米国 CISA 連邦機関にCisco Firewall 系機器に関する既知脆弱性と、それを悪用して「パッチ後も残存する」攻撃(FIRESTARTER 等)への即時対応を連邦機関に義務付けています...(2026.04.23)
こんにちは、丸山満彦です。
背景から...
CISA と英国 NCSC が共同で分析し、FIRESTARTERと名付けられたマルウェアによる APT が Ciscoの Cisco Firepower / Secure Firewallを狙い、永続化のためにファームウェアやプロセスに寄生するバックドアを使用していると評価しています...
この侵害は、 CVE‑2025‑20333 と CVE‑2025‑20362 の悪用によるものであると考えられるが、すでに侵入されてしまっている場合、パッチ適用だけでは既存の侵入を除去できない事例が観測ており、緊急の対応が必要と判断したようです。
そこで、Emergency Directive 25‑03(ED 25‑03)を改定し、あらたに、V1: ED 25-03を公表するに至ったようです。
パッチ適用だけでは侵害されている状態を解決できないため、具体的には各機関に対して次の3つの新たな指示を追加しています。
(指示3の概要:運用中の該当デバイスを特定し、メモリ/コアダンプを取得してCISAへ提出すること(4月24日まで)。提出したコアダンプはCISA側でハント/解析される。検出結果が「Compromise Detected」の場合は即時隔離(ネットワーク切断)・追加フォレンジック・CISAへの報告
指示4の概要:該当機種の全数インベントリとコアダンプ提出に加え、検出が陰性でもベンダーの最小修正版への更新(パッチ適用)と物理的なハードリセット(電源断等)を実施することを義務付ける
JPCERT/CCは2026.04.27に注意喚起をだしていますが、日本のNCOは対応しているのかしら...
● CISA
・2026.04.23 V1: ED 25-03: Identify and Mitigate Potential Compromise of Cisco Devices
| V1: ED 25-03: Identify and Mitigate Potential Compromise of Cisco Devices | V1: ED 25-03: Cisco デバイスの潜在的な侵害の識別と緩和 |
| This page contains a web-friendly version of the Cybersecurity and Infrastructure Security Agency’s V1: Emergency Directive 25-03: Identify and Mitigate Potential Compromise of Cisco Devices. | このページには、サイバーセキュリティ・インフラセキュリティ庁(CISA)の「V1: 緊急指令 25-03: シスコ製デバイスの潜在的な侵害の識別と緩和」のウェブ閲覧用バージョンが掲載されている。 |
| Section 3553(h) of title 44, U.S. Code, authorizes the Secretary of Homeland Security, in response to a known or reasonably suspected information security threat, vulnerability, or incident that represents a substantial threat to the information security of an agency, to “issue an emergency directive to the head of an agency to take any lawful action with respect to the operation of the information system, including such systems used or operated by another entity on behalf of an agency, that collects, processes, stores, transmits, disseminates, or otherwise maintains agency information, for the purpose of protecting the information system from, or mitigating, an information security threat.” 44 U.S.C. § 3553(h)(1)–(2). Section 2205(3) of the Homeland Security Act of 2002, as amended, delegates this authority to the Director of the Cybersecurity and Infrastructure Security Agency. 6 U.S.C. § 655(3). Federal agencies are required to comply with these directives. 44 U.S.C. § 3554 (a)(1)(B)(v). These directives do not apply to statutorily defined “national security systems” nor to systems operated by the Department of War or the Intelligence Community. 44 U.S.C. § 3553(d), (e)(2), (e)(3), (h)(1)(B). | 合衆国法典第44編第3553条(h)は、既知または合理的に疑われる情報セキュリティ上の脅威、 脆弱性、または政府機関の情報セキュリティに重大な脅威をもたらすインシデントに対し、「政府機関の情報を収集、処理、保存、送信、配布、またはその他の方法で管理する情報システム(当該機関に代わって他の事業体が使用または運用するシステムを含む)の運用に関して、当該情報システムを情報セキュリティ上の脅威から防御し、またはその脅威を緩和する目的で、あらゆる合法的な措置を講じるよう、政府機関の長に対して緊急指令を発出する」権限を付与している。44 U.S.C. § 3553(h)(1)–(2)。改正後の2002年国土安全保障法第2205条(3)は、この権限をサイバーセキュリティ・インフラセキュリティ庁長官に委任している。6 U.S.C. § 655(3)。連邦機関は、これらの指令を遵守しなければならない。44 U.S.C. § 3554 (a)(1)(B)(v)。これらの指令は、法令で定義された「国家安全保障システム」や、国防総省またはインテリジェンス・コミュニティが運用するシステムには適用されない。44 U.S.C. § 3553(d)、(e)(2)、(e)(3)、(h)(1)(B)。 |
| See Emergency Directive 25-03 for the Original Directive issued on September 25, 2025. | 2025年9月25日に発出された当初の指令については、緊急指令25-03を参照のこと。 |
| Background | 背景 |
