Threat actors exploited two critical zero-day vulnerabilities in Cisco firewalls, specifically CVE-2025-20362 and CVE-2025-20333, to bypass authentication and execute malicious code on affected appliances. The attacks resulted in the deployment of previously undocumented malware families, RayInitiator and LINE VIPER, which represent a significant evolution in both sophistication and evasion capabilities compared to earlier campaigns. The campaign has been attributed to a threat cluster known as ArcaneDoor, which is linked to the suspected China-based group UAT4356 (also tracked as Storm-1849). Security agencies, including the UK NCSC and U.S. CISA, issued warnings about the active exploitation of these vulnerabilities, emphasizing the urgency for organizations to patch affected Cisco Secure Firewall ASA and Secure FTD devices. The malware deployed in these attacks is capable of evading detection and maintaining persistence, posing a substantial risk to network security. Detection engineering teams responded by rapidly developing and updating detection rules across multiple platforms, including Elastic, YARA, Sigma, and KQL, to identify post-exploitation activity and suspicious child processes associated with the malware. The campaign also involved the use of advanced techniques to bypass security controls and escalate privileges within targeted environments. Cisco released security advisories and patches to address the vulnerabilities, and the flaws were added to the U.S. CISA Known Exploited Vulnerabilities catalog. The attacks targeted a range of organizations, with a focus on critical infrastructure and sectors with high-value assets. The rapid response from the security community included the sharing of indicators of compromise and technical analyses of the RayInitiator and LINE VIPER malware. The incident highlights the ongoing threat posed by sophisticated nation-state actors leveraging zero-day vulnerabilities in widely deployed network appliances. Organizations were urged to review their firewall configurations, apply available patches, and monitor for signs of compromise. The campaign underscores the importance of timely vulnerability management and the need for robust detection capabilities to counter evolving threats. Security researchers continue to analyze the malware families involved to better understand their capabilities and develop effective countermeasures. The incident serves as a reminder of the critical role that coordinated threat intelligence and rapid response play in defending against advanced persistent threats. The exploitation of these Cisco firewall vulnerabilities demonstrates the increasing complexity and impact of targeted attacks on enterprise infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
19 events from the most recent confirmed update back to the earliest known activity.
Authorities arrested two Dutch teenagers in connection with alleged Russian espionage activity. The case was cited as a notable law-enforcement development in the cyber and intelligence space.
A significant vulnerability affecting Supermicro BMC firmware was highlighted as a notable security issue. The flaw raised concerns over risks to server management infrastructure.
Akira ransomware operators were reported to have bypassed multi-factor authentication protections on SonicWall VPN appliances. The tactic enabled intrusions despite MFA being enabled.
Reports highlighted ransomware groups using stolen AWS access keys to compromise cloud environments. The activity showed a growing focus on cloud infrastructure as a ransomware intrusion vector.
A new LockBit 5.0 ransomware variant was reported, featuring improved evasion capabilities. The development signaled continued evolution of the LockBit ransomware ecosystem.
Researchers identified Olymp Loader as a new malware-as-a-service threat. Its emergence marked a new criminal service available for malware delivery operations.
Iran-aligned threat actor Nimbus Manticore was reported to have broadened its espionage operations into Western Europe. The campaign targeted critical infrastructure and used new malware variants.
Operation HAECHI VI resulted in the seizure of $439 million tied to global cybercrime groups. The action represented a major international law-enforcement disruption effort.
ENISA reported that recent airport disruptions were connected to ransomware activity. The assessment framed the incidents as part of the growing operational impact of cybercrime on transportation infrastructure.
Volvo North America was reported impacted by a breach connected to a ransomware attack on IT provider Miljödata. The incident illustrated downstream effects of third-party compromises.
A ransomware incident involving Union County, Ohio was reported to have affected 45,000 individuals. The event was listed among the week's significant breach and extortion cases.
Security reporting highlighted ongoing Brickstorm backdoor activity. The mention indicated continued use of the malware in intrusion operations.
Researchers reported a new variant of the XCSSET malware affecting macOS systems. The updated strain indicated ongoing development of the malware family.
A vulnerability in Libraesva Email Gateway was reported and attributed to exploitation by nation-state actors. The case highlighted continued targeting of email security infrastructure by advanced threat groups.
Separate from the firewall issues, Cisco IOS and IOS XE zero-day vulnerabilities were noted as being actively exploited. The reports underscored sustained attacker focus on Cisco network infrastructure.
The weekly reporting highlighted exploitation activity involving Fortra GoAnywhere MFT vulnerability CVE-2025-10035. The issue was presented as part of a broader pattern of attackers targeting enterprise software flaws.
CISA added multiple Cisco vulnerabilities and a Google Chromium issue to its Known Exploited Vulnerabilities catalog. The action reflected official recognition of active exploitation risk and the need for remediation.
Two Cisco firewall zero-day vulnerabilities, CVE-2025-20362 and CVE-2025-20333, were reported as actively exploited in the wild. The activity was attributed to the China-linked group UAT4356, also tracked as Storm-1849 and ArcaneDoor, which deployed RayInitiator and LINE VIPER malware.
Cloudflare reported blocking the largest distributed denial-of-service attack on record, which peaked at 22.2 Tbps. The attack was assessed as likely powered by the AISURU botnet.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcesecurityaffairs.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.