Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On

Vivo X Fold 5 Design Teased; Confirmed to Feature 8T LTPO Panels, Meet IP5X and IPX9+ Certifications

9 June 2025

Konami Press Start Showcase Will Highlight Metal Gear Solid Delta: Snake Eater, Silent Hill F, And More This Week

9 June 2025

A Researcher Figured Out How to Reveal Any Phone Number Linked to a Google Account

9 June 2025
Facebook X (Twitter) Instagram
Just In
  • Vivo X Fold 5 Design Teased; Confirmed to Feature 8T LTPO Panels, Meet IP5X and IPX9+ Certifications
  • Konami Press Start Showcase Will Highlight Metal Gear Solid Delta: Snake Eater, Silent Hill F, And More This Week
  • A Researcher Figured Out How to Reveal Any Phone Number Linked to a Google Account
  • Live-Action Legend Of Zelda Movie Delayed By A Few Weeks
  • Review: Typhur Dome 2
  • Realme Narzo 80 Lite 5G India Launch Teased; to Be Priced Under Rs 10,000 and Pack a 6,000mAh Battery
  • Aphelion Is A Sci-Fi Game Game About Crashing On An Alien Planet From Don’t Nod
  • Apple WWDC Live Blog: All the Updates, as They Happen
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » ‘ArcaneDoor’ Cyberspies Hacked Cisco Firewalls to Access Government Networks
News

‘ArcaneDoor’ Cyberspies Hacked Cisco Firewalls to Access Government Networks

News RoomBy News Room24 April 20243 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email

Network security appliances like firewalls are meant to keep hackers out. Instead, digital intruders are increasingly targeting them as the weak link that lets them pillage the very systems those devices are meant to protect. In the case of one hacking campaign over recent months, Cisco is now revealing that its firewalls served as beachheads for sophisticated hackers penetrating multiple government networks around the world.

On Wednesday, Cisco warned that its so-called Adaptive Security Appliances—devices that integrate a firewall and VPN with other security features—had been targeted by state-sponsored spies who exploited two zero-day vulnerabilities in the networking giant’s gear to compromise government targets globally in a hacking campaign it’s calling ArcaneDoor.

The hackers behind the intrusions, which Cisco’s security division Talos is calling UAT4356 and which Microsoft researchers who contributed to the investigation have named STORM-1849, couldn’t be clearly tied to any previous intrusion incidents the companies had tracked. Based on the group’s espionage focus and sophistication, however, Cisco says the hacking appeared to be state-sponsored.

“This actor utilized bespoke tooling that demonstrated a clear focus on espionage and an in-depth knowledge of the devices that they targeted, hallmarks of a sophisticated state-sponsored actor,” a blog post from Cisco’s Talos researchers reads.

Cisco declined to say which country it believed to be responsible for the intrusions, but sources familiar with the investigation tell WIRED the campaign appears to be aligned with China’s state interests.

Cisco says the hacking campaign began as early as November 2023, with the majority of intrusions taking place between December and early January of this year, when it learned of the first victim. “The investigation that followed identified additional victims, all of which involved government networks globally,” the company’s report reads.

In those intrusions, the hackers exploited two newly discovered vulnerabilities in Cisco’s ASA products. One, which it’s calling Line Dancer, let the hackers run their own malicious code in the memory of the network appliances, allowing them to issue commands to the devices, including the ability to spy on network traffic and steal data. A second vulnerability, which Cisco is calling Line Runner, would allow the hackers’ malware to maintain its access to the target devices even when they were rebooted or updated.

Cisco has released software updates to patch both vulnerabilities, and advises that customers implement them immediately, along with other recommendations for detecting whether they’ve been targeted.

The ArcaneDoor hacking campaign represents just the latest series of intrusions to target network perimeter applications sometimes referred to as “edge” devices like email servers, firewalls, and VPNs—often devices intended to provide security—whose vulnerabilities allowed hackers to obtain a staging point inside a victim’s network. Cisco’s Talos researchers warn of that broader trend in their report, referring to highly sensitive networks that they’ve seen targeted via edge devices in recent years. “Gaining a foothold on these devices allows an actor to directly pivot into an organization, reroute or modify traffic and monitor network communications,” they write. “In the past two years, we have seen a dramatic and sustained increase in the targeting of these devices in areas such as telecommunications providers and energy sector organizations—critical infrastructure entities that are likely strategic targets of interest for many foreign governments.”

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleHMD Pulse Pro, Pulse and Pulse+ With Unisoc T606 Chip, Gen 1 Repairability Launched: Price, Specifications
Next Article Atalanta vs Fiorentina live stream: Can you watch for free?

Related Articles

News

A Researcher Figured Out How to Reveal Any Phone Number Linked to a Google Account

9 June 2025
News

Review: Typhur Dome 2

9 June 2025
News

Apple WWDC Live Blog: All the Updates, as They Happen

9 June 2025
News

It’s Time to Kill Siri

9 June 2025
News

I Joined Every Class Action Lawsuit I Could Find, and So Can You

9 June 2025
News

How to Advocate for Trans Rights in Your Community

8 June 2025
Demo
Top Articles

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 202493 Views

5 laptops to buy instead of the M4 MacBook Pro

17 November 202466 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
Phones

Realme Narzo 80 Lite 5G India Launch Teased; to Be Priced Under Rs 10,000 and Pack a 6,000mAh Battery

News Room9 June 2025
Gaming

Aphelion Is A Sci-Fi Game Game About Crashing On An Alien Planet From Don’t Nod

News Room9 June 2025
News

Apple WWDC Live Blog: All the Updates, as They Happen

News Room9 June 2025
Most Popular

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025123 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 202493 Views
Our Picks

Live-Action Legend Of Zelda Movie Delayed By A Few Weeks

9 June 2025

Review: Typhur Dome 2

9 June 2025

Realme Narzo 80 Lite 5G India Launch Teased; to Be Priced Under Rs 10,000 and Pack a 6,000mAh Battery

9 June 2025

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.