FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches
2026-04-24T19:24:13Z•fa2e539653bd7bc02da1e644cc4f723b91b4e0ac11271c857a858767e63ad2fc
APTASAASP.NET CoreBitwarden CLICISACheckmarxCisco FirepowerFIRESTARTERGopherWhisperHarvesterKICSLMDeployNCSCSSRFTerrariumTropic TrooperUNC6692backdoorfake crypto walletsmalicious Docker imagesnpm wormphishingransomware/SystemBCsandbox escapesupply chain
What happened
The feed highlights multiple high-risk cyber incidents: a FIRESTARTER backdoor compromised a federal Cisco Firepower (ASA) device (CISA/NCSC disclosure) and reportedly survived prior security patches; a critical sandbox escape in Cohere's Terrarium (CVE-2026-5752, CVSS 9.3) allows host root code execution/container escape; Microsoft patched an ASP.NET Core privilege escalation (CVE-2026-40372, CVSS 9.1); LMDeploy SSRF (CVE-2026-33626, CVSS 7.5) was exploited within 13 hours of disclosure; and Apple fixed a notification retention issue (CVE-2026-28950). The feed also documents multiple active A
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- fa2e539653bd7bc02da1e644cc4f723b91b4e0ac11271c857a858767e63ad2fc
- Enrichment time
- 2026-04-24T19:24:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.