二本松哲也[verified]@t_nihonmatsuPatch
The message centers on identifying Firestarter backdoor vulnerabilities and outlines mitigation strategies, highlighting that patches alone are insufficient and recommending additional controls.
Team Cymru Research[verified]@teamcymru_S2Active Exploitation
The tweet lists the top 25 CVEs experiencing exploitation attempts over a 14‑day window, indicating active use in the wild but offering no technical or remediation details.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
The advisory reports that CVE-2025-20333/20362 is actively exploited via a FIRESTARTER backdoor on Cisco Firepower/ASA devices, with detailed technical exploitation and persistence mechanisms, despite patching efforts.
CrowdSec[verified]@Crowd_SecurityActive Exploitation
The post alerts that CVE-2025-20362, a VPN authentication bypass on Cisco ASA & FTD firewalls, is still actively exploited online and directs readers to a full analysis for defensive guidance.
Mr.Rabbit[verified]@01ra66itPatch
The announcement emphasizes that simply applying patches for CVE‑2025‑20333 and CVE‑2025‑20362 is insufficient; it advises additional controls such as re‑imaging and resetting credentials to mitigate persistent threats.
Misbar | مسبار[verified]@MisbarSecDisclosure
A warning about a "FIRESTARTER" backdoor affecting Cisco ASA firewalls, referencing CVE-2025-20362 and CVE-2025-20333, and recommending software updates, but without detailed technical or exploit information.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
The passage confirms that FIRESTARTER is actively exploiting CVE‑2025‑20333 and CVE‑2025‑20362 in the wild, with detailed technical information and a directive for remediation, but it does not mention a PoC or a specific exploit tool.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
The post details an active state‑sponsored exploitation campaign against Cisco Firepower devices using CVE‑2025‑20333/20362, describing infection methods, persistence, and recommended remediation.