Sept. 12, 2023, 12:17 a.m. | Satnam Narang

Cyber Exposure Alerts www.tenable.com

Ransomware groups including LockBit and Akira are reportedly exploiting a zero-day vulnerability in Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) appliances with VPN functionality enabled.


Background


On September 6, Cisco published an advisory for a zero-day vulnerability in the software for its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) appliances that has been reportedly exploited in the wild:










CVEDescriptionCVSSv3VPR*
CVE-2023-20269Cisco ASA and FTD Software Remote Access VPN Unauthorized Access Vulnerability5.03.2 …

advisory akira asa cisco cve defense exploited exploiting firepower lockbit ransomware ransomware groups security september software threat threat defense vpn vulnerability zero-day zero-day vulnerability

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

Cyber Security Culture – Communication and Content Specialist

@ H&M Group | Stockholm, Sweden

Container Hardening, Sr. (Remote | Top Secret)

@ Rackner | San Antonio, TX

GRC and Information Security Analyst

@ Intertek | United States

Information Security Officer

@ Sopra Steria | Bristol, United Kingdom

Casual Area Security Officer South Down Area

@ TSS | County Down, United Kingdom