Title: New Firestarter Malware Targets Cisco Devices, Warns Cybersecurity Agencies
Cybersecurity agencies in the U.S. and U.K. have issued urgent warnings regarding a persistent malware known as Firestarter, affecting Cisco Firepower and Secure Firewall devices. This custom backdoor, linked to a cyber-espionage group named UAT-4356, can survive security updates and patches, putting sensitive information at risk.
The threat actor reportedly gained access through vulnerabilities in Cisco’s software, leading to incidents in various sectors, including a federal agency. Firestarter’s stealthy nature allows it to remain undetected, reactivating even after attempts to remove it.
To protect against this threat, Cisco advises users to reimage their devices and apply the latest security updates. Running specific diagnostic commands can help identify compromised systems.
Risk Level: High. Organizations using affected Cisco devices should act swiftly to mitigate risks associated with this sophisticated malware.
Source: View Original Report
