ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Exploits

Cisco ASA and FTD Vulnerability CVE-2020-3259 Exploited by Akira Ransomware Group

Christi by Christi
February 18, 2024 - Updated on February 19, 2024
in Exploits, Malware
Reading Time: 2 mins read
Akira Ransomware Exploits Cisco Flaw CVE-2020-3259: Urgent Security Alert Akira group targets Cisco ASA and FTD devices, posing a grave threat.
Share on FacebookShare on Twitter

This week, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a critical alert regarding a security flaw affecting Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices. The vulnerability tracked as CVE-2020-3259, has been added to CISA’s Known Exploited Vulnerabilities catalog.

The Details

  • Vulnerability: CVE-2020-3259
  • Severity: High (CVSS score: 7.5)
  • Description: An information disclosure issue resides in the web services interface of ASA and FTD.
  • Fix: Cisco addressed the flaw in May 2020.

Ransomware Campaigns

The vulnerability has been exploited in ransomware campaigns, but CISA has not disclosed the specific ransomware groups involved.

Akira Ransomware Group

In January, cybersecurity firm Truesec reported that the Akira ransomware group actively exploited CVE-2020-3259. Truesec’s CSIRT team discovered forensic evidence pointing to ongoing attacks targeting Cisco ASA and FTD appliances.

How It Works

An attacker can trigger the vulnerability to extract sensitive data from the memory of affected devices, including usernames and passwords.

Entry Point

Truesec’s analysis of eight incidents revealed that the flaw in Cisco Anyconnect SSL VPN served as the entry point for at least six compromised devices.

You might also like

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

“When the vulnerability was made public in 2020, no known public exploits were available. However, there are now indications that this vulnerability might be actively exploited,” continues the report.

Akira Ransomware Group Strikes: A Menace to Organizations Worldwide

The notorious Akira ransomware group has been wreaking havoc since March 2023, leaving a trail of compromised organizations across various sectors, including education, finance, and real estate. Their audacious claims of infiltrating multiple networks have sent shockwaves through the cybersecurity community.

Like their ransomware counterparts, the Akira gang has devised a potent Linux encryptor specifically tailored to target VMware ESXi servers. Their sophisticated techniques have made them a formidable adversary, exploiting vulnerabilities with precision.

Known Vulnerability: CVE-2020-3259

The vulnerability in question, CVE-2020-3259, resides in the web services interface of Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices. Although Cisco addressed this flaw in May 2020, the Akira group relentlessly exploits it.

Government Response

Binding Operational Directive (BOD) 22-01, aptly named “Reducing the Significant Risk of Known Exploited Vulnerabilities,” mandates that federal agencies take swift action. They must address identified vulnerabilities by the specified due date to fortify their networks against malicious attacks stemming from the flaws listed in the catalog.

Private Sector Alert

Security experts emphasize that private organizations should also scrutinize the catalog and promptly rectify any vulnerabilities within their infrastructure. Vigilance is paramount to thwarting cyber threats.

The clock is ticking: CISA has ordered federal agencies to patch the CVE-2020-3259 vulnerability by March 7, 2024. The stakes are high, and the battle against cyber adversaries intensifies.

Tags: Akira
Previous Post

OpenAI and Microsoft Reveals Cyberattacks By State-Sponsored Hackers Using AI Models

Next Post

ESET Addresses High-Severity Vulnerability CVE-2024-0353 in Windows Products

Christi

Christi

Christi began her InfoSec carrier at the Illinois Institute of Technology where she received her Bachelor of Science degree in Applied Cybersecurity and Information Technology. Her passions include learning about new threats, data breaches, running, and playing with her dog, Pablo.

Recommended For You

Photo of the CISCO logo and text saying "You have been hacked!"

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

March 6, 2026
Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

December 25, 2024

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.