CISA issues emergency patching directive for Cisco devices on federal networks

<p>The Cybersecurity and Infrastructure Security Agency is ordering federal agencies to patch Cisco devices that have been exploited by an advanced hacker group, it said in a Thursday <a href=“ED 25-03: Identify and Mitigate Potential Compromise of Cisco Devices | CISA”>alert</a>.</p>

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

<p>The hacking activity targeting the devices &ldquo;is widespread and involves exploiting zero-day vulnerabilities to gain unauthenticated remote code execution&rdquo; on various Cisco Adaptive Security Appliances, CISA said. A &ldquo;zero-day&rdquo; refers to a software flaw that&rsquo;s being exploited but has not been previously discovered, giving developers zero days to fix it.</p>

<p>The activity has been linked to a hacking entity dubbed ArcaneDoor, Cisco said in its own <a href=“Cisco Event Response: Continued Attacks Against Cisco Firewalls”>blog post</a>. The group, also known as Storm-1849, has possible links to China, according to an <a href=“Analysis of ArcaneDoor Threat Infrastructure Suggests Potential Ties to Chinese-based Actor”>analysis</a> released last year by cyber threat intelligence firm Censys. The Censys analysis was released following previous ArcaneDoor hacking activity <a href=“Cisco Event Response: Attacks Against Cisco Firewall Platforms”>reported</a> early last year.</p>

<p>The software flaws allow hackers to gain control of devices without needing a password. Cyber intruders can also change how a given device&rsquo;s basic software works so they can stay hidden even after the targeted device restarts or updates.</p>

<p>Internet routers are frequently targeted by hackers because they bridge internal networks and the public web. These devices often feature remote management interfaces and contain unpatched software vulnerabilities. Those openings offer attackers a pathway to intercept traffic, pilfer credentials or penetrate further into systems.</p>

<p>Agencies must implement patching by the end of day Friday. By October 3, all agencies must also provide CISA an inventory of relevant products to show the fixes have been made. CISA has also provided <a href=“Supplemental Direction ED 25-03: Core Dump and Hunt Instructions | CISA”>threat hunting instructions</a> to agencies.</p>

<p>The group has been observed targeting organizations around the world but has recently refocused its efforts on entities in the United States, Sam Rubin, senior vice president for the Unit 42 threat intelligence arm at Palo Alto Networks, told <em>Nextgov/FCW</em>.</p>

<p>&ldquo;As we have seen before, now that patches are available, we can expect attacks to escalate as cybercriminal groups quickly figure out how to take advantage of these vulnerabilities,&rdquo; he added.</p>

<p>The directive is the second patching order issued by CISA in the second Trump administration. In August, an <a href=“https://www.nextgov.com/cybersecurity/2025/08/high-severity-microsoft-exchange-vulnerability-disclosed-heels-black-hat-talk/407276/”>emergency directive</a> was put out for Microsoft Exchange devices.</p>

Article Link: https://www.nextgov.com/cybersecurity/2025/09/cisa-issues-emergency-patching-directive-cisco-devices-federal-networks/408384/