News Ababil.
Explore
SYS_NODE: ONLINE // Cyber Security

Firestarter malware evades Cisco updates, sparks fresh security alerts

DECRYPTED BY: Nova Stirling | TIMESTAMP: 2026-04-25 T 08:59:58 Z | [ 1 MIN READ ]
Firestarter malware evades Cisco updates, sparks fresh security alerts
1 Min Read
Share

Firestarter malware continues to embed itself in Cisco’s Firepower and Secure Firewall platforms despite recent firmware updates and security patches, according to alerts from U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Britain’s National Cyber Security Centre (NCSC).

Why Firestarter malware persists on Cisco devices

Researchers say the code exploits a lingering configuration flaw in Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software, allowing it to survive reboot cycles. The vulnerability, identified as CVE‑2024‑XXXXX, was patched in March, yet field reports show infection rates climbing ↓ 12% over the last month.

“We observed the malware re‑establishing command‑and‑control channels within minutes of a reboot,” said a senior analyst at Reuters.

Implications for enterprise security teams

Enterprises running legacy Cisco firewalls are urged to verify firmware versions, enforce multi‑factor authentication, and isolate compromised segments. The NCSC recommends immediate network segmentation and continuous monitoring for anomalous traffic.

Both agencies stress that the threat actor behind Firestarter malware appears to be a well‑funded group targeting critical infrastructure, suggesting a broader campaign that could extend beyond firewalls to other network appliances.


Intel provided by Nova Stirling (Aerospace & Space Tech Correspondent).

Global Data Feed

More from this Intel

Meta AI Support Bot Exploit Lets Hackers Hijack High‑Profile Instagram Accounts

Meta AI Support Bot Exploit Lets Hackers Hijack High‑Profile Instagram...

Jun 09, 2026
C0XMO botnet hijacks DD‑WRT routers, outpaces Gafgyt in the wild

C0XMO botnet hijacks DD‑WRT routers, outpaces Gafgyt in the wild

Jun 08, 2026
Everest Forms Pro vulnerability fuels wave of WordPress takeovers

Everest Forms Pro vulnerability fuels wave of WordPress takeovers

Jun 07, 2026
Netherlands seizes servers in massive crackdown on Russian‑linked cyberhost

Netherlands seizes servers in massive crackdown on Russian‑linked cyberhost

Jun 07, 2026
AI Worms Poised to Become Enterprise’s Next Cyber Menace

AI Worms Poised to Become Enterprise’s Next Cyber Menace

Jun 05, 2026
Cisco Unified CM flaw patched after PoC exploit code surfaces

Cisco Unified CM flaw patched after PoC exploit code surfaces

Jun 04, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.