二本松哲也[verified]@t_nihonmatsuPatch
The post identifies a Firestarter backdoor targeting Cisco firewalls, cites specific CVEs, and recommends mitigation measures beyond patching.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
CISA/NCSC confirm active exploitation of CVE‑2025‑20333/20362 via the FIRESTARTER backdoor on Cisco Firepower/ASA devices since September 2025, with detailed technical findings presented in the report.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
The briefing confirms active exploitation of CVE‑2025‑20333/20362 via a persistent backdoor on Cisco ASA/Firepower devices, detailing its hooking and boot‑script persistence tactics, detection artifacts, and that only a complete power cycle cleans the device.
Mr.Rabbit[verified]@01ra66itPatch
JPCERT/CC warns that patching Cisco ASA/FTD CVE‑2025‑20333 and CVE‑2025‑20362 alone is insufficient because of persistent mechanisms and a FIRESTARTER backdoor; additional mitigations such as re‑imaging and credential resets are recommended.
Misbar | مسبار[verified]@MisbarSecActive Exploitation
Security authorities warn of the Firestarter backdoor on Cisco ASA firewalls, citing CVE-2025-20362 and CVE-2025-20333. While no exploit code is shared, the text indicates attackers are actively using the vulnerability and recommends software updates as a mitigation.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
CISA announces that the FIRESTARTER backdoor is actively exploiting CVE-2025-20333 and CVE-2025-20362 on federal Cisco ASA devices, persisting through firmware updates and necessitating full device reimaging for remediation.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
State-sponsored UAT-4356 actively exploits newly disclosed Cisco Firepower CVEs (CVE-2025-20333 & 20362) by injecting malicious code into the LINA process, establishing persistence, and enabling backdoor functionality, with detailed IOCs provided for detection.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
The tweet reports that ArcaneDoor has a persistence technique that survives firmware upgrades, and confirms CVE-2025-20333 is actively exploited and listed on CISA KEV.