Interestingly, although the Cisco blog says the USG approached them in May 2025, the first vuln - CVE-2025-20333 - was fixed just over a year ago (around September 2024 product updates).

Another angle to that - it suggests a whole lot of orgs don't patch Cisco ASA edge devices. Which we already know from the Akira ransomware incidents -- which were using 5 year old vulns.

0

If you have a fediverse account, you can quote this note from your own instance. Search https://cyberplace.social/users/GossiTheDog/statuses/115266287811083546 on your instance and quote it. (Note that quoting is not supported in Mastodon.)