CRITICAL: FIRESTARTER Backdoor Squats on Federal Cisco Firewall, Survives Every Patch
A US federal civilian executive branch agency had its Cisco Firepower firewall compromised by China-linked UAT4356 in September 2025, with the attackers maintaining access through March 2026 via FIRESTARTER, a backdoor that survives firmware updates and reboots. CISA Analysis Report AR26-113A confirms exploitation of CVE-2025-20333 (CVSS 9.9) and CVE-2025-20362 in Cisco ASA and FTD software.