
Two stories landed this week that, taken together, should make you uncomfortable about your edge and your toolchain at the same time. UAT-4356 is still actively exploiting Cisco Firepower devices — not with zero-days, but with n-day vulnerabilities that have patches attached to them. And the Bitwarden CLI compromise shows that a supply chain attack can walk right past your ipban rules, your firewall, and your endpoint tools because the malicious payload is already dressed in trusted clothes. If your threat model doesn’t account for both of these surfaces simultaneously, you’ve got a gap.
What UAT-4356 Is Actually Doing
Cisco Talos confirmed that UAT-4356 is exploiting CVE-2025-20333 and CVE-2025-20362 against Cisco Firepower’s FXOS — not theoretical exploitation, active targeting of vulnerable devices sitting on real network perimeters right now. These are known vulnerabilities with available patches, which makes this particularly grim. The attacker doesn’t need a novel technique when defenders haven’t finished patching the last round of fixes.
What makes UAT-4356 worth paying close attention to is the persistence angle. Cisco’s security blog makes clear this group isn’t running smash-and-grab operations — it’s digging in. That means a compromised Firepower device isn’t just a beachhead; it’s a long-term surveillance post and potentially a pivot point into your segmented environments. The device you trust to enforce your network perimeter becomes the attacker’s inside man.
The brute-force protection and IP banning controls you’ve built around your user-facing attack surface don’t do much when the compromised device is the perimeter. That’s the uncomfortable truth here. Automated threat protection at the edge assumes the edge itself is trustworthy.

Supply Chain Attacks Don’t Knock First
The Bitwarden CLI compromise is a different threat category entirely, but it shares the same frustrating characteristic: by the time you know something is wrong, the damage is already done. JFrog and Socket identified that @bitwarden/[email protected] contained malicious code embedded in bw1.js, part of the Checkmarx supply chain campaign that’s been running for a while now. This is the same campaign family that’s been poisoning npm packages systematically.
Think about what the Bitwarden CLI is used for. Developers use it in CI/CD pipelines to pull secrets. Sysadmins run it in scripts that touch credential stores. It’s a tool you’d explicitly not flag as suspicious because you installed it intentionally. That’s the whole point. A Chinese APT simultaneously abusing Microsoft Outlook, Slack, Discord, and file.io for command-and-control against Mongolian targets — reported by Dark Reading this same week — shows the same logic applied to C2 infrastructure: use what’s trusted, blend in, persist quietly.
Brute-force protection and traditional firewall rules at the perimeter block the attacker who’s rattling doorknobs from the outside. They do nothing for the attacker who arrives inside a package your build system just pulled and installed with elevated privileges.
What the Checkmarx Campaign Tells You About Dependency Risk
This isn’t the first time the Checkmarx supply chain campaign has targeted developer tooling, and it won’t be the last. The pattern is deliberate: target packages that have privileged access at build time or runtime, embed code that’s not immediately obvious in a diff review, and rely on developers trusting packages they’ve used before. Version 2026.4.0 wasn’t a brand-new package from an unknown author — it was an update to something already in production for thousands of teams.
- Pin your dependency versions and audit changelogs before updating security-adjacent tools
- Run package integrity checks — compare published checksums against what you actually downloaded
- Restrict CI/CD pipeline permissions so a compromised tool can’t reach credential stores directly
- Monitor outbound connections from build environments — supply chain payloads need to phone home
- Treat developer tooling with the same scrutiny you’d give a new vendor binary dropped on a production server
Fix the Foundations Before Adding More Tools
The irony of this week’s news isn’t subtle. UAT-4356 is exploiting n-day vulnerabilities — patches exist, deployment didn’t happen fast enough. The Bitwarden CLI compromise happened in a tool explicitly designed to help teams manage credentials securely. Security tooling itself becoming an attack vector while known CVEs stay unpatched on perimeter devices is a pretty succinct summary of where a lot of organizations are right now.
Here’s the operational reality. Your cyber security stack — IPBan Pro, EDR, SIEM, whatever combination you’re running — can only operate on the trust assumptions you build underneath it. If the firewall enforcing your threat protection policy is running vulnerable FXOS firmware, the policy is fiction. If the secrets management tool in your pipeline is exfiltrating credentials, your access controls are fiction.
Brute force protection and automated IP-layer controls like ipbanpro remain genuinely useful — they compress the attack surface on exposed services and cut attacker dwell time on credential-stuffing campaigns. But they’re part of a stack, not a substitute for one. The patch backlog on your network devices and the lack of supply chain integrity checks in your build pipeline are the actual gaps UAT-4356 and the Checkmarx campaign are walking through.
Patch FXOS. Audit your npm dependencies, especially anything that touches secrets. Lock down CI/CD pipeline egress. None of this is exotic advice, but that’s the point — the attackers landing headlines this week aren’t using exotic techniques. They’re using the gaps you already know about and haven’t closed yet.
Sources
- UAT-4356’s Targeting of Cisco Firepower Devices — Cisco Talos
- Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign — The Hacker News
- Chinese APT Abuses Multiple Cloud Tools to Spy on Mongolia — Dark Reading
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