| CISA is issuing V1 to supersede the required actions in Emergency Directive (ED) 25-03: Identify and Mitigate Potential Compromise of Cisco Devices. V1 provides updated and new required actions, an additional reporting requirement, and applies to any agency running affected products. V1 expands on the original ED 25-03 requirements with required actions three, four, and six. | CISAは、緊急指令(ED)25-03「Ciscoデバイスの潜在的な侵害の識別と緩和」における必須措置に代わるものとして、V1を発行する。V1は、更新されたおよび新たな必須措置、追加の報告要件を規定しており、影響を受ける製品を運用するあらゆる機関に適用される。V1は、必須措置3、4、および6を追加することで、元のED 25-03の要件を拡充するものである。 |
| The revision to ED 25-03 is in response to updated cyber threat intelligence concerning threat actors retaining persistence and continued unauthorized access to Cisco Firepower and Secure Firewall products with Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software. CISA analysis determines that applying the Cisco-provided security updates required by the original issuance of ED 25-03 does not necessarily remove an existing threat actor from the compromised device. Agencies who have completed the security update requirements are still susceptible to persistence and therefore must complete the updated required actions within this V1 ED. | ED 25-03の改訂は、Adaptive Security Appliance(ASA)またはFirepower Threat Defense(FTD)ソフトウェアを搭載したCisco FirepowerおよびSecure Firewall製品に対し、脅威アクターが持続性を維持し、不正アクセスを継続しているという最新のサイバー脅威インテリジェンスに対応するものである。CISAの分析によれば、ED 25-03の当初の発行で要求されたシスコ提供のセキュリティ更新プログラムを適用しても、侵害されたデバイスから既存の脅威アクターを必ずしも排除できるわけではない。セキュリティ更新要件を完了した機関であっても、依然として持続的な侵入のリスクにさらされているため、本V1版EDで更新された必須措置を完了しなければならない。 |
| CISA analysis continues to assess the following CVEs as an unacceptable risk to Federal Civilian and Executive Branch (FCEB) information systems: | CISAの分析では、以下のCVEを連邦文民行政機関(FCEB)の情報システムに対する容認できないリスクとして引き続き評価している: |
| CVE-2025-20333 – allows for remote code execution | CVE-2025-20333 – リモートコード実行を可能にする |
| CVE-2025-20362 – allows for privilege escalation | CVE-2025-20362 – 権限昇格を可能にする |
| In conjunction with this ED update, CISA released the FIRESTARTER Backdoor Malware Analysis Report with further details about the threat actor activity, malware functionality, detection methods, and mitigations. | 本EDの更新に伴い、CISAは「FIRESTARTERバックドアマルウェア分析レポート」を公開した。これには、脅威アクターの活動、マルウェアの機能、検知方法、および緩和策に関する詳細が記載されている。 |
| Scope | 適用範囲 |
| This Directive applies to agency assets in any federal information system, including an information system used or operated by another entity on behalf of an agency, that collects, processes, stores, transmits, disseminates, or otherwise maintains agency information. This Directive does not apply to contractors, but FCEB agencies may need to modify contracts to comply with the required actions of this Directive. | 本指令は、連邦情報システム内の機関資産に適用される。これには、機関に代わって他の事業体が使用または運用する情報システムを含み、当該システムが機関情報を収集、処理、保存、送信、配布、またはその他の方法で維持する場合が対象となる。本指令は請負業者には適用されないが、FCEB機関は本指令で要求される措置に準拠するため、契約内容を修正する必要がある場合がある。 |
| For federal information systems hosted in third-party environments, each agency is responsible for maintaining an inventory of its information systems hosted in those environments (FedRAMP Authorized or otherwise) and obtaining status updates pertaining to, and to ensure compliance with, this Directive. Agencies should work through the FedRAMP program office to obtain these updates for FedRAMP-authorized cloud service providers and work directly with service providers that are not FedRAMP-authorized. | サードパーティ環境にホストされている連邦情報システムについては、各機関は、当該環境(FedRAMP認可の有無を問わず)にホストされている自機関の情報システムの目録を維持し、本指令に関連する状況の更新情報を取得し、本指令への準拠を確保する責任を負う。各機関は、FedRAMP認可クラウドプロバイダに関する更新情報を取得するためにFedRAMPプログラムオフィスを通じて対応し、FedRAMP認可を受けていないプロバイダとは直接連携すべきである。 |
