DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Tech News

Old Vulnerabilities In Cisco Secure ASA Software And Cisco Secure FTD Software Still Being Exploited

DigitalCIO Bureau by DigitalCIO Bureau
November 7, 2025
in Tech News
0
HCLTech and Cisco Enhance Collaborative Environment for Modern Hybrid Workplaces
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Network security vendor Cisco has issued an urgent warning over a series of sophisticated and persistent cyberattacks targeting its popular security products, specifically the Cisco Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software.

The attacks, which have been ongoing since May 2025, have recently resulted in a new, critical variant that requires immediate action from customers to avoid serious disruptions.

On November 5, 2025, Cisco released an update announcing its awareness of a new attack variant. This variant targets unpatched devices and exploits vulnerabilities (designated CVE-2025-20333 and CVE-2025-20362) to cause a Denial of Service (DoS) condition. This results in an unexpected restart of firewall devices, potentially leading to a temporary network security outage.

Cisco urges all affected customers to immediately upgrade to the corrected software versions to eliminate the risk of DoS attacks.

Cisco describes the attack campaign as highly sophisticated. Initial observations in May 2025 involved compromises of certain ASA 5500-X Series devices with enabled VPN web services. The attackers’ goal was to install malware, execute commands, and potentially steal data.

Cisco notes that the attackers exploited multiple zero-day vulnerabilities (as yet unknown security flaws). They also used advanced evasion techniques, such as disabling logging and deliberately crashing devices to hinder forensic investigations.

The company estimates with high confidence that these recent activities are related to the same threat actor previously responsible for the infamous ArcaneDoor attack campaign in 2024.

A particularly concerning finding is that the attackers modified the firmware, specifically the ROMMON, on some compromised devices. This modification allowed the attackers to remain persistent within the network, even after a device reboot or software update.

This method of ensuring persistence has only been observed on older models of the Cisco ASA 5500-X Series, which lack modern security mechanisms like Secure Boot . Cisco has found no evidence of successful compromises or persistence on newer platforms that do feature these technologies.

Customers are strongly advised to follow Cisco’s guidance to determine their exposure and apply the recommended security updates as soon as possible.

Tags: CISCO
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

Kiteworks’ New Survey Reveals Critical Need to Shift From Legacy Web Forms

by DigitalCIO Bureau
December 8, 2025
0
Kiteworks’ New Survey Reveals Critical Need to Shift From Legacy Web Forms

Kiteworks has released its comprehensive 2025 Data Security and Compliance Risk: Data Forms Survey Report. The research of 324 cybersecurity, risk, IT, and compliance professionals exposes a stark...

Read moreDetails

Red Hat AI now runs on AWS Trainium and Inferentia chips

by DigitalCIO Bureau
December 5, 2025
0
Red Hat AI now runs on AWS Trainium and Inferentia chips

Red Hat has announced an expanded collaboration with Amazon Web Services (AWS) to power enterprise-grade generative AI (gen AI) on AWS with Red Hat AI and AWS AI...

Read moreDetails

Kellton Acquires ServiceNow services provider Kumori Technologies

by DigitalCIO Bureau
December 5, 2025
0
CRISIL To Acquire Bridge To India Energy

Kellton has announced the acquisition of Kumori Technologies, a specialized ServiceNow services provider. The acquisition strengthens Kellton’s global ServiceNow delivery capabilities and advances its vision of building integrated,...

Read moreDetails

Hexaware Launches New Delivery Center in Cairo

by DigitalCIO Bureau
December 4, 2025
0
Hexaware Launches New Delivery Center in Cairo

Hexaware Technologies has strengthened its global delivery network with a new center in Cairo. Launching with 100 professionals, it will serve customers in Egypt, the Middle East, and...

Read moreDetails

Tata Technologies appoints Anand Sinha as Chief Digital and Information Officer

by DigitalCIO Bureau
December 3, 2025
0
Tata Technologies appoints Anand Sinha as Chief Digital and Information Officer

Anand Kumar Sinha has joined Tata Technologies as Chief Digital and Information Officer (CIDO). With an extensive experience in technology, focusing on IT operations, Technology Infrastructure, cybersecurity, ERP, AI,...

Read moreDetails
Next Post
World Password Day: “Focus must shift from relying on passwords alone to building integrated, intelligent security”

Password Alert: '123456' And 'Minecraft' Remain Most Used

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

NeoSOFT Launches New Offices In Mumbai And Pune

NeoSOFT Launches New Offices In Mumbai And Pune

June 13, 2025
Tenable Appoints Shai Morag As Chief Product Officer

Tenable Adds New Features To Security Center

December 20, 2024

TCS Launched Mobile App

July 5, 2018

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Barracuda Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Digital Transformation Dynatrace E-books Fortinet Gartner GenAI Generative AI Google Cloud IBM Infographics Internet of Things (IoT) Kaspersky Microsoft Netskope New Relic NTT DATA Palo Alto Networks Panel Discussion Qlik Salesforce ServiceNow Sophos Tenable Trend Micro Veeam Veeam Software Vertiv Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?