Firestarter Malware Sparks Updated CISA Emergency Directive
CISA is warning of a persistent backdoor called Firestarter that’s being used in attacks against Cisco Firepower and Secure Firewall products.
All topics
CISA is warning of a persistent backdoor called Firestarter that’s being used in attacks against Cisco Firepower and Secure Firewall products.
This week we dig deep into the Vercel intrusion that emerged last weekend, how it happened, what the response was, and what the downstream effects may be for defenders. Then we talk about CISA’s bizarre delayed response to the Axios npm compromise and what it signals about the agency’s capabilities going forward.
Yet another supply chain attack has hit the open source ecosystem, this time impacting the Checkmarx KICS Docker Hub repository.
The three newly added bugs are CVE-2026-20122, CVE-2026-20128, and CVE-2026-20133, the last of which had not been identified in active attacks before.
The incident came to light on Sunday and the company says it has brought in an incident response provider to investigate the intrusion. Details of the intrusion are scant at this point.
It’s been A WEEK. Security news never sleeps, and neither does AI, so Dennis and Lindsey dive into all of the storylines coming from the Claude Mythos and Project Glasswing announcements, how organizations will deal with the coming flood of CVEs and patches, NIST’s decision to only enrich specific CVEs going forward, and what could possibly be next on […]