Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

    September 10, 2026

    APOD: 2026 September 10 – LDN 1295: The Giraffe Nebula

    September 10, 2026

    Jackery Explorer 2000 v2 portable power station review

    September 10, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»US Federal Agency’s Cisco Firewall Infected With ‘Firestarter’ Backdoor
    US Federal Agency’s Cisco Firewall Infected With ‘Firestarter’ Backdoor
    Cybersecurity

    US Federal Agency’s Cisco Firewall Infected With ‘Firestarter’ Backdoor

    The Tech GuyBy The Tech GuyApril 25, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    At least one US federal agency was infected with a backdoor as part of a widespread China-linked espionage campaign targeting Cisco firewalls.

    Advertisement

    In May 2024, Cisco patched two vulnerabilities in its Adaptive Security Appliance (ASA) firewall platform that had been exploited as zero-days in a state-sponsored campaign tracked as ArcaneDoor.

    A year later, the company fixed two more zero-days linked to the same campaign, tracked as CVE-2025-20333 and CVE-2025-20362, and impacting the VPN web server of ASA and Secure Firewall Threat Defense (FTD) software.

    In September 2025, the US cybersecurity agency CISA issued Emergency Directive 25-03 (ED 25-03), urging federal agencies to patch vulnerable Cisco devices in their environments immediately. In November, CISA updated its guidance to recommend additional mitigation actions.

    On Thursday, the agency updated ED 25-03 again, warning that patching vulnerable Cisco firewall devices did not remove malware deployed on them.

    Per the updated directive, federal agencies should upload device core dumps to the Malware Next Gen portal to verify whether they have been compromised, and notify CISA immediately if they have been, or apply the available patches if needed.

    Advertisement. Scroll to continue reading.

    The requirement applies to Firepower 1000, 2100, 4100, 9300 series and Secure Firewall 200, 1200, 3100, 4200, and 6100 series devices. All checks and updates should be performed by 11:59 PM EST on April 24, 2026, and devices should be hard-reset by April 30, CISA’s directive mandates.

    CISA’s updated directive is accompanied by instructions on the core dumps and by a deep dive into the Firestarter backdoor, which was identified as the malware used in these attacks.

    According to CISA, at least one federal agency was infected with Firestarter through the exploitation of a Firepower device vulnerable to CVE-2025-20333 and CVE-2025-20362. The backdoor is not removed by firmware updates, and devices compromised before patching remain vulnerable, it warns.

    Firestarter was deployed before September 25, persisted through remediation, and provided the attackers with remote access and control of the vulnerable firewall.

    “Firestarter attempts to install a hook—a way to intercept and modify normal operations—within Lina, the device’s core engine for network processing and security functions. This hook enables the execution of arbitrary shell code provided by the APT actors, including the deployment of Line Viper,” CISA explains.

    The backdoor resembles the RayInitiator bootkit, a previously detailed component of the ArcaneDoor campaign, and achieves persistence by modifying the mount list for Cisco Service Platform (CSP), which allows programs to execute during boot, Cisco explains.

    After a reboot, Firestarter restores the original list and removes the trojanized copy, meaning that the implant can be removed through a hard reboot, which involves unplugging the device from power, the company says.

    Cisco has attributed the attacks to UAT-4356, a state-sponsored threat actor focused on espionage, and has published a fresh advisory on CVE-2025-20333 and CVE-2025-20362’s continuous exploitation.

    Related: Organizations Warned of Exploited Cisco, Kentico, Zimbra Vulnerabilities

    Related: Cisco Patches Critical Vulnerabilities in Webex, ISE

    Related: Most Serious Cyberattacks Against the UK Now From Russia, Iran and China, Cyber Chief Says

    Related: FBI Warns of Data Security Risks From China-Made Mobile Apps

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

    September 10, 2026

    AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns

    September 10, 2026

    HelmGuard Raises $7.3 Million for Agentic GRC and Security

    September 9, 2026

    Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

    September 9, 2026

    The Hidden Instructions That Can Hijack AI Agents

    September 9, 2026

    Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

    September 9, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

    September 10, 2026

    APOD: 2026 September 10 – LDN 1295: The Giraffe Nebula

    September 10, 2026

    Jackery Explorer 2000 v2 portable power station review

    September 10, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.