custom-built backdoor dubbed “FIRESTARTER.” FIRESTARTER considerably overlaps with the technical capabilities of RayInitiator’s Stage 3 shellcode that processes incoming XML-based payloads to endpoint APIs.
In early 2024, Cisco Talos attributed ArcaneDoor , a state-sponsored campaign focused on gaining access to network perimeter devices for espionage, to UAT-4356.
Customers are advised to refer to Cisco’s Security Advisory for mitigatio
Zscaler
CVE-2026-20131: Analysis of FMC RCE | ThreatLabz
blogs_zscaler·2026-03-23·CVSS 10.0
[CRITICAL] CVE-2026-20131: Analysis of FMC RCE | ThreatLabz
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Unit42
Iranian Cyber Threat Evolution: From MBR Wipers to Identity Weaponization
blogs_unit42·2026-03-16
Iranian Cyber Threat Evolution: From MBR Wipers to Identity Weaponization
## Iranian Cyber Threat Evolution: From MBR Wipers to Identity Weaponization
Justin Moore
Published: March 16, 2026
General
Insights
Agonizing Serpens
Agrius
Curious Serpens
Evasive Serpens
OilRig
Shamoon
Telegram
Wiper
Recent cyberattacks attributed to Iranian threat actors extend beyond typical network disruption. Rather than an isolated incident of sabotage, this type of attack sits within a broader context defined by Iran's reliance on asymmetric retaliation and historical proxy doctrine. Iran-aligned threat actors increasingly leverage cyberspace as a strategic equalizer.
For the Islamic Revolutionary Guard Corps (IRGC) and the Ministry of Intelligence and Security (MOIS), cyber operations provide a low-cost, high-impact mechanism for retaliation without crossing any ge
Unit42
Insights: Increased Risk of Wiper Attacks
blogs_unit42·2026-03-12
Insights: Increased Risk of Wiper Attacks
Threat Research Center
Insights
General
## Insights: Increased Risk of Wiper Attacks
Andy Piazza
Eric Goldstrom
Steve Elovitz
Published: March 12, 2026
General
Insights
Hacktivism
Wiper
Unit 42 is tracking an increased risk of wiper attacks related to the conflict with Iran, including multiple related incidents impacting organizations in Israel and the US. For the latest intelligence on cyberattacks associated with this conflict, review our Threat Brief: March 2026 Escalation of Cyber Risk Related to Iran .
The primary vector for recent destructive operations from the Handala Hack group (aka Void Manticore, COBALT MYSTIQUE and Storm-1084/Storm-0842) reportedly involves the exploitation of identity through phishing and administrative access through Microsoft Intune. Handala H
Unit42
Bring the Fight to the Edge: Turning Time Into an Advantage in OT Security
blogs_unit42·2026-02-24
Bring the Fight to the Edge: Turning Time Into an Advantage in OT Security
## Bring the Fight to the Edge: Turning Time Into an Advantage in OT Security
Adam Robbie
Published: February 24, 2026
General
Insights
Defense
Operational Technology
Threat detection
## Why OT Defenses Often Start Too Late
Industrial organizations are facing a growing paradox in cybersecurity. While operational technology (OT) environments are increasingly connected, most security strategies still assume threats will only materialize once attackers reach the plant floor. In reality, attacks that disrupt industrial operations rarely begin in OT environments. They originate upstream, progress over time and frequently exploit the persistent assumption of isolation. This shift fundamentally changes how defenders must think about visibility, detection and response across Informatio
Unit42
Happy 9th Anniversary, CTA: A Celebration of Collaboration in Cyber Defense
blogs_unit42·2026-01-24
Happy 9th Anniversary, CTA: A Celebration of Collaboration in Cyber Defense
## Happy 9th Anniversary, CTA: A Celebration of Collaboration in Cyber Defense
Kathi Whitbey
Published: January 23, 2026
General
Insights
Cyber Threat Alliance
Unit 42
## The Genesis of Collective Defense
At certain moments in a career, you get the rare opportunity to look back and say, this work mattered . Not because of an individual accomplishment, but because it contributed to something larger — something that changed how an industry thinks and operates. The Cyber Threat Alliance (CTA) is one of those efforts.
