State-Backed Espionage Campaign Exploits Cisco Firewalls via Zero-Day Vulnerabilities
DEFENSE
A state-backed espionage campaign associated with ArcaneDoor is exploiting two zero-day vulnerabilities in Cisco's Adaptive Security Appliance and Firepower Threat Defense devices, enabling attackers to gain covert access and capture sensitive information. Cisco, CISA, and other security agencies have issued urgent warnings, as the vulnerabilities allow for arbitrary code execution and unauthenticated access to restricted URLs. With no patches available yet, experts recommend restricting access and enhancing intrusion detection measures to mitigate risks to national security and critical infrastructure.

Dec 22, 2025, 11:37 PM