Skip to main content

NCSC and partners issue advice to help network defenders mitigate targeting of CISCO firewall platforms

Joint advisory and malware analysis reports published to help mitigate malicious activity targeting certain Cisco devices.

The National Cyber Security Centre – a part of GCHQ – has shared new advice today (Wednesday) to help network defenders mitigate malicious activity targeting certain Cisco devices used globally.

Cisco has published a blog post detailing how a threat actor has been using sophisticated techniques to target devices running Adaptive Security Appliance and Firepower Threat Defense software.

The NCSC recommends following vendor best practice in the mitigation of this activity, which includes applying security updates to address vulnerabilities. More advice about addressing the vulnerabilities can be found in a separate alert.

To assist with detection of the activity and mitigation, the NCSC has also issued a joint advisory with international partners and published two reports which share detailed analysis of malware, dubbed Line Dancer and Line Runner, related to the malicious activity.

Network defenders are strongly encouraged to act upon the technical information and recommendations in these products to harden their defences.
The joint advisory, issued by the NCSC, the Australian Cyber Security Centre (ACSC) and the Canadian Centre for Cyber Security (CCCS), can be read on the CCCS website.  
 

Published

News type

Alert