When the CTA was first conceived in 2014, the cybersecurity industry looked very different than how it does today. Threat intelligence was widely viewed as a competitive advantage, tightly guarded and rarely shared beyond company walls. Collaboration between major sec
Unit42
Securing Vibe Coding Tools: Scaling Productivity Without Scaling Risk
blogs_unit42·2026-01-08
Securing Vibe Coding Tools: Scaling Productivity Without Scaling Risk
## Securing Vibe Coding Tools: Scaling Productivity Without Scaling Risk
Kate Middagh
Michael Spisak
Published: January 8, 2026
General
Insights
GenAI
## Vibe Coding and Vulnerability: Why Security Can’t Keep Up
The promise of AI-assisted development, or “vibe coding,” is undeniable: unprecedented speed and productivity for development teams. In a landscape defined by complex cloud-native architectures and intense demand for new software, this force multiplier is rapidly becoming standard practice. However, this speed comes at a severe, often unaddressed cost. As AI agents generate functional code in seconds, they are frequently failing to enforce critical security controls, introducing mass vulnerabilities, technical debt and real-world breach scenarios.
This challenge is magn
Bleepingcomputer
CISA retires 10 emergency cyber orders in rare bulk closure
blogs_bleepingcomputer·2026-01-08
CISA retires 10 emergency cyber orders in rare bulk closure
## CISA retires 10 emergency cyber orders in rare bulk closure
## Lawrence Abrams
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has retired 10 Emergency Directives issued between 2019 and 2024, saying that the required actions have been completed or are now covered by Binding Operational Directive 22-01.
CISA said this is the largest number of Emergency Directives it has closed at one time.
"By statute, CISA issues Emergency Directives to rapidly mitigate emerging threats and to minimize the impact by limiting directives to the shortest time possible," explains CISA .
"Following a comprehensive review of all active directives, CISA determined that required actions have been successfully implemented or are now encompassed through Binding Operational Directive (BOD) 2
Unit42
Stay Secure: Why Cyber Hygiene Should Be Part of Your Personal Hygiene
blogs_unit42·2025-12-17
Stay Secure: Why Cyber Hygiene Should Be Part of Your Personal Hygiene
## Stay Secure: Why Cyber Hygiene Should Be Part of Your Personal Hygiene
Ria Bhatia
Published: December 16, 2025
General
Insights
Cybersecurity
MFA
Patchwork
When you hear the term “personal hygiene,” chances are you think of basic routines such as staying clean, wearing deodorant and brushing your teeth. In today’s tech-driven world, another aspect of personal hygiene deserves more attention: cyber hygiene.
Cyber hygiene refers to the routine actions and practices to stay safe in our digital world. As more of our lives move online, from banking accounts to health records to social interactions, the importance of ensuring clean, secure digital habits has never been greater.
No matter how familiar we are with cyber hygiene, we can take specific initiatives to protect ourselves.
Unit42
The Browser Defense Playbook: Stopping the Attacks That Start on Your Screen
blogs_unit42·2025-12-03
The Browser Defense Playbook: Stopping the Attacks That Start on Your Screen
## The Browser Defense Playbook: Stopping the Attacks That Start on Your Screen
Unit 42
Published: December 2, 2025
General
Insights
Cloud Security
Defense
## The Browser: The New Center of Work — and Risk
The predominance of cloud-based apps and the trend towards remote work have made the browser the place where most work happens. In fact, about 85% of daily work takes place there .
In many ways, it’s a win for all involved.
Users can work from a wider range of locations and devices, accessing full “desktops” inside a browser tab. Organizations can manage apps and browser access easier than through localized desktop software. This all allows for greater central management, lower costs and better flexibility.
