(Oct. 3, 2025) – The Cybersecurity and Infrastructure Security Agency publicized
ED 25-03: Identify and Mitigate Potential Compromise of Cisco Devices, warning of an ongoing exploitation campaign targeting Cisco Adaptive Security Appliances. CISA warns, "The campaign is widespread and involves exploiting zero-day vulnerabilities to gain unauthenticated remote execution on ASAs, as well as manipulating read-only memory to persist through reboot system upgrade." They go on to say it is a "significant" threat and give required actions to mitigate the concern. Please review the
CISA Alert with your IT security team to conduct a proper threat analysis and identify any necessary IT risk management measures.
--
Larry Van Der Wege