April 25, 2024, 7:15 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Introduction


In coordination with multiple government agencies, Cisco announced yesterday the discovery of a new backdoor targeting their Adaptive Security Appliances (ASA). The threat actor is new, tracked by Cisco as UAT4356 and STORM-1849 by Microsoft, and leveraged two zero-day vulnerabilities in the campaign dubbed ArcaneDoor. The campaign started in November 2023, predating the recent attacks against Ivanti Connect Secure and Palo Alto Networks PAN-OS but unlike those campaigns, the zero days involved were not used for initial access (according …

actor adaptive security arcanedoor asa backdoor campaign cisco coordination defending devices discovery eclypsium government government agencies introduction microsoft network network devices november november 2023 security storm targeting threat threat actor uat4356 vulnerabilities zero-day zero-day vulnerabilities

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Security Operations Manager-West Coast

@ The Walt Disney Company | USA - CA - 2500 Broadway Street

Vulnerability Analyst - Remote (WFH)

@ Cognitive Medical Systems | Phoenix, AZ, US | Oak Ridge, TN, US | Austin, TX, US | Oregon, US | Austin, TX, US

Senior Mainframe Security Administrator

@ Danske Bank | Copenhagen V, Denmark