GKRootWire
AI xAI Publishes Details on Its Grok Web CrawlerAI Why 'Human-in-the-Loop' Might Have It BackwardsDev Tools Modular Ships Mojo 1.0, Marking the Language's Production DebutAI OpenAI's Head of Ethics Exits Less Than a Year Into the JobAI Researchers Show How to Extract Hidden Reasoning from Proprietary LLM APIsAI Nvidia Debuts Nemotron 3.5 Lightning and NeMo Switchyard for Local AI WorkflowsAI xAI Publishes Details on Its Grok Web CrawlerAI Why 'Human-in-the-Loop' Might Have It BackwardsDev Tools Modular Ships Mojo 1.0, Marking the Language's Production DebutAI OpenAI's Head of Ethics Exits Less Than a Year Into the JobAI Researchers Show How to Extract Hidden Reasoning from Proprietary LLM APIsAI Nvidia Debuts Nemotron 3.5 Lightning and NeMo Switchyard for Local AI Workflows
Security

Cisco Confirms Attackers Are Actively Crashing ASA and FTD VPN Devices

A high-severity denial-of-service bug in Cisco's Secure Firewall software is being exploited in the wild to knock devices offline remotely.

Cisco has issued a fresh security advisory confirming that a serious flaw in its Secure Firewall ASA and Firepower Threat Defense (FTD) software is under active attack. The vulnerability allows an unauthenticated remote attacker to send crafted traffic to a device's VPN components and force it to crash, cutting off connectivity until it reboots or is manually restored.

Because ASA and FTD appliances often sit at the edge of corporate networks handling remote-access and site-to-site VPN traffic, a successful attack can disrupt business operations for every user relying on that connection. Cisco has not detailed exactly who is behind the exploitation attempts or how widespread they are, but the company's decision to flag real-world exploitation alongside the fix signals that this isn't just a theoretical risk.

Cisco is urging administrators running affected ASA and FTD versions to apply the available software updates immediately. As with previous ASA-related incidents, these edge devices have repeatedly been a favorite target for both opportunistic attackers and more sophisticated groups looking for a foothold into enterprise networks.

Why it matters: VPN gateways are high-value targets precisely because they're exposed to the internet and central to remote access, so a denial-of-service bug here can be more disruptive than on internal systems. Cisco ASA/FTD devices have a history of being targeted by well-resourced threat actors even for non-DoS bugs, so any confirmed active exploitation should push admins to patch immediately rather than wait for a routine maintenance window.

Sources: BleepingComputer