Firestarter Malware Sparks Updated CISA Emergency Directive
CISA is warning of a persistent backdoor called Firestarter that’s being used in attacks against Cisco Firepower and Secure Firewall products.
All topics
CISA is warning of a persistent backdoor called Firestarter that’s being used in attacks against Cisco Firepower and Secure Firewall products.
The three newly added bugs are CVE-2026-20122, CVE-2026-20128, and CVE-2026-20133, the last of which had not been identified in active attacks before.
Cisco released software updates on Feb. 25 to fix the vulnerability, which affects both on-premises and cloud deployments of the Catalyst SD-WAN Controller.
Threat actors are attempting to exploit the Cisco remote code execution flaw (CVE-2026-20045) in the wild, according to a new security advisory.
The chain of discovery began with Amazon's security honeypot service, MadPot, which detected exploitation attempts for the Citrix Bleed Two vulnerability (CVE-2025-5777) before its public disclosure