But where work goes, attackers tend to follow.
In Unit 42’s 2025 G
Bleepingcomputer
CISA warns feds to fully patch actively exploited Cisco flaws
blogs_bleepingcomputer·2025-11-13·CVSS 8.6
CVE-2025-20362 [HIGH] CISA warns feds to fully patch actively exploited Cisco flaws
## CISA warns feds to fully patch actively exploited Cisco flaws
## Sergiu Gatlan
CISA warned U.S. federal agencies to fully patch two actively exploited vulnerabilities in Cisco Adaptive Security Appliances (ASA) and Firepower devices.
Tracked as CVE-2025-20362 and CVE-2025-20333 , these security flaws allow remote threat actors to access restricted URL endpoints without authentication and gain code execution on vulnerable Cisco firewall devices, respectively. If chained, they can enable unauthenticated attackers to gain complete control of unpatched devices remotely.
When it patched the two flaws in September, Cisco cautioned customers that they had been exploited as zero-days in attacks targeting 5500-X Series devices with VPN web services enabled. The company also linked these atta
Checkpoint
10th November – Threat Intelligence Report
blogs_checkpoint·2025-11-10
CVE-2024-38197 10th November – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 10th November – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 10th November, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The US Congressional Budget Office (CBO) has confirmed a cyber attack that resulted in a suspected foreign threat actor breaching its network and potentially exposing sensitive communications between congressional offices and CBO analysts. The incident may have led to the compromise of draft reports, economic forecasts,
Bleepingcomputer
Cisco: Actively exploited firewall flaws now abused for DoS attacks
blogs_bleepingcomputer·2025-11-07·CVSS 9.9
CVE-2025-20362 [CRITICAL] Cisco: Actively exploited firewall flaws now abused for DoS attacks
## Cisco: Actively exploited firewall flaws now abused for DoS attacks
## Sergiu Gatlan
Cisco warned this week that two vulnerabilities, which have been used in zero-day attacks, are now being exploited to force ASA and FTD firewalls into reboot loops.
The tech giant released security updates on September 25 to address the two security flaws, stating that CVE-2025-20362 enables remote threat actors to access restricted URL endpoints without authentication, while CVE-2025-20333 allows authenticated attackers to gain remote code execution on vulnerable devices.
When chained, these vulnerabilities allow remote, unauthenticated attackers to gain complete control over unpatched systems.
The same day, CISA issued an emergency directive ordering U.S. federal agencies to secure their Cisco fi
Bleepingcomputer
Critical Cisco UCCX flaw lets attackers run commands as root
blogs_bleepingcomputer·2025-11-06·CVSS 9.8
CVE-2025-20354 [CRITICAL] Critical Cisco UCCX flaw lets attackers run commands as root
## Critical Cisco UCCX flaw lets attackers run commands as root
## Sergiu Gatlan
Cisco has released security updates to patch a critical vulnerability in the Unified Contact Center Express (UCCX) software, which could enable attackers to execute commands with root privileges.
The Cisco UCCX platform, described by the company as a "contact center in a box," is a software solution for managing customer interactions in call centers, supporting up to 400 agents.
Tracked as CVE-2025-20354 , this security flaw was discovered in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX by security researcher Jahmel Harris, allowing unauthenticated attackers to execute arbitrary commands remotely with root permissions.
"This vulnerability is due to improper authentication mechanism
Zscaler
F5 Security Incident Advisory | Zscaler
blogs_zscaler·2025-10-16
F5 Security Incident Advisory | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Unit42
Anatomy of an Attack: The "BlackSuit Blitz" at a Global Equipment Manufacturer
blogs_unit42·2025-10-14
Anatomy of an Attack: The "BlackSuit Blitz" at a Global Equipment Manufacturer
Threat Research Center
Insights
General
## Anatomy of an Attack: The "BlackSuit Blitz" at a Global Equipment Manufacturer
Preston Miller
Published: October 14, 2025
General
Insights
BlackSuit ransomware
Ignoble Scorpius
Reconnaissance
Unit 42 recently assisted a prominent manufacturer who experienced a severe ransomware attack orchestrated by Ignoble Scorpius , the group that distributes BlackSuit ransomware. This incident serves as a reminder of how a seemingly minor issue — in this case, a single set of compromised VPN credentials — can lead to a full-scale corporate crisis with tremendous impact to the bottom line.
