<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

CISA Issues Emergency Directive After Nearly Year-Long Cisco Zero-Day Attack Campaign

CISA issues emergency directive as Chinese-linked attackers exploit Cisco firewall vulnerabilities, urging federal agencies to act swiftly.
Content Team

The Cybersecurity and Infrastructure Security Agency issued an emergency directive Thursday after discovering attackers have been exploiting Cisco firewall vulnerabilities since at least November 2024. The attacks began with reconnaissance activity and escalated to memory modification on hundreds of federal government firewalls.

Cisco launched its investigation in May but waited four months to disclose the vulnerabilities and release patches. CISA's Chris Butera said the delay was necessary for proper investigation and patch development. Federal agencies must take immediate action by Friday's deadline.

While officials won't confirm attribution, outside researchers link the espionage campaign to Chinese state-sponsored groups. CISA warns attackers may accelerate or shift tactics now that the vulnerabilities are public.

Source: CyberScoop

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo