In April 2026, CISA disclosed that a US federal agency had been breached through vulnerabilities in Cisco Adaptive Security Appliance and Firepower devices, CVE-2025-20333 and CVE-2025-20362.
The uncomfortable part of the timeline is not the initial compromise. It is that the attackers deployed a backdoor named FIRESTARTER before 25 September 2025, and retained access through March 2026 without needing the original vulnerabilities again. Roughly six months, across a patch cycle the agency had completed.
CISA's follow-up directives were unusually specific: confirm malware scans by Friday, inventory Firepower devices by 1 May, and do not unplug anything unless told to.
What actually happened
| Date | Event |
|---|---|
| Before 25 September 2025 | FIRESTARTER backdoor deployed on the appliance |
| September 2025 | Vulnerabilities patched |
| Through March 2026 | Access retained via the backdoor |
| April 2026 | CISA discloses, issues follow-up required actions |
Additional tradecraft included Line Viper malware creating illegitimate VPN sessions, and the use of inactive federal accounts. Both are notable because they produce activity that looks like ordinary remote work.
The gap: patching is a fix for the entrance, not for the guest
The agency did what it was supposed to do. It patched. And it stayed compromised for another six months, because a patch is a statement about how somebody may get in, not about who is already inside.
This is why time-to-patch is a less complete metric than it appears. What matters is the window between a vulnerability becoming reachable and it becoming unreachable, because that window is when persistence gets established. Once a backdoor is on the appliance, closing the vulnerability changes nothing about it.
Patching is a race, and the prize for winning is that nothing happened. The prize for losing is measured in months, not in the hours by which you missed.
There is a second point specific to edge appliances. A compromised ASA is not a compromised server behind the perimeter. It is the perimeter, with a privileged view of traffic and a trusted position in the network. The illegitimate VPN sessions in this incident were possible because the attacker controlled the device that decides what a VPN session is.
For a federal agency there is a compliance dimension as well. The follow-up directive asked for evidence: scan confirmations, device inventories, reporting to the National Cyber Director. Answering "we patched" was no longer sufficient, because the incident had demonstrated that patching and being clean are different claims.
What would have had to be true
The exploitation of an ASA vulnerability requires the appliance to answer the attacker. So does the operation of a backdoor on it, in the other direction, and so does the establishment of an illegitimate VPN session.
If the appliance had accepted connections only from networks where the agency's own attested devices were operating, the vulnerable window would not have been a window at all for anybody outside that set. The patch would still have been necessary. It would have been applied to a device that no stranger had been able to reach in the interim.
Where Veribound would have fitted
Veribound does not patch, does not sit in the path, and does not replace the appliance or the VPN. It informs the edge that is already deployed.
Agents attest that devices are still trusted. The scoring engine turns those attestations into per-device decisions. A trusted origin is the network that device is connecting from, in practice its public address, while the device behind it is still trusted. Those origins reach the customer's own equipment through a least-privilege adapter and land in an address group their existing policy already acts on.
Applied here:
- The vulnerable appliance is not reachable by a stranger, so the window between disclosure and patch is not a window for persistence.
- Inactive accounts stop being useful, because an account is only half of what is needed and the other half is an origin you trust.
- The evidence question gets easier, because "which origins could reach this device, and when" becomes a recorded answer rather than a reconstruction.
What it would not have done, and this is the important limit for this particular incident: it would not have removed a backdoor already installed. Once FIRESTARTER was on the appliance, nothing at the network edge undoes that. What earlier reachability control changes is whether the attacker gets the opportunity to install it, and the six months that followed are the cost of losing that opportunity by a matter of hours.
Source: CISA: US agency breached through Cisco vulnerability, FIRESTARTER backdoor allowed access through March, The Record, 23 April 2026.