CISA reports persistent FIRESTARTER backdoor on Cisco ASA device in federal network

2026-04-25T14:51:51Zb6c00869a2a864b3f03383a749369f9bd5b73a70ac698447931996e9ca8b1289
BitwardenCISACVE-2026-28950CVE-2026-33825CVE-2026-41651CheckmarxChina-linked actorsCisco ASAFIRESTARTERKnown Exploited VulnerabilityMicrosoft DefenderNCSCPack2TheRootPackageKitRAMP leak","GoGra","Microsoft Graph API","Linux malware"Signal phishingbackdoorconsumer IoT botnetdata breachiOSlocal privilege escalationnpm compromisepersistencepolitical targetingsupply chain

What happened

Feed of security news (Apr 23–25, 2026) reporting multiple high-impact incidents: CISA disclosed a persistent FIRESTARTER backdoor on a Cisco Firepower ASA in a U.S. federal civilian network that survived patches; a 12‑year Pack2TheRoot local privilege escalation in PackageKit (CVE-2026-41651, CVSS 8.8) lets unprivileged Linux users gain root; a Checkmarx supply-chain compromise injected malicious code into the Bitwarden CLI npm package (@bitwarden/cli 2026.4.0); Microsoft Defender vulnerability CVE-2026-33825 was added to CISA’s KEV; an iOS Notification Services flaw (CVE-2026-28950) that let

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
b6c00869a2a864b3f03383a749369f9bd5b73a70ac698447931996e9ca8b1289
Enrichment time
2026-04-25T14:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.