| All other provisions specified in this Directive remain applicable. | 本指令に規定されるその他のすべての条項は、引き続き適用される。 |
| Note: Entities outside of the FCEB that wish to perform the actions outlined in this section may follow the same CISA instructions to collect and upload a core dump file to CISA for analysis. | 注:FCEB以外の事業体で、本節に概説された措置を実施したい場合は、CISAの指示に従い、コアダンプファイルを収集してCISAにアップロードし、分析を受けることができる。 |
| Required Actions | 必要な措置 |
| This ED requires agencies to take the following actions: | 本緊急通知(ED)では、各機関に対し以下の措置を講じるよう求めている: |
| For all public-facing Cisco ASA devices: | すべての対外向けCisco ASAデバイスについて: |
| 1. Immediately identify all Cisco ASA platforms (ASA hardware, ASA-Service Module [ASA-SM], ASA Virtual [ASAv]). | 1. すべてのCisco ASAプラットフォーム(ASAハードウェア、ASA-Service Module [ASA-SM]、ASA Virtual [ASAv])を直ちに識別すること。 |
| 2. For all public-facing Cisco ASA hardware appliances identified in required action 1, follow CISA’s step-by-step Core Dump and Hunt Instructions Parts 1-3 and submit core dump(s) via the Malware Next Gen portal by 11:59PM EST on September 26, 2025. | 2. 必須措置1で識別されたすべての対外向けCisco ASAハードウェアアプライアンスについて、CISAの「Core Dump and Hunt Instructions Parts 1-3」の手順に従い、2025年9月26日午後11時59分(EST)までにMalware Next Genポータルを通じてコアダンプを提出すること。 |
| a. If the result is “Compromise Detected,” agencies must immediately disconnect the device from their network (but do not power off), report the incident to CISA, and work with CISA on incident response and eviction actions. | a. 結果が「侵害が検知された」の場合、各機関は直ちに当該デバイスをネットワークから切り離し(ただし電源は切らないこと)、CISAにインシデントを報告し、CISAと連携してインシデント対応および排除措置を実施しなければならない。 |
| b. If the result is “No Compromise Detected,”: | b. 結果が「侵害は検知されなかった」の場合: |
| i. For ASA hardware models with an end-of-support date on or before September 30, 2025, take the following action: | i. サポート終了日が2025年9月30日以前のASAハードウェアモデルについては、以下の措置を講じること: |
| i. Permanently disconnect these devices on or before September 30, 2025, as these legacy platforms/releases cannot meet current vendor support and update requirements. | i. これらのレガシープラットフォーム/リリースは、現在のベンダーのサポートおよび更新要件を満たせないため、2025年9月30日までに当該デバイスを恒久的に切断すること。 |
| ii. Agencies that cannot meet this requirement must apply the latest Cisco-provided updates for software by 11:59PM EST on September 26, 2025, report to CISA mission critical needs preventing such action and plans for eventual decommissioning of the device as directed by requirement 5. | ii. この要件を満たせない機関は、2025年9月26日午後11時59分(EST)までに、Ciscoが提供する最新のソフトウェア更新を適用し、そのような措置を妨げるミッションクリティカルな要件および要件5の指示に従ったデバイスの最終的な廃止計画についてCISAに報告しなければならない。 |
| ii. For ASA hardware models with an end-of-support date of August 31, 2026: Download and apply the latest Cisco-provided updates for software by 11:59PM EST on Sept. 26, 2025, and apply all subsequent updates via Cisco’s download portal within 48 hours of release. | ii. サポート終了日が2026年8月31日のASAハードウェアモデルについては: 2025年9月26日午後11時59分(EST)までに、Ciscoが提供する最新のソフトウェア更新プログラムをダウンロードして適用し、その後リリースされるすべての更新プログラムについては、リリースから48時間以内にCiscoのダウンロードポータル経由で適用すること。 |
| iii. [New Requirement] For any newly identified ASA hardware models, follow the requirements outlined in BOD 26-02: Mitigating Risk From End-of-Support Edge Devices. | iii. [新規要件] 新たに識別されたASAハードウェアモデルについては、BOD 26-02「サポート終了エッジデバイスからのリスク緩和」に概説された要件に従うこと。 |