## The Attack: A Combination of Reconnaissance and Ransomware
The Ignoble Scorpius attack began with a voice phishing (vishing) call. The attacker impersonat
Wiz
Crying Out Cloud Newsletter - October 2025 | Wiz
blogs_wiz·2025-10-12·CVSS 9.9
[CRITICAL] Crying Out Cloud Newsletter - October 2025 | Wiz
Welcome back! This month we’ve seen a lot of action, with both vulnerabilities and security incidents that have left users affected. We bring you the latest cloud security highlights, to help you stay informed and stay secure.
## 🔍 Highlights
## Shai-Hulud: Package Supply Chain Compromise Delivering Data-Stealing Malware
On September 15, 2025, malicious versions of multiple popular packages were published to npm. They contained a post-install script that harvested sensitive data and exfiltrated it to attacker-created public GitHub repos named Shai-Hulud . Beyond data theft, the malware exhibits worm-like behaviour: when a compromised package encounters additional npm tokens in its environment, it will automatically publish malicious versions of any packages it can access - spreading acr
Bleepingcomputer
Nearly 50,000 Cisco firewalls vulnerable to actively exploited flaws
blogs_bleepingcomputer·2025-09-30·CVSS 9.9
CVE-2025-20333 [CRITICAL] Nearly 50,000 Cisco firewalls vulnerable to actively exploited flaws
## Nearly 50,000 Cisco firewalls vulnerable to actively exploited flaws
## Bill Toulas
Roughly 50,000 Cisco Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) appliances exposed on the public web are vulnerable to two vulnerabilities actively leveraged by hackers.
The flaws, tracked as CVE-2025-20333 and CVE-2025-20362, enable arbitrary code execution and access to restricted URL endpoints associated with VPN access. Both security issues can be exploited remotely without authentication.
On September 25, Cisco warned that the issues were actively exploited in attacks that started before patches were available to customers.
No workarounds exist for either flaw, but temporary hardening steps could include restricting VPN web interface exposure and increasing logging and
Checkpoint
29th September – Threat Intelligence Report
blogs_checkpoint·2025-09-29
CVE-2025-26399 29th September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 29th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 29th September, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Stellantis, Automotive maker giant which owns Citroën, FIAT, Jeep, Chrysler, and Peugeot, has suffered a data breach that resulted in exposure of North American customer contact information after attackers accessed a third-party platform tied to its Salesforce environment. ShinyHunters threat actor claims responsibili
Unit42
Threat Insights: Active Exploitation of Cisco ASA Zero Days
blogs_unit42·2025-09-26·CVSS 9.9
[CRITICAL] Threat Insights: Active Exploitation of Cisco ASA Zero Days
## September 2025 Zero-Day Vulnerabilities Affecting Cisco Software
Unit 42 stopped monitoring this threat and updating the brief on Dec. 2, 2025. Please refer to the Cisco website for the latest information.
Cisco has reported that a sophisticated state-sponsored threat actor is actively exploiting multiple zero-day vulnerabilities in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software. Cisco identifies this as the same threat actor from a previous campaign they named ArcaneDoor.
This threat actor primarily targets government networks worldwide for data exfiltration. Cisco observed attackers exploiting these newly identified zero-day vulnerabilities while employing advanced evasion techniques to prevent logging and identification of this activity.
