DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Tech News

Old Vulnerabilities In Cisco Secure ASA Software And Cisco Secure FTD Software Still Being Exploited

DigitalCIO Bureau by DigitalCIO Bureau
November 7, 2025
in Tech News
0
HCLTech and Cisco Enhance Collaborative Environment for Modern Hybrid Workplaces
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Network security vendor Cisco has issued an urgent warning over a series of sophisticated and persistent cyberattacks targeting its popular security products, specifically the Cisco Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software.

The attacks, which have been ongoing since May 2025, have recently resulted in a new, critical variant that requires immediate action from customers to avoid serious disruptions.

On November 5, 2025, Cisco released an update announcing its awareness of a new attack variant. This variant targets unpatched devices and exploits vulnerabilities (designated CVE-2025-20333 and CVE-2025-20362) to cause a Denial of Service (DoS) condition. This results in an unexpected restart of firewall devices, potentially leading to a temporary network security outage.

Cisco urges all affected customers to immediately upgrade to the corrected software versions to eliminate the risk of DoS attacks.

Cisco describes the attack campaign as highly sophisticated. Initial observations in May 2025 involved compromises of certain ASA 5500-X Series devices with enabled VPN web services. The attackers’ goal was to install malware, execute commands, and potentially steal data.

Cisco notes that the attackers exploited multiple zero-day vulnerabilities (as yet unknown security flaws). They also used advanced evasion techniques, such as disabling logging and deliberately crashing devices to hinder forensic investigations.

The company estimates with high confidence that these recent activities are related to the same threat actor previously responsible for the infamous ArcaneDoor attack campaign in 2024.

A particularly concerning finding is that the attackers modified the firmware, specifically the ROMMON, on some compromised devices. This modification allowed the attackers to remain persistent within the network, even after a device reboot or software update.

This method of ensuring persistence has only been observed on older models of the Cisco ASA 5500-X Series, which lack modern security mechanisms like Secure Boot . Cisco has found no evidence of successful compromises or persistence on newer platforms that do feature these technologies.

Customers are strongly advised to follow Cisco’s guidance to determine their exposure and apply the recommended security updates as soon as possible.

Tags: CISCO
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

 Cloudera Announces Updates to its Platform

by DigitalCIO Bureau
November 25, 2025
0
 Cloudera Announces Updates to its Platform

Cloudera has announced a major platform update that integrates Trino, Cloudera Shared Data Experience (SDX), and Cloudera Octopai Data Lineage to deliver unified data access, control, smarter governance,...

Read moreDetails

Salesforce Blocks Gainsight Apps After Detecting Suspicious Activity

by DigitalCIO Bureau
November 24, 2025
0
Salesforce Acquires AI Customer Service Startup Airkit.ai

CRM giant Salesforce has immediately blocked access to applications from software vendor Gainsight after detecting "unusual activity." The incident may have led to unauthorized access to customer data...

Read moreDetails

Employees in India Lack Clear Guidance on Using AI at Work

by DigitalCIO Bureau
November 21, 2025
0
Employees in India Lack Clear Guidance on Using AI at Work

Udemy has released a research report, ‌“Ready or Not: The Emerging Gap Between Awareness and Action in ‌AI Transformation.” Drawing on a new survey conducted by YouGov, the...

Read moreDetails

Cloudflare Acquires AI Platform Replicate 

by DigitalCIO Bureau
November 20, 2025
0
Cloudflare Publishes Top Internet Trends For 2024

Cloudflare has agreed to acquire Replicate, an AI platform that makes it easy for developers to deploy and run AI models. This acquisition will accelerate the company’s vision...

Read moreDetails

Gartner: India IT Spending to Exceed $176 Billion Next Year

by DigitalCIO Bureau
November 19, 2025
0
Gartner: India IT Spending to Exceed $176 Billion Next Year

IT spending in India is expected to reach $176.3 billion in 2026, an increase of 10.6% from 2025, according to the latest forecast by business and technology insights...

Read moreDetails
Next Post
World Password Day: “Focus must shift from relying on passwords alone to building integrated, intelligent security”

Password Alert: '123456' And 'Minecraft' Remain Most Used

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Coforge and Newgen Elevates Partnership

BT Group Expands Strategic Partnership With ServiceNow

June 22, 2024
HPE to Acquire Juniper Networks to Accelerate AI-Driven Innovation

HPE to Acquire Juniper Networks to Accelerate AI-Driven Innovation

January 11, 2024
CISOs Need to Champion AI TRiSM to Improve AI Results

Elastic launches Elastic Cloud Serverless Powered by search AI lake

December 9, 2024

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Barracuda Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Digital Transformation Dynatrace E-books Fortinet Gartner GenAI Generative AI Google Cloud IBM Infographics Internet of Things (IoT) Kaspersky Microsoft Netskope New Relic NTT DATA NVIDIA Palo Alto Networks Panel Discussion Qlik Salesforce Sophos Tenable Trend Micro Veeam Veeam Software Vertiv Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?