Cisco confirmed that multiple government agencies engaged its incident response teams in May 2025 to investigate targeted attacks against Cisco Adaptive Security Appliance (ASA) 5500-X Series devices running Cisco Secure Firewall ASA Software with VPN web services enabled. Attackers exploited multiple zero-day vulnerabilities to implant malware, execute commands, and potentially exfiltrate data from compromised devices. The threat actor demonstrated advanced evasion techniques, including disabling logging, intercepting CLI commands, and intentionally crashing devices to hinder forensic analysis. Cisco’s investigation, which involved providing instrumented images and analyzing packet captures and firmware, led to the identification of a critical memory corruption bug in the ASA software. The company assessed with high confidence that the activity was linked to the same threat actor behind the ArcaneDoor campaign previously reported in 2024. While the vulnerable software is present on other hardware platforms and in Cisco Secure Firewall Threat Defense (FTD) Software, there is no evidence of successful compromise beyond the ASA 5500-X Series. Cisco published detailed detection guidance, highlighting that the threat actor continues to scan for vulnerable devices using frequently changing IP addresses, and that scanning activity alone does not indicate compromise. Only specific ASA 5500-X models running certain software releases with VPN web services enabled have been confirmed as compromised. The threat actor suppressed specific syslog messages in memory as a forensic countermeasure, and a downward shift in these logs may indicate malicious activity. On September 25, 2025, Cisco released security advisories addressing critical vulnerabilities, including CVE-2025-20333, CVE-2025-20362, and CVE-2025-20363, affecting a range of ASA and FTD software versions. The Canadian Centre for Cyber Security issued alerts urging organizations to review Cisco’s advisories, apply mitigations, and update affected devices. The vulnerabilities allow for remote code execution and unauthorized access via VPN web services and HTTP servers on affected firewall products. Cisco’s advisories provided a comprehensive list of affected software versions and recommended immediate action to mitigate risk. The incident underscores the sophistication of the threat actor, the importance of timely patching, and the need for enhanced monitoring of VPN-enabled firewall devices. Cisco’s response included collaboration with affected customers, deployment of enhanced detection capabilities, and ongoing monitoring for further malicious activity. Organizations are advised to follow Cisco’s guidance, monitor for suppressed syslog IDs, and engage Cisco Technical Assistance Center if compromise is suspected. The campaign highlights the persistent targeting of network edge devices by advanced threat actors and the criticality of maintaining up-to-date security controls.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Cisco identified a new attack variant targeting vulnerable firewall devices, indicating adversaries had evolved their exploitation activity beyond the previously documented attacks. This represents a fresh operational development following Cisco's earlier September and November advisories.
Cisco later published a separate security advisory for a remote code execution vulnerability affecting Cisco Secure Firewall ASA Software and Secure Firewall FTD Software VPN web servers. This marks a new vulnerability disclosure beyond the September unauthorized access issue.
Cisco published incident-response and detection-guide resources describing continued attacks against Cisco firewalls and linked the activity to the threat actor behind ArcaneDoor. The accompanying guidance indicates active exploitation and provides detection-focused information for defenders.
Cisco published a security advisory for an unauthorized access vulnerability affecting Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software VPN web servers. Canadian Centre for Cyber Security alerts published the same day reference this disclosure and the affected CVEs.
7 references tracked. Mallory keeps watching after this page renders.
cybersecuritydive.com
Open sourcesec.cloudapps.cisco.com
Open sourcesec.cloudapps.cisco.com
Open sourcecyber.gc.ca
Open sourcesec.cloudapps.cisco.com
Open sourcecyber.gc.ca
Open sourcesec.cloudapps.cisco.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.