| c. For all ASAv instances identified in required action 1, download and apply the latest Cisco-provided updates for software by 11:59PM EST on September 26, 2025, and apply all subsequent updates via Cisco’s download portal within 48 hours of release. | c. 必須措置1で識別されたすべてのASAvインスタンスについて、2025年9月26日午後11時59分(EST)までにCiscoが提供する最新のソフトウェア更新プログラムをダウンロードして適用し、その後のすべての更新プログラムはリリースから48時間以内にCiscoのダウンロードポータル経由で適用すること。 |
| For public-facing Cisco Firepower and Secure Firewall devices: | 外部に公開されているCisco FirepowerおよびSecure Firewallデバイスについて: |
| 3. [New Requirement] Immediately identify all Firepower 1000, 2100, 4100, 9300 series and Secure Firewall 200, 1200, 3100, 4200, and 6100 series devices. | 3. [新規要件] Firepower 1000、2100、4100、9300シリーズおよびSecure Firewall 200、1200、3100、4200、6100シリーズのすべてのデバイスを直ちに識別すること。 |
| 4. [New Requirement] For devices identified in required action 3, follow CISA’s step-by-step Core Dump and Hunt Instructions and submit core dump(s) via the Malware Next Gen portal by 11:59PM EST on April 24, 2026. | 4. [新規要件] 必須措置3で特定されたデバイスについては、CISAの「コアダンプおよびハント手順」に従い、2026年4月24日午後11時59分(EST)までにMalware Next Genポータル経由でコアダンプを提出すること。 |
| a. If the result is “Compromise Detected,” agencies must: keep the device powered on, immediately disconnect the device from their network, and report the incident to CISA, and work with CISA on incident response, forensics, and eviction actions. | a. 結果が「侵害が検知された」場合、各機関は次の措置を講じなければならない:デバイスの電源を入れたままにし、直ちにネットワークから切り離し、CISAにインシデントを報告するとともに、インシデント対応、フォレンジック調査、および排除措置についてCISAと協力する。 |
| b. If the result is “No Compromise Detected,” agencies must: | b. 結果が「侵害は検知されなかった」の場合、各機関は以下を行う必要がある: |
| i. Download and apply the latest Cisco-provided updates for software by 11:59PM EST on April 24, 2026. This includes: | i. 2026年4月24日午後11時59分(EST)までに、Ciscoが提供する最新のソフトウェア更新プログラムをダウンロードし、適用すること。これには以下が含まれる: |
| i. The software updates to address CVE-2025-20333 and CVE-2025-20362, if not already patched; and, | i. CVE-2025-20333およびCVE-2025-20362に対処するソフトウェア更新プログラム(まだ適用されていない場合);および、 |
| ii. The recently released patch created for this specific persistence issue (links provided by device type in CISA’s step-by-step Core Dump and Hunt Instructions). | ii. この特定の持続性問題のために作成された、最近リリースされたパッチ(CISAの段階的な「Core Dump and Hunt Instructions」において、デバイス種別ごとにリンクが提供されている)。 |
| ii. Perform a hard reset of the device(s) by physically unplugging the device’s power supply, as a reboot is not sufficient to expunge the malware, no later than April 30, 2026. | ii. 再起動だけではマルウェアを完全に除去できないため、2026年4月30日までに、デバイスの電源ケーブルを物理的に抜いてハードリセットを実行すること。 |
| i. Follow CISA’s step-by-step Core Dump and Hunt Instructions, which includes further guidance if a hard reset of the device cannot occur immediately after patch implementation. | i. CISAの「Core Dump and Hunt Instructions」の手順に従うこと。これには、パッチ適用直後にデバイスのハードリセットが実行できない場合の追加ガイダンスが含まれている。 |
| iii. Apply all subsequent updates via Cisco’s download portal within 48 hours of release. | iii. リリースから48時間以内に、Ciscoのダウンロードポータル経由で、その後のすべての更新を適用すること。 |
| All agencies must: | すべての機関は以下を行う必要がある: |
| 5. By 11:59 PM EST on October 2, 2025, report to CISA (using the provided template) a complete inventory of all instances of products within scope on agency networks, including details on actions taken and results. | 5. 2025年10月2日午後11時59分(EST)までに、対象範囲内の製品が機関ネットワーク上に存在するすべてのインスタンスの完全なインベントリを、実施した措置および結果の詳細を含め、CISAに(提供されたテンプレートを使用して)報告すること。 |
| 6. [New Requirement] By 11:59 PM EST on May 1, 2026, report to CISA (using the provided template) a complete inventory of all Firepower 1000, 2100, 4100, 9300 series and Secure Firewall 200, 1200, 3100, 4200, and 6100 series devices including details on actions taken and results. | 6. [新規要件] 2026年5月1日午後11時59分(EST)までに、CISAに対し(提供されたテンプレートを使用して)、Firepower 1000、2100、4100、9300シリーズおよびSecure Firewall 200、1200、 3100、4200、および6100シリーズの全デバイスの完全なインベントリを(実施した措置および結果の詳細を含め)CISAに報告すること。 |
| CISA Actions: | CISAの措置: |
| 1. CISA will provide agencies with a template that will be used for reporting agency actions following the issuance of this Directive. | 1. CISAは、本指令の発出後に各機関が実施した措置を報告するために使用するテンプレートを各機関に提供する。 |
| 2. CISA will continue efforts to identify instances and potential compromises associated with this threat activity, provide partner notifications, and will issue additional guidance and direction, as appropriate. | 2. CISAは、本脅威活動に関連する事例および潜在的な侵害の識別、パートナーへの通知の提供を継続し、必要に応じて追加のガイダンスおよび指示を発出する。 |
| 3. can provide technical assistance to agencies who are without internal capabilities sufficient to comply with this Directive. | 3. CISAは、本指令を遵守するための十分な内部能力を有しない機関に対し、技術的支援を提供することができる。 |
| 4. By February 1, 2026, CISA will provide a report to the Secretary of Homeland Security, the National Cyber Director, the Director of the Office of Management and Budget, and the Federal Chief Information Security Officer identifying cross-agency status and outstanding issues. | 4. 2026年2月1日までに、CISAは、省庁横断的な状況および未解決の問題を識別した報告書を、国土安全保障長官、国家サイバー長官室、行政管理予算局局長、および連邦最高情報セキュリティ責任者に提出する。 |
| 5. [New Action] By August 1, 2026, CISA will provide an updated report to the Secretary of Homeland Security, the National Cyber Director, the Director of the Office of Management and Budget, and the Federal Chief Information Security Officer identifying cross-agency status and outstanding issues. | 5. [新規措置] 2026年8月1日までに、CISAは、省庁横断的な状況および未解決の問題を識別した更新報告書を、国土安全保障長官、国家サイバー長官室、行政管理予算局局長、および連邦最高情報セキュリティ責任者に提出する。 |
| Additional Information | 追加情報 |
| Visit [web] or contact the following for: | 以下の情報については、[web] を参照するか、下記まで連絡すること: |
| ・General information, assistance, and reporting – [mail] | ・一般的な情報、支援、および報告 – [mail] |
| ・Reporting indications of compromise – [mail] | ・侵害の兆候の報告 – [mail] |
| For more information on the threat actor activity, malware functionality, detection methods, and mitigations please see CISA’s FIRESTARTER Backdoor Malware Analysis Report [web] | 脅威アクターの活動、マルウェアの機能、検知方法、および緩和に関する詳細については、CISAの「FIRESTARTERバックドアマルウェア分析レポート」を参照のこと [web] |
| For further instructions on how to perform a “core dump” please visit [web] | 「コアダンプ」の実行方法に関する詳細な手順については、[web] を参照のこと |
| For eviction guidance please visit [web] | 駆除の手順については、 [web] を参照のこと |
・2026.04.23 FIRESTARTER Backdoor
| FIRESTARTER Backdoor | FIRESTARTER バックドア |
| Malware Name | マルウェア名 |
| FIRESTARTER | FIRESTARTER |
| Original Publication | 初公表 |
| 23-Apr-26 | 2026年4月23日 |
| Executive Summary | エグゼクティブサマリー |
