/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Cisco details a hacking campaign that penetrated multiple governments' networks using two zero-day flaws in its VPN and firewall Adaptive Security Appliances

Change Healthcare Finally Admits It Paid Ransomware Hackers—and Still Faces a Patient Data Leak

Wired Andy Greenberg

Context & Ripple Effects

Cisco’s disclosure extends a recurring record of attacks on its network infrastructure: in 2023, the company patched two actively exploited IOS XE zero-days after large-scale compromise reports, while earlier coverage documented stealthy backdoors on Cisco routers in multiple countries.

The significance is the target set and access point. VPN and firewall appliances sit at network boundaries, so compromise can give an intruder a foothold before government defenders can rely on internal controls.

First-order effects

  • Affected government networks must assess exposure to the two ASA flaws, contain compromised appliances, and investigate whether attackers established persistence beyond the perimeter device.
  • Cisco’s ASA customers face an immediate incident-response and remediation priority, while Cisco’s security teams must translate campaign findings into actionable detection and mitigation guidance.

Second-order effects

  • Other organizations operating internet-facing VPN and firewall appliances are likely to accelerate asset inventories, log reviews, and patching decisions, even where government targeting has not been reported.
  • Security buyers may place greater weight on appliance lifecycle management and vendor response speed, because perimeter-device zero-days can bypass protections built for threats inside the network.

Third-order effects

  • If repeated exploitation of edge appliances persists, network-defense strategy will shift further from treating perimeter hardware as trusted infrastructure toward continuous monitoring of it as a high-value attack surface.
  • Government and other critical-network operators may increasingly judge vendors on vulnerability disclosure, forensic support, and the ability to reduce exposure in deployed fleets—not only on product features.

The trend: The campaign is one instance of the growing strategic focus on internet-facing security appliances as high-leverage entry points into consequential networks.

Discussion

  • @cisacyber @cisacyber on x
    🆕 Alert! 🚨 #Cisco Releases Security Updates Addressing ArcaneDoor, Vulnerabilities in Cisco Firewall Platforms. Update and review further guidance at: https://cisa.gov/... #cybersecurity #InfoSec
  • @a_greenberg Andy Greenberg on x
    Cisco warns that a group of state-sponsored hackers has exploited two zero days in its ASA security appliances to spy on government networks over the last several months. Sources close to the investigation tell us they suspect China. https://www.wired.com/...
  • @wdormann Will Dormann on x
    I get the impression that VPN endpoints are kind of important. Attackers are exploiting Cisco ASA devices in the wild. Cisco has fixed CVE-2024-20353 and CVE-2024-20359, but they have yet to discover the initial entry point vulnerability. 😬 https://blog.talosintelligence.com/ ...…
  • @hkashfi Hamid Kashfi on x
    I always read reports on APTs hitting Cisco & other vendors VPN appliances, not as a forensics report, but a crash course on product-specific offensive tips & tricks. Vulns eventually die but post-exploitation tricks often last very very long. https://blog.talosintelligence.com/ …
  • @ericgeller Eric Geller on x
    Here's Cisco's blog post: https://blog.talosintelligence.com/ ... “This actor utilized bespoke tooling that demonstrated a clear focus on espionage and an in-depth knowledge of the devices that they targeted, hallmarks of a sophisticated state-sponsored actor.”
  • @nicoleperlroth Nicole Perlroth on x
    Another day, another zero day in a security appliance (suspect China). I cannot stress enough how much the volume of Chinese zero days in security appliances has exploded since my book in 2021. Back then the biggest criticism was, “Nicole, why did you focus on zero days when...
  • @jamieantisocial Jamie Williams on x
    https://attack.mitre.org/... [image]
  • @bushidotoken Will on x
    ⚠️ Cisco ASA & FTD Zero Day Vulnerabilities are now tracked as CVE-2024-20353 and CVE-2024-20359 https://sec.cloudapps.cisco.com/ ...
  • r/technology r on reddit
    Cyberspies Hacked Cisco Firewalls to Access Government Networks - Sources suspect China is behind the targeted exploitation of two zero-day vulnerabilities in Cisco's security appliances
  • r/netsec r on reddit
    Cisco ASA exploit in the wild.
  • r/privacy r on reddit
    EXCLUSIVE: Cyberspies Hacked Cisco Firewalls to Access Government Networks