News Ababil.
Explore
SYS_NODE: ONLINE // Cyber Security

Firestarter malware evades Cisco updates, sparks fresh security alerts

DECRYPTED BY: Nova Stirling | TIMESTAMP: 2026-04-25 T 08:59:58 Z | [ 1 MIN READ ]
Firestarter malware evades Cisco updates, sparks fresh security alerts
1 Min Read
Share

Firestarter malware continues to embed itself in Cisco’s Firepower and Secure Firewall platforms despite recent firmware updates and security patches, according to alerts from U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Britain’s National Cyber Security Centre (NCSC).

Why Firestarter malware persists on Cisco devices

Researchers say the code exploits a lingering configuration flaw in Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software, allowing it to survive reboot cycles. The vulnerability, identified as CVE‑2024‑XXXXX, was patched in March, yet field reports show infection rates climbing ↓ 12% over the last month.

“We observed the malware re‑establishing command‑and‑control channels within minutes of a reboot,” said a senior analyst at Reuters.

Implications for enterprise security teams

Enterprises running legacy Cisco firewalls are urged to verify firmware versions, enforce multi‑factor authentication, and isolate compromised segments. The NCSC recommends immediate network segmentation and continuous monitoring for anomalous traffic.

Both agencies stress that the threat actor behind Firestarter malware appears to be a well‑funded group targeting critical infrastructure, suggesting a broader campaign that could extend beyond firewalls to other network appliances.


Intel provided by Nova Stirling (Aerospace & Space Tech Correspondent).

Global Data Feed

More from this Intel

Fast16 Malware Unveiled: Pre‑Stuxnet Sabotage Code Targeted Iran’s Nuclear Effort

Fast16 Malware Unveiled: Pre‑Stuxnet Sabotage Code Targeted Iran’s Nuclear Effort

Apr 24, 2026
Hackers Exploit Critical Breeze Cache WordPress Plugin Vulnerability

Hackers Exploit Critical Breeze Cache WordPress Plugin Vulnerability

Apr 24, 2026
Mirai campaign exploits D-Link routers to fuel new botnet surge

Mirai campaign exploits D-Link routers to fuel new botnet surge

Apr 23, 2026
North Korea’s Fake Job Scams Evolve into Self‑Propagating ‘Contagious Interview’ Threat

North Korea’s Fake Job Scams Evolve into Self‑Propagating ‘Contagious Interview’...

Apr 23, 2026
Gentlemen ransomware surges, redefining cyber‑crime threats

Gentlemen ransomware surges, redefining cyber‑crime threats

Apr 23, 2026
Google RCE flaw patched in AI antigravity tool

Google RCE flaw patched in AI antigravity tool

Apr 21, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.