CISA reports persistent FIRESTARTER backdoor on Cisco ASA device in federal network
2026-04-25T14:51:51Z•b6c00869a2a864b3f03383a749369f9bd5b73a70ac698447931996e9ca8b1289
BitwardenCISACVE-2026-28950CVE-2026-33825CVE-2026-41651CheckmarxChina-linked actorsCisco ASAFIRESTARTERKnown Exploited VulnerabilityMicrosoft DefenderNCSCPack2TheRootPackageKitRAMP leak","GoGra","Microsoft Graph API","Linux malware"Signal phishingbackdoorconsumer IoT botnetdata breachiOSlocal privilege escalationnpm compromisepersistencepolitical targetingsupply chain
What happened
Feed of security news (Apr 23–25, 2026) reporting multiple high-impact incidents: CISA disclosed a persistent FIRESTARTER backdoor on a Cisco Firepower ASA in a U.S. federal civilian network that survived patches; a 12‑year Pack2TheRoot local privilege escalation in PackageKit (CVE-2026-41651, CVSS 8.8) lets unprivileged Linux users gain root; a Checkmarx supply-chain compromise injected malicious code into the Bitwarden CLI npm package (@bitwarden/cli 2026.4.0); Microsoft Defender vulnerability CVE-2026-33825 was added to CISA’s KEV; an iOS Notification Services flaw (CVE-2026-28950) that let
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- b6c00869a2a864b3f03383a749369f9bd5b73a70ac698447931996e9ca8b1289
- Enrichment time
- 2026-04-25T14:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.