The t
Tenable
Cybersecurity Snapshot: CISA Highlights Vulnerability Management Importance in Breach Analysis, as Orgs Are Urged To Patch Cisco Zero-Days
blogs_tenable·2025-09-26
Cybersecurity Snapshot: CISA Highlights Vulnerability Management Importance in Breach Analysis, as Orgs Are Urged To Patch Cisco Zero-Days
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Zscaler
Cisco Firewall and VPN Zero Day Attacks | ThreatLabz
blogs_zscaler·2025-09-26·CVSS 9.9
[CRITICAL] Cisco Firewall and VPN Zero Day Attacks | ThreatLabz
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Unit42
Threat Insights: Active Exploitation of Cisco ASA Zero Days
blogs_unit42·2025-09-26·CVSS 9.9
CVE-2025-20333 [CRITICAL] Threat Insights: Active Exploitation of Cisco ASA Zero Days
Threat Research Center
Insights
General
## Threat Insights: Active Exploitation of Cisco ASA Zero Days
Andy Piazza
Published: September 26, 2025
General
Insights
Cisco
CVE-2025-20333
CVE-2025-20362
CVE-2025-20363
Zero-day
## September 2025 Zero-Day Vulnerabilities Affecting Cisco Software
Unit 42 stopped monitoring this threat and updating the brief on Dec. 2, 2025. Please refer to the Cisco website for the latest information.
Cisco has reported that a sophisticated state-sponsored threat actor is actively exploiting multiple zero-day vulnerabilities in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software. Cisco identifies this as the same threat actor from a previous campaign they named ArcaneDoor.
This threat actor primarily targets gove
Bleepingcomputer
CISA orders agencies to patch Cisco flaws exploited in zero-day attacks
blogs_bleepingcomputer·2025-09-25·CVSS 9.9
CVE-2025-20333 [CRITICAL] CISA orders agencies to patch Cisco flaws exploited in zero-day attacks
## CISA orders agencies to patch Cisco flaws exploited in zero-day attacks
## Sergiu Gatlan
CISA has issued a new emergency directive ordering U.S. federal agencies to secure their Cisco firewall devices against two flaws that have been exploited in zero-day attacks.
Emergency Directive 25-03 was issued to Federal Civilian Executive Branch (FCEB) agencies on September 25 and requires them to patch CVE-2025-20333 and CVE-2025-20362 vulnerabilities in Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) software.
"The campaign is widespread and involves exploiting zero-day vulnerabilities to gain unauthenticated remote code execution on ASAs, as well as manipulating read-only memory (ROM) to persist through reboot and system upgrade. This activity presents a significant ri
Tenable
CVE-2025-20333, CVE-2025-20362: Cisco Zero-Days Exploited | Tenable®
blogs_tenable·2025-09-25·CVSS 9.9
[CRITICAL] CVE-2025-20333, CVE-2025-20362: Cisco Zero-Days Exploited | Tenable®
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Cisco warns of ASA firewall zero-days exploited in attacks
blogs_bleepingcomputer·2025-09-25·CVSS 9.9
CVE-2025-20333 [CRITICAL] Cisco warns of ASA firewall zero-days exploited in attacks
## Cisco warns of ASA firewall zero-days exploited in attacks
## Sergiu Gatlan
Cisco warned customers today to patch two zero-day vulnerabilities that are actively being exploited in attacks and impact the company's firewall software.
The first one ( CVE-2025-20333 ) allows authenticated, remote attackers to execute arbitrary code on devices running vulnerable Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) software, while the second ( CVE-2025-20362 ) enables remote attackers to access restricted URL endpoints without authentication.
"The Cisco Product Security Incident Response Team (PSIRT) is aware of attempted exploitation of this vulnerability," the company warned in security advisories regarding the two zero-day flaws.
