FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches

2026-04-24T19:24:13Zfa2e539653bd7bc02da1e644cc4f723b91b4e0ac11271c857a858767e63ad2fc
APTASAASP.NET CoreBitwarden CLICISACheckmarxCisco FirepowerFIRESTARTERGopherWhisperHarvesterKICSLMDeployNCSCSSRFTerrariumTropic TrooperUNC6692backdoorfake crypto walletsmalicious Docker imagesnpm wormphishingransomware/SystemBCsandbox escapesupply chain

What happened

The feed highlights multiple high-risk cyber incidents: a FIRESTARTER backdoor compromised a federal Cisco Firepower (ASA) device (CISA/NCSC disclosure) and reportedly survived prior security patches; a critical sandbox escape in Cohere's Terrarium (CVE-2026-5752, CVSS 9.3) allows host root code execution/container escape; Microsoft patched an ASP.NET Core privilege escalation (CVE-2026-40372, CVSS 9.1); LMDeploy SSRF (CVE-2026-33626, CVSS 7.5) was exploited within 13 hours of disclosure; and Apple fixed a notification retention issue (CVE-2026-28950). The feed also documents multiple active A

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
fa2e539653bd7bc02da1e644cc4f723b91b4e0ac11271c857a858767e63ad2fc
Enrichment time
2026-04-24T19:24:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.