The Cybersecurity and Infrastructure Security Agency (CISA) has disclosed that a Cisco Firepower device utilized by a federal civilian agency was breached in September 2025 due to malware known as FIRESTARTER. This malware, identified by both CISA and the U.K.'s National Cyber Security Centre (NCSC), is believed to function as a backdoor, allowing unauthorized remote access to the affected system. The incident underscores the ongoing challenges of securing critical infrastructure against sophisticated cyber threats. Despite efforts to implement security patches, the persistence of such malware highlights the need for enhanced protective measures and vigilance within federal cybersecurity protocols. Agencies are urged to assess their systems for vulnerabilities and ensure that robust security practices are in place to mitigate the risk of similar attacks in the future.
FIRESTARTER Malware Compromises Federal Cisco Firepower Device
A federal agency's Cisco Firepower device was infiltrated by FIRESTARTER malware, raising concerns about security vulnerabilities.