"Cisco continues to strongly recommend t
Unit42
Trusted Connections, Hidden Risks: Token Management in the Third-Party Supply Chain
blogs_unit42·2025-09-12
Trusted Connections, Hidden Risks: Token Management in the Third-Party Supply Chain
## Trusted Connections, Hidden Risks: Token Management in the Third-Party Supply Chain
Bill Batchelor
Eyal Rafian
Nathaniel Quist
Published: September 12, 2025
General
Insights
Cloud Security
Salesforce
Salesloft
Supply chain
## A Day in the Life of a Security Defender
You are about to log off for the weekend when a high-severity alert flashes on your cloud security tool’s dashboard. A single, unfamiliar OAuth token is making hundreds of connections from three different IP addresses, two of which are flagged as belonging to an unknown VPN service.
The token belongs to a third-party application integrated with the company's Salesforce instance, one of those forgotten dormant integrations. A threat actor has stolen an OAuth token to bypass traditional defenses and is enumerat
Greynoiseio
25,000 IPs Scanned Cisco ASA Devices — New Vulnerability Potentially Incoming
blogs_greynoiseio·2025-09-04
25,000 IPs Scanned Cisco ASA Devices — New Vulnerability Potentially Incoming
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Unit42
Logit-Gap Steering: A New Frontier in Understanding and Probing LLM Safety
blogs_unit42·2025-08-20
Logit-Gap Steering: A New Frontier in Understanding and Probing LLM Safety
## Logit-Gap Steering: A New Frontier in Understanding and Probing LLM Safety
Tony Li
Hongliang Liu
Published: August 20, 2025
General
Insights
GenAI
LLM
## Introducing a New Angle on LLM Safety
Many publications have discussed the issues with tricking LLMs into responding to harmful requests. Our most recent academic research offers a new way to think about these issues, and it speaks to how defenders could improve LLM safety as well. The key is to consider some fundamental qualities of how safety features are built into LLM models.
LLMs are designed to refuse harmful queries through "alignment" training, a process that aims to make refusal responses far more likely than affirmative ones for unsafe prompts. A technical aspect of this process is the use of “logits,” the raw sc
Unit42
Muddled Libra’s Strike Teams: Amalgamated Evil
blogs_unit42·2025-08-12
Muddled Libra’s Strike Teams: Amalgamated Evil
## Muddled Libra’s Strike Teams: Amalgamated Evil
Kristopher Russo
Published: August 12, 2025
General
Insights
Muddled Libra
## Many From One
It’s disingenuous to consider Muddled Libra like a traditional monolithic attack group, one with defined structure and clear lines of leadership. Muddled Libra, Scattered Spider, Octo Tempest or any of the many other names the group is labeled with is not an organized entity but a loose collaboration of like-minded cybercriminals, or personas, with common interests tethered by social chat applications.
## Interrelated Strike Teams
Muddled Libra personas converge into strike teams, each with their own unique skillsets, tradecraft and objectives in tow. Since late 2022, Unit 42 has tracked at least seven distinct teams. Though in reality
Talos
ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
blogs_talos·2024-04-24·CVSS 9.9
CVE-2025-20333 [CRITICAL] ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
## ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
*Update 2025-09-25: Cisco is aware of new activity targeting certain Cisco Adaptive Security Appliances (ASA) 5500-X Series and has released three CVE’s related to the event: CVE-2025-20333 , CVE-2025-20362 and CVE-2025-20363 . The following Snort Rules cover these vulnerabilities: 65340, 46897.
We assess with high confidence this activity is related to same threat actor as ArcaneDoor in 2024.
We strongly recommend that Cisco customers upgrade their devices to the available fixed software and follow guidance in the security advisories.
*Updated 2024-04-25 16:57 GMT with minor wording corrections regarding the targeting of other vendors. ArcaneDoor is a campaign that is the latest example of state-s
Talos
ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
blogs_talos·2024-04-24·CVSS 9.9
CVE-2025-20333 [CRITICAL] ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
*Update 2025-09-25: Cisco is aware of new activity targeting certain Cisco Adaptive Security Appliances (ASA) 5500-X Series and has released three CVE’s related to the event: CVE-2025-20333, CVE-2025-20362 and CVE-2025-20363. The following Snort Rules cover these vulnerabilities: 65340, 46897.