| The Cybersecurity and Infrastructure Security Agency (CISA) analyzed a sample of FIRESTARTER malware obtained from a forensic investigation. CISA and the United Kingdom National Cyber Security Centre (NCSC) assess advanced persistent threat (APT) actors are using FIRESTARTER malware for persistence, specifically targeting publicly accessible Cisco Firepower and Secure Firewall devices running Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software. CISA and the NCSC are releasing this Malware Analysis Report to share analysis of one FIRESTARTER malware sample operating as a backdoor and urge organizations to take key response actions. | 米国サイバーセキュリティ・インフラセキュリティ庁(CISA)は、フォレンジック調査から入手したFIRESTARTERマルウェアのサンプルを分析した。CISAおよび英国国家サイバーセキュリティセンター(NCSC)は、高度持続的脅威(APT)アクターが、特にAdaptive Security Appliance(ASA)またはFirepower Threat Defense(FTD)ソフトウェアを実行している、一般にアクセス可能なCisco FirepowerおよびSecure Firewallデバイスを標的として、持続性を確保するためにFIRESTARTERマルウェアを使用していると評価している。CISAとNCSCは、バックドアとして動作する1つのFIRESTARTERマルウェアサンプルの分析結果を共有し、組織に対し重要な対応措置を講じるよう促すため、本マルウェア分析レポートを公開する。 |
| Note: The release of this Malware Analysis Report aligns with CISA’s update to V1: Emergency Directive (ED) 25-03: Identify and Mitigate Potential Compromise of Cisco Devices and Supplemental Direction ED 25-03: Core Dump and Hunt Instructions. The malware outlined in this report is relevant for both Cisco Firepower and Secure Firewall devices; however, CISA has only observed a successful implant of the malware in the wild on a Cisco Firepower device running ASA software. | 注:本マルウェア分析レポートの公開は、CISAによる「緊急指令(ED)25-03:Ciscoデバイスの潜在的な侵害の識別と緩和」のバージョン1への更新、および補足指針「ED 25-03: コアダンプおよびハンティング手順」の更新と連動している。本報告書で概説するマルウェアは、Cisco FirepowerおよびSecure Firewallデバイスの双方に関連するが、CISAが実環境でマルウェアの埋め込みに成功した事例を確認したのは、ASAソフトウェアを実行しているCisco Firepowerデバイス上のみである。 |
| Key Actions for U.S. FCEB Agencies | 米国FCEB機関向けの主要な対応措置 |
| Collect and submit core dumps to CISA’s Malware Next Generation platform. | コアダンプを収集し、CISAのMalware Next Generationプラットフォームに提出すること。 |
| Immediately report the submission via CISA’s 24/7 Operations Center; CISA will reach out with next steps. | CISAの24時間365日体制のオペレーションセンターを通じて、提出を直ちに報告すること。CISAから次の手順について連絡がある。 |
| Take no additional action until CISA provides further guidance. | CISAからさらなるガイダンスが提供されるまで、追加の措置を講じないこと。 |
| Key Actions for All Other Organizations | その他のすべての組織に対する主要な措置 |
| Use the YARA rules to detect FIRESTARTER malware against either a disk image or core dump of a device. | YARAルールを使用して、デバイスのディスクイメージまたはコアダンプに対してFIRESTARTERマルウェアを検知すること。 |
| Report any findings to CISA or the NCSC. | 発見事項はすべてCISAまたはNCSCに報告すること。 |
| If compromise is confirmed, conduct incident response actions. | 侵害が確認された場合は、インシデント対応措置を講じること。 |
| Intended Audience | 対象読者 |
| Organizations: Government and critical infrastructure organizations (Note: While this publication supplements CISA ED 25-03, the guidance is applicable to all organizations, including U.K. organizations.) | 組織:政府および重要インフラ組織(注:本公開資料はCISA ED 25-03を補足するものであるが、このガイダンスは英国の組織を含むすべての組織に適用される。 |
| Sector: Government Services and Facilities Sector | セクター:政府サービスおよび施設セクター |
| Roles: Digital forensics analysts, incident responders, vulnerability analysts, system administrators | 役割:デジタルフォレンジックアナリスト、インシデント対応担当者、脆弱性アナリスト、システム管理者 |
参考...
最初の版
・2025.09.25 ED 25-03: Identify and Mitigate Potential Compromise of Cisco Devices
● NCSC-NZ
・2026.04.24 FIRESTARTER Malware affecting Cisco ASA and FTD
● JPCERT/CC
・2026.04.27 Cisco ASAおよびFTDにおける複数の脆弱性(CVE-2025-20333、CVE-2025-20362)に関する注意喚起
● CISCO - Talos
・2026.04.23 UAT-4356's Targeting of Cisco Firepower Devices

















Recent Comments