Skip to main content
See every side of every news story
Published loading...Updated

Critical Cisco Firewall Holes Under Active Attack

CISA requires federal agencies to patch or disconnect Cisco firewall devices vulnerable to two zero-day exploits with severity scores up to 9.9, actively exploited by a sophisticated hacking group.

  • On September 25, CISA issued Emergency Directive 25-03 ordering federal civilian agencies to secure Cisco firewall devices vulnerable to two zero-day flaws.
  • This action followed a widespread, ongoing espionage campaign linked to the ArcaneDoor operation that exploited vulnerabilities since November 2023.
  • The campaign targeted Adaptive Security Appliance and Firepower Threat Defense devices, using advanced evasion, malware persistence in read-only memory, and disabling logs.
  • CISA directed agencies to identify, forensically analyze, disconnect compromised or end-of-support devices, and patch remaining devices by September 26, with reporting due October 3.
  • CISA and Cisco continue collaborative mitigation efforts while cautioning about evolving attacker tactics and urging critical infrastructure operators to report incidents promptly.
Insights by Ground AI
Podcasts & Opinions

23 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 73% of the sources are Center
73% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

Cybersecurity Dive broke the news in on Thursday, September 25, 2025.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal