DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Tech News

Old Vulnerabilities In Cisco Secure ASA Software And Cisco Secure FTD Software Still Being Exploited

DigitalCIO Bureau by DigitalCIO Bureau
November 7, 2025
in Tech News
0
HCLTech and Cisco Enhance Collaborative Environment for Modern Hybrid Workplaces
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Network security vendor Cisco has issued an urgent warning over a series of sophisticated and persistent cyberattacks targeting its popular security products, specifically the Cisco Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software.

The attacks, which have been ongoing since May 2025, have recently resulted in a new, critical variant that requires immediate action from customers to avoid serious disruptions.

On November 5, 2025, Cisco released an update announcing its awareness of a new attack variant. This variant targets unpatched devices and exploits vulnerabilities (designated CVE-2025-20333 and CVE-2025-20362) to cause a Denial of Service (DoS) condition. This results in an unexpected restart of firewall devices, potentially leading to a temporary network security outage.

Cisco urges all affected customers to immediately upgrade to the corrected software versions to eliminate the risk of DoS attacks.

Cisco describes the attack campaign as highly sophisticated. Initial observations in May 2025 involved compromises of certain ASA 5500-X Series devices with enabled VPN web services. The attackers’ goal was to install malware, execute commands, and potentially steal data.

Cisco notes that the attackers exploited multiple zero-day vulnerabilities (as yet unknown security flaws). They also used advanced evasion techniques, such as disabling logging and deliberately crashing devices to hinder forensic investigations.

The company estimates with high confidence that these recent activities are related to the same threat actor previously responsible for the infamous ArcaneDoor attack campaign in 2024.

A particularly concerning finding is that the attackers modified the firmware, specifically the ROMMON, on some compromised devices. This modification allowed the attackers to remain persistent within the network, even after a device reboot or software update.

This method of ensuring persistence has only been observed on older models of the Cisco ASA 5500-X Series, which lack modern security mechanisms like Secure Boot . Cisco has found no evidence of successful compromises or persistence on newer platforms that do feature these technologies.

Customers are strongly advised to follow Cisco’s guidance to determine their exposure and apply the recommended security updates as soon as possible.

Tags: CISCO
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

21-year-old from China wins TCS CodeVita 2026 as TCS sets new Guinness World Records for the world’s largest coding competition

by DigitalCIO Bureau
February 27, 2026
0
21-year-old from China wins TCS CodeVita 2026 as TCS sets new Guinness World Records for the world’s largest coding competition

TCS sets a new milestone with 146,922 participants, surpassing its 2021 Guinness World Records title to remain the world’s largest coding championship Tata Consultancy Services (TCS) announced the winners...

Read moreDetails

Qualcomm and Tata Electronics Partner to Manufacture Qualcomm Automotive Modules in India

by DigitalCIO Bureau
February 27, 2026
0
Qualcomm and Tata Electronics Partner to Manufacture Qualcomm Automotive Modules in India

Collaboration supports the nation’s “Make in India” initiative and global priority for supply chain diversification Companies’ manufacturing partnership aimed at supporting Indian and global automakers, strengthening supply-chain flexibility...

Read moreDetails

Fractal Launches PiEvolve, an Evolutionary Agentic Engine for Autonomous Machine Learning and Scientific Discovery

by DigitalCIO Bureau
February 27, 2026
0
Fractal Launches PiEvolve, an Evolutionary Agentic Engine for Autonomous Machine Learning and Scientific Discovery

Ranks among the top-performing agents on OpenAI’s MLE-Bench and sets new performance milestones Fractal (www.fractal.ai) announced the launch of PiEvolve, an evolutionary, agentic engine designed for autonomous machine...

Read moreDetails

LTM to Modernize India’s Tax Analytics Platform Leveraging NVIDIA AI Technology

by DigitalCIO Bureau
February 27, 2026
0
LTM to Modernize India’s Tax Analytics Platform Leveraging NVIDIA AI Technology

LTM (Name change from LTIMindtree, subject to shareholder approval) announced it is collaborating with NVIDIA to support the Central Board of Direct Taxes (CBDT) in modernizing India’s national tax analytics platform...

Read moreDetails

Securonix Introduces Agentic Mesh and the First Productivity-Based AI Model for the SOC

by DigitalCIO Bureau
February 26, 2026
0
Securonix Introduces Agentic Mesh and the First Productivity-Based AI Model for the SOC

Powered by Sam, the AI SOC Analyst, the Securonix Agentic Mesh delivers governed, explainable AI that measurably improves SOC productivity and enables board-ready outcomes. Securonix, Inc., in collaboration...

Read moreDetails
Next Post
World Password Day: “Focus must shift from relying on passwords alone to building integrated, intelligent security”

Password Alert: '123456' And 'Minecraft' Remain Most Used

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Accenture Acquires Customer Management IT and SirfinPA

Accenture Acquires IQT Group

December 21, 2024

Socionext Collaborates with Foxconn and Network Optix

January 8, 2020

Trai seeks views on traffic management under net neutrality

January 3, 2020

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Barracuda Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Digital Transformation Dynatrace E-books Fortinet Gartner GenAI Generative AI Google Cloud IBM Infographics Internet of Things (IoT) Kaspersky Microsoft NTT DATA NVIDIA Palo Alto Networks Panel Discussion Qlik Salesforce ServiceNow Sophos TCS Tenable Trend Micro Veeam Veeam Software Vertiv Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?