The Containment Era is here. →Explore

Executive Summary

In mid-2024, an advanced nation-state threat group—tracked as UAT4356 (Talos) and Storm-1849 (Microsoft)—launched a widespread espionage campaign exploiting newly discovered zero-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) in Cisco Adaptive Security Appliance (ASA) firewalls. These attackers gained persistent, full-device control by chaining zero-days, disabling logging, evading defenses, and implanting custom malware on federal networks, achieving potential data exfiltration and establishing long-term persistence beyond standard remediation steps. The Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive mandating immediate federal agency response, including mandatory patching or device disconnection.

This attack underscores the evolving sophistication and urgency of supply chain and perimeter device threats. As zero-day exploitation targeting network infrastructure escalates and aligns with global power competition, organizations must prioritize detection, segmented defense, and rapid vulnerability management to safeguard high-value assets and comply with emerging federal cyber mandates.

Why This Matters Now

This campaign represents a critical inflection point as nation-state actors increasingly exploit zero-days in network infrastructure to gain covert, persistent access to sensitive environments. The rapid issuance of federal directives highlights urgent operational and regulatory risks to organizations still relying on unpatched or unsupported perimeter devices.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers chained CVE-2025-20333 and CVE-2025-20362 zero-day flaws in Cisco Adaptive Security Appliances to gain persistent, full device control.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Cloud Network Security Framework controls such as zero trust segmentation, east-west traffic inspection, inline intrusion prevention, egress policy enforcement, and multicloud visibility would have greatly restricted the attacker's ability to move laterally, hide C2 traffic, and exfiltrate sensitive data—limiting both the reach and persistence of this campaign.

Initial Compromise

Control: Cloud Firewall (ACF) + Inline IPS (Suricata)

Mitigation: Prevention or detection of exploit attempts targeting firewall interfaces.

Privilege Escalation

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Detection of privilege escalation and suspicious device modifications.

Lateral Movement

Control: Zero Trust Segmentation + East-West Traffic Security

Mitigation: Blocked or tightly limited unauthorized lateral movement between network zones.

Command & Control

Control: Threat Detection & Anomaly Response + Multicloud Visibility & Control

Mitigation: Anomalous communications and evasion attempts quickly detected and alerted.

Exfiltration

Control: Egress Security & Policy Enforcement + Encrypted Traffic (HPE)

Mitigation: Outbound data transfer policy violations blocked or alerted.

Impact (Mitigations)

Reduced operational impact and faster threat containment.

Impact at a Glance

Affected Business Functions

  • Network Security
  • Remote Access Services
  • Data Protection
Operational Disruption

Estimated downtime: 5 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential unauthorized access to sensitive data due to compromised firewall devices.

Recommended Actions

  • Urgently patch or disconnect vulnerable Cisco ASA firewall devices and deploy inline IPS/firewalls to block future exploit attempts.
  • Implement zero trust segmentation and microsegmentation to contain lateral movement from any single compromised device or service.
  • Enforce comprehensive egress policies and inspect encrypted outbound traffic to detect and prevent data exfiltration.
  • Deploy advanced threat anomaly detection and continuous monitoring to quickly identify C2 communications and unauthorized system changes.
  • Centralize multicloud traffic visibility and automate incident response workflows for rapid isolation and recovery of affected cloud and hybrid assets.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image