CISA and the UK's National Cyber Security Centre named FIRESTARTER on 24 April: a backdoor hidden in the startup code of Cisco firewalls that survives every security patch. One unnamed US government agency applied all the patches on schedule and was still infected six months later.
The only way to remove it is a full power-down and cold restart, turning every routine patch job into a physical maintenance event. For any organisation running Cisco firewalls, the patch record alone no longer confirms the device is clean.