We assess with high confidence this activity is related to same threat actor as ArcaneDoor in 2024.
We strongly recommend that Cisco customers upgrade their devices to the available fixed software and follow guidance in the security advisories.
*Updated 2024-04-25 16:57 GMT with minor wording corrections regarding the targeting of other vendors.
ArcaneDoor is a campaign that is the latest example of state-sponsored actors targeting perimeter network devices from multiple vendors. Coveted by these
Recorded Future
September 2025 CVE Landscape
blogs_recorded_future·CVSS 7.2
[HIGH] September 2025 CVE Landscape
# September 2025 CVE Landscape
In September 2025, Recorded Future’s Insikt Group® identified sixteen high-impact vulnerabilities that should be prioritized for remediation. This represents a decrease from the eighteen identified in August, with the number of Very Critical vulnerabilities also decreasing (11) month over month.
These vulnerabilities have affected the following vendors: Sudo, Libraesva, Fortra, Cisco, Adminer, Google, Dassault Systèmes, Linux, Android, Sitecore, TP-Link, and Meta Platforms.
September was dominated by flaws in Cisco and TP-Link, which together represented six of the sixteen vulnerabilities. Cisco’s IOS, IOS XE, and Secure Firewall products were affected by flaws, including stack-based and classic buffer overflows (CWE-121, CWE-120) and missing authorization
Greynoiseio
NoiseLetter October 2025
blogs_greynoiseio
NoiseLetter October 2025
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Recorded Future
September 2025 CVE Landscape
blogs_recorded_future·CVSS 7.2
[HIGH] September 2025 CVE Landscape
## September 2025 CVE Landscape
In September 2025, Recorded Future’s Insikt Group® identified sixteen high-impact vulnerabilities that should be prioritized for remediation. This represents a decrease from the eighteen identified in August, with the number of Very Critical vulnerabilities also decreasing (11) month over month.
These vulnerabilities have affected the following vendors: Sudo, Libraesva, Fortra, Cisco, Adminer, Google, Dassault Systèmes, Linux, Android, Sitecore, TP-Link, and Meta Platforms.
September was dominated by flaws in Cisco and TP-Link, which together represented six of the sixteen vulnerabilities. Cisco’s IOS, IOS XE, and Secure Firewall products were affected by flaws, including stack-based and classic buffer overflows (CWE-121, CWE-120) and missing authorizatio
Zscaler
CXO Monthly Roundup, September 2025: Cisco Firewall and VPN vulnerabilities, Shai-Hulud NPM worm emerges, APT37's Rust backdoor, SmokeLoader's additional variant, and COLDRIVER's latest
blogs_zscaler·CVSS 9.9
[CRITICAL] CXO Monthly Roundup, September 2025: Cisco Firewall and VPN vulnerabilities, Shai-Hulud NPM worm emerges, APT37's Rust backdoor, SmokeLoader's additional variant, and COLDRIVER's latest
## CXO Monthly Roundup, September 2025: Cisco Firewall and VPN vulnerabilities, Shai-Hulud NPM worm emerges, APT37's Rust backdoor, SmokeLoader's additional variant, and COLDRIVER's latest campaign, and new discoveries from ThreatLabz
Deepen Desai
Contributor
Zscaler
## Oct 10, 2025
Highlights from the Zscaler ThreatLabz team's September 2025 research.
The CXO Monthly Roundup provides the latest Zscaler ThreatLabz research, alongside insights into other cyber-related subjects that matter to technology executives. This September roundup highlights Cisco Firewall and VPN vulnerabilities, the emergence of the Shai-Hulud NPM worm, APT37's use of a Rust backdoor, new SmokeLoader variants, COLDRIVER's latest campaign, and other key discoveries from ThreatLabz, including malware families li
2025-09-25
Published
2025-09-25
Added to CISA KEV
Exploited in the wild