CISA: Implementation Guidance for Emergency Directive on Cisco ASA and Firepower Device Vulnerabilities


CISA has released Emergency Cisco Directive 25-03 Implementation Guidance to assist federal agencies in addressing critical vulnerabilities in Cisco Adaptive Security Appliances (ASA) and Firepower devices.

Emergency Directive 25-03: Identify and Mitigate Potential Compromise of Cisco Devices, issued on Sept. 25, identified known vulnerabilities CVE-2025-20333 and CVE-2025-20362, and mandated immediate action to mitigate risks. Threat actors continue to target these devices, posing significant risk to all organizations. The implementation guidance provides information on the minimum software versions that address these vulnerabilities and direct federal agencies to conduct corrective patching measures on devices that are not compliant with these requirements.

Read more…
Source: U.S. Cybersecurity and Infrastructure Security Agency


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Millions of UK airport customer details accessed in major cyberattack

    August 27, 2026

    A cyber security breach targeting three major UK airports has led to the personal data of around 8.7 million customers being accessed, operator Manchester Airport Group (MAG) has confirmed. The group, which oversees Manchester Airport, London Stansted and East Midlands Airport, assured the public that “at no point has passenger safety or aviation security been compromised”, adding that no payment or banking details ...

  • China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems

    August 26, 2026

    The Federal Bureau of Investigation, National Security Agency, and Cyber National Mission Force are releasing this joint cybersecurity advisory to alert organizations concerning China-linked cyber threat actors, who use the acronyms QTFY, QT, and QTCYBER for themselves and their tools and have developed malicious distributed platforms to compromise the networks of US and foreign organizations. ...

  • Medical device maker Boston Scientific says a cyberattack is causing a ‘global disruption’ to its operations

    August 26, 2026

    A cyberattack on U.S. medical device maker Boston Scientific is causing an ongoing “global disruption” to its operations, according to a federal regulatory filing on Wednesday. This is the latest health tech giant to face a cyberattack in recent weeks. The Massachusetts-based company, which makes medically implanted devices like pacemakers and defibrillators, confirmed in a filing with the ...

  • ShinyHunters and ReliaQuest trade blows over claimed breach

    August 24, 2026

    ShinyHunters has claimed another cybersecurity scalp, but ReliaQuest says the crew’s social engineering attack only got as far as one employee identity before its defenses slammed the door. The ransomware baddies listed US-based infosec biz ReliaQuest on its leak site on August 23, claiming the corporation as its latest victim. The listing, seen by The Register, links to ...

  • Experts warn 2,000 hacked WordPress sites were secretly running a global crime ring

    August 22, 2026

    Check Point Research has unearthed a global cybercrime ring that relied on a network of WordPress websites. The investigation into an operation dubbed “StopAndProtect” found a network of 5,000 infected computers around the globe, and 2,000 WordPress domains. WordPress currently provides content management for around 43% of websites worldwide, making it the most significant CMS available. ...

  • Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants

    August 21, 2026

    Private equity giant Apollo Global Management has confirmed a data breach in which hackers stole reams of personal information from the company’s cloud systems. The breach comes a month after security researchers sounded the alarm on a new hacking campaign targeting financial and private equity giants. The financial giant confirmed the incident in a letter filed with California’s ...