
- Attackers exploit two zero-days in Cisco ASA firewalls for remote access and persistence
- Campaign uses stealth tactics like log disabling and firmware tampering to evade detection
- Cisco urges upgrades to Secure Boot-enabled models and full resets of compromised devices
Cisco is warning customers of an ongoing campaign against companies using some of its services, having become aware of a “new attack variant” recently.